skill-graph-audit
Audit Skill() refs; detect hubs, isolates, and dangling targets Skill: skill-graph-audit Owner: athola Summary: Audit Skill() refs; detect hubs, isolates, and dangling targets Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:04:29.511Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:28:35.983Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:28:27.913Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:45:32.077Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:51.280Z | us
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 10, 2026
Version
1.9.19
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 10, 2026
- Latest release
- 1.9.19release · observed Aug 26, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-abstract-skill-graph-audit- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/snapshot"
Documentation
CLAWHUB
105,625 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: skill-graph-audit
description: Audit Skill() refs; detect hubs, isolates, and dangling targets
version: 1.9.8
triggers:
- auditing skills
metadata: {"openclaw": {"homepage": "https://github.com/athola/claude-night-market/tree/master/plugins/abstract", "emoji": "\ud83e\udd9e"}}
source: claude-night-market
source_plugin: abstract
---
> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.
# Skill Graph Audit
## Overview
Build a directed graph of `Skill(plugin:name)` invocations across the
marketplace and surface composition patterns: which skills are heavily
referenced (hubs), which orchestrate many others (orchestrators), which
have no incoming or outgoing references (isolates), and which point at
non-existent skills (dangling references).
The federation graph is now derivable from source rather than
hand-curated.
## When To Use
- Before a documentation pass on skill composition
- After a renaming or retirement to catch broken `Skill()` references
- During quarterly audits to spot orphaned skills
- When evaluating consolidation candidates (hubs are higher-risk to merge)
- When a new skill's outbound references should be sanity-checked
## When NOT To Use
- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead
- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`
- For hook-specific audits -- use `Skill(abstract:hooks-eval)`
## Quick Start
```bash
python3 plugins/abstract/scripts/skill_graph.py \
--plugins-root plugins --top-n 10
```
For machine-readable output:
```bash
python3 plugins/abstract/scripts/skill_graph.py \
--plugins-root plugins --format json --output reports/skill-graph.json
```
See `modules/usage.md` for full CLI reference and example workflows.
## Core Outputs
| Output | Meaning | Action when high |
|--------|---------|------------------|
| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |
| Orchestrators | Skills that call many others | Verify each ref still resolves |
| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |
| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |
| Dangling -- external | Reference to external plugin | Document plugin dependency |
| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |
See `modules/interpretation.md` for false-positive guidance and
isolation taxonomy.
## Dogfood Evidence
This skill itself was scaffolded TDD-first; on first run against
`plugins/`, it caught two genuine dangling refs that the manual
audit (2026-04-25) had missed:
- `attune:makefile-generation -> abstract:makefile-dogfooder`
(script name confused with skill name)
- `imbue:karpathy-principles -> spec-kit:speckit-clarify`
(command referenced as skill)
Both we_meta.json
{
"ownerId": "kn7d107jg9jv602h9ytsegydq184a42s",
"slug": "nm-abstract-skill-graph-audit",
"version": "1.9.19",
"publishedAt": 1787749469511
}modules/interpretation.md
--- name: skill-graph-audit-interpretation description: How to interpret graph metrics, including isolate taxonomy and false-positive guidance. --- # Interpreting Graph Metrics ## Isolate Taxonomy A skill flagged as "isolate" (zero inbound, zero outbound) is not necessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate roles produce zero edges: ### 1. Library skills Skills consumed via `dependencies:` frontmatter from other skills or via Python imports rather than `Skill()` calls. Example: `abstract:shared-patterns`. **Action**: confirm `dependencies:` field in callers. ### 2. Entrypoint skills Skills invoked directly by users via slash commands or by an external orchestrator (e.g. `egregore:summon`). Example: `abstract:plugin-review`. **Action**: confirm a corresponding command file exists in `plugins/<plugin>/commands/`. ### 3. Hook-target skills Skills that hooks redirect to. Example: `imbue:proof-of-work`. **Action**: confirm a `PreToolUse`/`PostToolUse` hook in `plugins/<plugin>/hooks.json` references the skill. A skill that fits none of the three is a true orphan and a candidate for retirement. ## Hub Sensitivity Skills with high inbound count are load-bearing. Before retiring or splitting one: - Run `rg "Skill\\(<plugin>:<name>\\)" plugins/` to enumerate callers - Open a deprecation issue with at least 30-day notice - Provide a migration target in the deprecation note The current top-5 hubs (as of 2026-04-25) are: 1. `scribe:slop-detector` 2. `attune:project-brainstorming` 3. `sanctum:git-workspace-review` 4. `attune:project-planning` 5. `attune:project-specification` ## Dangling Reference Triage | Class | Default action | |-------|----------------| | bugs | Fix in the same PR; do not merge with bugs > 0 | | external | Confirm external plugin is documented in plugin.json | | placeholders | Annotate with `<!-- template -->` to suppress | ## Cross-Plugin Coupling A high count of cross-plugin edges (src plugin != dst plugin) is healthy ecosystem behaviour, not a problem. A high count of intra-plugin edges (src plugin == dst plugin) suggests a plugin-internal federation worth documenting in the plugin's README. ## Common False Positives - Skill names in code blocks demonstrating example usage are still parsed. If documenting a hypothetical skill, use `<plugin>:<name>` without backticks or surround with `<!-- example -->`. - Skill names mentioned in `docs/decisions/` outside SKILL.md files are not parsed (only SKILL.md is the source of truth).
modules/usage.md
---
name: skill-graph-audit-usage
description: CLI reference and example workflows for the skill graph audit tool.
---
# Usage Reference
## CLI Flags
```text
python3 plugins/abstract/scripts/skill_graph.py [OPTIONS]
--plugins-root PATH Root containing <plugin>/skills/<name>/ tree
(default: plugins)
--top-n INT Top N hubs/orchestrators to show (default: 10)
--format {text,json} Output format (default: text)
--output PATH Write to file instead of stdout
```
## Common Workflows
### Pre-release dangling-ref check
```bash
python3 plugins/abstract/scripts/skill_graph.py \
--plugins-root plugins --format json --output /tmp/graph.json
python3 -c "
import json
report = json.load(open('/tmp/graph.json'))
bugs = report['dangling_refs']['bugs']
if bugs:
print(f'BLOCKING: {len(bugs)} dangling refs')
for b in bugs:
print(f' {b[\"source\"]} -> {b[\"target\"]}')
raise SystemExit(1)
print('OK: 0 internal dangling references')
"
```
### Find consolidation candidates
Hubs with >5 inbound references are core API; orchestrators with
>5 outbound references are coordination points. The intersection
(hub AND orchestrator) is the federation backbone.
```bash
python3 plugins/abstract/scripts/skill_graph.py --top-n 20 \
| tee /tmp/graph.txt
```
### Update composition documentation
Generate the federation table for `docs/quality-gates.md` from
report JSON instead of curating manually.
## Updating External Plugin Allowlist
If a new external plugin is referenced (one not yet in
`KNOWN_EXTERNAL_PLUGINS`), update the constant in
`plugins/abstract/scripts/skill_graph.py` so refs to it are
classified as `external` rather than `bugs`.
## Limitations
- Detects only `Skill(plugin:name)` invocations. Free-text mentions
in prose are not parsed.
- Self-references (a skill referencing itself) are skipped to avoid
cycles in counts.
- Module-level `dependencies:` and `modules:` frontmatter are not
yet treated as edges; see backlog item for planned extension.skill-card.md
## Description: Audit Skill() refs; detect hubs, isolates, and dangling targets. This skill is ready for commercial/non-commercial use. ## Publisher: [athola](https://clawhub.ai/user/athola) ### License/Terms of Use: MIT-0 ## Use Case: Developers and maintainers use this skill to audit Skill() references across a marketplace, identify hubs, orchestrators, isolates, and dangling targets, and sanity-check composition before documentation, renaming, retirement, or release work. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill references a skill_graph.py implementation that is not included in this package. Mitigation: Confirm the script comes from the intended source before running commands from the workflow. Risk: Graph audit output can be misleading if it is stale or if a Skill() syntax variant is not detected. Mitigation: Run the documented test-suite correctness check or round-trip smoke check before using results for release or retirement decisions. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit) - [Clawdis homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) - [Usage Reference](artifact/modules/usage.md) - [Interpreting Graph Metrics](artifact/modules/interpretation.md) ## Skill Output: **Output Type(s):** [Text, Markdown, Shell commands, Guidance] **Output Format:** [Markdown with inline bash and JSON examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Can guide generation of text or JSON graph audit reports through the referenced CLI.] ## Skill Version(s): 1.9.19 (source: server release evidence; artifact frontmatter reports 1.9.8) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit",
"sourceUrl": "https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T22:47:19.093Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T22:47:19.093Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/athola/nm-abstract-skill-graph-audit",
"sourceUrl": "https://clawhub.ai/athola/nm-abstract-skill-graph-audit",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T22:47:19.093Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.19",
"href": "https://clawhub.ai/athola/nm-abstract-skill-graph-audit",
"sourceUrl": "https://clawhub.ai/athola/nm-abstract-skill-graph-audit",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:04:29.511Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.19",
"description": "Release v1.9.19",
"href": "https://clawhub.ai/athola/nm-abstract-skill-graph-audit",
"sourceUrl": "https://clawhub.ai/athola/nm-abstract-skill-graph-audit",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-26T13:04:29.511Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
