Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Indexing Code

DSecurity

Code relationship graph and temporal intelligence via abyss CLI. Provides caller tracing, impact analysis, hotspot detection, and file-level context gathering. Agent automatically runs abyss before modifying code to check impact. Works with any agent that has shell access.

239 stars
0 votes
0 copies
0 views
Added 9/6/2026
ai-agentsgoshellbashnodegitapi

Works with

claude codecliapimcp

Security Analysis

D42/100
criticalPipes output to a shell interpreter
mediumUses curl or wget to download content
criticalDownloads and executes remote scripts — classic supply chain attack

Pro scans all 11 files and shows the line behind each finding

Scanned 9/6/2026

$npx -y skills add telagod/code-abyss --skill indexing-code --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Indexing Code?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Indexing Code
[![Security: D — Skills Directory](https://www.skillsdirectory.com/api/skills/telagod-indexing-code/badge)](https://www.skillsdirectory.com/skills/telagod-indexing-code)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: indexing-code
description: Code relationship graph and temporal intelligence via abyss CLI. Provides caller tracing, impact analysis, hotspot detection, and file-level context gathering. Agent automatically runs abyss before modifying code to check impact. Works with any agent that has shell access.
user-invocable: false
allowed-tools: Bash, Read
---

# 代码关系图 · abyss

> 不是搜索工具,是代码的调用图 + 时间智能。通过 shell 调用 `abyss` CLI。

## 前置

进入项目时,检查并初始化索引:

```sh
command -v abyss >/dev/null && [ ! -f .code-abyss/index.db ] && abyss index
```

## 核心行为

### 改文件前:跑 `abyss context`

即将修改任何代码文件时,先获取该文件的完整上下文(不需要知道函数名):

```sh
abyss context <要修改的文件路径> --json
```

返回:该文件所有函数的外部调用方、依赖的类型和函数、热点评分、耦合文件。

根据返回结果:
- 有 production callers:检查改动是否会破坏调用方,改完逐个同步
- hotspot score > 5000:高风险文件,跑 `abyss impact <func> --json` 深入分析
- impact risk > 7/10:跟用户确认方案后再改
- 有 uncovered paths:提醒用户补测试
- 有 coupled files:检查耦合文件是否需要同步修改

### 其他场景

| 场景 | 命令 |
|------|------|
| 初识项目架构 | `abyss map --json` |
| 追查 bug 来源 | `abyss history <file> --symbol <func> --json` |
| 搜索代码(比 grep 好) | `abyss search "关键词" --json` |

## 输出说明

`--json` 输出结构化 JSON,agent 直接解析。不加 `--json` 输出人类可读文本。

### context 输出关键字段

```json
{
  "symbols_with_external_callers": [
    { "symbol": "SetError",
      "external_callers": [
        { "file": "handler.go", "line": 42, "caller": "HandleRequest",
          "confidence": 0.95, "is_test": false }
      ],
      "possible_callers": []
    }
  ],
  "dependencies": [{ "name": "Account", "file": "types.go", "kind": "type_ref" }],
  "hotspot": { "score": 5200, "changes_30d": 12, "complexity": 433 },
  "coupled_files": [{ "file": "gateway.go", "co_changes": 13, "coupling": "65%" }]
}
```

- `external_callers`:confidence ≥ 0.7 的可信调用方,按解析档位标注(1.0 同文件 / 0.95 同包 / 0.9 import 限定 / 0.8 全局唯一)
- `possible_callers`:confidence < 0.7 的歧义匹配——参考线索,不是事实,勿据此改调用方

### impact 输出关键字段

```json
{
  "direct_callers": 17,
  "transitive_callers": 521,
  "uncovered_paths": ["handler.go:DoSomething"],
  "risk_score": 8.5,
  "risk_factors": ["high blast radius", "319 paths without test coverage"]
}
```

