Agent skill

Ripwire Before You Build

by redhat-et in redhat-et/ripwire

Starting a FEATURE (multi-symbol work): the plan, the API boundary, the scope — how big does this change get — from the codebase's real structure.

Apache-2.0Auto-check: notes

Install Ripwire Before You Build

skills CLI
$ npx skills add redhat-et/ripwire --skill ripwire-before-you-build -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redhat-et/ripwire ripwire-before-you-build --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ripwire-before-you-build .claude/skills/ripwire-before-you-build && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ripwire-before-you-build
GitHub stars
2.4k
Token cost
~2k tokens
SKILL.md length
978 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Starting a FEATURE (multi-symbol work): the plan, the API boundary, the scope — how big does this change get — from the codebase's real structure.

  • Works in 3 steps: If highly-relevant symbols already exist… → Integration seams — ripwire --seams… → Coupling cost — ripwire --deps…
  • SKILL.md covers Common first move — recall +…, Feasibility spike — "is this…, Plan — "give me the ordered… and Interface — "what should the…, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ripwire Before You Build is an agent skill from redhat-et/ripwire. Starting a FEATURE (multi-symbol work): the plan, the API boundary, the scope — how big does this change get — from the codebase's real structure. Implementing an EXISTING interface? --lego=Iface lists its contract and current implementors. ONE standalone symbol → reuse-first. A small feature with an obvious home needs none of this.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you want without reading the repo, then check you built what you meant — blast… The licence is Apache-2.0.

Example prompts

  • “/ripwire-before-you-build”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. If highly-relevant symbols already exist with in > 0, the approach is partially implemented — build
  2. Integration seams — ripwire --seams --legend=compact → (untested cross-module edges). If your
  3. Coupling cost — ripwire --deps --legend=compact (skim + shape=`). Adding a dependency on a

What it can do on your machine

Read from SKILL.md and the folder at commit 60dd3b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ripwire Before You Build loads about 2k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 978 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redhat-et/ripwire at commit 60dd3b3, republished under its Apache-2.0 licence (© redhat-et). 978 words, ~1,962 tokens.

Download SKILL.mdSave it as .claude/skills/ripwire-before-you-build/SKILL.md (or your agent's skills folder).
name
ripwire-before-you-build
description
Starting a FEATURE (multi-symbol work): the plan, the API boundary, the scope — how big does this change get — from the codebase's real structure. Implementing an EXISTING interface? --lego=Iface lists its contract and current implementors. ONE standalone symbol → reuse-first. A small feature with an obvious home needs none of this.
allowed-tools
Bash, Read

Before you build — with ripwire

Routing: • Writing ONE symbol (fn/class/helper) and want to reuse rather than reinvent → ripwire-reuse-first. • You've already written the change and want the pre-submit check → ripwire-change-check. • You want to judge whether the code you wrote got better/worse → ripwire-quality-bar. • Restructuring EXISTING code (not new work) → ripwire-fresh-eyes. • Not sure which skill? → ripwire-router.

<dir> = repo root. FEATURE/APPROACH = your task in 2–4 plain words; SYM = a representative symbol. Run only the sections your question needs — they share the same building blocks.

Common first move — recall + reusable blocks

Almost every section starts here; do it once. One-call shortcut: ripwire <dir> --pack-task="FEATURE" --legend=compact assembles the recall + --for ranking + top bodies + caller signatures + notes + tests_to_run into ONE bundle under one token budget — reach for it first instead of firing the calls below one at a time; drop to the individual calls only when you need a specific section's full output.

  • Recall prior decisions — ripwire <dir> --recall="FEATURE" → full bodies of the most relevant markdown docs (planning/design notes, READMEs) ranked by relevance. If a doc already covers this, read it fully — the decision may be made. Look for explicit "rejected" / "future work" language.
  • Reusable building blocks — the one-call write-mode bundle — ripwire <dir> --for="FEATURE" → <sigs> ranked by task-relevance, each carrying the quality lens in the same call: cx/ccx (complexity), in/amp (reuse count / change-amplification), churn (recent-commits), clone="1" (duplicated), tested="1", plus the inline <doc> block. That's read-context-and-quality-signal in ONE call — you learn what to reuse AND what's fragile (high-churn, high-amp, cloned, or untested) before you write a line, not after. High-in symbols are already widely composed — prefer extending them over reimplementing; treat a high-churn/high-amp one as something to touch carefully and test around.
  • The shape to imitate for each new symbol — ripwire <dir> --exemplar=fn|method|class|struct|iface|var --legend=compact or --exemplar="<the sub-task in words>" (top match's kind inferred) → the repo's single best-in-class instance of that shape — cognitive complexity must clear an eligibility ceiling first (a blob can never win no matter how reused/tested), then among eligible candidates it's ranked tested=1 first, highest fan-in second, lowest cognitive-cx as the final tie-break — full body under <bodies>. Run it per new symbol the feature adds so each one copies a proven shape (structure, error handling, naming) instead of being invented from memory. (Deep-dive on exemplar-by-ROLE → ripwire-reuse-first.)
  • Implementing against an interface? — ripwire <dir> --lego=I --legend=compact (or --lego=file:I to disambiguate a same-named type) → the interface's method contract (the exact signatures you must satisfy) plus every existing implementor, own-language only. Read one existing impl as the template so your new one matches the house pattern (method order, error handling, registration) instead of guessing the shape from the interface alone. The single highest-value call when the thing you're building has to satisfy an I.

