codescape

A guide for using Codescape, a code graph that maps a project's structure and how its parts connect. It helps an agent find relevant files and code locations before reading or changing them.

In plain words
What is it for?
Orienting yourself in an unfamiliar codebase, finding where a symbol is defined, tracing flows, checking what code a change may affect, and locating exact file-and-line positions.
Why use it?
It reduces the need to open many files or search through the whole project just to understand its shape. The guide emphasizes checking the exact code after the graph points to it.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/danielc000/loom/codescape
Any agent
npx skills add DanielC000/loom --skill codescape
Clone the repo
git clone --depth 1 https://github.com/DanielC000/loom

Made for: Claude Code, Codex.

Per session 90 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 830 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00090 $0.00830
Opus 5 $0.00045 $0.00415
Sonnet 5 $0.00018 $0.00166
Haiku 4.5 $0.00009 $0.00083

Measured 2d ago against content hash d3803a106399, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codescape scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

packages/daemon/assets/skills/codescape/SKILL.md · 55 lines

How it starts

The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.

codescape

Codescape is a code-graph MCP — a per-project, ingested snapshot of the repo's structure. When your project exposes the Codescape MCP tools (overview / list_flows / describe_symbol / what_touches / trace_flow / boundary_map / render_tree), it is your PRIMARY orientation instrument, not a fallback.

The one thing to internalize: use the graph for structure, coordinates, and reachability, then open files ONLY to read the exact bytes you must verify or edit — at the coordinates the graph gave you. The graph REPLACES orient + locate; reading is only confirm/edit. If you re-derive the map by reading, or grep to LOCATE what the graph already pinpoints, you throw the whole point away — a measured speed / fewer-reads win collapses back into verify-by-reading.

Use the graph for three things

  • ORIENT — the shape. What exists and how flows run through the system end to end (frontend + backend, across parts/services). Reach a correct mental map with FAR fewer reads than opening files. Start here (overview / list_flows / trace_flow) before you open anything.
  • LOCATE — the coordinates. Which file:line each piece lives at. describe_symbol / overview / what_touches / trace_flow return citation-grade file:line — take the exact coordinates FROM the graph; don't grep to find what it already pinpoints.
  • REACHABILITY — what could happen. "What could render" (components + conditional branches) and "what scenarios are possible." Grep is actively BAD at these; the graph answers questions reading-by-hand can't.

Then read — targeted, at the coordinates

Open Read/grep ONLY for the irreducible step: the actual bytes you must verify or edit, opened DIRECTLY at the file:line Codescape gave you — never searched for from scratch. A few pinpoint reads, not a re-explore.

Honest boundaries (don't oversell it)

Codescape is complementary, not a replacement — grep/Read still win for:

  • Exact-string / literal search — a specific token, error string, config value: grep it.
  • Freshest state — the graph is only as fresh as the last ingest; for code that just changed, confirm against the file.
  • Non-modeled content — comments, config values, prose, anything that isn't a code symbol: grep.

Read the full file on GitHub · 55 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 55 lines · 90 tokens per session scan A d3803a106399

Subscribe to this mod's changes

codescape is a skill published in the GitHub repository DanielC000/loom (7 stars, last pushed 5d ago), licensed MIT. It adds 90 tokens to every session and 830 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

hr-onboarding

A new-hire onboarding plan as a single page — first week schedule, buddy + manager intro, learning track, equipment checklist, and "you're set when…" outcomes. Use when the brief mentions "onboarding", "new hire", "first week plan", or "入职".

nexu-io/open-design · 62 tokens

html-ppt-taste-brutalist

16:9 HTML deck in tactical-telemetry / CRT-terminal taste. Deactivated-CRT charcoal slides, white-phosphor monospace, hazard-red accent, scanline overlay, ASCII syntax, density over decoration. Distilled from Leonxlnx/taste-skill brutalist-skill (Tactical Telemetry mode).

nexu-io/open-design · 78 tokens

ligandmpnn

Inverse-fold a backbone with ligand, nucleic-acid, and metal context using LigandMPNN (Dauparas et al. 2023, github.com/dauparas/LigandMPNN). Reach for this skill to redesign the residues lining a binding pocket around a bound small molecule or cofactor, to design metal-coordinating sites where the geometry must be…

aipoch/open-science · 100 tokens

evo2

Score, embed, and generate DNA sequences with Evo 2, a long-context genomic foundation model. Use this skill when: (1) Computing per-nucleotide or per-sequence likelihoods for variant effect scoring, (2) Embedding genomic windows for downstream classification, (3) Generating DNA conditioned on a prefix, (4) Scoring…

aipoch/open-science · 83 tokens

package-author

当用户要把手头的工具打包/标准化成 pinvou 插件包时使用——包括纯技能(SKILL.md)、纯 MCP 服务或它们的组合包。用户说"打包/做成插件包/标准化这个工具/给我一个能上传的标准包/写 plugin.json/加个图标"等,或给了散乱脚本/目录要整理成可上传 zip 时,用本技能把内容规范成 plugin-protocol 标准包(补 plugin.json、补 mcp/manifest.json、补 SKILL.md、补图标、校验命名)。.

Pinvou/pinvou-agent · 133 tokens

google-meet

Google Meet via gws: create spaces, fetch join links, list recordings.

Open-Curiosity/gini-agent · 20 tokens