Agent skill

Slm Graph

by qualixar in qualixar/superlocalmemory

Index and query a codebase as a structural graph — build the code graph, trace blast radius of a change, find callers/callees/inheritors, semantic code search by meaning, assemble PR review context…

AGPL-3.0Auto-check: notesDevelopment

Install Slm Graph

skills CLI
$ npx skills add qualixar/superlocalmemory --skill slm-graph -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install qualixar/superlocalmemory slm-graph --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/qualixar/superlocalmemory.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugin/skills/slm-graph .claude/skills/slm-graph && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
slm-graph
GitHub stars
227
Token cost
~2.7k tokens
SKILL.md length
839 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Index and query a codebase as a structural graph — build the code graph, trace blast radius of a change, find callers/callees/inheritors, semantic code search by meaning, assemble PR review context…

  • Works in 6 steps: build_code_graph — index a repository → query_graph — traverse relationships → get_blast_radius — impact analysis → …
  • The user asks how code connects
  • SKILL.md covers Tool Reference, Realistic Workflow, Error Handling and Profile Requirement, plus 1 more section
  • Calls git

What it does

Slm Graph is an agent skill from qualixar/superlocalmemory. Index and query a codebase as a structural graph — build the code graph, trace blast radius of a change, find callers/callees/inheritors, semantic code search by meaning, assemble PR review context, and detect what changed since last index. Use when the user asks how code connects, what breaks if X changes, what calls a function, what a class inherits from, how to navigate an unfamiliar codebase, or to understand risk before editing.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Pull requests and Codebase onboarding. It works with Model Context Protocol. The repository describes itself as: Open-source governed, local-first memory control plane for AI agents and teams. arXiv:2608.08253. The licence is AGPL-3.0.

When your agent uses it

  • The user asks how code connects
  • What breaks if X changes
  • What calls a function
  • What a class inherits from

Example prompts

  • “/slm-graph”

Requirements

  • Pre-approved tools (allowed-tools): build_code_graph, query_graph, get_blast_radius, semantic_search_code, get_review_context, detect_changes, Bash

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. build_code_graph — index a repository
  2. query_graph — traverse relationships
  3. get_blast_radius — impact analysis
  4. semantic_search_code — find code by meaning
  5. get_review_context — assemble PR review context
  6. detect_changes — what changed since last index

What it can do on your machine

Read from SKILL.md and the folder at commit ce2d7a9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • build_code_graph
    • query_graph
    • get_blast_radius
    • semantic_search_code
    • get_review_context
    • detect_changes
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Slm Graph loads about 2.7k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 839 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: build_code_graph, query_graph, get_blast_radius, semantic_search_code, get_review_context, detect_ch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from qualixar/superlocalmemory at commit ce2d7a9, republished under its AGPL-3.0 licence (© qualixar). 839 words, ~2,749 tokens.

Download SKILL.mdSave it as .claude/skills/slm-graph/SKILL.md (or your agent's skills folder).
name
slm-graph
description
Index and query a codebase as a structural graph — build the code graph, trace blast radius of a change, find callers/callees/inheritors, semantic code search by meaning, assemble PR review context, and detect what changed since last index. Use when the user asks how code connects, what breaks if X changes, what calls a function, what a class inherits from, how to navigate an unfamiliar codebase, or to understand risk before editing.
allowed-tools
build_code_graph, query_graph, get_blast_radius, semantic_search_code, get_review_context, detect_changes, Bash
when_to_use
- what calls X - what breaks if I change Y - what does Z inherit from - find code that handles authentication - impact analysis before editing - code…

slm-graph — Code Intelligence Skill

Index any repo as a code knowledge graph and answer structural questions about it: callers, callees, impact radius, semantic search, and review context. Requires the code MCP profile (set SLM_MCP_PROFILE=code in your plugin .mcp.json).

Prerequisite rule: every tool except build_code_graph self-guards — if the graph is not built it returns {"success": false, "error": "Code graph not built. Run build_code_graph first."}. Always index first.


Tool Reference

1. build_code_graph — index a repository
build_code_graph(
    repo_path: str,
    languages: str = "",
    exclude_patterns: str = "",
) -> {success, files_parsed, nodes, edges, flows, communities, duration_ms}

Parses all supported source files, extracts functions/classes/imports, builds the call graph, detects execution flows, and identifies code communities. Replaces any previous index for the same repo.

