Agent skill

Ripwire Repo Map

by redhat-et in redhat-et/ripwire

Maps a repository with the ripwire CLI before reading code, ranking what to touch, who calls it and which tests to run.

Apache-2.0Auto-check passedDevelopment

Install Ripwire Repo Map

skills CLI
$ npx skills add redhat-et/ripwire --skill ripwire-repo-map -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redhat-et/ripwire ripwire-repo-map --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hermes/ripwire-repo-map .claude/skills/ripwire-repo-map && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ripwire-repo-map
GitHub stars
2.4k
Token cost
~1.2k tokens
SKILL.md length
515 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Maps a repository with the ripwire CLI before reading code, ranking what to touch, who calls it and which tests to run.

  • Works in 6 steps: First call on a tree parses (~1s at… → top-k is NOT read by --for's own bundle… → Markdown/docs-only or shell-only repos… → …
  • Landing in an unfamiliar repository and needing its structure fast
  • SKILL.md covers When to reach for it (instead…, Core verbs (all take a repo…, Honesty signals — read them… and Pitfalls, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ripwire is a zero-dependency C++23 command-line tool that builds a ranked, deterministic call graph of a repository, works offline with no API key or daemon, and caches after the first parse. The skill tells the agent to reach for it through the terminal when landing cold in a repo, searching for code by concept, assessing a proposed change, resuming after compaction or reviewing code the agent did not write.

Core commands take a repo directory: `--report` for an architecture summary, `--for` with a task described in plain words for a ranked list, and `--callers` for blast radius. The agent reads the map and then opens only the files it surfaces. It is also taught to read honesty signals before trusting output: confidence and margin on the result, estimated tokens, whether bodies were shipped, a `--skipped` list of dropped files, and an `amb` marker for ambiguous call matches. Trivial single-file lookups are better served by plain search.

When your agent uses it

  • Landing in an unfamiliar repository and needing its structure fast
  • Finding where a feature or concept lives without grepping the whole tree
  • Seeing who calls a function and which tests to run before a change
  • Resuming in-flight work after a context reset

Example prompts

  • “Map this repo with ripwire before we change anything.”
  • “Where is the code that handles webhook retries?”
  • “Who calls parseConfig, and which tests should I run if I change it?”

Requirements

  • The ripwire release binary on PATH

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. First call on a tree parses (~1s at 1,500+ files; measured ≈1.2s wall for a 2,355-file /
  2. top-k is NOT read by --for's own bundle (it shapes the default map and --query; it still
  3. Markdown/docs-only or shell-only repos yield few call-graph edges — --report is still useful, edges are not.
  4. The tool indexes signatures, not necessarily full bodies, by default on conceptual queries — --expand
  5. Cache/notes live in the repo tree (.ripwire_notes for --note-add); the notes file is meant to be committed.
  6. ripwire output can be large on big repos — budget with --max-tokens=8000 / --top-k=50 where supported.

What it can do on your machine

Read from SKILL.md and the folder at commit 60dd3b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ripwire Repo Map loads about 1.2k tokens when it runs. Until then it costs about 16 tokens; SKILL.md has 515 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~16
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redhat-et/ripwire at commit 60dd3b3, republished under its Apache-2.0 licence (© redhat-et). 515 words, ~1,227 tokens.

Download SKILL.mdSave it as .claude/skills/ripwire-repo-map/SKILL.md (or your agent's skills folder).
name
ripwire-repo-map
description
Use ripwire CLI to map a repo before reading it.
version
1.0.0
author
Ashutosh Singh
license
Apache-2.0
platforms
linux, macos
prerequisites.commands
ripwire

ripwire — deterministic repo map before reading code

ripwire (v0.4.x at authoring time; the release binary must be on PATH) is a zero-dependency C++23 CLI that builds a ranked, deterministic call graph of any repo in ~1s (parses once, then auto-caches warm). It answers "what to touch, what it breaks, which tests to run" for a fraction of the tokens of grep + whole-file reads. No API key, no daemon, no index server, offline. Invoke it via the terminal tool.

When to reach for it (instead of blind grep / whole-file reads)

  • Landing cold in a repo or subsystem — "what's here, how is it organized, what matters"
  • "Where is the code for X" — a task, feature, or concept in your own words
  • A change is proposed — what breaks, who calls it, which tests must run
  • Resuming work after compaction / a new session on in-flight work
  • Reviewing code you did not write (fresh eyes), or pre-commit change vetting

Do NOT use for trivial single-file lookups (plain rg/search_files wins) or broad common-word questions — ripwire shines on specific technical asks.

Core verbs (all take a repo dir; --help is authoritative)

bash
ripwire <dir> --report            # architecture summary: modules, god-files, cycles, top symbols
ripwire <dir> --for="<task in your own words>"   # ranked task lens: what to touch first, with 1-hop edges
ripwire <dir> --callers=someFunc --legend=compact  # who calls it (blast radius)
ripwire <dir> --test-gate --legend=compact         # which tests must run before committing
ripwire <dir> --tree --legend=compact              # file-by-file: top symbols per file
ripwire <dir> --hotspots --legend=compact          # files ranked by churn × complexity
ripwire <dir> --communities --legend=compact       # cohesive modules (Louvain) + bridges — where a new feature belongs
ripwire <dir> --situ              # what the working tree already changed + its blast radius (resuming work)
ripwire <dir> --notes --legend=compact             # pinned gotchas from past sessions (field notes)
ripwire <git-url>                 # orient in a remote repo (shallow-clones into a cached temp dir; --refetch refreshes)

Read the map, then open only the files it surfaces (god-files and hotspots first). For a body of one ranked symbol: ripwire <dir> --for="..." --expand=path:name (paste p=/n= off the row).

Honesty signals — read them before trusting a result

  • The --for lens reports confidence=/margin_pct= on its result root and the output carries est_tokens= — confidence="low" or a flat ranking means treat the set as a starting point, not an answer.
  • --for bundles: bodies="0" = no full bodies shipped (reason="compact-route"; --auto-bodies restores them. A reason="budget" means the caller's token budget cut them — raise the budget instead).
  • --skipped lists files the index dropped (oversize, or .gitignored — default ignored; --no-ignore restores the full walk). A "not found" is only trustworthy after checking this.
  • amb="K" on a symbol means K of its outbound calls matched several possible definitions — the resolver split the weight instead of choosing one. Read the source if the target matters. (lpin= is a separate, disclosed guess the resolver made; same remedy.)
Show full SKILL.md (173 more words)Show less

Pitfalls

  1. First call on a tree parses (~1s at 1,500+ files; measured ≈1.2s wall for a 2,355-file / 77k-edge checkout on Apple M2). Later calls are warm and near-instant — chain verbs freely.
  2. --top-k is NOT read by --for's own bundle (it shapes the default map and --query; it still applies to --format=candidates with --for).
  3. Markdown/docs-only or shell-only repos yield few call-graph edges — --report is still useful, edges are not.
  4. The tool indexes signatures, not necessarily full bodies, by default on conceptual queries — --expand or --auto-bodies when you need the body.
  5. Cache/notes live in the repo tree (.ripwire_notes for --note-add); the notes file is meant to be committed.
  6. ripwire output can be large on big repos — budget with --max-tokens=8000 / --top-k=50 where supported.
  • Upstream: https://github.com/redhat-et/ripwire (Apache-2.0; releases ship prebuilt macOS/Linux binaries + SHA-256)
  • The project ships 18 agent skills (Claude Code/Codex format) under skills/ in its repo — this Hermes skill is the distilled Hermes-format counterpart to that family (ripwire-orient is the closest base); read those upstream for deeper flows.

© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hermes/ripwire-repo-map of redhat-et/ripwire.

Open the folder on GitHubat commit 60dd3b3

Compare with similar skills

Ripwire Repo Map next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ripwire Repo Map compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ripwire Repo Map this skillredhat-et/ripwire2.4k—~1.2kAutomated safety check: PassApache-2.0
Repomix Codebase Exploreryamadashy/repomix29k—~2.7kAutomated safety check: PassMIT
Acquire Codebase Knowledgegithub/awesome-copilot40k1 repos~2.3kAutomated safety check: PassMIT
tilth Code Reading CLIjahala/tilth352—~1.1kAutomated safety check: PassMIT
BiSheng Approval Module Referencedataelement/bisheng12k—~4kAutomated safety check: PassApache-2.0
BTCA Local Repo Searchstickerdaniel/linkedin-mcp-server3.8k—~660Automated safety check: PassApache-2.0

Similar skills

  • Repomix Codebase Explorer

    yamadashy/repomix

    Packs a local or remote repository into a single AI-friendly file with the Repomix CLI, then reads and searches that output to explain structure, find patterns or report metrics.

