Agent skill

Call Graph Analysis

by openshift-eng in openshift-eng/ai-helpers

Perform definitive call graph analysis to prove whether vulnerable functions are reachable from program entry points

Apache-2.0Auto-check: notesDevelopment

Install Call Graph Analysis

skills CLI
$ npx skills add openshift-eng/ai-helpers --skill call-graph-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openshift-eng/ai-helpers call-graph-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/compliance/skills/call-graph-analysis .claude/skills/call-graph-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
call-graph-analysis
GitHub stars
120
Token cost
~3.1k tokens
SKILL.md length
930 words
Files
1
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0

At a glance

Perform definitive call graph analysis to prove whether vulnerable functions are reachable from program entry points

  • Works in 7 steps: Verify Tools Are Available → Identify Main Packages and Build Call… → Check if Vulnerable Function Exists in… → …
  • Tasks that involve Codebase onboarding
  • SKILL.md covers When to Use This Skill, Prerequisites, Critical Rules and Timeout and Algorithm Convention, plus 5 more sections
  • Calls go, brew and apt-get

What it does

Call Graph Analysis is an agent skill from openshift-eng/ai-helpers. Perform definitive call graph analysis to prove whether vulnerable functions are reachable from program entry points

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Codebase onboarding. It works with Go. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Codebase onboarding

Example prompts

  • “/call-graph-analysis”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Verify Tools Are Available
  2. Identify Main Packages and Build Call Graph
  3. Check if Vulnerable Function Exists in Graph
  4. Find Execution Paths from Entry Points
  5. Generate DOT Graph for Visualization
  6. Parse and Format Call Chain
  7. Assess Risk Level

What it can do on your machine

Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • brew
    • apt-get

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Call Graph Analysis loads about 3.1k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 930 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:27
    on): `brew install graphviz` (macOS) or `sudo apt-get install graphviz` (Linux)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 930 words, ~3,094 tokens.

Download SKILL.mdSave it as .claude/skills/call-graph-analysis/SKILL.md (or your agent's skills folder).
name
call-graph-analysis
description
Perform definitive call graph analysis to prove whether vulnerable functions are reachable from program entry points

Call Graph Reachability Analysis

Provides highest-confidence vulnerability assessment by proving whether vulnerable functions can actually be reached during program execution.

When to Use This Skill

Use this skill when:

  • You need definitive proof that a vulnerable function is or isn't reachable
  • Medium/high confidence analysis shows possible vulnerability but needs confirmation
  • Generating evidence for security compliance or audit requirements
  • govulncheck is unavailable or didn't find the CVE
  • You need visual proof of execution paths for stakeholders

Prerequisites

Required Tools
  • callgraph: go install golang.org/x/tools/cmd/callgraph@latest
  • digraph: go install golang.org/x/tools/cmd/digraph@latest
  • Go workspace with go.mod file
Optional Tools
  • graphviz (for visualization): brew install graphviz (macOS) or sudo apt-get install graphviz (Linux)
  • sfdp or dot command (part of graphviz)
Input Requirements
  • CVE vulnerable function signature (e.g., <package-path>.<function-name>)
  • Package path from CVE analysis
  • Workspace path to analyze
  • Algorithm preference (optional, default: vta) — passed via --algo from parent command
  • CVE_ID — used to construct the output directory
  • OUT_DIR (optional, default: ${AI_HELPERS_WORKSPACE:-.}/.work/compliance/analyze-cve/${CVE_ID}) — where artifacts are written; same workspace base as Phase 0.7's REPOS_BASE

Critical Rules

  1. Always use timeout -k 10 — plain timeout sends SIGTERM but callgraph can ignore it when stuck in SSA construction or type resolution. -k 10 sends SIGKILL after 10s grace, guaranteeing termination.
  2. Never run callgraph on ./... for repos with more than ~50 packages. Target specific main packages (e.g. ./cmd/controller, ./main.go) and let the tool pull in transitive deps automatically.
  3. Always redirect output to a file (> file 2>&1). Never pipe callgraph output to another command — if the reader closes, callgraph can hang on SIGPIPE.