  • repo_path — absolute path to the repository root. Must exist.
  • languages — comma-separated language filter, e.g. "python,typescript". Empty string = index all supported languages.
  • exclude_patterns — comma-separated glob patterns to exclude, e.g. "**/node_modules/**,**/.venv/**". Empty = no exclusions.

When to (re)build:

  • Before using any other graph tool for the first time on a repo.
  • After significant changes to the codebase (pull, merge, large refactor).
  • When detect_changes or query_graph returns stale/unexpected results.
  • Rebuild is safe and idempotent — it replaces the previous index atomically per file.
# Index the full repo
build_code_graph(repo_path="/abs/path/to/myrepo")

# Index only Python, skip tests and generated code
build_code_graph(
    repo_path="/abs/path/to/myrepo",
    languages="python",
    exclude_patterns="**/tests/**,**/generated/**"
)

2. query_graph — traverse relationships
query_graph(
    pattern: str,
    target: str = "",
    limit: int = 20,
) -> {success, pattern, target, results: [{qualified_name, kind, file_path, name}]}

Query the graph for structural relationships. pattern is required and must be one of the eight valid values below. target is a qualified name, partial name, or node ID — matched with exact-then-LIKE fallback.

Valid patterns:

patternreturns
callers_offunctions/methods that call target
callees_offunctions/methods that target calls
imports_ofmodules/symbols that target imports
imported_bywho imports target
tests_fortest nodes associated with target
inherits_frombase classes of target
inherited_bysubclasses of target
containssymbols defined inside target (e.g. methods in a class)
# Who calls the auth handler?
query_graph(pattern="callers_of", target="authenticate_user")

# What does the payment processor import?
query_graph(pattern="imports_of", target="PaymentProcessor", limit=30)

# What classes inherit from BaseModel?
query_graph(pattern="inherited_by", target="BaseModel")

3. get_blast_radius — impact analysis
get_blast_radius(
    changed_files: str,
    max_depth: int = 2,
    max_nodes: int = 500,
) -> {success, changed_nodes, impacted_nodes, impacted_files, edges, depth_reached, truncated}

Computes the full impact radius for one or more changed files using bidirectional BFS (callers and callees). Returns every node and file reachable within max_depth hops. Use this before editing to understand risk surface.

  • changed_files — comma-separated file paths relative to the repo root, e.g. "src/auth/handler.py,src/auth/models.py".
  • max_depth — BFS depth. Default 2. Increase to 3–4 for deep call chains; lower to 1 for a quick first-degree check.
  • max_nodes — caps the result set. If truncated=true in the response, the real blast radius is larger.
# What breaks if I change the auth handler?
get_blast_radius(changed_files="src/auth/handler.py")

# Deeper analysis across two files
get_blast_radius(
    changed_files="src/payments/gateway.py,src/payments/models.py",
    max_depth=3,
    max_nodes=200
)

If truncated is true, narrow the scope with max_nodes or reduce max_depth to get a reliable result.


4. semantic_search_code — find code by meaning
semantic_search_code(
    query: str,
    kind: str = "",
    limit: int = 20,
) -> {success, results: [{qualified_name, kind, file_path, score, line_start, name}]}

Hybrid FTS5 + vector search over all indexed code entities. Use when you know what the code does but not what it's called.

  • query — natural language description, e.g. "retry logic for HTTP requests" or "parse JWT token from header".
  • kind — optional filter: "Function", "Class", "File", or "Test". Empty = all kinds. Case-insensitive match in the engine.
  • limit — max results. Default 20.

Results include a score field (higher = more relevant).

# Find where authentication is handled
semantic_search_code(query="authenticate user from request token")

# Find only test functions that cover database writes
semantic_search_code(query="database write transaction rollback", kind="Test")

# Find the rate limiter class
semantic_search_code(query="rate limiting middleware", kind="Class", limit=5)

5. get_review_context — assemble PR review context
get_review_context(
    changed_files: str,
    include_source: bool = True,
) -> {success, summary, review_items, test_gaps, risk_score}

Produces a token-optimized review package for a set of changed files: a plain-language summary, a ranked list of review items with per-node risk scores, and a list of changed symbols that have no associated test coverage.

  • changed_files — comma-separated file paths relative to the repo root.
  • include_source — whether to include source code snippets in the context (default True). Set False to reduce token usage when you only need the risk analysis.

risk_score is a float 0–1 on the overall changeset. review_items[].risk_score is per-node.

