Agent skill

Ripwire Layers

by redhat-et in redhat-et/ripwire

Architecture HEALTH and ENFORCEMENT — 'is this a dependency mess / does the UI reach into the database / enforce module boundaries in CI?': cycles, the godfile, propagation cost (how far a touch…

Apache-2.0Auto-check: notesAgent Workflows

Install Ripwire Layers

skills CLI
$ npx skills add redhat-et/ripwire --skill ripwire-layers -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redhat-et/ripwire ripwire-layers --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ripwire-layers .claude/skills/ripwire-layers && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ripwire-layers
GitHub stars
2.4k
Token cost
~1.5k tokens
SKILL.md length
751 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Architecture HEALTH and ENFORCEMENT — 'is this a dependency mess / does the UI reach into the database / enforce module boundaries in CI?': cycles, the godfile, propagation cost (how far a touch…

  • Works in 4 steps: Layering rules (if a rules file exists)… → Dependency health — ripwire --deps… → Module clustering — ripwire… → …
  • Agent Workflows work in your project
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ripwire Layers is an agent skill from redhat-et/ripwire. Architecture HEALTH and ENFORCEMENT — 'is this a dependency mess / does the UI reach into the database / enforce module boundaries in CI?': cycles, the godfile, propagation cost (how far a touch ripples), --arch rules with a baseline gate. Overview without gating → orient. One pass answers it.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows. The repository describes itself as: The ripgrep of AI context: a zero-dependency C++23 CLI + MCP server for coding agents. Find what you want without reading the repo, then check you built what you meant — blast… The licence is Apache-2.0.

When your agent uses it

  • Agent Workflows work in your project

Example prompts

  • “/ripwire-layers”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Layering rules (if a rules file exists) — ripwire --arch=rules.txt
  2. Dependency health — ripwire --deps --legend=compact
  3. Module clustering — ripwire --communities --legend=compact
  4. Mermaid diagram (optional, for visual review) — ripwire --mermaid

What it can do on your machine

Read from SKILL.md and the folder at commit 60dd3b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ripwire Layers loads about 1.5k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 751 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redhat-et/ripwire at commit 60dd3b3, republished under its Apache-2.0 licence (© redhat-et). 751 words, ~1,460 tokens.

Download SKILL.mdSave it as .claude/skills/ripwire-layers/SKILL.md (or your agent's skills folder).
name
ripwire-layers
description
Architecture HEALTH and ENFORCEMENT — 'is this a dependency mess / does the UI reach into the database / enforce module boundaries in CI?': cycles, the godfile, propagation cost (how far a touch ripples), --arch rules with a baseline gate. Overview without gating → orient. One pass answers it.
allowed-tools
Bash, Read

Layers with ripwire

Nearest neighbours: • You want the file→file dependency graph itself (not a health read) → --deps is step 2 below, or go straight to it if you already know you want godfiles/cycles. • Reviewing YOUR OWN diff for coupling risk, not a repo-wide sweep → ripwire-change-check. • Unfamiliar subsystem, general risk sweep (not architecture-specific) → ripwire-fresh-eyes.

Trigger: you want a factual picture of architectural health before a large refactor, or you're reviewing whether the codebase is trending toward or away from clean layering.

<dir> = repo root. Every metric below has a NUMBER → THRESHOLD → ACTION — don't stop at reporting it.

  1. Layering rules (if a rules file exists) — ripwire <dir> --arch=rules.txt Output: <arch> with violations listed by layer pair and file. Exit 2 = NEW violations found (CI gate). If no rules file exists yet, this step is the prompt to write one (grammar: layer NAME = substr…, deny FROM -> TO, allow FROM -> TO; # comments). Action: every violation is a concrete edge to either fix (remove the dependency) or explicitly allow (document why it's intentional) — don't leave it silently baselined forever.

    Adopting rules on a codebase with existing debt — the baseline workflow:

    • ripwire <dir> --arch=rules.txt --baseline — accept every CURRENT violation as known debt: writes a .ripwire_arch_baseline sidecar in the CWD (commit it), exits 0.
    • From then on, plain --arch=rules.txt suppresses baselined violations and exits 2 only on NEW ones — the gate stops the bleeding without demanding an up-front cleanup.
    • --arch=rules.txt --baseline-update — deliberately accept new debt by merging current violations into the sidecar (exit 0). Use sparingly, in its own reviewed commit.

    --arch=rules.txt also emits <metrics propagation_cost="X.XXX"> — the DSM (design-structure-matrix) transitive-closure density: the fraction of the file-dep graph reachable from an average file (MacCormack; a validated coupling form, computed here as a directory-level estimate from name-based deps). Direction: lower is better — 0 means files are mostly isolated from each other's transitive reach, 1 means touching any file risks rippling through the whole tree. Action at a high reading (no fixed universal threshold — compare against this same repo's own history/other modules, or treat >0.3 as worth a look): a high propagation cost is a change-amplification TAX — every edit here is more likely to have knock-on effects. Don't just report the number; find which directories are driving it (the <m path=... ca= ce=> per-module rows) and formalize a boundary between them — a layer/deny rule in rules.txt that would have caught the coupling.

  2. Dependency health — ripwire <dir> --deps --legend=compact Output: <deps> with <health> metrics:

    • acd (average component dependency) — lower is better
    • nccd (normalized CCD) — < 0.25 is healthy
    • shape — "horizontal" (layered, good) vs "vertical" (coupled, risk) Then <godfiles> ranked by afferent (dependents) — each godfile is an implicit layer boundary that hasn't been formalized. afferent/cycles are validated defect predictors; nccd (Lakos) and the --arch Martin Ca/Ce/I/A/D I/A/D/zone= block are design heuristics — mechanistically plausible, widely implemented, but no independent outcome-based study has validated them. Trust the god-file/cycle read hardest; treat nccd/D as descriptive, not proof. Action: a file in the top-3 by afferent is doing double duty as a de-facto layer boundary with no rule enforcing it — that's the concrete next step, not just a note: add it as a named layer in rules.txt and write the deny rules that keep new dependents out of its internals. A cycle in --report is worse than a high-afferent file — break it before formalizing anything downstream of it.
  3. Module clustering — ripwire <dir> --communities --legend=compact Output: <communities modules="N"> clusters with dominant directory and lead symbols. <bridge edges="N"> shows where clusters are tightly coupled across module boundaries. High bridge counts between non-adjacent modules are the layering violations --arch catches. Action: a high bridge count between two clusters that AREN'T adjacent in your intended layering is the specific violation to gate — turn it into a deny FROM -> TO rule rather than leaving it as an observation; a high bridge count between clusters that ARE meant to talk to each other is fine and doesn't need a rule.

  4. Mermaid diagram (optional, for visual review) — ripwire <dir> --mermaid Output: a flowchart LR Mermaid snippet with module nodes and inter-module call counts. Paste at mermaid.live to render. Edges labeled with high counts are the hot coupling seams — same action as step 3: a heavy edge crossing an intended boundary becomes a deny rule.

Show full SKILL.md (47 more words)Show less

Output

Health summary: shape=, nccd=, propagation_cost=, cycle count (from --report), top 3 god-files, and any --arch violations. Classify overall health: healthy / at-risk / needs restructuring — and for anything "at-risk" or worse, name the specific boundary to formalize (which layer, which deny rule) rather than stopping at the classification.

© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ripwire-layers of redhat-et/ripwire.

Open the folder on GitHubat commit 60dd3b3

Compare with similar skills

Ripwire Layers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ripwire Layers compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ripwire Layers this skillredhat-et/ripwire2.4k—~1.5kAutomated safety check: NotesApache-2.0
MCP Server Builderanthropics/skills180k64 repos~2.3kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k11 repos~4.1kAutomated safety check: NotesApache-2.0
Using Superpowersfarm-fe/farm5.6k35 repos~1.4kAutomated safety check: PassMIT
Executing Plans Inlineobra/superpowers296k2 repos~5.1kAutomated safety check: PassMIT
Claude Code Agent Developmentanthropics/claude-plugins-official38k8 repos~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 64 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 11 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Using Superpowers

    farm-fe/farm

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    5.6k GitHub starsUsed in 35 repos~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    296k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 8 repos~2.8k tokens
    Agent WorkflowsAuto-check passed
  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    795 GitHub starsUsed in 89 repos~8.2k tokens
    Agent WorkflowsAuto-check passed

More from redhat-et/ripwire

All 19 skills in this repo
  • Ripwire Output Emission

    redhat-et/ripwire

    Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.

    2.4k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Ripwire Change Check

    redhat-et/ripwire

    Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.

    2.4k GitHub stars~4.3k tokensUpdated today
    Auto-check: notes
  • Ripwire Graph Query

    redhat-et/ripwire

    Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

    2.4k GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Ripwire Subsystem Handoff

    redhat-et/ripwire

    Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

    2.4k GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • Ripwire Code Navigation

    redhat-et/ripwire

    Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.

    2.4k GitHub stars~4.8k tokensUpdated today
    Auto-check: notes
  • Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.

    2.4k GitHub stars~3.1k tokensUpdated today
    Auto-check: notes

Categories

Questions about Ripwire Layers

What does Ripwire Layers do?

Architecture HEALTH and ENFORCEMENT — 'is this a dependency mess / does the UI reach into the database / enforce module boundaries in CI?': cycles, the godfile, propagation cost (how far a touch…. Ripwire Layers is an agent skill from redhat-et/ripwire.': cycles, the godfile, propagation cost (how far a touch ripples), --arch rules with a baseline gate.

When should I use Ripwire Layers?

Ripwire Layers fits situations like: agent Workflows work in your project.

How do I install Ripwire Layers in Claude Code?

Run `npx skills add redhat-et/ripwire --skill ripwire-layers -a claude-code`. Or copy the skill folder (skills/ripwire-layers in redhat-et/ripwire) into .claude/skills/ripwire-layers in your project. Claude Code loads it when a task matches its description.

How do I install Ripwire Layers in Codex?

Run `npx skills add redhat-et/ripwire --skill ripwire-layers -a codex`. Or copy the skill folder (skills/ripwire-layers in redhat-et/ripwire) into .agents/skills/ripwire-layers in your project. Codex loads it when a task matches its description.

Can I use Ripwire Layers in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-layers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-layers, .gemini/skills/ripwire-layers, .github/skills/ripwire-layers and .opencode/skills/ripwire-layers in your project.

What does Ripwire Layers need to run?

SKILL.md names no scripts, command-line tools or credentials: Ripwire Layers is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, Read.

Does Ripwire Layers access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ripwire Layers safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ripwire Layers use?

Ripwire Layers is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ripwire Layers use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ripwire Layers?

Skills that share tags, products or a category with Ripwire Layers: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 296k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ripwire Layers?

redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,419 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.

Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.