diagramming-code
An agent skill by trailofbits, from trailofbits/skills. Tags: analysis, architecture, diagramming, documentation.
What it does
Generates Mermaid diagrams from Trailmark code graphs. Produces call graphs, class hierarchies, module dependency maps, containment diagrams, complexity heatmaps, and attack surface data flow visualizations. Use when visualizing code architecture, drawing call graphs, generating class diagrams, creating dependency maps, producing complexity heatmaps, or visualizing data flow and attack surface paths as Mermaid diagrams.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add trailofbits/skills --skill diagramming-code
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/trailofbits/skills
cp -r skills/plugins/trailmark/skills/diagramming-code ~/.claude/skills/diagramming-code
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- trailofbits/skills (all skills from this repository)
- Path
- plugins/trailmark/skills/diagramming-code/SKILL.md
- Branch
- main
- Collection
- trailmark
- Updated
- 2026-09-19
Related skills
- trailmark-summary — Runs a Trailmark summary analysis on a codebase. Returns auto-detected languages, entry point count, and dependency list.
- crypto-protocol-diagram — spthy) models and generates Mermaid sequenceDiagrams with cryptographic annotations.
- trailmark — Builds and queries multi-language source and binary code graphs for security analysis. toml`, and SQL schema graphs.
- trailmark-structural — 5+ data such as proxy counts, subgraph edges, type/reference summaries, and entrypoint attributes.
- audit-context-building — Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.
- audit-prep-assistant — Prepares codebases for security review using Trail of Bits' checklist.