# Get review context for a PR touching two files
get_review_context(changed_files="src/auth/handler.py,src/auth/utils.py")

# Risk summary only, no source snippets
get_review_context(
    changed_files="src/payments/gateway.py",
    include_source=False
)

Show full SKILL.md (314 more words)Show less
6. detect_changes — what changed since last index
detect_changes(
    base: str = "HEAD~1",
) -> {success, summary, risk_score, changed_functions, test_gaps, review_priorities}

Runs git diff against base, maps the changed hunks to graph nodes, and returns a risk-scored list of changed functions, test gaps, and review priorities. Requires the repo to be a git repository.

  • base — git ref to diff against. Default "HEAD~1" (one commit back). Any valid git ref works: "main", "v3.6.13", a commit SHA, etc.
# What changed in the last commit?
detect_changes()

# What changed since the release branch?
detect_changes(base="release/v3.6.13")

# What changed relative to main?
detect_changes(base="main")

Returns error if the repo root is not a git repository or if git is not available.


Realistic Workflow

Explore an unfamiliar codebase
# 1. Index it
build_code_graph(repo_path="/abs/path/to/repo")

# 2. Find the entry point by meaning
semantic_search_code(query="request router entry point", kind="Function")

# 3. Trace what it calls
query_graph(pattern="callees_of", target="handle_request")

# 4. See who else calls the same core function
query_graph(pattern="callers_of", target="authenticate_user")
Before editing a function
# 1. Know what you are touching
semantic_search_code(query="retry HTTP requests with backoff")

# 2. Understand blast radius before making the change
get_blast_radius(changed_files="src/http/client.py")

# 3. Check test gaps
get_review_context(changed_files="src/http/client.py")
Pre-commit / PR review
# 1. What changed in this branch vs main?
detect_changes(base="main")

# 2. Full impact analysis for the changed files
get_blast_radius(changed_files="src/auth/handler.py,src/auth/models.py")

# 3. Assemble review context
get_review_context(changed_files="src/auth/handler.py,src/auth/models.py")

Error Handling

All tools return {"success": false, "error": "<message>"} on failure — they never raise.

Error messageCauseFix
Code graph not built. Run build_code_graph first.No index existsCall build_code_graph(repo_path=...) first
Repository path does not exist: <path>Bad repo_path in buildPass an absolute path that exists
Git not available or not a git repository: ...detect_changes needs gitOnly works in git repos with git installed
Invalid pattern '...'Wrong pattern in query_graphUse one of the 8 valid pattern strings
No node found matching '<target>'Target not in indexRebuild or check the qualified name via semantic_search_code

If build_code_graph returns files_parsed: 0, no supported source files were found — check repo_path and exclude_patterns.


Profile Requirement

This skill uses graph tools that are only active under the code MCP profile (or full / power). Your plugin .mcp.json must include:

json
"env": {
  "SLM_MCP_PROFILE": "code",
  "SLM_AGENT_ID": "claude_code"
}

Without this, the six graph tools are not registered and will appear as unknown tools. Run slm status to confirm the active profile.

Switching profiles at runtime (v3.8.0+): Use switch_profile("code") via MCP to activate the code profile in a session that started with a different profile. See slm-profile for the full profile switching workflow.


  • slm-profile — workspace isolation and profile switching (required for code tools)
  • slm-recall — retrieve architectural decisions before graph queries
  • slm-status — confirm the active profile and graph index health

SuperLocalMemory v4.1.21 · Qualixar · AGPL-3.0-or-later

© qualixar, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugin/skills/slm-graph of qualixar/superlocalmemory.

Open the folder on GitHubat commit ce2d7a9

Compare with similar skills

Slm Graph next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Slm Graph compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Slm Graph this skillqualixar/superlocalmemory227—~2.7kAutomated safety check: NotesAGPL-3.0
Compasscrabbuild/compass168—~5kAutomated safety check: PassCustom licence
GitHub MCPvibeeval/vibecosystem531—~2.3kAutomated safety check: NotesMIT
Review PRPrefectHQ/fastmcp28k—~3.1kAutomated safety check: PassApache-2.0
ObservalObserval/Observal4.1k—~2.2kAutomated safety check: PassApache-2.0
Adopt PR Branch Contextpydantic/pydantic-ai-harness946—~1.8kAutomated safety check: PassMIT

Similar skills

  • Compass

    crabbuild/compass

    A skill your agent uses for graph-first AI coding sessions and repository analysis: session initialization, architecture maps, dependency or call-graph tracing, symbol and repository search…

    168 GitHub stars~5k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • GitHub MCP

    vibeeval/vibecosystem

    GitHub MCP Server ile GitHub API erisimi. An agent skill from vibeeval/vibecosystem.

