{"id":"b6969728-4c7a-419c-9417-3f3cdad9c1b1","entityType":"agent","slug":"clawhub-athola-nm-abstract-skill-graph-audit","name":"skill-graph-audit","canonicalUrl":"https://www.xpersona.co/agent/clawhub-athola-nm-abstract-skill-graph-audit","canonicalPath":"/agent/clawhub-athola-nm-abstract-skill-graph-audit","generatedAt":"2026-10-11T01:48:17.207Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T22:47:19.093Z","emptyReason":null},"description":"Audit Skill() refs; detect hubs, isolates, and dangling targets Skill: skill-graph-audit Owner: athola Summary: Audit Skill() refs; detect hubs, isolates, and dangling targets Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:04:29.511Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:28:35.983Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:28:27.913Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:45:32.077Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:51.280Z | us","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-abstract-skill-graph-audit","sourceUrl":"https://clawhub.ai/athola/nm-abstract-skill-graph-audit","homepage":"https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/athola/nm-abstract-skill-graph-audit","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Audit Skill() refs; detect hubs, isolates, and dangling targets Skill: skill-graph-audit Owner: athola Summary: Audit Skill() refs; detect hubs, isolates, and d"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:47:19.093Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:47:19.093Z","emptyReason":null},"stars":null,"forks":null,"downloads":1238,"packageName":null,"latestVersion":"1.9.19","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T22:47:19.033Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T22:47:19.093Z","lastCrawledAt":"2026-10-10T22:47:19.033Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T22:47:19.033Z","lastVerifiedAt":null,"highlights":[{"version":"1.9.19","createdAt":"2026-08-26T13:04:29.511Z","changelog":"Release v1.9.19","fileCount":5,"zipByteSize":6236},{"version":"1.9.18","createdAt":"2026-08-15T21:28:35.983Z","changelog":"Release v1.9.18","fileCount":5,"zipByteSize":6144},{"version":"1.9.17","createdAt":"2026-07-30T05:28:27.913Z","changelog":"Release v1.9.17","fileCount":5,"zipByteSize":6318},{"version":"1.9.16","createdAt":"2026-07-14T19:45:32.077Z","changelog":"Release v1.9.16","fileCount":5,"zipByteSize":6283},{"version":"1.9.15","createdAt":"2026-07-04T21:19:51.280Z","changelog":"Release v1.9.15","fileCount":5,"zipByteSize":6270},{"version":"1.9.14","createdAt":"2026-06-30T17:50:25.759Z","changelog":"Release v1.9.14","fileCount":5,"zipByteSize":6319},{"version":"1.9.13","createdAt":"2026-06-27T16:15:00.115Z","changelog":"Release v1.9.13","fileCount":5,"zipByteSize":6249},{"version":"1.9.12","createdAt":"2026-06-19T03:08:14.091Z","changelog":"Release v1.9.12","fileCount":5,"zipByteSize":6217}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17emme0e2m3cpf7k2jvp3a84984b8z9:nm-abstract-skill-graph-audit","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T01:48:17.204Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-athola-nm-abstract-skill-graph-audit/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T22:47:19.093Z","emptyReason":null},"readme":"Skill: skill-graph-audit\n\nOwner: athola\n\nSummary: Audit Skill() refs; detect hubs, isolates, and dangling targets\n\nTags: latest:1.9.19\n\nVersion history:\n\nv1.9.19 | 2026-08-26T13:04:29.511Z | user\n\nRelease v1.9.19\n\nv1.9.18 | 2026-08-15T21:28:35.983Z | user\n\nRelease v1.9.18\n\nv1.9.17 | 2026-07-30T05:28:27.913Z | user\n\nRelease v1.9.17\n\nv1.9.16 | 2026-07-14T19:45:32.077Z | user\n\nRelease v1.9.16\n\nv1.9.15 | 2026-07-04T21:19:51.280Z | user\n\nRelease v1.9.15\n\nv1.9.14 | 2026-06-30T17:50:25.759Z | user\n\nRelease v1.9.14\n\nv1.9.13 | 2026-06-27T16:15:00.115Z | user\n\nRelease v1.9.13\n\nv1.9.12 | 2026-06-19T03:08:14.091Z | user\n\nRelease v1.9.12\n\nv1.0.0 | 2026-06-07T21:22:18.466Z | auto\n\n- Initial release of skill-graph-audit for auditing Skill() references across the marketplace\n- Identifies graph patterns: hubs, orchestrators, isolates, and dangling skill references\n- Supports machine-readable and CLI output for integration into workflows\n- Provides actionable guidance for each report type (e.g., how to address dangling or isolated skills)\n- Includes verification steps and test coverage for reliable audits\n- Documents related audit skills for deeper or alternative analyses\n\nArchive index:\n\nArchive v1.9.19: 5 files, 6236 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (2009b), SKILL.md (4374b), _meta.json (149b)\n\nFile v1.9.19:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.9.19:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.19\",\n  \"publishedAt\": 1787749469511\n}\n\nFile v1.9.19:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.9.19:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.9.19:skill-card.md\n\n## Description:\n\nAudit Skill() refs; detect hubs, isolates, and dangling targets.