ai-maestro-code-graph-query
Analyze Code Graph Dependencies
Changing code without dependency context can break callers, serializers, and related components. This skill uses AI Maestro graph commands to inspect relationships before edits.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "ai-maestro-code-graph-query" from https://skillstore.io/skills/23blocks-os-ai-maestro-code-graph-query.md and its manifest at https://skillstore.io/api/skills/23blocks-os-ai-maestro-code-graph-query/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "ai-maestro-code-graph-query". Find the impact of changing the payment processing function.
Expected outcome:
- The function is called by checkout, subscription renewal, and refund workflows.
- It calls validation, card charging, and transaction logging logic.
- Review checkout and renewal tests before changing the function signature.
Using "ai-maestro-code-graph-query". Check dependencies for the user model before adding a field.
Expected outcome:
- The model has serializers for public profile and admin views.
- It is associated with accounts, sessions, orders, and audit records.
- Update serializer coverage and migration tests before exposing the new field.
Security Audit
High RiskThe skill provides useful AI Maestro code graph workflows, but it relies on Bash execution and strongly mandates automatic graph queries after reading files. The highest risks are unbundled PATH-resolved scripts, hidden home-directory installation under ~/.local/bin, and coercive prompt text that can push agents to execute commands without fresh user intent.
Confirmed security concerns (2)
Capability review items (31)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Filesystem access (8)
โ๏ธ External commands (40)
๐ Network access (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/23blocks-os-ai-maestro-code-graph-query/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/23blocks-os-ai-maestro-code-graph-query?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/23blocks-os-ai-maestro-code-graph-query?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/23blocks-os-ai-maestro-code-graph-query/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/23blocks-os-ai-maestro-code-graph-query.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
23blocks-OS. (2026). ai-maestro-code-graph-query security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/23blocks-os-ai-maestro-code-graph-query/audits/6BibTeX citation
@techreport{23blocks-os-23blocks-os-ai-maestro-code-graph-query-2026,
author = {23blocks-OS},
title = {ai-maestro-code-graph-query security audit report (audit version 6)},
institution = {Skillstore},
year = {2026},
number = {6},
url = {https://skillstore.io/skills/23blocks-os-ai-maestro-code-graph-query/audits/6},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ai-maestro-code-graph-query security audit report (audit version 6)"
version: "unspecified"
type: report
authors:
- name: "23blocks-OS"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/23blocks-os-ai-maestro-code-graph-query/audits/6"
identifiers:
- type: other
value: "skillstore:23blocks-os-ai-maestro-code-graph-query:audit:6"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Review Model Change Impact
Find serializers, associations, and dependent code before changing a model.
Prepare Safer Refactors
Identify callers and callees before changing a function signature or moving logic.
Explore Unknown Codebases
Map relationships between controllers, services, jobs, and components during onboarding.
Try These Prompts
Use the code graph to describe this component. Summarize what it depends on and what depends on it.
Find callers and callees for this function. Explain which callers need review before I edit it.
Find serializers, associations, and related components for this model. Highlight any risky downstream dependencies.
Trace the call path between this entry point and this internal function. Explain the main layers and change risks.
Best Practices
- Confirm graph commands with the user before running Bash in a repository.
- Refresh the graph index after meaningful code changes.
- Compare graph results with tests before making high-impact refactors.
Avoid
- Running PATH-resolved graph scripts without checking their source.
- Treating graph output as complete when the index may be stale.
- Changing public functions without reviewing callers and tests.
Frequently Asked Questions
What does this skill connect to?
Does it require Bash?
Can it work without an indexed graph?
Does it send code to an external service?
Why review commands before use?
Who benefits most from this skill?
Developer Details
Author
23blocks-OSLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
c1fdca50ff516318f65fed0d7f9e82797c5171dc
Maintenance freshness
7/20/2026
Usage
27 downloads ยท 188 views
File structure
๐ output.json
๐ SKILL.md