Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add hashgraph-online/awesome-codex-plugins --skill graphifygit clone --depth 1 https://github.com/hashgraph-online/awesome-codex-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hashgraph-online/awesome-codex-plugins/graphify)<a href="https://agentmods.dev/skills/hashgraph-online/awesome-codex-plugins/graphify"><img src="https://agentmods.dev/badge/skills/hashgraph-online/awesome-codex-plugins/graphify/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hashgraph-online/awesome-codex-plugins/graphify"><img src="https://agentmods.dev/badge/skills/hashgraph-online/awesome-codex-plugins/graphify.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00057 | $0.00608 |
| Opus 5 | $0.00028 | $0.00304 |
| Sonnet 5 | $0.00011 | $0.00122 |
| Haiku 4.5 | $0.00006 | $0.00061 |
Grade A, and why
graphify scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Graphify
用途
- 对已有仓库做结构化认知:模块关系、调用路径、关键依赖、热点边界。
- 在设计和实现前补“证据层”,降低只靠直觉拆任务的风险。
- 为
/team-plan、/team-execute、/team-review提供可回溯的图谱证据。
触发信号
- brownfield 项目,且改动面跨多个目录或服务。
- 需求涉及“这个能力到底在哪里实现”“改这个会影响哪些模块”。
- 评审阶段需要对依赖路径、耦合点和影响范围做结构化证明。
默认工作流
- 先跑
npm run graphify:doctor,确认 Python 与 Graphify CLI 可用。 - 在项目根目录生成/更新图谱,统一输出到
graphify-out/。 - 用
query/path/explain回答任务相关的结构问题,形成可引用结论。 - 把关键发现回落到主链:
- 规划阶段 ->
/team-plan的 challenge/design/readiness 证据 - 执行阶段 ->
/team-execute的 story slice 影响面说明 - 评审阶段 ->
/team-review的风险与回归边界说明
- 规划阶段 ->
- 结论需要通过 handoff 或 artifact 写入项目文档,不停留在临时会话。
输出约定
- 统一目录:
graphify-out/ - 最小交付内容:
- 本次分析目标(问题是什么)
- 查询/路径命令与核心结果(结果是什么)
- 对主链决策的影响(接下来做什么)
边界与禁用项
- Graphify 只是可选能力,不替代 workflow-engine,也不创建并行责任链。
- 不在本仓库执行
graphify codex install或graphify claude install,避免改写现有 AGENTS/hooks 契约。 - 不自动安装 Python 或
graphifyy;环境依赖由使用方负责。
推荐组合
- 结构不清的 brownfield 任务:
/team-help -> graphify(build/query/path/explain) -> /team-plan - 高风险改动评估:
/team-execute -> graphify(path/explain) -> /handoff -> /team-review
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 52 lines · 57 tokens per session scan A fcdde4019e10
graphify is a skill published in the GitHub repository hashgraph-online/awesome-codex-plugins (956 stars, last pushed today), licensed Apache-2.0. It adds 57 tokens to every session and 608 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-05.
Other skills, from other repositories
search
Search 2500+ curated ChatGPT and LLM open-source repositories. Use when the user asks to find tools, libraries, or repos related to ChatGPT, LLMs, RAG, agents, langchain, NLP, AI development, or any open-source AI tooling.
sprr
Single PR reviewer for awesome-quant. Use when the user asks to review, validate, comment on, label, close, or merge one specific pull request that adds README.md entries. Triggers include "sprr", "review PR", "check PR", and "validate contribution".
bprr
Bulk PR reviewer for awesome-quant. Use when the user asks to review all open PRs, review unreviewed PRs, bulk review, or mentions "bprr". Reviews open PRs lacking the reviewed label and presents a summary before any merge/comment/label action.
drawio-reconstruction
Reconstructs reference images into high-fidelity, editable Draw.io files with rendered previews: native Draw.io elements carry text and structure, SVG covers simple icons that match the reference, and cropped or transparent PNGs preserve complex visuals. Use when the user wants a diagram image, research figure…
benchmark-paper-template
Structures Benchmark and Evaluation papers using the five-pillar framework (Research Gap, Construction Pipeline, Evaluation Framework, Empirical Findings, optional Companion Method). Returns a completeness audit, a six-part Introduction logic chain, a Section 2-7 skeleton, and a pre-submission checklist. Use when…
reverse-engineering-android-malware-with-jadx
Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify malicious functionality including data theft, C2 communication, privilege escalation, and overlay attacks. Examines manifest permissions, receivers, services, and native libraries. Activates for requests…