    29k GitHub stars~2.7k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    DevelopmentAuto-check passed
  • Replaces grep, cat, find and ls with the tilth CLI, which returns AST-aware outlines, definitions, usages and callers across many languages in one call.

    352 GitHub stars~1.1k tokensUpdated 13 days ago
    DevelopmentAuto-check passed
  • Maps BiSheng's approval-center architecture to exact service files and methods, so a change to approval logic can be located without searching the whole repo.

    12k GitHub stars~4k tokensUpdated today
    DevelopmentAuto-check passed
  • BTCA Local Repo Search

    stickerdaniel/linkedin-mcp-server

    Searches git repositories cloned locally under a sandbox folder to answer questions with cited links and complete code snippets.

    3.8k GitHub stars~660 tokensUpdated today
    DevelopmentAuto-check passed
  • trace-mcp Code Navigation

    nikolai-vysotskyi/trace-mcp

    Routes code exploration through trace-mcp's indexed dependency graph, using symbol search, outlines, call graphs and change-impact tools instead of Read, Grep and Glob.

    188 GitHub stars~1.6k tokensUpdated today
    DevelopmentAuto-check: notes

More from redhat-et/ripwire

All 19 skills in this repo
  • Ripwire Output Emission

    redhat-et/ripwire

    Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.

    2.4k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Ripwire Change Check

    redhat-et/ripwire

    Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.

    2.4k GitHub stars~4.3k tokensUpdated yesterday
    Auto-check: notes
  • Ripwire Graph Query

    redhat-et/ripwire

    Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

    2.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes
  • Ripwire Subsystem Handoff

    redhat-et/ripwire

    Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

    2.4k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • Ripwire Code Navigation

    redhat-et/ripwire

    Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.

    2.4k GitHub stars~4.8k tokensUpdated yesterday
    Auto-check: notes
  • Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.

    2.4k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Ripwire Repo Map

What does Ripwire Repo Map do?

Maps a repository with the ripwire CLI before reading code, ranking what to touch, who calls it and which tests to run. Ripwire is a zero-dependency C++23 command-line tool that builds a ranked, deterministic call graph of a repository, works offline with no API key or daemon, and caches after the first parse. The skill tells the agent to reach for it through the terminal when landing cold in a repo, searching for code by concept, assessing a proposed change, resuming after compaction or reviewing code the agent did not write.

When should I use Ripwire Repo Map?

Ripwire Repo Map fits situations like: landing in an unfamiliar repository and needing its structure fast; finding where a feature or concept lives without grepping the whole tree; seeing who calls a function and which tests to run before a change; resuming in-flight work after a context reset.

How do I install Ripwire Repo Map in Claude Code?

Run `npx skills add redhat-et/ripwire --skill ripwire-repo-map -a claude-code`. Or copy the skill folder (skills/hermes/ripwire-repo-map in redhat-et/ripwire) into .claude/skills/ripwire-repo-map in your project. Claude Code loads it when a task matches its description.

How do I install Ripwire Repo Map in Codex?

Run `npx skills add redhat-et/ripwire --skill ripwire-repo-map -a codex`. Or copy the skill folder (skills/hermes/ripwire-repo-map in redhat-et/ripwire) into .agents/skills/ripwire-repo-map in your project. Codex loads it when a task matches its description.

Can I use Ripwire Repo Map in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-repo-map -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-repo-map, .gemini/skills/ripwire-repo-map, .github/skills/ripwire-repo-map and .opencode/skills/ripwire-repo-map in your project.

What does Ripwire Repo Map need to run?

SKILL.md names no scripts, command-line tools or credentials: Ripwire Repo Map is instructions for the agent only. Our summary lists: The ripwire release binary on PATH.

Does Ripwire Repo Map access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ripwire Repo Map safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ripwire Repo Map use?

Ripwire Repo Map is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ripwire Repo Map use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ripwire Repo Map?

Skills that share tags, products or a category with Ripwire Repo Map: Repomix Codebase Explorer (yamadashy/repomix, 29k stars), Acquire Codebase Knowledge (github/awesome-copilot, 40k stars), tilth Code Reading CLI (jahala/tilth, 352 stars) and BiSheng Approval Module Reference (dataelement/bisheng, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ripwire Repo Map?

redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,428 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.