Timeout and Algorithm Convention

  • Use the algorithm specified by the user via --algo (default: vta).
  • All callgraph invocations use timeout -k 10 300 (5 minutes + 10s force-kill) to prevent hanging.
  • Scope: target the specific main package (e.g. ./cmd/controller), not ./.... The callgraph tool resolves transitive deps automatically — there is no need to include the entire repo.
  • If the chosen algorithm times out: fall back to the next faster algorithm (vta → rta → cha), then narrow scope further to a single binary entry point.

Implementation Steps

Step 1: Verify Tools Are Available
bash
# Check for callgraph
which callgraph || echo "callgraph not found - install with: go install golang.org/x/tools/cmd/callgraph@latest"

# Check for digraph
which digraph || echo "digraph not found - install with: go install golang.org/x/tools/cmd/digraph@latest"

# Optional: Check for graphviz
which sfdp || echo "graphviz not found - visual graphs won't be generated (optional)"

Decision Point:

  • IF callgraph OR digraph missing → Exit this skill, return to parent analysis
  • IF both present → Continue
Step 2: Identify Main Packages and Build Call Graph

First, discover the main packages that serve as entry points:

bash
# Find main packages
MAIN_PKGS=$(find . -name "main.go" -exec dirname {} \; | sort -u)
echo "Main packages: ${MAIN_PKGS}"

Pick the most relevant main package for the analysis (typically the controller or server binary, not CLI tools or test helpers). If unsure, prefer the package that imports the vulnerable package's parent tree.

bash
# Select exactly one TARGET_PKG before running callgraph
if [ -z "${TARGET_PKG:-}" ]; then
  TARGET_PKG=$(printf '%s\n' ${MAIN_PKGS} | grep -E '(^|/)(cmd/)?(controller|manager|operator|server|main)(/|$)' | head -1)
  [ -z "${TARGET_PKG}" ] && TARGET_PKG=$(printf '%s\n' ${MAIN_PKGS} | head -1)
fi

# Normalize to a package path callgraph accepts (./cmd/foo or .)
case "${TARGET_PKG}" in
  .|./) TARGET_PKG="." ;;
  *) TARGET_PKG="./${TARGET_PKG#./}" ;;
esac

if [ -z "${TARGET_PKG}" ] || [ "${TARGET_PKG}" = "./" ]; then
  echo "ERROR: No main package found for call graph analysis"
  exit 1
fi
echo "Selected TARGET_PKG=${TARGET_PKG}"
bash
ALGO="${USER_ALGO:-vta}"
OUT_DIR="${OUT_DIR:-${AI_HELPERS_WORKSPACE:-.}/.work/compliance/analyze-cve/${CVE_ID}}"
mkdir -p "${OUT_DIR}"

# TARGET_PKG is the specific main package (e.g. ./cmd/controller, .)
# NEVER use ./... — it causes VTA to explode on large repos
echo "Building call graph: algo=${ALGO}, target=${TARGET_PKG}"
timeout -k 10 300 env CGO_ENABLED=0 callgraph -algo "${ALGO}" -format=digraph "${TARGET_PKG}" > "${OUT_DIR}/callgraph.txt" 2>&1
CG_EXIT=$?
echo "callgraph exit: ${CG_EXIT}, lines: $(wc -l < "${OUT_DIR}/callgraph.txt")"

Progressive fallback if the command times out or fails:

bash
# Fallback 1: faster algorithm
if [ $CG_EXIT -eq 124 ] || [ $CG_EXIT -eq 137 ]; then
  echo "⚠ ${ALGO} timed out — falling back to rta"
  timeout -k 10 300 env CGO_ENABLED=0 callgraph -algo rta -format=digraph "${TARGET_PKG}" > "${OUT_DIR}/callgraph.txt" 2>&1
  CG_EXIT=$?
fi