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and maintainers use this skill to audit Skill() references across a marketplace, identify hubs, orchestrators, isolates, and dangling targets, and sanity-check composition before documentation, renaming, retirement, or release work.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill references a skill_graph.py implementation that is not included in this package.\n\nMitigation: Confirm the script comes from the intended source before running commands from the workflow.\n\nRisk: Graph audit output can be misleading if it is stale or if a Skill() syntax variant is not detected.\n\nMitigation: Run the documented test-suite correctness check or round-trip smoke check before using results for release or retirement decisions.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit)\n- [Clawdis homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract)\n- [Usage Reference](artifact/modules/usage.md)\n- [Interpreting Graph Metrics](artifact/modules/interpretation.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown with inline bash and JSON examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can guide generation of text or JSON graph audit reports through the referenced CLI.]\n\n## Skill Version(s):\n\n1.9.19 (source: server release evidence; artifact frontmatter reports 1.9.8)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.9.18: 5 files, 6144 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (1871b), SKILL.md (4374b), _meta.json (149b)\n\nFile v1.9.18:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.9.18:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.18\",\n  \"publishedAt\": 1786829315983\n}\n\nFile v1.9.18:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.9.18:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.9.18:skill-card.md\n\n## Description:\n\nAudit Skill() refs; detect hubs, isolates, and dangling targets.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and maintainers use this skill to audit Skill(plugin:name) references across a plugin marketplace, identify hubs and orchestrators, and catch dangling or orphaned skill relationships before documentation, renaming, retirement, or release work.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The trigger may activate during general discussion of skill audits.\n\nMitigation: Use the skill only when intentionally analyzing a plugin or skill repository.\n\nRisk: Generated graph recommendations can affect retirement, consolidation, or dangling-reference work.\n\nMitigation: Review generated reports before acting on dangling-reference or consolidation recommendations.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit)\n- [OpenClaw homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and optional JSON report guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May guide generation of text or JSON graph reports that classify hubs, orchestrators, isolates, and dangling references.]\n\n## Skill Version(s):\n\n1.9.18 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.9.17: 5 files, 6318 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (2316b), SKILL.md (4374b), _meta.json (149b)\n\nFile v1.9.17:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.9.17:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.17\",\n  \"publishedAt\": 1785389307913\n}\n\nFile v1.9.17:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.9.17:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.9.17:skill-card.md\n\n## Description: <br>\nAudit Skill() refs; detect hubs, isolates, and dangling targets. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and maintainers use this skill to audit OpenClaw skill reference graphs, find heavily referenced hubs and orchestrators, identify isolates, and catch dangling Skill() references before documentation, renaming, retirement, or release work. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Running the referenced audit against a plugins root reads skill files under that path, which can expose private repository contents to the local report workflow. <br>\nMitigation: Run it only against repositories and plugin roots you intend to inspect, and review the referenced script or plugin before using it on private sources. <br>\nRisk: The audit focuses on Skill(plugin:name) references and can miss unsupported reference forms or include documented examples as findings. <br>\nMitigation: Use the documented test-suite and smoke-check workflows, then review dangling references and isolates before making retirement or merge decisions. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit) <br>\n- [OpenClaw homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n- [Usage reference](artifact/modules/usage.md) <br>\n- [Interpretation guide](artifact/modules/interpretation.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Shell commands, Markdown, Code, Configuration] <br>\n**Output Format:** [Markdown with inline bash and Python code blocks] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Can guide text or JSON report generation through the referenced skill_graph.py workflow.] <br>\n\n## Skill Version(s): <br>\n1.9.17 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.16: 5 files, 6283 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (2220b), SKILL.md (4374b), _meta.json (149b)\n\nFile v1.9.16:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.9.16:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.16\",\n  \"publishedAt\": 1784058332077\n}\n\nFile v1.9.16:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.9.16:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.9.16:skill-card.md\n\n## Description: <br>\nAudits Skill() references to detect hubs, isolates, and dangling targets. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and maintainers use this skill to audit skill-composition references before documentation passes, releases, renames, retirements, and consolidation reviews. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Audit reports may be stale or incomplete if generated against the wrong plugin root or if references use unsupported syntax. <br>\nMitigation: Run the documented test-suite check or round-trip smoke check, then review generated reports before making changes. <br>\nRisk: Dangling-reference fixes or external-plugin allowlist updates can change skill-composition behavior. <br>\nMitigation: Review proposed changes before applying them, especially when updating external-plugin allowlists or retiring referenced skills. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit) <br>\n- [OpenClaw homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n- [Usage reference](artifact/modules/usage.md) <br>\n- [Interpreting graph metrics](artifact/modules/interpretation.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, configuration, text, json] <br>\n**Output Format:** [Markdown guidance with shell command examples and optional text or JSON audit reports] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The referenced audit only parses Skill(plugin:name) invocations and does not treat module dependencies as graph edges.] <br>\n\n## Skill Version(s): <br>\n1.9.16 (source: server release metadata; artifact frontmatter lists 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.15: 5 files, 6270 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (2223b), SKILL.md (4374b), _meta.json (149b)\n\nFile v1.9.15:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.9.15:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.15\",\n  \"publishedAt\": 1783199991280\n}\n\nFile v1.9.15:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.9.15:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.9.15:skill-card.md\n\n## Description: <br>\nAudit Skill() references to detect hubs, isolates, and dangling targets. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and maintainers use this skill to audit Skill(plugin:name) references across a marketplace, identify load-bearing hubs and orchestrators, find isolates, and triage dangling references before documentation, rename, retirement, or release work. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Graph-audit findings can influence skill renaming, retirement, dependency documentation, or release blocking decisions. <br>\nMitigation: Review generated findings before making marketplace changes, and confirm dangling references before editing or retiring skills. <br>\nRisk: Security guidance for this release notes potential production observability/admin access and local operational-memory exposure when related operational skills are installed. <br>\nMitigation: Use scoped API tokens, review Slack or admin mutation commands before running them, and avoid storing secrets or sensitive incident details in shared org memory. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit) <br>\n- [Project homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Code, Guidance] <br>\n**Output Format:** [Markdown with inline shell commands and optional JSON report guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Graph-audit output may include ranked hubs, orchestrators, isolates, and dangling-reference categories.] <br>\n\n## Skill Version(s): <br>\n1.9.15 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.14: 5 files, 6319 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (2299b), SKILL.md (4374b), _meta.json (149b)\n\nFile v1.9.14:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.9.14:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.14\",\n  \"publishedAt\": 1782841825759\n}\n\nFile v1.9.14:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.9.14:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.9.14:skill-card.md\n\n## Description: <br>\nAudit Skill() refs; detect hubs, isolates, and dangling targets. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and maintainers use this skill to audit Skill(plugin:name) references across a plugin marketplace, identify hubs and isolates, and triage dangling or external references before documentation, renaming, retirement, or release work. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill may activate during broad discussions about skills rather than an intended audit task. <br>\nMitigation: Use a narrow trigger phrase or invoke it explicitly when a skill graph audit is needed. <br>\nRisk: Audit reports are derived from the local plugin tree and can reflect stale source, missing plugins, or documented example references. <br>\nMitigation: Review flagged dangling references, confirm external plugin dependencies, and use the documented test or smoke-check workflow before acting on remediation decisions. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit) <br>\n- [Project homepage metadata](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n- [Usage Reference](modules/usage.md) <br>\n- [Interpreting Graph Metrics](modules/interpretation.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell command examples and optional JSON audit report output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The generated guidance may describe local plugin graph findings such as hubs, orchestrators, isolates, and dangling references.] <br>\n\n## Skill Version(s): <br>\n1.9.14 (source: server release metadata; artifact frontmatter says 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.13: 5 files, 6249 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (2209b), SKILL.md (4374b), _meta.json (149b)\n\nFile v1.9.13:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.9.13:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.13\",\n  \"publishedAt\": 1782576900115\n}\n\nFile v1.9.13:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.9.13:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.9.13:skill-card.md\n\n## Description: <br>\nAudits Skill() references to detect hubs, isolates, and dangling targets. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and skill maintainers use this skill to audit Skill() reference graphs before documentation passes, renames, retirements, quarterly audits, and composition reviews. It helps identify heavily referenced hubs, orchestrator skills, isolates, and dangling references that may need repair or documentation. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The documented audit command scans the plugins tree selected by the user and can write reports to a chosen output path. <br>\nMitigation: Run it against the intended plugins root and review the output path before execution. <br>\nRisk: Installing the broader source plugin may include external Claude Code plugin components beyond this skill card evidence. <br>\nMitigation: Review those external plugin components separately before using them. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit) <br>\n- [Clawdis homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n- [Usage reference](modules/usage.md) <br>\n- [Interpretation guide](modules/interpretation.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, shell commands, configuration] <br>\n**Output Format:** [Markdown guidance with CLI examples and optional JSON report output paths] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Guides agents to inspect Skill() references and classify hubs, orchestrators, isolates, and dangling targets.] <br>\n\n## Skill Version(s): <br>\n1.9.13 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.9.12: 5 files, 6217 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (2034b), SKILL.md (4374b), _meta.json (149b)\n\nFile v1.9.12:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.9.12:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.12\",\n  \"publishedAt\": 1781838494091\n}\n\nFile v1.9.12:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.9.12:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.9.12:skill-card.md\n\n## Description: <br>\nAudit Skill() refs; detect hubs, isolates, and dangling targets. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and maintainers use this skill to audit Skill() references across a skill marketplace, identify hubs, orchestrators, isolates, and dangling references, and plan composition maintenance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Broad trigger phrasing may activate the skill during unrelated skill-audit discussions. <br>\nMitigation: Invoke it explicitly for Skill() graph audits and narrow the review to relevant skill or repository files. <br>\nRisk: Graph findings can include false positives from example Skill() references or miss free-text mentions that are outside the parser's scope. <br>\nMitigation: Review reported dangling references and limitations before renaming, retiring, or changing dependent skills. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/nm-abstract-skill-graph-audit) <br>\n- [Project homepage from metadata](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Analysis, Guidance, Shell commands, Markdown] <br>\n**Output Format:** [Markdown with inline shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May summarize graph findings, suggest validation commands, and reference JSON report paths when applicable.] <br>\n\n## Skill Version(s): <br>\n1.9.12 (source: server release evidence; artifact frontmatter lists 1.9.8) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.0: 5 files, 6249 bytes\n\nFiles: modules/interpretation.md (2555b), modules/usage.md (2056b), skill-card.md (2204b), SKILL.md (4374b), _meta.json (148b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth were converted to correct command-style references in the\nsame session.\n\n## Verification\n\nTwo ways to validate the audit output is trustworthy:\n\n1. **Test-suite correctness check**: Run `pytest -o addopts=\n   plugins/abstract/tests/scripts/test_skill_graph.py` to confirm\n   extraction, graph construction, ranking, isolate detection, and\n   dangling-ref classification all pass on the current code. The\n   `-o addopts=` flag bypasses the package-wide coverage gate, which\n   would otherwise fail on a single-file run.\n2. **Round-trip smoke check**: Note the dangling-ref count from a\n   baseline run, fix one or more flagged references, then rerun and\n   verify the count drops by at least the number fixed. If the count\n   does not move, the report is stale or the regex missed a syntax\n   variant.\n\n## Related Skills\n\n- `Skill(abstract:skills-eval)` -- per-skill quality scoring\n- `Skill(abstract:plugin-review)` -- plugin manifest + structure\n- `Skill(abstract:hooks-eval)` -- hook-specific validation\n- `Skill(abstract:rules-eval)` -- rules directory validation\n\n## References\n\n- Implementation: `plugins/abstract/scripts/skill_graph.py`\n- Tests: `plugins/abstract/tests/scripts/test_skill_graph.py`\n- Composition documentation:\n  `docs/quality-gates.md#skill-level-quality-gate-composition`\n- Skill role taxonomy: `docs/skill-integration-guide.md#skill-role-taxonomy`\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1780867338466\n}\n\nFile v1.0.0:modules/interpretation.md\n\n---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth).\n\nFile v1.0.0:modules/usage.md\n\n---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension.\n\nFile v1.0.0:skill-card.md\n\n## Description: <br>\nAudit Skill() refs; detect hubs, isolates, and dangling targets. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[athola](https://clawhub.ai/user/athola) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and skill maintainers use this skill to audit Skill(plugin:name) references across a marketplace, identify hubs, orchestrators, isolates, and dangling references, and plan safer documentation, rename, retirement, and pre-release checks. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can guide command-line and workflow changes that may affect repositories or release gates. <br>\nMitigation: Review requested commands before execution, especially for GitHub, account, moderation, or other high-impact operations. <br>\nRisk: Graph audit reports may miss references outside Skill(plugin:name) syntax or module dependency metadata. <br>\nMitigation: Use the report as a focused audit input and review dependency frontmatter, hook references, and related documentation when making rename, retirement, or release decisions. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/athola/nm-abstract-skill-graph-audit) <br>\n- [Publisher profile](https://clawhub.ai/user/athola) <br>\n- [Project homepage from metadata](https://github.com/athola/claude-night-market/tree/master/plugins/abstract) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and optional JSON report workflows] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Guides use of a graph audit workflow that can emit text summaries or machine-readable JSON reports.] <br>\n\n## Skill Version(s): <br>\n1.0.0 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: skill-graph-audit Owner: athola Summary: Audit Skill() refs; detect hubs, isolates, and dangling targets Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:04:29.511Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:28:35.983Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:28:27.913Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:45:32.077Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:51.280Z | us","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10"},{"language":"bash","snippet":"python3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json"},{"language":"text","snippet":"python3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout"},{"language":"bash","snippet":"python3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\""},{"language":"bash","snippet":"python3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt"},{"language":"bash","snippet":"python3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: skill-graph-audit\ndescription: Audit Skill() refs; detect hubs, isolates, and dangling targets\nversion: 1.9.8\ntriggers:\n  - auditing skills\nmetadata: {\"openclaw\": {\"homepage\": \"https://github.com/athola/claude-night-market/tree/master/plugins/abstract\", \"emoji\": \"\\ud83e\\udd9e\"}}\nsource: claude-night-market\nsource_plugin: abstract\n---\n\n> **Night Market Skill** — ported from [claude-night-market/abstract](https://github.com/athola/claude-night-market/tree/master/plugins/abstract). For the full experience with agents, hooks, and commands, install the Claude Code plugin.