Token导航 LogoToken导航TokenDH.com
前端设计敏感数据github未标认证来源可访问许可证需确认审计提醒

flowzap-diagrams流程图

Agent Skill

flowzap-diagrams 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

297

周安装

12

GitHub Stars

2

下载量

93
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:flowzap-diagrams(流程图)
来源仓库:https://github.com/flowzap-xyz/flowzap-mcp
仓库路径:skills/flowzap-diagrams
安装命令:
npx skills add https://github.com/flowzap-xyz/flowzap-mcp --skill flowzap-diagrams
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/flowzap-xyz/flowzap-mcp --skill flowzap-diagrams

简介

flowzap-diagrams 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息。

  • 适合在 Codex、Claude、Cursor、Gemini CLI 中围绕仓库状态、代码变更或协作事项进行整理。
  • 通过 npx skills add 命令从指定 GitHub 仓库安装并使用。
  • 安装前需确认权限范围、维护状态,注意是否触发联网、命令执行或文件读写。
  • 建议结合原始 README 和仓库内容核验具体用法和功能边界。

SKILL.md

FlowZap Diagram Skill

Generate valid FlowZap Code (.fz) diagrams from natural-language descriptions, validate them, and return shareable playground URLs — all without leaving your coding agent.

When to use this skill

  • User asks for a workflow, flowchart, process diagram, sequence diagram, or achitecture diagram.
  • User pastes HTTP logs, OpenAPI specs, or code and wants them visualised.
  • User wants to compare two diagram versions (diff) or patch an existing diagram.

MCP server setup (one-time)

If the FlowZap MCP server is not already configured, install it:

# Claude Code
claude mcp add --transport stdio flowzap -- npx flowzap-mcp@1.3.5

# Or add to .mcp.json / claude_desktop_config.json / cursor / windsurf config:
{
  "mcpServers": {
    "flowzap": {
      "command": "npx",
      "args": ["flowzap-mcp@1.3.5"]
    }
  }
}

Package verification

The pinned version 1.3.5 can be verified against the npm registry:

FieldValue
npmflowzap-mcp@1.3.5
Integrity (SHA-512)sha512-MjiOEHoG08UdLflnls6Ij07bXiJmuGbCrWSm5fycizZ70PecVeAb0DSrrFxAPOB8hQcZ0Y/WQtXbgRRQr/t/nA==
Shasum374c7a966c1a1f350216c513df32383a772d360d
Sourcegithub.com/flowzap-xyz/flowzap-mcp
LicenseMIT

To verify locally before use:

npm view flowzap-mcp@1.3.5 dist.integrity dist.shasum

Compatible tools: Claude Desktop, Claude Code, Cursor, Windsurf, OpenAI Codex, Warp, Zed, Cline, Roo Code, Continue.dev, Sourcegraph Cody.

Not compatible: Replit, Lovable.dev.

Available MCP tools

ToolPurpose
flowzap_validateCheck.fz syntax before sharing
flowzap_create_playgroundGet a shareable playground URL
flowzap_get_syntaxRetrieve full DSL docs at runtime
flowzap_export_graphExport diagram as structured JSON (lanes, nodes, edges)
flowzap_artifact_to_diagramParse HTTP logs / OpenAPI / code → diagram + playground URL
flowzap_diffStructured diff between two.fz versions
flowzap_apply_changePatch a diagram (insert/remove/update nodes/edges)

FlowZap Code DSL — quick reference

FlowZap Code is not Mermaid, not PlantUML. It is a unique DSL offering a simple syntax for a triple-view option to workflow, sequence and architecture diagrams.

Shapes (only 4)

ShapeUse for
circleStart / End events
rectangleProcess steps / actions
diamondDecisions (Yes/No branching)
taskboxAssigned tasks (owner, description, system)

Syntax rules

  • Node IDs are globally unique, sequential, no gaps: n1, n2, n3
  • Node attributes use colon: label:"Text"
  • Edge labels use equals inside brackets: [label="Text"]
  • Handles are required on every edge: n1.handle(right) -> n2.handle(left)
  • Directions: left, right, top, bottom
  • Cross-lane edges: prefix target with lane name: sales.n5.handle(top)
  • Lane display label: one # Label comment right after opening brace
  • Loops: loop [condition] n1 n2 n3 — flat, inside a lane block
  • Layout: prefer horizontal left→right; use top/bottom only for cross-lane hops

Multi-lane sequence design

  • Ping-pong rule: For multi-participant processes, every cross-lane interaction must alternate back-and-forth between lanes. A request from Lane A → Lane B must be followed by a response from Lane B → Lane A before any new request from Lane A. This ensures the sequence view renders meaningful request-response message pairs rather than one-way broadcasts.

