Diagramming Code

trailofbits/skills/plugins/trailmark/skills/diagramming-code

作者 trailofbits82fe82262526無授權條款7.4K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫昨天更新

Generates Mermaid diagrams from Trailmark code graphs. Produces call graphs, class hierarchies, module dependency maps, containment diagrams, complexity heatmaps, and attack surface data flow visualizations. Use when visualizing code architecture, drawing call graphs, generating class diagrams, creating dependency maps, producing complexity heatmaps, or visualizing data flow and attack surface paths as Mermaid diagrams.

AI 產生的概覽

根據 Trailmark 程式碼圖產生 Mermaid 圖表,例如呼叫圖、類別階層與相依性圖。

功能
此技能會把程式碼庫經 Trailmark 解析後的圖轉換成 Mermaid 圖表文字。它支援呼叫圖、類別繼承階層、模組相依圖、包含關係圖、複雜度熱圖以及資料流檢視,並可設定焦點節點、走訪深度、版面方向與複雜度門檻。內附指令碼負責產生 Mermaid 語法,輸出為可直接嵌入程式碼區塊的原始 Mermaid 文字。
適用情境
適合需要視覺化程式碼架構的情況,例如繪製函式之間的呼叫路徑、對應模組匯入關係、呈現類別結構、標示複雜度熱點,或追蹤從進入點到敏感函式的資料流。不適合只查詢圖形而不做視覺化,也不適合手繪的架構圖。
執行需求
必須安裝 Trailmark,通常以 uv tool install trailmark 安裝,並透過 uv 執行指令。此技能附有可執行指令碼 scripts/diagram.py 以及參考文件;在 Trailmark 0.4.0 以上版本,經版本檢查後可使用原生的 trailmark diagram 指令。若尚未安裝 Trailmark,則需要網路連線才能安裝。

Diagramming Code

Generates Mermaid diagrams from Trailmark's code graph. A pre-made script handles Mermaid syntax generation; Claude selects the diagram type and parameters. Trailmark 0.4.0 includes a native trailmark diagram command; use it only after a version/command check, otherwise use this skill's bundled script.

When to Use

  • Visualizing call paths between functions
  • Drawing class inheritance hierarchies
  • Mapping module import dependencies
  • Showing class structure with members
  • Highlighting complexity hotspots with color coding
  • Tracing data flow from entrypoints to sensitive functions

When NOT to Use

  • Querying the graph without visualization (use the trailmark skill)
  • Mutation testing triage (use the genotoxic skill)
  • Architecture diagrams not derived from code (draw by hand)

Prerequisites

trailmark must be installed. If uv run trailmark fails, run:

bash
uv tool install trailmark# Python snippets: uv run --with trailmark python -   (a tool env is not importable)

DO NOT fall back to hand-writing Mermaid from source code reading. The script uses Trailmark's parsed graph for accuracy. If installation fails, report the error to the user.

Version Gate

Check whether native v0.4 diagram support exists:

bash
trailmark diagram --help 2>/dev/null || uv run trailmark diagram --help 2>/dev/null

If this succeeds, you may use trailmark diagram. If it fails, use uv run {baseDir}/scripts/diagram.py, which keeps the older skill workflow intact. Do not assume the native CLI exists on Trailmark 0.2.x.


Quick Start

bash
uv run {baseDir}/scripts/diagram.py \    --target {targetDir} --language auto --type call-graph \    --focus main --depth 2
# Trailmark 0.4.0+ equivalent after the Version Gate succeedsuv run trailmark diagram \    --target {targetDir} --language auto --type call-graph \    --focus main --depth 2

Output is raw Mermaid text. Wrap in a fenced code block:

markdown
```mermaidflowchart TB    ...```

Diagram Types

├─ "Who calls what?"               → --type call-graph├─ "Class inheritance?"             → --type class-hierarchy├─ "Module dependencies?"           → --type module-deps├─ "Class members and structure?"   → --type containment├─ "Where is complexity highest?"   → --type complexity└─ "Path from input to function?"   → --type data-flow

For detailed examples of each type, see references/diagram-types.md [blocked].


Workflow

Diagram Progress:- [ ] Step 1: Verify trailmark is installed- [ ] Step 2: Identify diagram type from user request- [ ] Step 3: Determine focus node and parameters- [ ] Step 4: Run diagram.py script (or native trailmark diagram on v0.4+)- [ ] Step 5: Verify output is non-empty and well-formed- [ ] Step 6: Embed diagram in response

Step 1: Run uv run trailmark analyze --language auto --summary {targetDir}. Install if it fails. Then run pre-analysis via the programmatic API:

python
from trailmark.query.api import QueryEngine
engine = QueryEngine.from_directory("{targetDir}", language="auto")engine.preanalysis()

Pre-analysis enriches the graph with blast radius, taint propagation, and privilege boundary data used by data-flow diagrams.

If auto-detection is wrong for the target, rerun with an explicit language or comma-separated list such as python,rust.

Step 2: Match the user's request to a --type using the decision tree above.

Step 3: For call-graph and data-flow, identify the focus function. Default --depth 2. Use --direction LR for dependency flows.

Step 4: Run the script and capture stdout. If the native v0.4 CLI is available, either command is acceptable; prefer the bundled script when you need behavior consistent with this skill's references.

Step 5: Check: output starts with flowchart or classDiagram, contains at least one node. If empty or malformed, consult references/mermaid-syntax.md [blocked].

Step 6: Wrap output in ```mermaid ``` code fence.


Script Reference

uv run {baseDir}/scripts/diagram.py [OPTIONS]# or, on Trailmark 0.4.0+:uv run trailmark diagram [OPTIONS]
ArgumentShortDefaultDescription
--target-trequiredDirectory to analyze
--language-lpythonSource language
--type-TrequiredDiagram type (see above)
--focus-fnoneCenter diagram on this node
--depth-d2BFS traversal depth
--directionTBLayout: TB (top-bottom) or LR (left-right)
--threshold10Min complexity for complexity type

Examples

bash
# Call graph centered on a functionuv run {baseDir}/scripts/diagram.py -t src/ -T call-graph -f parse_file
# Class hierarchy for a Rust projectuv run {baseDir}/scripts/diagram.py -t src/ -l rust -T class-hierarchy
# Module dependency map, left-to-rightuv run {baseDir}/scripts/diagram.py -t src/ -T module-deps --direction LR
# Class membersuv run {baseDir}/scripts/diagram.py -t src/ -T containment
# Complexity heatmap (threshold 5)uv run {baseDir}/scripts/diagram.py -t src/ -T complexity --threshold 5
# Data flow from entrypoints to a specific functionuv run {baseDir}/scripts/diagram.py -t src/ -T data-flow -f execute_query

Customization

Direction: Use TB (default) for hierarchical views, LR for left-to-right flows like dependency chains.

Depth: Increase --depth to see more of the call graph. Decrease to reduce clutter. The script warns if the diagram exceeds 100 nodes.

Focus: Always use --focus for call-graph on non-trivial codebases. For data-flow, omitting focus auto-targets the top 10 complexity hotspots.

Language: Prefer --language auto for polyglot or unfamiliar repos. Use an explicit language only when you know the target is single-language or you need to exclude unrelated components.


Supporting Documentation

  • references/diagram-types.md [blocked] - Detailed docs and Mermaid examples for each diagram type
  • references/mermaid-syntax.md [blocked] - ID sanitization, escaping, style definitions, and common pitfalls

來源與署名

來源:trailofbits/skills位於plugins/trailmark/skills/diagramming-code提交82fe822

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架