## CLI 速查

```
abyss index                           # 建索引(~5s)
abyss context <file> [--json]         # 文件完整上下文(改代码前用这个)
abyss callers <symbol> [--json]       # 谁调了这个函数(默认隐藏 confidence < 0.7)
abyss callers <symbol> --min-confidence 0   # 连歧义匹配一起看
abyss impact <symbol> [--json]        # 改了会影响什么(低置信边被排除时会在 risk_factors 标注)
abyss hook pre-edit                   # agent hook:stdin 读 tool JSON,增量刷新索引后输出警告
abyss hook post-edit                  # agent hook:编辑后增量刷新索引
abyss search "query" [--json]         # 搜索代码
abyss map [--json]                    # 项目热点+耦合
abyss history <file> [--symbol X]     # 变更历史
abyss stats                           # 索引统计
```

## Hook 自动执行

Hook 注入按 host 分两条路径(hybrid 切割架构,2026-06-25 锁定):

**claude / codex / gemini** — 由 abyss CLI 的 `attach` 子命令负责(production 主入口,abyss v0.5.20+):

```sh
abyss attach claude     # → ~/.claude/settings.json
abyss attach codex      # → ~/.codex/config.toml(Codex 0.125+ 数组表)
abyss attach gemini     # → ~/.gemini/settings.json(SessionStart/BeforeTool/AfterTool)
abyss attach all        # 三平台一次完成
```

幂等,重跑覆盖旧 shape,不污染其它键。

二进制查找顺序:PATH → `~/.code-abyss/bin/abyss`。两处都没有时 hook 静默停用,后装 abyss 即生效,无需重装。

> **v4.8.x → v4.9 deprecation 期变更**
> - `--with-hooks` 对 claude/codex/gemini 仍写入 hook,但 install.js 打印 warning 引导改用 `abyss attach <host>`;v5.0 移除该路径(openclaw/pi/hermes 的 `--with-hooks` 永久保留并改造为 spawn install-hooks.sh)
> - `--with-abyss` **已移除**(Agent OS v5.1)。请用 `curl -fsSL https://raw.githubusercontent.com/telagod/abyss/main/install.sh | bash`;claude/codex/gemini graph hooks 用 `abyss attach <host>`
> - `--with-mcp` 注册 abyss MCP 进入 deprecation,引导用户改用 `abyss mcp` 客户端自配;v5.0 移除

**openclaw / pi / hermes** — 由 code-abyss npm 包负责(abyss CLI 不接管这三平台,见 abyss `src/attach/mod.rs` 注释):

```sh
npx code-abyss --target openclaw --with-hooks   # 自动 spawn install-hooks.sh
npx code-abyss --target pi       --with-hooks
npx code-abyss --target hermes   --with-hooks
```

或脱离安装器直接跑脚本:

```sh
bash skills/indexing-code/hooks/common/install-hooks.sh auto   # 自动检测平台
```

自动检测平台并注入对应 hook 配置(幂等,JSON 合并用 node):

| 平台 | Hook 事件 | 配置位置 |
|------|----------|---------|
| Claude Code | `PreToolUse`(Edit\|Write) | `.claude/settings.json` |
| Codex CLI | `PreToolUse`(Bash\|shell\|apply_patch\|Edit\|Write) | `~/.codex/config.toml` |
| Gemini CLI | `BeforeTool`(write_file\|replace) | `~/.gemini/settings.json` |
| Pi Agent | `tool_call`(edit_file\|write_file) | `~/.pi/agent/settings.json` |
| Hermes | `pre_tool_call` | `~/.hermes/config.yaml` 或 plugin |
| OpenClaw | `before_tool_call` | plugin `api.on()` |

统一入口是 `abyss hook pre-edit`(shell 脚本只是带存在性守卫的薄壳):自动识别各平台 stdin JSON 形状、增量刷新索引(警告反映文件当前状态而非旧索引)、输出生产调用方 / 歧义引用 / 热点警告。编辑后可挂 `abyss hook post-edit` 保持索引新鲜。agent 无需手动调用。

Attribution

telagodtelagod
View sourceSee grades on GitHubMore from telagod →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →