Build GraphSAFE
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
Overview
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
a9c894db76a7OBSERVED · 2026-10-06What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: build-graph description: Build or update the code review knowledge graph. Run this first to initialize, or let hooks keep it updated automatically. argument-hint: "[full]" --- # Build Graph Build or incrementally update the knowledge graph for this repository. ## Steps 1. Call `list_graph_stats_tool`. If `last_updated` is null, the graph has never been built. 2. For a first build, or when the argument is `full`, call `build_or_update_graph_tool(full_rebuild=True)`. Otherwise call `build_or_update_graph_tool()` for an incremental update. 3. Report the response: `status` (`ok`, `partial` or `error`) and `summary`. ## When to Use - First set-up of a repository, or after a branch switch or large refactor. - When the graph looks stale. Hooks installed by `code-review-graph install` run an update after each edit and before each commit, so manual builds are rarely needed. ## Notes - The database is `.code-review-graph/graph.db` in the repository root. - Binary files, dependency and build directories, and patterns in `.code-review-graphignore` are skipped. - For the list of supported languages call `get_docs_section_tool(section_name="languages")`.
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
a9c894db76a7full audit observations/trust-audit/skill/tirth8205__build-graph.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | a9c894db76a7 | SAFE | B | 89 | first audit |
Questions
What does the Build Graph skill do?
Local-first code intelligence graph for MCP and CLI. Builds a persistent map of your codebase so AI coding tools read only what matters, with benchmarked context reductions on reviews and large-repo workflows.
Is Build Graph safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Build Graph access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (a9c894db76a7), read on 2026-10-06. The repository is watched, and a new audit runs when it changes — this is the first audit.