polyviz

A deterministic diagram renderer for Polygraph artifacts, which are files describing a state machine, its rules, failures, or compatibility results. It produces branded SVG diagrams and can optionally produce PNG images.

In plain words
What is it for?
Use it to render state-machine graphs, invariants, failure counterexamples, and version-compatibility results. It can read a visualization JSON file or a Polygraph artifact directory.
Why use it?
It turns verification results into repeatable visual diagrams without making another model request. The same inputs produce the same output, making generated images easier to compare and review.

Plugin for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Claude Code
/plugin marketplace add cognitive-fab/polygraph
agentmods
npx agentmods add plugins/cognitive-fab/polygraph/polyviz
Clone the repo
git clone --depth 1 https://github.com/cognitive-fab/polygraph

Made for: Claude Code.

Per session not measured What this adds to a session before it is invoked.
When invoked not measured Not applicable: nothing here is loaded into a session.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Security

Grade A, and why

polyviz scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

polyviz/.claude-plugin/plugin.json · 25 lines

What it actually says

{
  "name": "polyviz",
  "displayName": "polyviz",
  "version": "0.1.0",
  "description": "A deterministic, artifact-derived diagram renderer for Polygraph. Turns the artifacts the suite already produces — the state machine, the invariants, the counterexample, the polyvers compat verdict — into a fixed catalog of clean, brand-consistent SVGs (optional PNG). Same inputs → byte-identical output; no model call at render time. Renders from a viz-model JSON or straight from a Polygraph/polyvers artifacts directory (adapters derive the machine graph by bounded BFS over the module, read the invariants, resolve a failing findings.json to its counterexample trace, and map compat-report.json). Optional runtime components: the state-machine graph needs elkjs and PNG needs @resvg/resvg-js (both optionalDependencies, loaded lazily); the pure viz-model → SVG path needs neither and executes no user code. Deriving the machine graph from a real run does execute the target module (bounded reachability).",
  "author": {
    "name": "jdubray",
    "url": "https://github.com/jdubray"
  },
  "homepage": "https://github.com/cognitive-fab/polygraph",
  "repository": "https://github.com/cognitive-fab/polygraph",
  "license": "Apache-2.0",
  "keywords": [
    "visualization",
    "diagram",
    "svg",
    "state-machine",
    "verification",
    "polygraph",
    "polyvers",
    "deterministic",
    "counterexample"
  ]
}
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 25 lines scan A 62dd7fa32e0f

Subscribe to this mod's changes

polyviz is a plugin published in the GitHub repository cognitive-fab/polygraph (11 stars, last pushed 5d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.