Skip to content
Back to skills

Call Graph

ASecurity

Map the callers and dependencies of a symbol to understand blast radius before changing it

  • 3 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 3, 2026
ai-agentsgo

Works with

  • cli

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill call-graph --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Call Graph?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Call Graph
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-call-graph/badge)](https://www.skillsdirectory.com/skills/black141312-call-graph)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: call-graph
description: Map the callers and dependencies of a symbol to understand blast radius before changing it
category: code-understanding
---

# Call Graph

Use before modifying or removing a function, method, or type when you need to know who depends on it and what it depends on.

1. Pin down the exact symbol: its definition, signature, and the module/namespace that exports it.
2. Find callers — grep for the name across the repo, then filter out shadowing, comments, and unrelated same-name symbols.
3. Find dependencies — list the functions, types, and external modules this symbol calls or uses.
4. Follow indirection: interfaces/abstract methods, dynamic dispatch, dependency injection, event handlers, and re-exports that hide real call sites.
5. Note entry points that reach the symbol (HTTP routes, CLI commands, jobs, tests) so you know the real blast radius.
6. Summarize as inbound (callers) and outbound (dependencies), flagging anything public/exported or crossing a package boundary.

## Rules
- A grep for the bare name over-matches; confirm each hit is the same symbol, not a namesake.
- Account for indirect calls — interface implementations and string-keyed dispatch will not show as direct references.
- Treat exported/public symbols as having unknown external callers; say so when the repo is a library.
- Distinguish test-only callers from production callers; they imply different risk.
- Report concrete file:line references, not vague counts.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…