\n\n\n# Skill Graph Audit\n\n## Overview\n\nBuild a directed graph of `Skill(plugin:name)` invocations across the\nmarketplace and surface composition patterns: which skills are heavily\nreferenced (hubs), which orchestrate many others (orchestrators), which\nhave no incoming or outgoing references (isolates), and which point at\nnon-existent skills (dangling references).\n\nThe federation graph is now derivable from source rather than\nhand-curated.\n\n## When To Use\n\n- Before a documentation pass on skill composition\n- After a renaming or retirement to catch broken `Skill()` references\n- During quarterly audits to spot orphaned skills\n- When evaluating consolidation candidates (hubs are higher-risk to merge)\n- When a new skill's outbound references should be sanity-checked\n\n## When NOT To Use\n\n- For per-skill quality scoring -- use `Skill(abstract:skills-eval)` instead\n- For frontmatter/structure validation -- use `Skill(abstract:plugin-review)`\n- For hook-specific audits -- use `Skill(abstract:hooks-eval)`\n\n## Quick Start\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --top-n 10\n```\n\nFor machine-readable output:\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output reports/skill-graph.json\n```\n\nSee `modules/usage.md` for full CLI reference and example workflows.\n\n## Core Outputs\n\n| Output | Meaning | Action when high |\n|--------|---------|------------------|\n| Hubs | Most-referenced skills | Treat as core API; retire with extreme care |\n| Orchestrators | Skills that call many others | Verify each ref still resolves |\n| Isolates | Zero in / zero out | Check role: library? entrypoint? typo? |\n| Dangling -- bugs | Missing internal target | Fix immediately (typo or retired skill) |\n| Dangling -- external | Reference to external plugin | Document plugin dependency |\n| Dangling -- placeholders | Template text like `-NAME` | Verify intentional |\n\nSee `modules/interpretation.md` for false-positive guidance and\nisolation taxonomy.\n\n## Dogfood Evidence\n\nThis skill itself was scaffolded TDD-first; on first run against\n`plugins/`, it caught two genuine dangling refs that the manual\naudit (2026-04-25) had missed:\n\n- `attune:makefile-generation -> abstract:makefile-dogfooder`\n  (script name confused with skill name)\n- `imbue:karpathy-principles -> spec-kit:speckit-clarify`\n  (command referenced as skill)\n\nBoth we"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7d107jg9jv602h9ytsegydq184a42s\",\n  \"slug\": \"nm-abstract-skill-graph-audit\",\n  \"version\": \"1.9.19\",\n  \"publishedAt\": 1787749469511\n}"},{"path":"modules/interpretation.md","content":"---\nname: skill-graph-audit-interpretation\ndescription: How to interpret graph metrics, including isolate taxonomy and false-positive guidance.\n---\n\n# Interpreting Graph Metrics\n\n## Isolate Taxonomy\n\nA skill flagged as \"isolate\" (zero inbound, zero outbound) is not\nnecessarily broken. Per `docs/skill-integration-guide.md#skill-role-taxonomy`, three legitimate\nroles produce zero edges:\n\n### 1. Library skills\n\nSkills consumed via `dependencies:` frontmatter from other skills\nor via Python imports rather than `Skill()` calls. Example:\n`abstract:shared-patterns`. **Action**: confirm `dependencies:` field\nin callers.\n\n### 2. Entrypoint skills\n\nSkills invoked directly by users via slash commands or by an\nexternal orchestrator (e.g. `egregore:summon`). Example:\n`abstract:plugin-review`. **Action**: confirm a corresponding\ncommand file exists in `plugins/<plugin>/commands/`.\n\n### 3. Hook-target skills\n\nSkills that hooks redirect to. Example: `imbue:proof-of-work`.\n**Action**: confirm a `PreToolUse`/`PostToolUse` hook in\n`plugins/<plugin>/hooks.json` references the skill.\n\nA skill that fits none of the three is a true orphan and a\ncandidate for retirement.\n\n## Hub Sensitivity\n\nSkills with high inbound count are load-bearing. Before retiring\nor splitting one:\n\n- Run `rg \"Skill\\\\(<plugin>:<name>\\\\)\" plugins/` to enumerate callers\n- Open a deprecation issue with at least 30-day notice\n- Provide a migration target in the deprecation note\n\nThe current top-5 hubs (as of 2026-04-25) are:\n\n1. `scribe:slop-detector`\n2. `attune:project-brainstorming`\n3. `sanctum:git-workspace-review`\n4. `attune:project-planning`\n5. `attune:project-specification`\n\n## Dangling Reference Triage\n\n| Class | Default action |\n|-------|----------------|\n| bugs | Fix in the same PR; do not merge with bugs > 0 |\n| external | Confirm external plugin is documented in plugin.json |\n| placeholders | Annotate with `<!-- template -->` to suppress |\n\n## Cross-Plugin Coupling\n\nA high count of cross-plugin edges (src plugin != dst plugin) is\nhealthy ecosystem behaviour, not a problem. A high count of\nintra-plugin edges (src plugin == dst plugin) suggests a\nplugin-internal federation worth documenting in the plugin's\nREADME.