Agent skill

Ripwire Graph Query

by redhat-et in redhat-et/ripwire

Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

Apache-2.0Auto-check: notesDevelopment

Install Ripwire Graph Query

skills CLI
$ npx skills add redhat-et/ripwire --skill ripwire-graph-query -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redhat-et/ripwire ripwire-graph-query --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ripwire-graph-query .claude/skills/ripwire-graph-query && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ripwire-graph-query
GitHub stars
2.4k
Token cost
~1.1k tokens
SKILL.md length
407 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

  • Listing high-complexity functions in one directory before planning a refactor
  • SKILL.md covers Planning a refactor: find the…, The operators, Verified examples… and Calibration
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Finding which functions with many callers sit within a few hops of an entry point

What it does

Ripwire's fixed verbs (callers, callees, uses, path, impact) handle one-hop questions, and this skill is for the cases that need several conditions at once. The command ripwire with --graph-query evaluates a small functional expression to a ranked set of symbols, capped by --top-k at 200 by default. The operator set is closed, with no user rules and no unbounded recursion: sources are name and all, filters cover kind, cyclomatic complexity, caller count and file path regex, closures follow callers or callees up to a depth, and and, or and not combine them.

The main use is planning a refactor. One query sizes the cluster of high-complexity functions in a target directory, and a second sizes the callers that touching it would affect. A small cluster with a very large caller closure points to a compatibility shim or staged rollout rather than an in-place rewrite. Counts change with every commit, so you read the header on your own run. Repo-wide architecture health belongs to ripwire-layers.

When your agent uses it

  • Listing high-complexity functions in one directory before planning a refactor
  • Finding which functions with many callers sit within a few hops of an entry point
  • Spotting untested symbols close to main
  • Estimating how many callers a change to a hotspot could affect

Example prompts

  • “Which high-complexity functions under src/ can reach the payment handler?”
  • “Show untested symbols within one hop of main.”
  • “List functions with 10 or more callers in src/ and rank them.”
  • “Size the blast radius before I refactor the parser cluster.”

Requirements

  • The ripwire CLI
  • Pre-approved tools (allowed-tools): Bash, Read

What it can do on your machine

Read from SKILL.md and the folder at commit 255dc19. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ripwire Graph Query loads about 1.1k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 407 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redhat-et/ripwire at commit 255dc19, republished under its Apache-2.0 licence (© redhat-et). 407 words, ~1,118 tokens.

Download SKILL.mdSave it as .claude/skills/ripwire-graph-query/SKILL.md (or your agent's skills folder).
name
ripwire-graph-query
description
A call-graph question the fixed verbs can't phrase — 'which high-complexity functions can reach X?', 'what has 10+ callers in src/?', 'untested symbols within one hop of main'. --graph-query: a small closed expression language — kind, complexity, fan-in, tested filters; a file or cluster; bounded hops; and/or/not.
allowed-tools
Bash, Read

Graph queries with ripwire

One-hop questions have cheaper verbs — ripwire-navigate (--callers, --callees, --uses, --path, --impact). Reach for --graph-query only when you need to COMBINE conditions. Repo-wide architecture health (not one query) → ripwire-layers.

Planning a refactor: find the cluster AND its blast radius

The refactor-planning question is always two conditions at once — "what's messy" AND "what would touching it affect" — which is exactly what a single fixed verb can't phrase:

# the refactor short-list: high-complexity functions in the target area
ripwire <dir> --graph-query='and(cx(all,15),file(all,"src/"))' --legend=compact

# now the blast radius: everyone who transitively calls into that cluster (≤3 hops)
ripwire <dir> --graph-query='callers(and(cx(all,15),file(all,"src/")),3)' --legend=compact

(Verified on this repo's shape, not its exact numbers — count= drifts every commit: the first query returns the high-cx symbols under src/, each <s t= n= p=> (kind/name/path); the second returns the transitive caller set, typically smaller than the cluster itself because many hits are leaf-ish or call each other. Read the header's own count=/shown= on your run, don't trust a number pasted here. Narrow file(...) to your actual target directory before trusting the numbers.)

