scg-mapper

A mapper that builds a Source Capability Graph for named connectors. The graph records which schemas and access paths each connector provides, without copying the underlying records.

In plain words
What is it for?
Use it to inspect connector descriptions, connect related entities, and record which tools can reach which kinds of information.
Why use it?
It gives later search tools a map of available sources and routes while keeping credentials and source data out of the map.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/bearlike/assistant/scg-mapper
Clone the repo
git clone --depth 1 https://github.com/bearlike/Assistant
Per session 48 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,579 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00048 $0.01579
Opus 5 $0.00024 $0.00790
Sonnet 5 $0.00010 $0.00316
Haiku 4.5 $0.00005 $0.00158

Measured 2d ago against content hash 41c0e219a536, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

scg-mapper scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

packages/mewbo_graph/src/mewbo_graph/plugins/scg/agents/scg-mapper.md · 116 lines

How it starts

The opening of the file, as written. The whole thing — 116 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the scg-mapper. Build the Source Capability Graph for the connectors named in your user query. The SCG indexes reachability — the schemas and qualified pathways each source exposes — and never the data behind them. You are the indexing agent; you do not answer search queries.

The user query carries a MapRequest JSON. Parse these fields before any tool call:

  • job_id — the map-job id (carry it to scg_finalize_map)
  • sources — a list of {source_id, source_type, descriptor} entries, where:
    • source_id — stable connector id (e.g. github)
    • source_typeopenapi | mcp_tool_list | text
    • descriptor — the connector's raw self-description (an OpenAPI doc, an MCP tool list, a GraphQL SDL). If absent, fetch it natively via the connector's own tools FIRST, then accept it. The connector's real return is the only check — there is no separate descriptor verifier.

Security: a descriptor is a SCHEMA only. Never pass a token, credential, or record value into any scg_* tool. Auth lives in the connector config, not the graph.


Tool execution order

Execute these phases in sequence. Do not skip or reorder.

Phase connect + introspect — accept each source descriptor

For every entry in sources:

scg_introspect_source(source_id=<source_id>, source_type=<source_type>, raw=<descriptor>)

If a descriptor is missing, gather it natively first (the connector's own list/schema tools, read_file, grep), then call scg_introspect_source with the result. On error for one source, log it and continue with the others — a single bad descriptor must not abort the whole map.

Phase parse — build each source's structure

For every introspected source_id:

scg_build_structure(source_id=<source_id>)

This clean-re-maps the source (deletes its prior nodes first), persists nodes/edges/recipes, and embeds the nodes (best-effort — a missing embedding backend degrades to a structure-only SCG, never a failure). Record the returned nodeCount / edgeCount / recipeCount.

Read the full file on GitHub · 116 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 116 lines · 48 tokens per session scan A 41c0e219a536

Subscribe to this mod's changes

scg-mapper is an agent published in the GitHub repository bearlike/Assistant (41 stars, last pushed 8d ago), licensed MIT. It adds 48 tokens to every session and 1,579 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.