\n\n## Common False Positives\n\n- Skill names in code blocks demonstrating example usage are still\n  parsed. If documenting a hypothetical skill, use `<plugin>:<name>`\n  without backticks or surround with `<!-- example -->`.\n- Skill names mentioned in `docs/decisions/` outside SKILL.md files\n  are not parsed (only SKILL.md is the source of truth)."},{"path":"modules/usage.md","content":"---\nname: skill-graph-audit-usage\ndescription: CLI reference and example workflows for the skill graph audit tool.\n---\n\n# Usage Reference\n\n## CLI Flags\n\n```text\npython3 plugins/abstract/scripts/skill_graph.py [OPTIONS]\n\n  --plugins-root PATH    Root containing <plugin>/skills/<name>/ tree\n                         (default: plugins)\n  --top-n INT            Top N hubs/orchestrators to show (default: 10)\n  --format {text,json}   Output format (default: text)\n  --output PATH          Write to file instead of stdout\n```\n\n## Common Workflows\n\n### Pre-release dangling-ref check\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py \\\n  --plugins-root plugins --format json --output /tmp/graph.json\n\npython3 -c \"\nimport json\nreport = json.load(open('/tmp/graph.json'))\nbugs = report['dangling_refs']['bugs']\nif bugs:\n    print(f'BLOCKING: {len(bugs)} dangling refs')\n    for b in bugs:\n        print(f'  {b[\\\"source\\\"]} -> {b[\\\"target\\\"]}')\n    raise SystemExit(1)\nprint('OK: 0 internal dangling references')\n\"\n```\n\n### Find consolidation candidates\n\nHubs with >5 inbound references are core API; orchestrators with\n>5 outbound references are coordination points. The intersection\n(hub AND orchestrator) is the federation backbone.\n\n```bash\npython3 plugins/abstract/scripts/skill_graph.py --top-n 20 \\\n  | tee /tmp/graph.txt\n```\n\n### Update composition documentation\n\nGenerate the federation table for `docs/quality-gates.md` from\nreport JSON instead of curating manually.\n\n## Updating External Plugin Allowlist\n\nIf a new external plugin is referenced (one not yet in\n`KNOWN_EXTERNAL_PLUGINS`), update the constant in\n`plugins/abstract/scripts/skill_graph.py` so refs to it are\nclassified as `external` rather than `bugs`.\n\n## Limitations\n\n- Detects only `Skill(plugin:name)` invocations. Free-text mentions\n  in prose are not parsed.\n- Self-references (a skill referencing itself) are skipped to avoid\n  cycles in counts.\n- Module-level `dependencies:` and `modules:` frontmatter are not\n  yet treated as edges; see backlog item for planned extension."},{"path":"skill-card.md","content":"## Description:\n\nAudit Skill() refs; detect hubs, isolates, and dangling targets.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[athola](https://clawhub.ai/user/athola)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and maintainers use this skill to audit Skill() references across a marketplace, identify hubs, orchestrators, isolates, and dangling targets, and sanity-check composition before documentation, renaming, retirement, or release work.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill references a skill_graph.py implementation that is not included in this package.\n\nMitigation: Confirm the script comes from the intended source before running commands from the workflow.\n\nRisk: Graph audit output can be misleading if it is stale or if a Skill() syntax variant is not detected.\n\nMitigation: Run the documented test-suite correctness check or round-trip smoke check before using results for release or retirement decisions.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/athola/skills/nm-abstract-skill-graph-audit)\n- [Clawdis homepage](https://github.com/athola/claude-night-market/tree/master/plugins/abstract)\n- [Usage Reference](artifact/modules/usage.md)\n- [Interpreting Graph Metrics](artifact/modules/interpretation.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown with inline bash and JSON examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can guide generation of text or JSON graph audit reports through the referenced CLI.]\n\n## Skill Version(s):\n\n1.9.19 (source: server release evidence; artifact frontmatter reports 1.9.8)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Audit Skill() refs; detect hubs, isolates, and dangling targets Skill: skill-graph-audit Owner: athola Summary: Audit Skill() refs; detect hubs, isolates, and dangling targets Tags: latest:1.9.19 Version history: v1.9.19 | 2026-08-26T13:04:29.511Z | user Release v1.9.19 v1.9.18 | 2026-08-15T21:28:35.983Z | user Release v1.9.18 v1.9.17 | 2026-07-30T05:28:27.913Z | user Release v1.9.17 v1.9.16 | 2026-07-14T19:45:32.077Z | user Release v1.9.16 v1.9.15 | 2026-07-04T21:19:51.280Z | us","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1527,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T22:47:19.093Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T22:47:19.093Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T01:48:17.207Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}