plugins/github-copilot-modernization/skills/building-java-knowledge-graph/SKILL.md
Analyzes JVM projects (Java/Kotlin/Scala/Groovy) and generates knowledge graphs with tree-sitter parsing. Requires Python 3 on the host and a JVM project with Maven/Gradle/Ant/Ivy build files. Skips gracefully if either prerequisite is missing. Triggers when asked to "build knowledge graph", "analyze project structure", "parse Java codebase", or "generate dependency graph".
npx skillsauth add microsoft/github-copilot-modernization building-java-knowledge-graphInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Step 1 — Verify JVM project:
find "$PROJECT_ROOT" -maxdepth 5 -type f \( -name "*.java" -o -name "*.kt" -o -name "*.scala" -o -name "*.groovy" \) | head -1
If no JVM files found: skip this skill. Set
knowledge_graph_dirtonullinsetup_artifacts. Non-fatal — downstream agents fall back to direct source analysis.
Step 2 — Verify Python:
python3 --version 2>/dev/null || python --version 2>/dev/null
If unavailable: skip this skill with same fallback as above.
# First-time setup (~1 minute)
pip3 install --user 'tree-sitter<0.21'
python3 scripts/install_grammars.py
# Optional: SVG generation
brew install graphviz # macOS
# Analyze project
python3 scripts/build_knowledge_graph.py /path/to/project output-dir
⚠️ DESTRUCTIVE OUTPUT: The script wipes ALL files in output-dir before writing. NEVER point it at a shared directory like {{BASE_PATH}}/ or {{BASE_PATH}}/artifacts/. Use a dedicated subdirectory:
# ✅ SAFE — dedicated subdirectory
python3 scripts/build_knowledge_graph.py /path/to/project {{BASE_PATH}}/artifacts/kg_output
# ❌ DANGER — will delete constitution.md, board.md, other artifacts!
python3 scripts/build_knowledge_graph.py /path/to/project {{BASE_PATH}}
After the script finishes, copy knowledge-graph.json to {{BASE_PATH}}/ for other agents to consume.
application*.properties, application*.yaml/ymlsettings.gradle parsingAll outputs are written under the provided artifact path (pass as 2nd argument to the script).
knowledge-graph.json ← complete graph (nodes + edges)
module-dependencies.{dot,svg} ← module dependency diagram
module-{name}.{dot,svg} ← per-module class diagrams
project-{name}.{dot,svg} ← complete project diagram
references/schema.md — node/edge types, ID patterns, fields, visualization colorsreferences/querying.md — jq and Python query examplesscripts/build_knowledge_graph.py — main analyzerscripts/install_grammars.py — grammar installerdevelopment
Scan dependency manifests against known CVEs and remediate by upgrading vulnerable dependencies to patched versions, then rebuild and re-scan to confirm. Self-contained scan→fix→verify loop for any project with a dependency manifest. Use when: a cve-remediation task is dispatched; dependency set changed (version bump, new framework); assessment flagged vulnerable or EOL dependencies; or user asked to "fix CVEs", "patch vulnerabilities", or "dependency security". Triggers: "cve", "remediate cve", "fix cves", "patch vulnerable dependencies", "vulnerability scanning", "dependency security", "vulnerable dependencies", "security advisories", "npm audit", "pnpm audit", "maven audit", "gradle audit", "dependency scan", "vulnerability remediation". NOT for: security audit of auth/input/secrets/OWASP code paths (use security-review).
development
Generate dependency map diagram from project build files
documentation
Generate data architecture and persistence layer documentation with data model diagram
documentation
Generate core business workflow documentation with sequence diagram