Feasibility spike — "is this approach even viable?"

After the recall + --for above:

  1. If highly-relevant symbols already exist with in > 0, the approach is partially implemented — build on it. If --recall shows it was decided against, stop.
  2. Integration seams — ripwire <dir> --seams --legend=compact → <seams> (untested cross-module edges). If your approach must connect two modules with no test-covered seam between them, that's an integration cost.
  3. Coupling cost — ripwire <dir> --deps --legend=compact (skim <godfiles> + shape=). Adding a dependency on a god-file adds coupling cost for every future change — flag it. → Verdict: "build on existing" / "greenfield but seams exist" / "needs new seam, flag risk".
Show full SKILL.md (431 more words)Show less

Plan — "give me the ordered implementation steps"

  1. Recall + --for (above) — check whether any existing symbol already solves part of the problem. Low in= = an underused candidate to extend or replace; high in= = load-bearing, extend cautiously.
  2. Integration seams — ripwire <dir> --seams --legend=compact. Each seam is a wiring point; your plan should name which seam(s) the new code wires through, and add a test at each new seam it creates.
  3. Impact of anything you'll modify — ripwire <dir> --impact=SYM --legend=compact. Large reaches= → plan a staged rollout or a compatibility shim. → Plan: ordered steps (recall → design → wire seams → write tests → implement), each naming the specific file+symbol to touch, the blast radius of any modification, and its test gate (from --affected). Flag any step that creates a new seam without a test.

Interface — "what should the boundary / API look like?"

  1. Neighborhood of the subsystem — ripwire <dir> --around=SYM --legend=compact --metrics [--around-depth=2] → the ego graph with ranks + call edges. --metrics is what adds the in= fan-in annotation (bare --around emits none); high-in= symbols are already acting as the de-facto API surface.
  2. The seam it lives on — ripwire <dir> --seams --legend=compact. If your subsystem straddles a <seam from="X" to="Y">, that's where the interface belongs.
  3. Who currently crosses the boundary — ripwire <dir> --callers=SYM --legend=compact for the top 2–3 in the ego graph. Callers from outside the subsystem's directory are the external clients the interface must serve.
  4. What to hide — ripwire <dir> --deps --legend=compact, skim instab=. High-instability internal files (leaves) stay behind the interface; stable (low-instability) files may be safe to expose. → Proposal: the 3–5 high-fan-in, called-from-outside symbols that form the natural API surface, the seam they live on, and the internal symbols to hide. Write it in terms of callers' needs, not internals.

Sizing rubric — "how big is this change?"

  1. Blast radius — ripwire <dir> --impact=SYM --legend=compact → reaches="N" is the blast-radius symbol count (count distinct p= files for the file count); defs="D">1 means overloads, each a separate blast root.
  2. Affected tests — ripwire <dir> --affected=fileA.cpp,fileB.h --legend=compact (the files defining SYM, from --impact). tests="0" = no test cover — flag it.
  3. Caller-stack depth — ripwire <dir> --callers=SYM --legend=compact, then spot-check --callers=<top-caller> one level up. A 2-hop caller graph is a tactical change; 5+ hops is architectural.
  4. Hidden coupling — ripwire <dir> --cochange=fileA.cpp --legend=compact; surprising="1" partners must be verified manually even if not in the blast radius. → Classify: local (≤5 blast, tests exist) / moderate (5–20) / wide (>20 or no tests).

Honesty

ripwire maps structure, not data flow; seams/impact are name-based (dynamic dispatch/callbacks/macros can be missing). Compose from what exists; note what's genuinely missing rather than reinventing it.

© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ripwire-before-you-build of redhat-et/ripwire.