    531 GitHub stars~2.3k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check: notes
  • Review PR

    PrefectHQ/fastmcp

    Assess a FastMCP pull request for justified behavior, compatibility, and correctness, then follow CI and review feedback to a revision-specific verdict.

    28k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Observal

    Observal/Observal

    A skill your agent uses when starting any task the organization may already have an approved skill, prompt, MCP server, or Agent for: reviewing code, a commit, a diff, or a pull request; writing…

    4.1k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Adopt PR Branch Context

    pydantic/pydantic-ai-harness

    Official

    Fills in issue-brief.md and pr-decisions.md for an existing pull request, so you can pick up a PR mid-flight with its linked issue and past review decisions summarized.

    946 GitHub stars~1.8k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Octocode Code Research

    bgauryy/octocode

    Researches code with evidence: traces callers, imports and cross-repo links, diagnoses failures and reports findings with exact file and line references and a confidence label.

    946 GitHub stars~1.5k tokensUpdated 4 days ago
    DevelopmentAuto-check passed

More from qualixar/superlocalmemory

All 13 skills in this repo
  • Superlocalmemory

    qualixar/superlocalmemory

    AI agent memory with mathematical foundations. An agent skill from qualixar/superlocalmemory.

    227 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Slm Loop

    qualixar/superlocalmemory

    Run gate-verified bounded loops with SuperLocalMemory as the durable ledger.

    227 GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Slm Recall

    qualixar/superlocalmemory

    Search and retrieve facts, decisions, and past context from SuperLocalMemory.

    227 GitHub stars~3.3k tokensUpdated today
    Auto-check: notes
  • Slm Remember

    qualixar/superlocalmemory

    Capture durable facts, decisions, constraints, and gotchas into SuperLocalMemory.

    227 GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Slm Scope

    qualixar/superlocalmemory

    Controls memory visibility across profiles — personal (private, default), shared (selected profiles), or global (all profiles on this machine).

    227 GitHub stars~1.4k tokensUpdated today
    Auto-check: notes
  • Slm Status

    qualixar/superlocalmemory

    Health and optimization stats for SuperLocalMemory — call slmoptimizestats() for live compression and cache counters (compressruns, tokenssavedcompress, cacheproxyhits, cacheproxymisses…

    227 GitHub stars~1.7k tokensUpdated today
    Auto-check: notes

Questions about Slm Graph

What does Slm Graph do?

Index and query a codebase as a structural graph — build the code graph, trace blast radius of a change, find callers/callees/inheritors, semantic code search by meaning, assemble PR review context…. Slm Graph is an agent skill from qualixar/superlocalmemory. Index and query a codebase as a structural graph — build the code graph, trace blast radius of a change, find callers/callees/inheritors, semantic code search by meaning, assemble PR review context, and detect what changed since last index.

When should I use Slm Graph?

Slm Graph fits situations like: the user asks how code connects; what breaks if X changes; what calls a function; what a class inherits from.

How do I install Slm Graph in Claude Code?

Run `npx skills add qualixar/superlocalmemory --skill slm-graph -a claude-code`. Or copy the skill folder (plugin/skills/slm-graph in qualixar/superlocalmemory) into .claude/skills/slm-graph in your project. Claude Code loads it when a task matches its description.

How do I install Slm Graph in Codex?

Run `npx skills add qualixar/superlocalmemory --skill slm-graph -a codex`. Or copy the skill folder (plugin/skills/slm-graph in qualixar/superlocalmemory) into .agents/skills/slm-graph in your project. Codex loads it when a task matches its description.

Can I use Slm Graph in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add qualixar/superlocalmemory --skill slm-graph -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/slm-graph, .gemini/skills/slm-graph, .github/skills/slm-graph and .opencode/skills/slm-graph in your project.

What does Slm Graph need to run?

Going by SKILL.md and its folder, Slm Graph needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: build_code_graph, query_graph, get_blast_radius, semantic_search_code, get_review_context, detect_changes, Bash.

Does Slm Graph access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Slm Graph safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Slm Graph use?

Slm Graph is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Slm Graph use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Slm Graph?

Skills that share tags, products or a category with Slm Graph: Compass (crabbuild/compass, 168 stars), GitHub MCP (vibeeval/vibecosystem, 531 stars), Review PR (PrefectHQ/fastmcp, 28k stars) and Observal (Observal/Observal, 4.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Slm Graph?

qualixar (a GitHub organization) maintains it in qualixar/superlocalmemory, which has 227 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.

Source: qualixar/superlocalmemory on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.