gitnexus

gitnexus is a skill for Claude Code, Codex from hashgraph-online/awesome-codex-plugins. It costs 58 tokens per session (781 once invoked), scanned A, original, Apache-2.0.

A code-graph analysis add-on for examining an existing codebase, including symbols, call paths, execution flows, and effects across repositories. It can query GitNexus through its command-line or MCP interfaces.

In plain words
What is it for?
Use it to investigate a symbol's callers and dependants, trace where a process starts and flows, measure the likely impact of a change, and support planning or review with recorded findings.
Why use it?
It helps answer what will be affected before changing a function or API. This reduces the risk of missing dependent modules, services, or repositories in an older or unfamiliar codebase.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/hashgraph-online/awesome-codex-plugins/gitnexus
Any agent
npx skills add hashgraph-online/awesome-codex-plugins --skill gitnexus
Clone the repo
git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for gitnexus

README.md
[![agentmods](https://agentmods.dev/badge/skills/hashgraph-online/awesome-codex-plugins/gitnexus.svg)](https://agentmods.dev/skills/hashgraph-online/awesome-codex-plugins/gitnexus)
Your own site
<a href="https://agentmods.dev/skills/hashgraph-online/awesome-codex-plugins/gitnexus"><img src="https://agentmods.dev/badge/skills/hashgraph-online/awesome-codex-plugins/gitnexus.svg" alt="Measured on agentmods" height="20"></a>
Per session 58 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 781 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00058 $0.00781
Opus 5 $0.00029 $0.00391
Sonnet 5 $0.00012 $0.00156
Haiku 4.5 $0.00006 $0.00078

Measured today against content hash 7597557d303d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gitnexus scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/Colin4k1024/tsp/skills/gitnexus/SKILL.md · 61 lines

What it actually says

GitNexus

用途

  • 对存量仓库做更深代码图谱分析:符号上下游、调用链、执行流、跨仓影响面。
  • 在改动前用 impact / detect_changes 类证据确认 blast radius。
  • /team-plan/team-execute/team-review 提供可追溯的 MCP/图谱证据。

触发信号

  • brownfield 项目改动跨多个模块、服务或仓库。
  • 需要回答“改这个 symbol/API 会影响谁”“这段流程从哪里进入、流向哪里”。
  • 评审或发布前需要对 git diff 做影响面确认。
  • Graphify 的轻量结构扫描不够,需要 MCP tool、资源或多仓上下文。

默认工作流

  1. 先跑 npm run gitnexus:doctor,确认 Node、npm/npx 与上游包元数据。
  2. 用户自行确认 GitNexus 上游许可证和项目使用场景是否匹配。
  3. 在目标项目根目录显式执行索引命令,并保留 TSP 的 AGENTS/CLAUDE 契约:
    npx --yes gitnexus@latest analyze --skip-agents-md
    
  4. 通过 MCP 或 CLI 查询 query/context/impact/detect_changes 等结果。
  5. 把关键发现回落到主链:
    • 规划阶段 -> /team-plan 的 Brownfield Context Snapshot 和 readiness 证据
    • 执行阶段 -> /team-execute 的 story slice 影响面说明
    • 评审阶段 -> /team-review 的风险、回归边界和放行建议

输出约定

  • GitNexus 索引由上游工具管理,通常写入目标仓库 .gitnexus/ 与用户级 registry。
  • TSP 侧只沉淀结论,不沉淀上游数据库:
    • 分析目标
    • 查询入口(MCP tool/resource 或 CLI 命令)
    • 核心发现
    • /team-* 决策的影响
    • 后续验证或回退建议

边界与禁用项

  • 不把 GitNexus 当作 TSP 依赖或默认安装项。
  • 不自动运行 gitnexus setup,避免改写用户全局 MCP/editor 配置。
  • 不在 TSP 管理仓库里运行不带 --skip-agents-mdgitnexus analyze
  • 不复制 GitNexus 源码、hooks、skills 或生成产物到 TSP canonical source。
  • 当前按上游 npm 元数据视为非商业许可证约束;商业使用前需要用户自行确认授权。

推荐组合

  • 轻量 brownfield 结构扫描:/team-help -> /update-codemaps -> graphify -> /team-plan
  • 深影响面分析:/team-help -> /update-codemaps -> GitNexus impact/detect_changes -> /team-plan
  • 高风险评审:/team-execute -> GitNexus detect_changes -> /handoff -> /team-review
Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today First seen · 61 lines · 58 tokens per session scan A 7597557d303d

Subscribe to this mod's changes

gitnexus is a skill published in the GitHub repository hashgraph-online/awesome-codex-plugins (924 stars, last pushed today), licensed Apache-2.0. It adds 58 tokens to every session and 781 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.

Related

Other skills, from other repositories

search

Search 2500+ curated ChatGPT and LLM open-source repositories. Use when the user asks to find tools, libraries, or repos related to ChatGPT, LLMs, RAG, agents, langchain, NLP, AI development, or any open-source AI tooling.

taishi-i/awesome-ChatGPT-repositories · 57 tokens

similar-resources

Given a Japanese NLP GitHub repo or Hugging Face model/dataset (URL / owner/repo / tool name), find repositories or models/datasets that do the same or related processing. Mines the bundled dataset for content-similar items, then expands via web research across both GitHub and Hugging Face, then merges and re-ranks.

taishi-i/awesome-japanese-nlp-resources · 70 tokens

sprr

Single PR reviewer for awesome-quant. Use when the user asks to review, validate, comment on, label, close, or merge one specific pull request that adds README.md entries. Triggers include "sprr", "review PR", "check PR", and "validate contribution".

wilsonfreitas/awesome-quant · 60 tokens

bprr

Bulk PR reviewer for awesome-quant. Use when the user asks to review all open PRs, review unreviewed PRs, bulk review, or mentions "bprr". Reviews open PRs lacking the reviewed label and presents a summary before any merge/comment/label action.

wilsonfreitas/awesome-quant · 61 tokens

reverse-engineering-android-malware-with-jadx

Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests…

adriannoes/awesome-agentic-ai · 82 tokens

implementing-code-signing-for-artifacts

This skill covers implementing code signing for build artifacts to ensure integrity and authenticity throughout the software supply chain. It addresses signing binaries, packages, and containers using GPG, Sigstore, and platform-specific signing tools, establishing trust chains, and verifying signatures in deployment…

adriannoes/awesome-agentic-ai · 62 tokens