# Fallback 2: fastest algorithm
if [ $CG_EXIT -eq 124 ] || [ $CG_EXIT -eq 137 ]; then
  echo "⚠ rta timed out — falling back to cha"
  timeout -k 10 300 env CGO_ENABLED=0 callgraph -algo cha -format=digraph "${TARGET_PKG}" > "${OUT_DIR}/callgraph.txt" 2>&1
  CG_EXIT=$?
fi

if [ $CG_EXIT -eq 124 ] || [ $CG_EXIT -eq 137 ]; then
  echo "✗ All algorithms timed out — call graph analysis skipped"
fi

Error Handling:

  • IF build fails (compilation errors) → Note in report that call graph cannot be built
  • IF command times out → Fallback chain: vta → rta → cha, all on the same target package
  • IF all algorithms time out → Skip call graph, assign NEEDS_REVIEW
  • IF successful → Continue to Step 3

Output: ${OUT_DIR}/callgraph.txt containing the call graph rooted at the target binary

Step 3: Check if Vulnerable Function Exists in Graph

Extract the vulnerable function signature from CVE details.

bash
# Search for exact function in the cached call graph
VULN_FUNC="<package-path>.<vulnerable-function>"
cat "${OUT_DIR}/callgraph.txt" | digraph nodes | grep "${VULN_FUNC}$"

Decision Point:

  • IF function found in this TARGET_PKG graph → Continue to Step 4
  • IF function NOT found in this graph → Try the next candidate from MAIN_PKGS (different TARGET_PKG) before concluding
  • IF every examined main package shows no path → Return NEEDS_REVIEW (or MEDIUM if other evidence exists) — do not assign LOW RISK from a single unexamined or inconclusive graph
Show full SKILL.md (379 more words)Show less
Step 4: Find Execution Paths from Entry Points

Search for paths from main entry points to the vulnerable function.

bash
# Find path from main() to vulnerable function using cached call graph
ENTRY_POINT="command-line-arguments.main"
VULN_FUNC="<package-path>.<vulnerable-function>"

cat "${OUT_DIR}/callgraph.txt" | \
  digraph somepath "${ENTRY_POINT}" "${VULN_FUNC}"

Alternative Entry Points to Check:

  • command-line-arguments.main (main program)
  • Test entry points: *_test.go test functions
  • Init functions: *.init
  • HTTP handlers if it's a web service

Interpretation:

  • IF path found → Vulnerable function IS reachable → HIGH RISK
  • IF no path found → Check alternative entry points
  • IF still no path → Function may be in unreachable code → MEDIUM RISK

Output: Text representation of call chain or empty result

Step 5: Generate DOT Graph for Visualization

If path exists, generate visual representation:

bash
# Generate DOT format from cached call graph
cat "${OUT_DIR}/callgraph.txt" | \
  digraph somepath "${ENTRY_POINT}" "${VULN_FUNC}" | \
  digraph to dot > "${OUT_DIR}/callgraph.dot"

# Convert to SVG (if graphviz available)
if which sfdp > /dev/null; then
  sfdp -Tsvg -o"${OUT_DIR}/callgraph.svg" -Goverlap=scale "${OUT_DIR}/callgraph.dot"
  echo "Visual graph saved to: ${OUT_DIR}/callgraph.svg"
else
  echo "Graphviz not available - DOT file saved to: ${OUT_DIR}/callgraph.dot"
fi

Output Files:

  • ${OUT_DIR}/callgraph.dot - DOT notation of call path
  • ${OUT_DIR}/callgraph.svg - Visual graph (if graphviz available)
Step 6: Parse and Format Call Chain

Extract human-readable call chain from digraph output:

bash
# Get call chain as text from cached call graph
cat "${OUT_DIR}/callgraph.txt" | \
  digraph somepath "${ENTRY_POINT}" "${VULN_FUNC}" | \
  digraph to dot | \
  grep " -> " | \
  sed 's/"//g' | \
  sed 's/;//g'

Example Output:

text
command-line-arguments.main -> <package-path>.Handler
<package-path>.Handler -> <package-path>.ProcessFunction
<package-path>.ProcessFunction -> <vulnerable-package>.<vulnerable-function>

