code-review-graph

A code-structure map that shows how files and parts of a codebase are connected. It parses source code into a searchable graph so an assistant can find related files without reading the whole project.

In plain words
What is it for?
Use it to find a change's affected files, detect unused code, preview refactors, and map system architecture across a large or multi-repository project.
Why use it?
It reduces irrelevant code in the assistant's working context, especially in large repositories. This makes changes easier to review and their possible effects easier to trace.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/phuonghx/aim-cli/code-review-graph
Any agent
npx skills add phuonghx/aim-cli --skill code-review-graph
Clone the repo
git clone --depth 1 https://github.com/phuonghx/aim-cli

Made for: Claude Code, Codex.

Per session 82 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,558 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00082 $0.01558
Opus 5 $0.00041 $0.00779
Sonnet 5 $0.00016 $0.00312
Haiku 4.5 $0.00008 $0.00156

Measured yesterday against content hash 33bf2b33de9b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

code-review-graph scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

aim/templates/aim-agents/skills/code-review-graph/SKILL.md · 126 lines

How it starts

The opening of the file, as written. The whole thing — 126 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Code Review Graph — Structural Context over Brute-Force Reading

Instead of letting an assistant read an entire directory to understand a change, hand it a structural map. The graph returns only the files actually connected to what you touched.

What It Is

code-review-graph runs as an MCP server. It uses Tree-sitter to parse source into an abstract syntax tree, stores the resulting nodes and relationships in SQLite, and answers context queries from that graph. Ask "what does changing this file affect?" and it returns the impacted files — the blast radius — rather than the whole tree.

The token savings track codebase size:

Repo What to expect
Huge monorepo (10K+ files) Largest win — only a sliver gets read
Mid-size app (1–5K files) Solid reduction on cross-file changes
Small project (<200 files) Marginal — graph upkeep can outweigh it

Scoping to the blast radius also trims noise, which tends to sharpen review focus. Treat any cited multiplier as illustrative and measure on your own repo.

Deciding Whether to Use It

Lean in when the repo is 500+ files, changes routinely span modules, monthly token spend is meaningful, or you live in monorepo / microservice / cross-package territory.

Skip it when the repo is under ~200 files with self-contained edits, the code leans heavily on dynamic tricks (reflection, runtime codegen, dynamic imports), or you want zero maintenance — the graph must stay in sync to be useful.

Benchmark first when you're in the 200–500 file range or mixing static and dynamic patterns; test on representative commits before committing.

Opt-In Bootstrap

On a mid-to-large project, confirm availability before depending on it:

  1. Is the tool installed? Get-Command code-review-graph (Windows) or which code-review-graph (Unix).
  2. Does a .code-review-graph/ directory already exist in the workspace?
  3. Installed but no index? Ask before running code-review-graph build — it scans the whole project.
  4. Not installed and the project is large? Offer to pip install code-review-graph and build a local map, but never install or build without the user agreeing.

Read the full file on GitHub · 126 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 126 lines · 82 tokens per session scan A 33bf2b33de9b

Subscribe to this mod's changes

code-review-graph is a skill published in the GitHub repository phuonghx/aim-cli (1 stars, last pushed 2mo ago), licensed MIT. It adds 82 tokens to every session and 1,558 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

hs-release

Cut a core Hindsight release (vX.Y.Z) and open the changelog + blog PR. Use when asked to cut/start a release, bump the version, or publish a new Hindsight version.

vectorize-io/hindsight · 45 tokens

hindsight-local

Store user preferences, learnings from tasks, and procedure outcomes. Use to remember what works and recall context before new tasks. (user).

vectorize-io/hindsight · 32 tokens

research-repository

Build a repository that makes findings findable, reusable, and cumulative across teams. Use when the same research keeps getting redone. For synthesising one study, use affinity-diagram.

Owl-Listener/designer-skills · 43 tokens

design-negotiation

Advocate for design quality, scope, and timeline with partners and leadership using evidence and shared goals. Use in the conversation itself. For the commercial vocabulary behind it, use business-design (ux-strategy).

Owl-Listener/designer-skills · 48 tokens

user-persona

Build research-grounded personas with goals, frustrations, and behavioural patterns. Use when decisions need a consistent user reference. For one session's emotional snapshot use empathy-map; for motivation framing use jobs-to-be-done.

Owl-Listener/designer-skills · 50 tokens

version-control-strategy

Define version control for design files, components, and libraries — branching, naming, and release. Use when file history is chaotic. For design system contribution rules, use design-system-governance (design-systems).

Owl-Listener/designer-skills · 50 tokens