Run the first to size the cluster, the second to size the risk — a small high-cx cluster with a huge callers() closure is a refactor that needs a compatibility shim or a staged rollout, not a rewrite in place; a small cluster with a small closure is safe to just rewrite.

ripwire <dir> --graph-query='EXPR' --legend=compact evaluates a small functional expression to a deterministic, ranked node set (capped at --top-k, default 200). It is a fixed, closed operator set — not Datalog: no user rules, no unbounded recursion.

Show full SKILL.md (177 more words)Show less

The operators

KindFormMeaning
sourcename("X")symbols named X (unions same-name defs)
sourceallevery INDEXED symbol
filterkind(EXPR, K)keep kind K: fn method cls struct iface var sec
filtercx(EXPR, N)keep cyclomatic complexity ≥ N
filterfanin(EXPR, N)keep in-degree (caller count) ≥ N
filterfile(EXPR, "RE")keep symbols whose file path matches the ECMAScript regex RE
closurecallers(EXPR [, D=1])nodes that transitively (≤ D hops) CALL anything in EXPR
closurecallees(EXPR [, D=1])nodes transitively (≤ D hops) CALLED BY anything in EXPR
joinand(A, B) / or(A, B)intersection / union
joinnot(A, B)difference (A minus B)

Verified examples (single-quote the whole expression for the shell)

# the functions that transitively (≤2 hops) call buildGraph
ripwire <dir> --graph-query='and(callers(name("buildGraph"),2),kind(all,fn))' --legend=compact

# high-complexity symbols in src/  (the refactor short-list)
ripwire <dir> --graph-query='and(cx(all,15),file(all,"src/"))' --legend=compact

# heavily-depended-on symbols (10+ callers) — the de-facto API surface
ripwire <dir> --graph-query='fanin(all,10)' --legend=compact

# everything main can reach within 2 hops
ripwire <dir> --graph-query='callees(name("main"),2)' --legend=compact

# functions NOT reachable from main's callers  (difference)
ripwire <dir> --graph-query='not(kind(all,fn),callers(name("main")))' --legend=compact

# a two-symbol watchlist
ripwire <dir> --graph-query='or(name("buildGraph"),name("rankGraph"))' --legend=compact

Calibration

  • Results come back importance-ranked and capped at top-k — count= vs shown= in the header tells you if the cap bit; narrow the query or raise --top-k.
  • Closures walk the same name-based edges as --callers — dynamic dispatch / callbacks / macros can be missing, and amb edges were guessed. Verify in source when which-target matters.
  • A malformed expression (unknown operator, bad file() regex) reports the parse error and yields nothing — it never half-answers.

© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ripwire-graph-query of redhat-et/ripwire.

Open the folder on GitHubat commit 255dc19

Compare with similar skills

Ripwire Graph Query next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ripwire Graph Query compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ripwire Graph Query this skillredhat-et/ripwire2.4k—~1.1kAutomated safety check: NotesApache-2.0
Gograph Go Repository Intelligenceozgurcd/gograph227—~4.8kAutomated safety check: NotesMIT
ast-grep Structural Searchcode-yeongyu/oh-my-openagent70k—~3.3kAutomated safety check: PassMIT
Ast GrepBiFangKNT/mtga1.2k—~802Automated safety check: PassAGPL-3.0
Lsp Code Analysislsp-client/lsp-skill119—~3kAutomated safety check: PassMIT
jscpd Duplicate Code Detectorkucherenko/jscpd6.3k—~4.6kAutomated safety check: PassMIT

Similar skills

  • Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration.

    227 GitHub stars~4.8k tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • ast-grep Structural Search

    code-yeongyu/oh-my-openagent

    Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script.

