Skip to content
Back to skills

Build Dependency Graph

ASecurity

Systematically enumerate import and call relationships across a codebase, build a structured dependency graph, and emit both dependency-graph.yaml (structured data) and dependency-graph.md (mermaid diagrams + module clusters). Used by tech-architect.

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 10, 2026
developmentpythongojavabashnode

Security analysis

A100/100

Scanned September 10, 2026

npx -y skills add kapilvirenahuja/garura --skill build-dependency-graph --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Build Dependency Graph?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Build Dependency Graph
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/kapilvirenahuja-build-dependency-graph/badge)](https://www.skillsdirectory.com/skills/kapilvirenahuja-build-dependency-graph)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: build-dependency-graph
description: Systematically enumerate import and call relationships across a codebase, build a structured dependency graph, and emit both dependency-graph.yaml (structured data) and dependency-graph.md (mermaid diagrams + module clusters). Used by tech-architect.
user-invocable: false
model: sonnet
allowed-tools: Read, Write, Grep, Glob, Bash
deprecated: true
deprecated_note: '#434 ProductOS realignment — superseded by the command model; retained for Phase E reference, not installed'
---

# build-dependency-graph

Model-invocable skill for structured dependency-graph artifact authorship.

## Purpose

Walk import/require/use statements across a codebase, collapse to module-level edges, and write a structured graph plus a visual representation. Emit two artifacts: `dependency-graph.yaml` (data) and `dependency-graph.md` (mermaid + narrative).

Previously carved out of tech-architect as a "core architect capability." This skill owns it now.

## Input

| Field | Required | Description |
|-------|----------|-------------|
| `project_root` | yes | Codebase root |
| `focus_paths` | optional | Sub-paths to include (default: all source dirs) |
| `language_hint` | optional | Language(s) present: py, ts, js, go, java, ... (otherwise auto-detect) |
| `output_base` | yes | Directory to write both artifacts |

## Process

1. **Detect language(s).** From extensions + config files (go.mod, pyproject.toml, package.json).

2. **Enumerate import statements.** Grep systematically by language:
   - Python: `^\s*(from|import)\s+`
   - TS/JS: `^\s*import\s.*from|^\s*const\s.*require\(`
   - Go: `^import\s*\(|^\s*"`  (inside `import ( ... )` blocks)
   - Java: `^import\s+`

3. **Build file-level edges.** `source_file → target_symbol` pairs.

4. **Collapse to module-level edges.** Group by top-level package/directory.

5. **Detect cycles.** Tarjan/Kosaraju over the module graph. Record each SCC with >1 node as a cycle.

6. **Identify hubs.** Modules with fan-in or fan-out above configurable thresholds (defaults: fan-in >= 8, fan-out >= 8).

7. **Emit dependency-graph.yaml:**

   ```yaml
   project_root: "{project_root}"
   generated_at: "{ISO-8601}"
   languages: [ ... ]
   modules:
     - id: "{module-path}"
       files: {count}
       fan_in: {n}
       fan_out: {n}
   edges:
     - from: "{module}"
       to: "{module}"
       weight: {count of file-level edges}
   cycles:
     - modules: [ "...", "..." ]
       size: {n}
   hubs:
     - module: "{id}"
       fan_in: {n}
       fan_out: {n}
       reason: high_fan_in | high_fan_out | both
   ```

8. **Emit dependency-graph.md:**

   - Mermaid `graph LR` of module-level edges
   - Cluster diagrams per top-level package
   - Cycle callout sections with offending module list
   - Hub callouts

## Output

```yaml
dependency_graph_yaml_path: "{output_base}/dependency-graph.yaml"
dependency_graph_md_path: "{output_base}/dependency-graph.md"
module_count: {n}
edge_count: {n}
cycle_count: {n}
status: written
```

## Boundaries

- Read-only.
- Module-level aggregation — do not emit per-file edges in the YAML (too noisy); keep them only in internal computation.
- Mermaid diagrams in the `.md` must remain renderable — cap at ~60 nodes; for larger codebases split by top-level package.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…