Manage code knowledge graphs via code-review-graph (CRG). An agent skill from xwtro0tk1t-cloud/harness.

No licenceAuto-check passedKnowledge Management

Install Graph

skills CLI
$ npx skills add xwtro0tk1t-cloud/harness --skill graph -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xwtro0tk1t-cloud/harness graph --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xwtro0tk1t-cloud/harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/bundled-skills/graph .claude/skills/graph && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
graph
GitHub stars
265
Token cost
~1.1k tokens
SKILL.md length
189 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
None found

At a glance

Manage code knowledge graphs via code-review-graph (CRG). An agent skill from xwtro0tk1t-cloud/harness.

  • User says build graph
  • SKILL.md covers Overview, Commands, Graceful Degradation and Storage
  • Calls python
  • Harness init detects CRG

What it does

Graph is an agent skill from xwtro0tk1t-cloud/harness. Manage code knowledge graphs via code-review-graph (CRG). Build, update, and check status of project code graphs stored in .code-review-graph/graph.db. Use when: (1) user says "build graph", "update graph", "graph status", "/graph", (2) Harness init detects CRG, (3) preparing to use /explore commands. Gracefully degrades if CRG is not installed.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Knowledge Management, covering Knowledge graphs and Code review. The repository describes itself as: Harness is an AI Agent development guardrail Meta-Skill that establishes four layers of defense for any project in one command: knowledge management, architecture constraints…

When your agent uses it

  • User says build graph
  • Harness init detects CRG
  • Preparing to use /explore commands

Example prompts

  • “build graph”
  • “update graph”
  • “graph status”
  • “/graph”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 3e8bb50. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Graph loads about 1.1k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 189 words (~1,051 tokens).

“Manage project code knowledge graphs powered by code-review-graph. The graph stores code structure (functions, classes, calls, imports) in .code-review-graph/graph.db (SQLite) and enables architecture understanding, impact analysis, and caller/callee tracing.”

— opening of SKILL.md by xwtro0tk1t-cloud
name
graph

Read the full SKILL.md on GitHub

Files

Just SKILL.md in bundled-skills/graph of xwtro0tk1t-cloud/harness.

Open the folder on GitHubat commit 3e8bb50

Compare with similar skills

Graph next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Graph compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Graph this skillxwtro0tk1t-cloud/harness265—~1.1kAutomated safety check: PassNone
Codexqa Code Wikiopenqa-cn/codexqa152—~1.3kAutomated safety check: PassApache-2.0
Understand Diff AnalysisEgonex-AI/Understand-Anything85k1 repos~1.4kAutomated safety check: PassMIT
Code Review Graph Buildertirth8205/code-review-graph32k—~295Automated safety check: PassMIT
Knowledge Graph PR Reviewtirth8205/code-review-graph32k—~452Automated safety check: PassMIT
HypatiaMarchLiu/hypatia239—~7.9kAutomated safety check: NotesMIT

Similar skills

  • Codexqa Code Wiki

    openqa-cn/codexqa

    Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.

    152 GitHub stars~1.3k tokensUpdated 4 days ago
    Knowledge ManagementAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    85k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Code Review Graph Builder

    tirth8205/code-review-graph

    Builds or incrementally updates the code-review knowledge graph for a repository and reports whether the build succeeded, partly or failed.

    32k GitHub stars~295 tokensUpdated today
    DevelopmentAuto-check passed
  • Knowledge Graph PR Review

    tirth8205/code-review-graph

    Reviews a pull request or branch diff with a code knowledge graph and produces a structured review that includes blast-radius analysis.

    32k GitHub stars~452 tokensUpdated today
    DevelopmentAuto-check passed
  • Hypatia

    MarchLiu/hypatia

    Interact with the Hypatia AI memory system using natural language.

    239 GitHub stars~7.9k tokensUpdated 8 days ago
    Knowledge ManagementAuto-check: notes
  • Code Review

    OpenDCAI/DataMind

    Comprehensive code review guidance — process, checklist, feedback conventions.

    406 GitHub stars~340 tokensUpdated 17 days ago
    DevelopmentAuto-check passed

More from xwtro0tk1t-cloud/harness

  • Design Review

    xwtro0tk1t-cloud/harness

    Dispatch an independent challenger agent to adversarially review a spec or implementation plan against the actual codebase.

    265 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Explore

    xwtro0tk1t-cloud/harness

    Graph-driven project understanding using code-review-graph (CRG).

    265 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Sca AI Denoise

    xwtro0tk1t-cloud/harness

    SCA 漏洞 AI 降噪与风险优先级评估。对 Grype/Snyk/Xray 等 SCA 工具的漏洞发现进行多维度风险评估,按 P0-P3 分级,过滤噪音(DoS、本地提权、低影响信息泄露),聚焦真正可利用的高风险漏洞。当用户需要对 SCA 扫描结果降噪、漏洞优先级排序、或供应链风险评估时使用。

    265 GitHub stars~787 tokensUpdated 5 mo ago
    Auto-check passed
  • Security Review Skill Creator

    xwtro0tk1t-cloud/harness

    生成安全审计 skill。两种模式:(1) 项目模式——根据项目文档生成定制化审计 skill;(2) 通用模式——仅指定语言+框架,从参考资料库生成通用审计 skill。当用户想创建安全审计 skill、生成审计规则、或提到"生成安全审计skill"、"创建code review skill"、"生成 Java 审计 skill"时使用。

    265 GitHub stars~5.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Security Review Skill For Terraform

    xwtro0tk1t-cloud/harness

    审计 Terraform / IaC 代码安全(AWS 基础设施)。检测硬编码凭据、过宽 Security Group(0.0.0.0/0)、IAM 权限过大(Action/Resource )、S3 公开访问、RDS 未加密/公开、State 文件泄露、ECS/EKS 容器特权、CloudTrail/VPC FlowLog 缺失、不安全 Provider/Module 引用等。当审计…

    265 GitHub stars~4.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Security Review Skill For Docker

    xwtro0tk1t-cloud/harness

    审计 Docker/容器部署安全。检测 Dockerfile、docker-compose.yml、Kubernetes manifests 中的安全问题:特权容器、root 运行、敏感挂载、资源无限制、密钥泄露、Base Image 不合规、网络暴露等。当审计容器配置、Docker 安全、K8s 部署安全、或检查基础设施安全时使用。支持…

    265 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check: warnings

Questions about Graph

What does Graph do?

Manage code knowledge graphs via code-review-graph (CRG). An agent skill from xwtro0tk1t-cloud/harness. Graph is an agent skill from xwtro0tk1t-cloud/harness. Manage code knowledge graphs via code-review-graph (CRG).

When should I use Graph?

Graph fits situations like: user says build graph; harness init detects CRG; preparing to use /explore commands.

How do I install Graph in Claude Code?

Run `npx skills add xwtro0tk1t-cloud/harness --skill graph -a claude-code`. Or copy the skill folder (bundled-skills/graph in xwtro0tk1t-cloud/harness) into .claude/skills/graph in your project. Claude Code loads it when a task matches its description.

How do I install Graph in Codex?

Run `npx skills add xwtro0tk1t-cloud/harness --skill graph -a codex`. Or copy the skill folder (bundled-skills/graph in xwtro0tk1t-cloud/harness) into .agents/skills/graph in your project. Codex loads it when a task matches its description.

Can I use Graph in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xwtro0tk1t-cloud/harness --skill graph -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/graph, .gemini/skills/graph, .github/skills/graph and .opencode/skills/graph in your project.

What does Graph need to run?

Going by SKILL.md and its folder, Graph needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Graph access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Graph safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Graph use?

No licence was found for Graph or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Graph use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Graph?

Skills that share tags, products or a category with Graph: Codexqa Code Wiki (openqa-cn/codexqa, 152 stars), Understand Diff Analysis (Egonex-AI/Understand-Anything, 85k stars), Code Review Graph Builder (tirth8205/code-review-graph, 32k stars) and Knowledge Graph PR Review (tirth8205/code-review-graph, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Graph?

xwtro0tk1t-cloud (a GitHub user) maintains it in xwtro0tk1t-cloud/harness, which has 265 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on May 4, 2026.

Source: xwtro0tk1t-cloud/harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.