    70k GitHub stars~3.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Ast Grep

    BiFangKNT/mtga

    Write and debug ast-grep rules for structural code search and rewrite.

    1.2k GitHub stars~802 tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Lsp Code Analysis

    lsp-client/lsp-skill

    Semantic code analysis via LSP. An agent skill from lsp-client/lsp-skill.

    119 GitHub stars~3k tokensUpdated 8 mo ago
    DevelopmentAuto-check passed
  • Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication.

    6.3k GitHub stars~4.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Get Call Paths

    opensage-agent/opensage-adk

    Get a path in the call graph from a source function to a specified destination function in the codebase.

    127 GitHub stars~272 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from redhat-et/ripwire

All 19 skills in this repo
  • Ripwire Output Emission

    redhat-et/ripwire

    Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.

    2.4k GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Ripwire Change Check

    redhat-et/ripwire

    Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.

    2.4k GitHub stars~4.3k tokensUpdated 2 days ago
    Auto-check: notes
  • Ripwire Subsystem Handoff

    redhat-et/ripwire

    Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

    2.4k GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Ripwire Code Navigation

    redhat-et/ripwire

    Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.

    2.4k GitHub stars~4.8k tokensUpdated 2 days ago
    Auto-check: notes
  • Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.

    2.4k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check: notes
  • Maps an unfamiliar repo or subsystem with the ripwire CLI before reading files, climbing an escalation ladder only until you are oriented.

    2.4k GitHub stars~4.5k tokensUpdated 2 days ago
    Auto-check: notes

Categories

Questions about Ripwire Graph Query

What does Ripwire Graph Query do?

Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode. Ripwire's fixed verbs (callers, callees, uses, path, impact) handle one-hop questions, and this skill is for the cases that need several conditions at once. The command ripwire with --graph-query evaluates a small functional expression to a ranked set of symbols, capped by --top-k at 200 by default.

When should I use Ripwire Graph Query?

Ripwire Graph Query fits situations like: listing high-complexity functions in one directory before planning a refactor; finding which functions with many callers sit within a few hops of an entry point; spotting untested symbols close to main; estimating how many callers a change to a hotspot could affect.

How do I install Ripwire Graph Query in Claude Code?

Run `npx skills add redhat-et/ripwire --skill ripwire-graph-query -a claude-code`. Or copy the skill folder (skills/ripwire-graph-query in redhat-et/ripwire) into .claude/skills/ripwire-graph-query in your project. Claude Code loads it when a task matches its description.

How do I install Ripwire Graph Query in Codex?

Run `npx skills add redhat-et/ripwire --skill ripwire-graph-query -a codex`. Or copy the skill folder (skills/ripwire-graph-query in redhat-et/ripwire) into .agents/skills/ripwire-graph-query in your project. Codex loads it when a task matches its description.

Can I use Ripwire Graph Query in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-graph-query -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-graph-query, .gemini/skills/ripwire-graph-query, .github/skills/ripwire-graph-query and .opencode/skills/ripwire-graph-query in your project.

What does Ripwire Graph Query need to run?

SKILL.md names no scripts, command-line tools or credentials: Ripwire Graph Query is instructions for the agent only. Our summary lists: The ripwire CLI. Its frontmatter pre-approves these tools: Bash, Read.

Does Ripwire Graph Query access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ripwire Graph Query safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ripwire Graph Query use?

Ripwire Graph Query is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ripwire Graph Query use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ripwire Graph Query?

Skills that share tags, products or a category with Ripwire Graph Query: Gograph Go Repository Intelligence (ozgurcd/gograph, 227 stars), ast-grep Structural Search (code-yeongyu/oh-my-openagent, 70k stars), Ast Grep (BiFangKNT/mtga, 1.2k stars) and Lsp Code Analysis (lsp-client/lsp-skill, 119 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ripwire Graph Query?

redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,412 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 4, 2026.

Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.