Format for Report:

text
Execution Path Found:
main → Handler → ProcessFunction → <vulnerable-function> (VULNERABLE)
Step 7: Assess Risk Level

HIGH RISK:

  • Reachable path from main() to vulnerable function
  • Action: Proceed to remediation

MEDIUM RISK:

  • Function in graph but no direct path from main()
  • Action: Recommend manual review + remediation

LOW RISK:

  • Function not found in call graph
  • Action: Recommend manual review to confirm

Return Value

Return structured result to parent analysis:

json
{
  "method": "call-graph-reachability",
  "algorithm": "vta",
  "vulnerable_function": "<package-path>.<vulnerable-function>",
  "found_in_graph": true,
  "reachable_from_main": true,
  "call_chain": "main → Handler → ProcessFunction → <vulnerable-function>",
  "risk_level": "HIGH",
  "evidence": {
    "callgraph_file": "${OUT_DIR}/callgraph.txt",
    "dot_file": "${OUT_DIR}/callgraph.dot",
    "svg_file": "${OUT_DIR}/callgraph.svg"
  }
}

Error Handling

Build Failures
  • IF project doesn't compile → Note in report, cannot perform call graph analysis
  • Suggest: Fix compilation errors first
Very Large Codebases
  • IF chosen algorithm times out (>5 minutes) → Fall back to next faster algorithm (vta → rta → cha)
  • IF all algorithms time out on the chosen main package → Try a narrower entry point (single binary)
  • IF still failing → Skip call graph, assign NEEDS_REVIEW, document the limitation
  • NEVER use ./... as scope — always target a specific main package
Missing Entry Points
  • IF command-line-arguments.main not found → Look for other entry points
  • Web services: Check HTTP handler registrations
  • Libraries: Call graph analysis may not be applicable
Tool Installation Issues
  • IF tools cannot be installed → Fall back to lower confidence methods
  • Document limitation in final report

Example: Generic Analysis Workflow

bash
# Setup
CVE_ID="CVE-YYYY-NNNNN"
OUT_DIR="${AI_HELPERS_WORKSPACE:-.}/.work/compliance/analyze-cve/${CVE_ID}"
mkdir -p "${OUT_DIR}"

# Step 1: Build call graph targeting a specific main package
timeout -k 10 300 env CGO_ENABLED=0 callgraph -algo vta -format=digraph ./cmd/controller > "${OUT_DIR}/callgraph.txt" 2>&1

# Step 2: Check if function is called
digraph nodes < "${OUT_DIR}/callgraph.txt" | grep "<package-path>.<vulnerable-function>$"

# Step 3: Find path from main
digraph somepath command-line-arguments.main "<package-path>.<vulnerable-function>" < "${OUT_DIR}/callgraph.txt"

# Step 4: Generate visual graph (if graphviz available)
digraph somepath command-line-arguments.main "<package-path>.<vulnerable-function>" < "${OUT_DIR}/callgraph.txt" | \
  digraph to dot | sfdp -Tsvg -o"${OUT_DIR}/callgraph.svg"

# Result: HIGH RISK — reachable path found

Integration with analyze-cve

This skill is called from Method 5 of the codebase-impact-analysis skill.

When to Invoke:

  • After basic dependency checks show package is present
  • Mandatory whenever the vulnerable package is in go.mod (see codebase-impact-analysis Method 5) — not just for "highest confidence"
  • When tools are available (checked in Phase 0)

Return to Parent:

  • Provide risk level (HIGH/MEDIUM/LOW)
  • Include evidence (call chain, graph files)
  • Update report with reachability findings

© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/compliance/skills/call-graph-analysis of openshift-eng/ai-helpers.

