Agent skill

Graph DB Writes

by samugit83 in samugit83/redamon

Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

MITAuto-check passedSecurity

Install Graph DB Writes

skills CLI
$ npx skills add samugit83/redamon --skill graph-db-writes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install samugit83/redamon graph-db-writes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/samugit83/redamon.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/graph-db-writes .claude/skills/graph-db-writes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
graph-db-writes
GitHub stars
3k
Token cost
~2.2k tokens
SKILL.md length
873 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

  • Tasks that involve Penetration testing
  • SKILL.md covers When to Use, Critical Rules, MERGE: the copy target and Which mixin, plus 1 more section
  • Calls python3
  • Tasks that involve Threat modeling

What it does

Graph DB Writes is an agent skill from samugit83/redamon. Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must be updated together. A MERGE missing the tenant key silently merges one project's data into another's. Trigger: editing anything under graphdb/mixins/; adding or changing an updategraphfrom method; writing a Cypher MERGE/CREATE that adds a node, relationship or property; adding a new node label to the graph.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Penetration testing, Threat modeling and Multi-tenancy. It works with Neo4j. The repository describes itself as: Open-source, self-hosted AI penetration testing framework: maps your attack surface into a graph, autonomously exploits it from a Kali sandbox with human approval gates, and… The licence is MIT.

When your agent uses it

  • Tasks that involve Penetration testing
  • Tasks that involve Threat modeling
  • Tasks that involve Multi-tenancy

Example prompts

  • “s data into another”
  • “/graph-db-writes”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 5dd993c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Graph DB Writes loads about 2.2k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 873 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from samugit83/redamon at commit 5dd993c, republished under its MIT licence (© samugit83). 873 words, ~2,207 tokens.

Download SKILL.mdSave it as .claude/skills/graph-db-writes/SKILL.md (or your agent's skills folder).
name
graph-db-writes
description
Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must be updated together. A MERGE missing the tenant key silently merges one project's data into another's. Trigger: editing anything under graph_db/mixins/; adding or changing an update_graph_from_* method; writing a Cypher MERGE/CREATE that adds a node, relationship or property; adding a new node label to the graph.
license
MIT
metadata.author
redamon
metadata.version
1.1.0
metadata.scope
root
metadata.auto_invoke
Writing to the Neo4j graph or editing a graph_db mixin, Adding a node label, relationship, or property to the graph schema

When to Use

  • Adding or changing any Cypher that writes nodes/relationships/properties, in a graph_db mixin or a scan tool that persists to the graph.

For placing a whole new recon tool (which includes its graph write), use recon-tool-integration; this skill is the graph-write rules it depends on.


Critical Rules

  • NEVER add the tenant key to a reference node, and NEVER omit it from an entity node. Entity nodes (per-project findings) MERGE on {<natural_key>, user_id, project_id} - the tenant-isolation triple. A MERGE missing user_id/project_id merges one project's data into another's, silently. Global reference nodes (e.g. CVE) key on their natural id only (MERGE (c:CVE {id: $cve_id})); adding tenant keys there fragments shared data.
  • NEVER edit graph_db/neo4j_client.py directly. It is a thin orchestrator that combines the mixins by inheritance. Graph methods live in the mixin for their domain (see the table below).
  • NEVER unconditionally SET a field another tool owns. Use ON CREATE SET for provenance/first-writer fields (e.g. source) so a later tool merging the same node does not clobber them; use plain SET only for this tool's own enrichment fields. Reference: graph_db/mixins/graphql_mixin.py:189.
  • NEVER collect a field in a tool and not write it to the graph. Every field in the tool's output dict must land on a node property or relationship, or it is silent data loss. If it fits no node, map it to the closest property or say why it is dropped.
  • NEVER put a map, or a list of maps, in a property. Neo4j rejects it, so SET v += $props fails the whole node write and the mixin's per-finding except turns that into a silently dropped finding. Flatten first: nuclei's cves arrive as {id,cvss,url} maps and are stored as id strings via nuclei_cve_ids in graph_db/mixins/recon/vuln_mixin.py.
  • NEVER delete a finding a person has touched, and NEVER clear findings up front. A scan MERGEs its findings (which refreshes updated_at) and afterwards prunes the ones it did not touch - ingest-then-prune, never clear-then-ingest. A half-failed scan that reported nothing would otherwise empty the project, so the CALLER decides whether to prune and only does so after an ingest that actually produced findings. Nodes an operator muted and ones carrying triage_source = 'human' are never deleted, only stamped stale_since: they hold an operator's mute, verdict and the fix items written against them. A mute a node-filter RULE applied (muted_by starting rule:) is not a person's decision and is pruned like any stale finding. Reference: prune_unseen_findings in graph_db/mixins/base_mixin.py, and the four clears that spare them. A delete that spares muted findings takes the node's write lock (SET n._prune_lock = true REMOVE n._prune_lock) BEFORE it reads n:Muted, or a mute committing in between is deleted with the node. An external agent's MCP mute keeps the owner's id in muted_by, so it is kept like a person's; its muted_channel/muted_token stamp must be REMOVEd by every unmute and cleared by every other mute, or a later mute inherits it.
  • NEVER prune a source or host the run could not re-check (circuit breakers). When a data provider was paused or a scan host was skipped, "not seen this run" does NOT mean "gone". The caller passes keep_hosts (anchored regexes, matched against _KEEP_HOST_FIELDS with toStringOrNull, passed as a Cypher parameter) to prune_unseen_findings, and skips the prune entirely for a degraded source. What was cut is recorded on the Domain coverage record — recon_coverage_at, recon_coverage_gaps, recon_skipped_hosts, recon_nuclei_truncated (written by update_graph_coverage in graph_db/mixins/recon/domain_mixin.py). Those four are in the webapp's VOLATILE_PROPERTIES, so they never make a Domain read as "changed" in the Recon Delta.
  • NEVER write an unscoped MATCH for an entity node. Uniqueness is the (id, user_id, project_id) triple, so a natural id is NOT unique across the database and MATCH (n {id: $id}) can read or write another project's node. Every read and write carries user_id/project_id; agent-facing queries go through scope_query, never inject_tenant_filter alone.
  • ALWAYS reuse an existing node label before inventing one. Discovered hostnames are Subdomain, not a new label. Check graph_db/schema_sections.md first - that is the single declaration of every label, property and relationship.
  • ALWAYS declare a new label / relationship / property in ONE place: graph_db/schema_sections.md, then re-seed with python3 tooling/scripts/seed_schema_catalog.py. A uniqueness key also goes in graph_db/schema_keys.py, from which schema.py renders its CREATE CONSTRAINT statements. Do NOT copy the schema into the prompt or into GRAPH.SCHEMA.md: the prompt splices the catalog in at __GRAPH_SCHEMA__, and GRAPH.SCHEMA.md deliberately no longer lists labels at all. Three copies is what drifted, and four tests now fail if you make a fourth. Editing or removing a line there fails test_the_composed_document_still_contains_the_baseline in recon/tests/test_schema_catalog.py (additions pass: it is a CONTAINS check, so a stale golden file can sit unnoticed). Refresh the fixture in the same commit with the command in that test's docstring, then read the fixture diff. Still update NODE_COLORS in webapp/src/app/graph/config/colors.ts, which is presentation, not schema.
Show full SKILL.md (84 more words)Show less

MERGE: the copy target

cypher
// entity node - tenant-scoped: the {natural key, user_id, project_id} triple is mandatory
MERGE (bu:BaseURL {url: $baseurl, user_id: $user_id, project_id: $project_id})
  ON CREATE SET bu.source = 'graphql_scan', bu.updated_at = datetime()   // provenance: first writer only
MERGE (e:Endpoint {path: $path, method: 'POST', baseurl: $baseurl, user_id: $user_id, project_id: $project_id})
  ON CREATE SET e.source = 'graphql_scan'
  SET e += $props                                                        // this tool's own enrichment fields
MERGE (bu)-[:HAS_ENDPOINT]->(e)

// reference node - global: natural id only, NO tenant key
MERGE (c:CVE {id: $cve_id})

Copied from graph_db/mixins/graphql_mixin.py.