Open the folder on GitHubat commit 60dd3b3

Compare with similar skills

Ripwire Before You Build next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ripwire Before You Build compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ripwire Before You Build this skillredhat-et/ripwire2.4k—~2kAutomated safety check: NotesApache-2.0
StartDonchitos/Claude-Code-Game-Studios26k—~6.5kAutomated safety check: PassMIT
Symbols APIJetBrains/intellij-community21k—~2.7kAutomated safety check: PassCustom licence
Diagnosing Stacktrace SymbolicationPostHog/posthog40k—~2.2kAutomated safety check: PassCustom licence
Implementing Zero Trust With Hashicorp Boundarymukul975/Anthropic-Cybersecurity-Skills34k—~3.9kAutomated safety check: NotesApache-2.0
Poly SymbolsJetBrains/intellij-community21k—~4.2kAutomated safety check: PassCustom licence

Similar skills

  • Start

    Donchitos/Claude-Code-Game-Studios

    First-time onboarding — asks where you are, then guides you to the right workflow.

    26k GitHub stars~6.5k tokensUpdated yesterday
    Game DevelopmentAuto-check passed
  • Symbols API

    JetBrains/intellij-community

    Official

    Use IntelliJ Symbol API for declarations, references, and rename.

    21k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Official

    Help users debug PostHog Error Tracking stack-trace symbolication for any supported platform — JavaScript/TypeScript web, React Native (Hermes), Android (Proguard / R8), or iOS / macOS (dSYM).

    40k GitHub stars~2.2k tokensUpdated today
    MobileAuto-check passed
  • Implementing Zero Trust With Hashicorp Boundary

    mukul975/Anthropic-Cybersecurity-Skills

    Installs and configures HashiCorp Boundary as a default-deny, identity-aware proxy for infrastructure access, including controller/worker setup, Vault-backed credential brokering, session recording…

    34k GitHub stars~3.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Poly Symbols

    JetBrains/intellij-community

    Official

    Implement PolySymbols completion, references, and rename. An agent skill from JetBrains/intellij-community.

    21k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Session Start Hook

    asgeirtj/system_prompts_leaks

    Creating and developing startup hooks for Claude Code on the web.

    69k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed

More from redhat-et/ripwire

All 19 skills in this repo
  • Ripwire Output Emission

    redhat-et/ripwire

    Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.

    2.4k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Ripwire Change Check

    redhat-et/ripwire

    Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.

    2.4k GitHub stars~4.3k tokensUpdated yesterday
    Auto-check: notes
  • Ripwire Graph Query

    redhat-et/ripwire

    Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

    2.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes
  • Ripwire Subsystem Handoff

    redhat-et/ripwire

    Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

    2.4k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • Ripwire Code Navigation

    redhat-et/ripwire

    Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.

    2.4k GitHub stars~4.8k tokensUpdated yesterday
    Auto-check: notes
  • Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.

    2.4k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check: notes

Questions about Ripwire Before You Build

What does Ripwire Before You Build do?

Starting a FEATURE (multi-symbol work): the plan, the API boundary, the scope — how big does this change get — from the codebase's real structure. Ripwire Before You Build is an agent skill from redhat-et/ripwire. Starting a FEATURE (multi-symbol work): the plan, the API boundary, the scope — how big does this change get — from the codebase's real structure.

How do I install Ripwire Before You Build in Claude Code?

Run `npx skills add redhat-et/ripwire --skill ripwire-before-you-build -a claude-code`. Or copy the skill folder (skills/ripwire-before-you-build in redhat-et/ripwire) into .claude/skills/ripwire-before-you-build in your project. Claude Code loads it when a task matches its description.

How do I install Ripwire Before You Build in Codex?

Run `npx skills add redhat-et/ripwire --skill ripwire-before-you-build -a codex`. Or copy the skill folder (skills/ripwire-before-you-build in redhat-et/ripwire) into .agents/skills/ripwire-before-you-build in your project. Codex loads it when a task matches its description.

Can I use Ripwire Before You Build in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-before-you-build -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-before-you-build, .gemini/skills/ripwire-before-you-build, .github/skills/ripwire-before-you-build and .opencode/skills/ripwire-before-you-build in your project.

What does Ripwire Before You Build need to run?

SKILL.md names no scripts, command-line tools or credentials: Ripwire Before You Build is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, Read.

Does Ripwire Before You Build access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ripwire Before You Build safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ripwire Before You Build use?

Ripwire Before You Build is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ripwire Before You Build use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ripwire Before You Build?

Skills that share tags, products or a category with Ripwire Before You Build: Start (Donchitos/Claude-Code-Game-Studios, 26k stars), Symbols API (JetBrains/intellij-community, 21k stars), Diagnosing Stacktrace Symbolication (PostHog/posthog, 40k stars) and Implementing Zero Trust With Hashicorp Boundary (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ripwire Before You Build?

redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,428 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.