Atlas / Skills / ruvnet / Kg Extract

Kg ExtractCAUTION

skills/ruvnet/kg-extract

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Verdict
CAUTION
Grade
B
Trust score
89 /100
Version
—
Hosts
—
License
MIT
Stars
73,288
01

Overview

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Read from source at commit ef7d4f0535e5OBSERVED · 2026-09-26
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: kg-extract
description: Extract entities and relations from source files to build a knowledge graph
argument-hint: "<path>"
allowed-tools: Read Glob Grep mcp__plugin_ruflo-core_ruflo__agentdb_hierarchical-store mcp__plugin_ruflo-core_ruflo__agentdb_causal-edge mcp__plugin_ruflo-core_ruflo__agentdb_pattern-store mcp__plugin_ruflo-core_ruflo__embeddings_generate Bash
---

# KG Extract

Extract entities (classes, functions, modules, types, concepts) and their relations (imports, extends, implements, depends-on, calls) from source files, then store them as a knowledge graph in AgentDB.

## When to use

When you need to build or update a knowledge graph from source code or documentation. Useful for understanding codebase structure, dependency analysis, and impact assessment.

## Steps

1. **Scan files** -- use `Glob` and `Read` to enumerate and read source files at the given path
2. **Identify entities** -- extract classes, functions, modules, types, and config references from each file
3. **Map relations** -- for each entity, determine its relations to other entities. **Critical: TypeScript `import type` and inline `type` specifiers (`import { type Foo, bar }`) are erased at compile time and MUST NOT be counted as value imports** -- they're a separate, weaker relation. Misclassifying them produces phantom runtime cycles (see ruvnet/ruflo#2049).
   - `imports`: value imports (`import { x } from '...'`, `require(...)`) -- weight `0.9`
   - `type-depends-on`: TypeScript type-only imports (`import type { Foo } from '...'` and `import { type Foo, value } from '...'`) -- weight `0.1`, **never used for cycle detection or runtime impact analysis**
   - `extends`: class inheritance -- weight `0.9`
   - `implements`: interface implementations -- weight `0.7`
   - `depends-on`: constructor dependencies, injected services -- weight `0.8`
   - `calls`: function/method invocations -- weight `0.7`
   - `references`: documentation mentions, comments -- weight `0.3`

   **Regex hint for classifying TS imports** (so a naive `from '...'` grep doesn't conflate the two):
   ```
   ^\s*import\s+type\s+               → type-depends-on (entire import is type-only)
   ^\s*import\s*\{[^}]*\btype\s+\w+   → split: type specifiers → type-depends-on, value specifiers → imports
   ^\s*import\s+[^{]*\bfrom\s+        → imports (value)
   ```
4. **Store in AgentDB** -- call `mcp__plugin_ruflo-core_ruflo__agentdb_hierarchical-store` for each entity with metadata (name, type, file, line, description)
5. **Create edges** -- call `mcp__plugin_ruflo-core_ruflo__agentdb_causal-edge` for each relation with source, target, relation type, and weight
6. **Report** -- summarize: total entities by type, total relations by type, files scanned

## CLI alternative

```bash
npx @claude-flow/cli@latest memory store --namespace knowledge-graph --key "entity-NAME" --value "METADATA_JSON"
npx @claude-flow/cli@latest memory search --query "entities in auth module" --namespace knowledge-graph
```
03

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMInventory / provenance · inv.symlink · CWE-1104
crates
crates
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/agents
plugin/agents
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/commands
plugin/commands
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/skills
plugin/skills
Why it matters. link not followed

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha ef7d4f0535e5full audit observations/trust-audit/skill/ruvnet__kg-extract.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-26ef7d4f0535e5CAUTIONB89first audit
05

Questions

What does the Kg Extract skill do?

🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

Is Kg Extract safe to install?

With care. The audit graded it B (89/100) and found 4 things worth knowing before you trust this skill, listed below with the exact line each was found on.

What can Kg Extract access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (ef7d4f0535e5), read on 2026-09-26. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement