Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Code Graph

ASecurity

Query the pre-built code-review-graph knowledge graph (Tree-sitter, whole monorepo) instead of walking call chains with Grep+Read — 2-6x cheaper, and it catches dynamic dispatch that grep misses. Use for ANY task that spans multiple files, even when the user never mentions a graph or asks for it - fixing or tracing a bug ("fix this bug", "why does X happen", "trace this"), exploring unfamiliar code ("how does X work", "who calls X", "what imports Y", "where is X used or handled"), planning or...

22,052 stars
0 votes
0 copies
1 views
Added 9/19/2026
developmentnodecode-reviewgit

Works with

mcp

Security Analysis

A100/100

Scanned 9/19/2026

$npx -y skills add handsontable/handsontable --skill code-graph --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Code Graph?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Code Graph
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/handsontable-code-graph/badge)](https://www.skillsdirectory.com/skills/handsontable-code-graph)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: code-graph
description: Query the pre-built code-review-graph knowledge graph (Tree-sitter, whole monorepo) instead of walking call chains with Grep+Read — 2-6x cheaper, and it catches dynamic dispatch that grep misses. Use for ANY task that spans multiple files, even when the user never mentions a graph or asks for it - fixing or tracing a bug ("fix this bug", "why does X happen", "trace this"), exploring unfamiliar code ("how does X work", "who calls X", "what imports Y", "where is X used or handled"), planning or doing a refactor ("rename X", "is it safe to change or remove X", "what would break", "blast radius", "find dead code"), or reviewing changes ("review this PR", "review this branch or diff"). If you are about to Grep for a symbol to find its callers, callees, or importers, stop and use this skill instead.
---

# Code graph (code-review-graph MCP)

One pre-built Tree-sitter knowledge graph over the whole monorepo answers cross-file questions far more cheaply than walking call chains with Grep+Read. It serves four modes — explore, debug, refactor, review — that share the same setup and tools.

## Bootstrap once per session

Graph MCP tools are deferred at session start, so a direct call fails with `InputValidationError`. Before your first graph call, load the schemas with one `ToolSearch`:

```
ToolSearch query: "select:mcp__code-review-graph__query_graph_tool,mcp__code-review-graph__get_impact_radius_tool,mcp__code-review-graph__detect_changes_tool,mcp__code-review-graph__get_affected_flows_tool"
```

Comma-separate whichever tools the task needs. One cheap call unblocks every graph query for the rest of the session.

## Keep the graph current

A graph built on another branch makes `detect_changes` report function names from unrelated files. Verify and rebuild when needed (the `PostToolUse` hook keeps it in sync after edits, so a manual rebuild is only needed after `git checkout` / `git pull` / large merges):

```
pipx run code-review-graph==2.3.6 status
pipx run code-review-graph==2.3.6 build
```

## Pick your mode

### Explore and understand

1. `list_graph_stats` for overall metrics.
2. `list_communities`, then `get_community` for a specific area.
3. `semantic_search_nodes` to find a function or class by name (keyword match, not natural language).
4. `query_graph` with `callers_of` / `callees_of` / `importers_of` to trace relationships, or `children_of` on a class to list its methods.
5. `list_flows` and `get_flow` to follow execution paths.

### Debug an issue

1. `semantic_search_nodes` to locate code related to the symptom.
2. `query_graph` `callers_of` and `callees_of` to trace the call chain in both directions — the entry point that triggers the bug is usually upstream.
3. `get_flow` for full execution paths through suspect areas.
4. `get_impact_radius` on suspect files to see what else is affected.
5. Recent changes are the most common cause — verify the branch, then use `detect_changes`.

### Plan a refactor

1. `get_impact_radius` and `get_affected_flows` to measure blast radius before touching code.
2. `refactor_tool` mode `rename` previews every affected location; `dead_code` finds unreferenced code; `suggest` proposes community-driven splits.
3. `apply_refactor_tool` with the `refactor_id` applies a previewed rename.
4. After changes, `detect_changes` to verify the impact.

**Caveat:** `refactor_tool`, `apply_refactor_tool`, and `find_large_functions` are not empirically validated on this codebase. Treat their output as hypotheses, not prescriptions — verify each edit against the real code, and always preview before applying.

### Review changes

1. `detect_changes` for risk-scored change analysis.
2. `get_affected_flows` for impacted execution paths.
3. `get_impact_radius` for the blast radius.
4. Test coverage: grep for `*.spec.js` / `*.unit.js` (do NOT use `tests_for` — it returns 0 incorrectly for many files). Suggest specific cases for untested changes.

Report findings grouped by risk (high/medium/low): what changed and why it matters, test-coverage status, suggested improvements, and an overall merge recommendation.

## Cross-cutting rules

- Always pass `detail_level: "minimal"` — standard mode repeats absolute paths per node and inflates tokens ~6x.
- Use fully qualified names: `path/to/file.ts::ClassName.methodName`. Bare names return an "ambiguous" error.
- Do NOT call `get_architecture_overview` — it returns ~3.9M characters and overflows context. Use `list_communities` + `get_community` instead.
- For single-file structure, grep is cheaper than `children_of`.
- Full setup, version pin, rebuild, and troubleshooting: `.ai/MCP.md` ("code-review-graph MCP").

Target: complete any graph task in ≤5 tool calls.

Attribution

handsontablehandsontable
View sourceMore from handsontable →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

285172 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10311 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →