Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/marcinhamiga/code-indexing-mcp/impact-analysisnpx skills add MarcinHamiga/code-indexing-mcp --skill impact-analysisgit clone --depth 1 https://github.com/MarcinHamiga/code-indexing-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/marcinhamiga/code-indexing-mcp/impact-analysis)<a href="https://agentmods.dev/skills/marcinhamiga/code-indexing-mcp/impact-analysis"><img src="https://agentmods.dev/badge/skills/marcinhamiga/code-indexing-mcp/impact-analysis.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00027 | $0.01203 |
| Opus 5 | $0.00014 | $0.00602 |
| Sonnet 5 | $0.00005 | $0.00241 |
| Haiku 4.5 | $0.00003 | $0.00120 |
Grade A, and why
impact-analysis scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 52 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are analyzing the impact of changing: $target (a symbol, module, or API plus the intended change). If the target or the intended change is unclear, ask the user with the AskUserQuestion tool before starting.
The core rule of this skill: map usages with the index tools, not with grep.
1. Ensure the index is ready
- Call
mcp__code-indexing-mcp__project_statusfor the target project. If the project is unknown, callmcp__code-indexing-mcp__list_projectsand, if needed,mcp__code-indexing-mcp__init_project. - If the index is missing or stale relative to the files the change touches, call
mcp__code-indexing-mcp__index_projectfirst. Tell the user if indexing will take a moment.
2. Resolve the target
mcp__code-indexing-mcp__find_symbolwith an exact match on the target name to locate every definition. If several unrelated symbols match, ask the user which one is meant — do not guess.mcp__code-indexing-mcp__get_chunk— read the definition itself so the analysis is grounded in what the symbol actually does and exposes.
3. Map direct usages and refactor impact
mcp__code-indexing-mcp__find_referencesandmcp__code-indexing-mcp__analyze_refactoronly understand C#, Go, Java, JavaScript, Python, Rust, TSX, and TypeScript declarations; selecting a declaration in any other language returnsUNSUPPORTED_LANGUAGErather than an empty (and misleadingly clean) result. If the target lives in another language, say so and fall back tosearch_code/grep for that part of the analysis.mcp__code-indexing-mcp__find_references— pass the selected declaration'schunk_id, or its project/path/qualified-symbol tuple, to retrieve structural uses. Treatexactas binding evidence,likelyas a required review, andunresolvedplus limitations as blind spots; do not promote them to exact yourself.mcp__code-indexing-mcp__analyze_refactor— for a rename or signature proposal, use its discriminatedoperationinput before planning edits.must_changeis deterministic,likely_changeandreviewneed human inspection, andevidencecan show aliases that bind the target but need no spelling edit (or, for a signature change, compatible call sites).mcp__code-indexing-mcp__emit_refactor_patch— after reviewing ananalyze_refactorresult, call it with the same selector and rename operation to turn the deterministicmust_changesubset into a byte-exact unified diff the user can apply withgit apply. It never edits source files:likely_change/reviewfindings and stale or unverifiable files come back inunappliedandconflictedinstead of the patch, so keep them on the review checklist. Signature changes returnUNSUPPORTED_OPERATION.- Read
completeness.statebefore you characterise the blast radius. Onlycompletemeans every indexed file was analyzed;complete_with_dynamic_limitationsmeans everything was analyzed but some findings rest on conservative, non-structural evidence;incompletemeans whole files were not analyzed at all. The namedlimitations(other languages, parse failures, stale files) name the gap in either non-completecase. Report that gap to the user instead of presenting the finding list as exhaustive. - If you apply the edits, use each finding's
edit_start_byte/edit_end_byte, which cover just the identifier. The widerstart_byte/end_bytespan the whole reference, so replacing that range turnsauth.authorize(u)intopermit(u)and drops the alias fromimport authorize as check. Null edit offsets mean edit that site by hand. - For each distinct file in the results,
mcp__code-indexing-mcp__file_outlineto place the usage in context, andmcp__code-indexing-mcp__get_chunkwhere the exact call matters (signature changes, argument reordering).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 52 lines · 27 tokens per session scan A 6586d735a8fc
impact-analysis is a skill published in the GitHub repository MarcinHamiga/code-indexing-mcp (0 stars, last pushed 4d ago), licensed MIT. It adds 27 tokens to every session and 1,203 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…