Code Graph Mermaid Diagrams
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
Deep-dive codebase analysis that explains how things actually work — business rules, architecture patterns, auth flows, data models, integrations, and performance hotspots.
$ npx skills add rsmdt/the-startup --skill analyze -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rsmdt/the-startup analyze --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rsmdt/the-startup.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/start/skills/analyze .claude/skills/analyze && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyze" agent skill from https://github.com/rsmdt/the-startup/tree/main/plugins/start/skills/analyze into .claude/skills/analyze/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rsmdt/the-startup/tree/main/plugins/start/skills/analyzeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rsmdt/the-startup --skill analyze -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rsmdt/the-startup analyze --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rsmdt/the-startup.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/start/skills/analyze .agents/skills/analyze && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyze" agent skill from https://github.com/rsmdt/the-startup/tree/main/plugins/start/skills/analyze into .agents/skills/analyze/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rsmdt/the-startup --skill analyze -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rsmdt/the-startup analyze --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rsmdt/the-startup.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/start/skills/analyze .cursor/skills/analyze && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyze" agent skill from https://github.com/rsmdt/the-startup/tree/main/plugins/start/skills/analyze into .cursor/skills/analyze/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rsmdt/the-startup.git --path plugins/start/skills/analyze--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rsmdt/the-startup --skill analyze -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rsmdt/the-startup analyze --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rsmdt/the-startup.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/start/skills/analyze .gemini/skills/analyze && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyze" agent skill from https://github.com/rsmdt/the-startup/tree/main/plugins/start/skills/analyze into .gemini/skills/analyze/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rsmdt/the-startup analyzeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rsmdt/the-startup --skill analyze -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rsmdt/the-startup.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/start/skills/analyze .github/skills/analyze && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyze" agent skill from https://github.com/rsmdt/the-startup/tree/main/plugins/start/skills/analyze into .github/skills/analyze/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rsmdt/the-startup --skill analyze -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rsmdt/the-startup analyze --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rsmdt/the-startup.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/start/skills/analyze .opencode/skills/analyze && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyze" agent skill from https://github.com/rsmdt/the-startup/tree/main/plugins/start/skills/analyze into .opencode/skills/analyze/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyze", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzeDeep-dive codebase analysis that explains how things actually work — business rules, architecture patterns, auth flows, data models, integrations, and performance hotspots.
Analyze is an agent skill from rsmdt/the-startup. Deep-dive codebase analysis that explains how things actually work — business rules, architecture patterns, auth flows, data models, integrations, and performance hotspots. Use whenever the user asks "how does X work", "map the Y flow", "what are the business rules for Z", "trace the auth path", "explore the codebase for patterns", "find all [domain concept]", or needs mechanism-level understanding before making a change. Produces What/How/Why findings with file:line evidence, cross-cutting connections, and…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files (for example `evals/evals.json`, `examples/output-example.md` and `reference/output-format.md`).
It sits in Development, covering Software architecture, Codebase onboarding and Authentication. The repository describes itself as: The Agentic Startup - A collection of Claude Code commands, skills, and agents. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 88d447c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analyze loads about 1.9k tokens when it runs. Until then it costs about 140 tokens; SKILL.md has 780 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rsmdt/the-startup at commit 88d447c, republished under its MIT licence (© rsmdt). 780 words, ~1,863 tokens.
.claude/skills/analyze/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Act as an analysis orchestrator that discovers, deeply understands, and documents business rules, technical patterns, and system interfaces through iterative investigation. Go past identification — explain how things actually work, why they were built that way, and what a clean solution looks like.
Analysis Target: $ARGUMENTS
Discovery {
category: Business | Technical | Security | Performance | Integration | Data
finding: string
mechanism: string // HOW it works — trace the actual logic, data flow, or control flow
rationale: string // WHY it works this way — design intent, constraints, trade-offs
evidence: string // file:line references (multiple)
implications: string // what this means for the codebase
documentation: string // suggested doc content
location: string // docs/domain/ | docs/patterns/ | docs/interfaces/ | docs/research/
}State {
target = $ARGUMENTS
perspectives = [] // determined in step 1
mode: Standard | Agent Team
discoveries: Discovery[]
}Always:
reference/perspectives.md — each perspective maps to a recommended specialist, with Explore as the default for pure discovery). Don't spawn a generic subagent when a dedicated specialist fits better.docs/domain/, docs/patterns/, docs/interfaces/, and docs/research/ is pre-authorized. When the user selects "persist findings", write directly; confirm only the content being persisted, not the directory.Never:
Read reference/perspectives.md for perspective definitions and the focus-area mapping. Resolve $ARGUMENTS to a perspective set:
match (target) { maps to a focus area => select matching perspectives unclear or multi-area => AskUserQuestion to confirm scope before spawning agents }
AskUserQuestion: Standard (default) — parallel fire-and-forget subagents. Fastest for single-cycle analysis. Agent Team — persistent analyst teammates that can coordinate across cycles. Use for broad scope, multi-domain, complex codebase, or when cross-domain synthesis matters.
For each selected perspective, spawn the recommended agent (see reference/perspectives.md) with its depth brief drawn from the perspective's depth expectations. Pass the target and the specific questions each perspective owns.
Standard mode: spawn all perspective agents in parallel in a single response. Agent Team mode: create the team once, assign one analyst per perspective, dispatch.
Process findings in three layers:
Layer 1 — Mechanism check. For each finding, confirm the agent answered HOW. If a finding is surface-level (e.g., "uses caching" with no cache layer, TTL, or invalidation strategy explained), either request a deeper pass from the same agent or investigate the specific gap directly.
Layer 2 — Cross-cutting connections. Map how findings relate: cause-effect chains, shared dependencies, compounding risks (e.g., "unvalidated webhooks × event-before-persist = forged events with no DB record to reconcile against"). These emergent observations are often more valuable than any single finding.
Layer 3 — Solution framing. For every finding that surfaces a problem or opportunity:
Then deduplicate by evidence, group by theme, and build the cycle summary.
Follow reference/output-format.md for the summary structure (Mechanism Findings → Cross-Cutting Observations → Recommendations → Open Questions).
Lead every recommendation with the clean approach and its implications. Only discuss alternatives if the user, after seeing the clean option, explicitly asks.
AskUserQuestion: Continue to next area | Go deeper on [specific finding] | Persist findings to docs/ | Complete analysis
Write approved findings to the perspective's doc location (see reference/perspectives.md — docs/domain/, docs/patterns/, docs/interfaces/, or docs/research/). Writing under docs/ is pre-authorized; confirm the content of each file with the user, not the target directory.
© rsmdt, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files in plugins/start/skills/analyze of rsmdt/the-startup.
Open the folder on GitHubat commit 88d447c
Analyze next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyze this skillrsmdt/the-startup | 551 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Code Graph Mermaid Diagramstrailofbits/skills | 7.4k | 1 repos | ~1.7k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| GitDiagram Repository Overviewahmedkhaleel2004/gitdiagram | 18k | — | ~427 | Automated safety check: Pass | MIT | |
| Deepwiki Rssopaco/deepwiki-rs | 3.1k | — | ~748 | Automated safety check: Pass | MIT | |
| GitDiagram Repo Architectureahmedkhaleel2004/gitdiagram | 18k | — | ~429 | Automated safety check: Pass | MIT | |
| NGINX Ingress Controller Structurenginx/kubernetes-ingress | 5.1k | — | ~3.8k | Automated safety check: Pass | Apache-2.0 |
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
ahmedkhaleel2004/gitdiagram
Explains the architecture of a public GitHub repository through GitDiagram: how the code is organized, the main components with paths, and a Mermaid diagram.
sopaco/deepwiki-rs
AI-powered Rust documentation generation engine for comprehensive codebase analysis, C4 architecture diagrams, and automated technical documentation.
ahmedkhaleel2004/gitdiagram
Explains how a public GitHub repository is built by fetching its GitDiagram architecture diagram, components and optional explainer video.
nginx/kubernetes-ingress
Maps the NGINX Kubernetes Ingress Controller codebase: repository layout, architectural layers, layer-crossing rules and which files are generated.
cursor/plugins
Answers how-does-this-work and where-should-this-live questions by exploring the codebase with read-only subagents and writing an onboarding-depth explanation.
rsmdt/the-startup
Implementation entry point. An agent skill from rsmdt/the-startup.
rsmdt/the-startup
Factory loop orchestrator for multi-feature or multi-component implementation manifests.
rsmdt/the-startup
Context enrichment for agentic AI application development using LangChain, Vercel AI SDK, and assistant-ui.
rsmdt/the-startup
REST and GraphQL API design patterns, OpenAPI/Swagger specifications, versioning strategies, and authentication patterns.
rsmdt/the-startup
System architecture patterns including monolith, microservices, event-driven, and serverless, with C4 modeling, scalability strategies, and technology selection criteria.
rsmdt/the-startup
You MUST use this before any creative work — creating features, building components, adding functionality, or modifying behavior.
Categories
Deep-dive codebase analysis that explains how things actually work — business rules, architecture patterns, auth flows, data models, integrations, and performance hotspots. Analyze is an agent skill from rsmdt/the-startup. Deep-dive codebase analysis that explains how things actually work — business rules, architecture patterns, auth flows, data models, integrations, and performance hotspots.
Analyze fits situations like: the user asks how does X work; what are the business rules for Z; trace the auth path; explore the codebase for patterns.
Run `npx skills add rsmdt/the-startup --skill analyze -a claude-code`. Or copy the skill folder (plugins/start/skills/analyze in rsmdt/the-startup) into .claude/skills/analyze in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rsmdt/the-startup --skill analyze -a codex`. Or copy the skill folder (plugins/start/skills/analyze in rsmdt/the-startup) into .agents/skills/analyze in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rsmdt/the-startup --skill analyze -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyze, .gemini/skills/analyze, .github/skills/analyze and .opencode/skills/analyze in your project.
SKILL.md names no scripts, command-line tools or credentials: Analyze is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Analyze is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Analyze: Code Graph Mermaid Diagrams (trailofbits/skills, 7.4k stars), GitDiagram Repository Overview (ahmedkhaleel2004/gitdiagram, 18k stars), Deepwiki Rs (sopaco/deepwiki-rs, 3.1k stars) and GitDiagram Repo Architecture (ahmedkhaleel2004/gitdiagram, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rsmdt (a GitHub user) maintains it in rsmdt/the-startup, which has 551 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on August 3, 2026.
Source: rsmdt/the-startup on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.