Open the folder on GitHubat commit a627176

Compare with similar skills

Call Graph Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Call Graph Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Call Graph Analysis this skillopenshift-eng/ai-helpers120—~3.1kAutomated safety check: NotesApache-2.0
Grepaiyoanbernabeu/grepai1.9k—~1.1kAutomated safety check: PassMIT
Releaseyoanbernabeu/grepai1.9k—~918Automated safety check: PassMIT
Gograph Go Repository Intelligenceozgurcd/gograph227—~4.8kAutomated safety check: NotesMIT
NGINX Ingress Controller Structurenginx/kubernetes-ingress5.1k—~3.8kAutomated safety check: PassApache-2.0
Golang Goplscontext-labs/whip1.1k1 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • Grepai

    yoanbernabeu/grepai

    Semantic code search and call-graph tracing. An agent skill from yoanbernabeu/grepai.

    1.9k GitHub stars~1.1k tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Release

    yoanbernabeu/grepai

    Create a new release for grepai. An agent skill from yoanbernabeu/grepai.

    1.9k GitHub stars~918 tokensUpdated 16 days ago
    DevelopmentAuto-check passed
  • Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration.

    227 GitHub stars~4.8k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • NGINX Ingress Controller Structure

    nginx/kubernetes-ingress

    Maps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated.

    5.1k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Golang Gopls

    context-labs/whip

    Golang semantic code intelligence via gopls — go-to-definition, references, call hierarchy, symbols, diagnostics, rename, refactors.

    1.1k GitHub starsUsed in 1 repo~2.3k tokens
    DevelopmentAuto-check passed
  • Codebase Knowledge Graph Q&A

    Egonex-AI/Understand-Anything

    Answers questions about a codebase by searching a prebuilt knowledge graph of its files, functions, classes and dependencies, not by rereading every source file.

    85k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed

More from openshift-eng/ai-helpers

All 118 skills in this repo
  • Investigate CI Reliability

    openshift-eng/ai-helpers

    Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.

    120 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Address Review PR

    openshift-eng/ai-helpers

    Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.

    120 GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Categorize Activity Types

    openshift-eng/ai-helpers

    Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.

    120 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Has Review Work

    openshift-eng/ai-helpers

    Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.

    120 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Must Gather Analyzer

    openshift-eng/ai-helpers

    Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.

    120 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Payload Autodl JSON

    openshift-eng/ai-helpers

    Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file

    120 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Call Graph Analysis

What does Call Graph Analysis do?

Perform definitive call graph analysis to prove whether vulnerable functions are reachable from program entry points. Call Graph Analysis is an agent skill from openshift-eng/ai-helpers.

When should I use Call Graph Analysis?

Call Graph Analysis fits situations like: tasks that involve Codebase onboarding.

How do I install Call Graph Analysis in Claude Code?

Run `npx skills add openshift-eng/ai-helpers --skill call-graph-analysis -a claude-code`. Or copy the skill folder (plugins/compliance/skills/call-graph-analysis in openshift-eng/ai-helpers) into .claude/skills/call-graph-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Call Graph Analysis in Codex?

Run `npx skills add openshift-eng/ai-helpers --skill call-graph-analysis -a codex`. Or copy the skill folder (plugins/compliance/skills/call-graph-analysis in openshift-eng/ai-helpers) into .agents/skills/call-graph-analysis in your project. Codex loads it when a task matches its description.

Can I use Call Graph Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill call-graph-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/call-graph-analysis, .gemini/skills/call-graph-analysis, .github/skills/call-graph-analysis and .opencode/skills/call-graph-analysis in your project.

What does Call Graph Analysis need to run?

Going by SKILL.md and its folder, Call Graph Analysis needs the command-line tools its instructions call (go, brew and apt-get).

Does Call Graph Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Call Graph Analysis safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Call Graph Analysis use?

Call Graph Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Call Graph Analysis use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Call Graph Analysis?

Skills that share tags, products or a category with Call Graph Analysis: Grepai (yoanbernabeu/grepai, 1.9k stars), Release (yoanbernabeu/grepai, 1.9k stars), Gograph Go Repository Intelligence (ozgurcd/gograph, 227 stars) and NGINX Ingress Controller Structure (nginx/kubernetes-ingress, 5.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Call Graph Analysis?

openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.

Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.