跳到主要内容
知仓学习社ZHICANG

code-to-diagram

Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts. Uses AST parsing to map import dependencies for Pyth…

读凭据执行命令读文件严重 1 · 高危 1zebbern/claude-code-guide

它会碰到什么

扫了多少3 个文本文件,21 KB
它会碰到什么读凭据执行命令读文件
命中总数6 处
命中统计严重 1 · 高 1 · 中 4 · 低 0
逐条看命中(2 条严重或高危)
  • 严重 scripts/analyze_codebase.py:123cred-paths
    "env", ".env", ".idea", ".vscode", "coverage", ".cache",
  • scripts/analyze_codebase.py:379exec-spawn
    result = subprocess.run(

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Code to Diagram

Extract import and dependency relationships from a codebase via AST parsing, and automatically generate three types of diagrams:

  1. Architecture Diagram — Module/directory-level dependency relationships
  2. Flowchart — File-level import call chains
  3. Org Chart — Directory/file hierarchy structure

Supported languages: Python, JavaScript, TypeScript, Go, Java

Output formats: Mermaid text (.mmd) or SVG images (requires mmdc installed on the system)

Usage

Basic: Analyze an Entire Project

python3 scripts/analyze_codebase.py /path/to/project

Outputs three Mermaid diagrams to stdout and writes .mmd files to the current directory.

Specify Diagram Type

# Architecture diagram only
python3 scripts/analyze_codebase.py /path/to/project --type architecture

# Flowchart only
python3 scripts/analyze_codebase.py /path/to/project --type flowchart

# Org chart only
python3 scripts/analyze_codebase.py /path/to/project --type org

Specify Output Directory and Format

# Output to a specific directory
python3 scripts/analyze_codebase.py /path/to/project --output /tmp/diagrams

# Output as SVG (requires mmdc)
python3 scripts/analyze_codebase.py /path/to/project --format svg

# Output both Mermaid and SVG
python3 scripts/analyze_codebase.py /path/to/project --format both

Output JSON Analysis Results

python3 scripts/analyze_codebase.py /path/to/project --json

Parameters

| Parameter | Description |

|-----------|-------------|

| directory | Code directory to analyze (required) |

| --type, -t | Diagram type: architecture, flowchart, org, all (default: all) |

| --output, -o | Output directory (default: current directory) |

| --format, -f | Output format: mermaid, svg, both (default: mermaid) |

| --max-files | Maximum number of files to scan (default: 500) |

| --max-depth | Maximum depth for org chart (default: 4) |

| --json | Output analysis results in JSON format |

How It Works

  1. Scan phase: Recursively traverse the directory, skipping node_modules, .git, __pycache__, etc.
  2. Parse phase:
  • Python files: uses the ast module to parse import and from ... import statements
  • JS/TS files: uses regex to match import, require, and export from
  • Go files: uses regex to match import statements
  • Java files: uses regex to match import statements
  1. Resolve internal dependencies: Maps import paths to actual files within the project
  2. Generate diagrams: Converts dependency relationships into Mermaid diagram syntax
  3. Render (optional): Calls mmdc (Mermaid CLI) to render .mmd files as SVG

Use Cases

  • Quickly understand the module structure of an unfamiliar project
  • Visualize dependencies during code review
  • Create architecture diagrams for technical documentation
  • Detect circular dependencies or excessive coupling
  • Analyze project structure before refactoring

Dependencies

  • Python 3.7+ (standard library only, no extra packages needed)
  • SVG output requires @mermaid-js/mermaid-cli (optional)

Notes

  • Only analyzes static import relationships; dynamic imports are not tracked
  • For large projects, use --max-files to limit the scan scope
  • Mermaid diagrams with too many nodes may be hard to render; use --type to generate diagrams separately

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。