Which mixin

WritingMixin
core recon phases (subdomains, IPs, ports, HTTP, endpoints)recon_mixin.py
passive OSINT enrichmentosint_mixin.py
secrets / credentialssecret_mixin.py
vuln scan (GVM)gvm_mixin.py
GraphQL probesgraphql_mixin.py
supply-chain packagessupply_chain_mixin.py

Resources

© samugit83, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/graph-db-writes of samugit83/redamon.

Open the folder on GitHubat commit 5dd993c

Compare with similar skills

Graph DB Writes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Graph DB Writes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Graph DB Writes this skillsamugit83/redamon3k—~2.2kAutomated safety check: PassMIT
Securitytelagod/code-abyss244—~907Automated safety check: PassMIT
Csono-session/pstack136—~12kAutomated safety check: NotesMIT
Senior Securitydavila7/claude-code-templates33k2 repos~1.1kAutomated safety check: NotesMIT
Openfdd Mt Securitybbartling/open-fdd173—~2.2kAutomated safety check: PassCustom licence
Threat Model Disciplinehypnguyen1209/offensive-claude388—~660Automated safety check: PassMIT

Similar skills

  • Security

    telagod/code-abyss

    Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

    244 GitHub stars~907 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Cso

    no-session/pstack

    Chief Security Officer mode. An agent skill from no-session/pstack.

    136 GitHub stars~12k tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • Senior Security

    davila7/claude-code-templates

    Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

    33k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check: notes
  • Openfdd Mt Security

    bbartling/open-fdd

    Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.

    173 GitHub stars~2.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Threat Model Discipline

    hypnguyen1209/offensive-claude

    A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…

    388 GitHub stars~660 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Secure By Design

    ooiyeefei/ccc

    Run an enterprise security review of a system design or existing code before it ships.

    495 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from samugit83/redamon

All 15 skills in this repo
  • Add Community Skill

    samugit83/redamon

    Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

    3k GitHub stars~775 tokensUpdated yesterday
    Auto-check passed
  • Add Partial Recon

    samugit83/redamon

    Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

    3k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Agentic Tool Integration

    samugit83/redamon

    Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

    3k GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Builtin Agent Skill

    samugit83/redamon

    Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…

    3k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • LLM Provider Integration

    samugit83/redamon

    Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

    3k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • MCP Server Tools

    samugit83/redamon

    Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.

    3k GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Graph DB Writes

What does Graph DB Writes do?

Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…. Graph DB Writes is an agent skill from samugit83/redamon. Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must be updated together.

When should I use Graph DB Writes?

Graph DB Writes fits situations like: tasks that involve Penetration testing; tasks that involve Threat modeling; tasks that involve Multi-tenancy.

How do I install Graph DB Writes in Claude Code?

Run `npx skills add samugit83/redamon --skill graph-db-writes -a claude-code`. Or copy the skill folder (skills/graph-db-writes in samugit83/redamon) into .claude/skills/graph-db-writes in your project. Claude Code loads it when a task matches its description.

How do I install Graph DB Writes in Codex?

Run `npx skills add samugit83/redamon --skill graph-db-writes -a codex`. Or copy the skill folder (skills/graph-db-writes in samugit83/redamon) into .agents/skills/graph-db-writes in your project. Codex loads it when a task matches its description.

Can I use Graph DB Writes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add samugit83/redamon --skill graph-db-writes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/graph-db-writes, .gemini/skills/graph-db-writes, .github/skills/graph-db-writes and .opencode/skills/graph-db-writes in your project.

What does Graph DB Writes need to run?

Going by SKILL.md and its folder, Graph DB Writes needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Graph DB Writes access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Graph DB Writes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Graph DB Writes use?

Graph DB Writes is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Graph DB Writes use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Graph DB Writes?

Skills that share tags, products or a category with Graph DB Writes: Security (telagod/code-abyss, 244 stars), Cso (no-session/pstack, 136 stars), Senior Security (davila7/claude-code-templates, 33k stars) and Openfdd Mt Security (bbartling/open-fdd, 173 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Graph DB Writes?

samugit83 (a GitHub user) maintains it in samugit83/redamon, which has 2,982 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 8, 2026.

Source: samugit83/redamon on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.