Gotchas — never do these

  • Do NOT use label="Text" on nodes (must be label:"Text").
  • Do NOT use label:"Text" on edges (must be [label="Text"]).
  • Do NOT skip node numbers (n1, n3 → invalid; must be n1, n2).
  • Do NOT omit lane prefix on cross-lane edges.
  • Do NOT output Mermaid, PlantUML, or any other syntax.
  • Do NOT add comments except the single # Display Label per lane.
  • Do NOT place loop outside a lane's braces.
  • Do NOT use a taskbox shape unless the user explicitly requests it.

Minimal templates

Single lane:

process { # Process
n1: circle label:"Start"
n2: rectangle label:"Step"
n3: circle label:"End"
n1.handle(right) -> n2.handle(left)
n2.handle(right) -> n3.handle(left)
}

Two lanes with cross-lane edge:

user { # User
n1: circle label:"Start"
n2: rectangle label:"Submit"
n1.handle(right) -> n2.handle(left)
n2.handle(bottom) -> app.n3.handle(top) [label="Send"]
}

app { # App
n3: rectangle label:"Process"
n4: circle label:"Done"
n3.handle(right) -> n4.handle(left)
}

Decision branch:

flow { # Flow
n1: rectangle label:"Check"
n2: diamond label:"OK?"
n3: rectangle label:"Fix"
n4: rectangle label:"Proceed"
n1.handle(right) -> n2.handle(left)
n2.handle(bottom) -> n3.handle(top) [label="No"]
n2.handle(right) -> n4.handle(left) [label="Yes"]
}

For the full DSL specification and advanced multi-lane examples: See references/syntax.md

Workflow: how to generate a diagram

  1. Identify the actors/systems (→ lanes) and steps (→ nodes) from the user's description.
  2. Write FlowZap Code following all rules above.
  3. Call flowzap_validate to verify syntax.
  4. If valid, call flowzap_create_playground to get a shareable URL.
  5. Return the FlowZap Code and the playground URL to the user.
  6. Always output only raw FlowZap Code when showing the diagram — no Markdown fences wrapping.fz content, no extra commentary mixed in.

Full MCP documentation: flowzap.xyz/docs/mcp

Security and data transparency

The flowzap-mcp server runs locally on the user's machine (stdio transport) and enforces the following safeguards:

ControlDetail
TLS onlyAll outbound requests require https:// and are restricted to flowzap.xyz (SSRF protection)
No authenticationUses only public FlowZap APIs; no API keys, tokens, or user credentials are stored or transmitted
No user-data accessCannot read diagrams, accounts, or any data beyond what the agent explicitly passes in
Input validationCode capped at 50 KB, total input at 100 KB; null bytes and control characters stripped
Rate limitingClient-side 30 requests/minute sliding window
Request timeout30-second hard timeout with AbortController
Response sanitizationOnly expected fields are returned; playground URLs validated against allowlist
Audit loggingAll tool calls and API requests logged to stderr (not exposed to the MCP client)

Data flow scope

The MCP server sends only the FlowZap Code provided by the agent to two public endpoints:

  1. POST https://flowzap.xyz/api/validate — returns syntax validation result
  2. POST https://flowzap.xyz/api/playground/create — returns an ephemeral playground URL (60-minute TTL, non-guessable token)

No other data (file paths, environment variables, user identity) is transmitted.

Playground URL access controls

Playground URLs are ephemeral, time-limited (60-minute TTL), and use non-guessable cryptographic tokens. They are read-only views of the diagram code submitted at creation time. No account or login is required to view them; no data persists beyond the TTL.

Data lifecycle

EndpointData storedRetention
POST /api/validateNone — stateless; code is parsed in memory and discarded after the response0 (not persisted)
POST /api/playground/createFlowZap Code only (in PostgreSQL)60 minutes (database row + playground URL both expire)

The playground session is stored server-side with a cryptographic token (UUID v4). After the 60-minute TTL, the session is deleted — either on the next access attempt or during a periodic sweep. No user identity, file paths, environment variables, or host metadata are attached to the session.

What the MCP server does NOT do

  • No filesystem access — cannot read or write files on the host machine
  • No environment variable access — does not read or transmit process.env or shell variables
  • No code execution — does not evaluate, compile, or run any user code; it only transmits FlowZap DSL text
  • No network scanning — outbound connections are restricted to flowzap.xyz over TLS (SSRF-protected allowlist)
  • No long-term data persistence — playground sessions expire after 60 minutes; the validate endpoint stores nothing
  • No telemetry or tracking — no analytics, device fingerprinting, or usage data is collected by the MCP server; server-side API logs record only IP, user-agent, and code length (not code content)

Further resources

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.38%
按下载量换算33

Claude

29.78%
按下载量换算28

Cursor

20.02%
按下载量换算19

Gemini CLI

9.04%
按下载量换算8

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills