Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/quangphu1912/codebase-analyzer/extract-tool-graphnpx skills add quangphu1912/codebase-analyzer --skill extract-tool-graphgit clone --depth 1 https://github.com/quangphu1912/codebase-analyzerWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00031 | $0.01042 |
| Opus 5 | $0.00015 | $0.00521 |
| Sonnet 5 | $0.00006 | $0.00208 |
| Haiku 4.5 | $0.00003 | $0.00104 |
Grade A, and why
extract-tool-graph scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Announce at start: "Using codebase-analyzer to extract the tool graph."
Overview
Map ALL tools/capabilities that exist in the codebase, including those conditionally excluded. The tool graph reveals what the system CAN do, even if it doesn't currently expose it.
Prerequisite: Reads docs/analysis/agent-loop.md and docs/analysis/build-pipeline.md.
Process
Step 1: Find Tool Definitions
Search for every tool definition across the codebase:
- Function handlers — request/response handlers, middleware chains
- API endpoints — route registrations, controller methods
- CLI commands — argument parsers, subcommand definitions
- Plugin hooks — lifecycle callbacks, event subscribers, extension points
Use broad search patterns: route registrations, decorator annotations, command maps, handler dictionaries, and interface implementations.
Step 2: Map Tool Registry
Trace how tools are registered and discovered:
- Static registries (maps, arrays, enums defined at module load)
- Dynamic registries (tools added at runtime via registration calls)
- Convention-based discovery (auto-loading from directories, reflection)
- Dependency injection containers (services registered by name or interface)
Step 3: Identify Conditional Registration
Find tools defined but only registered under certain conditions:
- Feature-flag-guarded registrations (
if config.featureEnabled('x')) - Environment-dependent registrations (
if process.env.NODE_ENV === 'production') - Role-dependent registrations (
if user.role === 'admin') - Provider-specific registrations (
if provider === 'openai')
These tools EXIST in the code but are invisible at runtime. They are the hidden capability surface.
Step 4: Find Dynamic Tool Registration
Trace tools loaded from external sources:
- Database-driven tool menus or permission sets
- Config-file-driven feature lists
- Plugin system tool discovery (scanning directories, loading modules)
- Remote API-driven capability negotiation
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 115 lines · 31 tokens per session scan A 40b64031eb3b
extract-tool-graph is a skill published in the GitHub repository quangphu1912/codebase-analyzer (2 stars, last pushed 4mo ago), licensed MIT. It adds 31 tokens to every session and 1,042 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…