Agent skill

Static Code Analysis

by aAAaqwq in aAAaqwq/AGI-Super-Team

Implement static code analysis with linters, formatters, and security scanners to catch bugs early.

MITAuto-check passedDevelopment

Install Static Code Analysis

skills CLI
$ npx skills add aAAaqwq/AGI-Super-Team --skill static-code-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aAAaqwq/AGI-Super-Team static-code-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/static-code-analysis .claude/skills/static-code-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
static-code-analysis
GitHub stars
105
Token cost
~664 tokens
SKILL.md length
147 words
Files
8 (incl. scripts, references)
Skills in repo
161
Repo updated
First seen
Licence
MIT

At a glance

Implement static code analysis with linters, formatters, and security scanners to catch bugs early.

  • Enforcing code standards
  • SKILL.md covers Table of Contents, Overview, When to Use and Quick Start, plus 2 more sections
  • Runs Shell scripts from its folder
  • Detecting security vulnerabilities

What it does

Static Code Analysis is an agent skill from aAAaqwq/AGI-Super-Team. Implement static code analysis with linters, formatters, and security scanners to catch bugs early. Use when enforcing code standards, detecting security vulnerabilities, or automating code review.

Its SKILL.md is about 660 tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `references/custom-ast-analysis.md`, `references/eslint-configuration.md` and `references/pre-commit-hooks.md`).

It sits in Development, covering Linting and formatting and Vulnerability scanning. It works with ESLint and Python. The repository describes itself as: An installable, cross-framework AI organization: C-suite agents, expert subagents, curated skills, independent review, and one-command setup across 18 AI client/runtime adapters. The licence is MIT.

When your agent uses it

  • Enforcing code standards
  • Detecting security vulnerabilities
  • Automating code review

Example prompts

  • “/static-code-analysis”

Requirements

  • Python 3
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 331ecd3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Static Code Analysis loads about 664 tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 147 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~664
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aAAaqwq/AGI-Super-Team at commit 331ecd3, republished under its MIT licence (© aAAaqwq). 147 words, ~664 tokens.

Download SKILL.mdSave it as .claude/skills/static-code-analysis/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
static-code-analysis
description
Implement static code analysis with linters, formatters, and security scanners to catch bugs early. Use when enforcing code standards, detecting security vulnerabilities, or automating code review.

Static Code Analysis

Table of Contents

Overview

Use automated tools to analyze code without executing it, catching bugs, security issues, and style violations early.

When to Use

  • Enforcing coding standards
  • Security vulnerability detection
  • Bug prevention
  • Code review automation
  • CI/CD pipelines
  • Pre-commit hooks
  • Refactoring assistance

Quick Start

Minimal working example:

javascript
// .eslintrc.js
module.exports = {
  extends: [
    "eslint:recommended",
    "plugin:@typescript-eslint/recommended",
    "plugin:security/recommended",
  ],
  plugins: ["@typescript-eslint", "security", "import"],
  rules: {
    "no-console": ["warn", { allow: ["error", "warn"] }],
    "no-unused-vars": "error",
    "prefer-const": "error",
    eqeqeq: ["error", "always"],
    "no-eval": "error",
    "security/detect-object-injection": "warn",
    "security/detect-non-literal-regexp": "warn",
    "@typescript-eslint/no-explicit-any": "warn",
    "@typescript-eslint/explicit-function-return-type": "error",
    "import/order": [
      "error",
      {
        groups: [
          "builtin",
          "external",
          "internal",
// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
ESLint ConfigurationESLint Configuration
Python Linting (pylint + mypy)Python Linting (pylint + mypy)
Pre-commit HooksPre-commit Hooks
SonarQube IntegrationSonarQube Integration
Custom AST AnalysisCustom AST Analysis
Security ScanningSecurity Scanning

Best Practices

✅ DO
  • Run linters in CI/CD
  • Use pre-commit hooks
  • Configure IDE integration
  • Fix issues incrementally
  • Document custom rules
  • Share configuration across team
  • Automate security scanning
❌ DON'T
  • Ignore all warnings
  • Skip linter setup
  • Commit lint violations
  • Use overly strict rules initially
  • Skip security scans
  • Disable rules without reason

© aAAaqwq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in skills/static-code-analysis of aAAaqwq/AGI-Super-Team.

  • SKILL.md
  • references/custom-ast-analysis.md
  • references/eslint-configuration.md
  • references/pre-commit-hooks.md
  • references/python-linting-pylint-mypy.md
  • references/security-scanning.md
  • references/sonarqube-integration.md
  • scripts/security-checklist.sh

Open the folder on GitHubat commit 331ecd3

Compare with similar skills

Static Code Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Static Code Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Static Code Analysis this skillaAAaqwq/AGI-Super-Team105—~664Automated safety check: PassMIT
Ha Code QualityFutureTense/keymaster349—~462Automated safety check: PassMIT
Cb Code QualityBlkLeg/CircuitBreaker201—~1.9kAutomated safety check: PassMIT
MozlintBrowserWorks/waterfox-android3761 repos~1kAutomated safety check: PassCustom licence
Fix Security Issuehardisgroupcom/sfdx-hardis400—~1.3kAutomated safety check: NotesAGPL-3.0
Pre Pushartcc/freelingo158—~732Automated safety check: PassAGPL-3.0

Similar skills

  • Ha Code Quality

    FutureTense/keymaster

    Standards and commands for linting, code formatting, typing validation (Ruff, MyPy, Codespell, ESLint, Pre-commit/Prek, Tox), and adherence to Home Assistant Python 3.14 standards in Keymaster.

    349 GitHub stars~462 tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Cb Code Quality

    BlkLeg/CircuitBreaker

    Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.

    201 GitHub stars~1.9k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Mozlint

    BrowserWorks/waterfox-android

    You MUST use this skill when working with Firefox's linting infrastructure (mozlint), adding new linters, modifying existing linters, running linters, or dealing with linting issues.

    376 GitHub starsUsed in 1 repo~1k tokens
    DevelopmentAuto-check passed
  • Fix Security Issue

    hardisgroupcom/sfdx-hardis

    Handle CVE/vulnerability reports from security linters (trivy, osv-scanner, etc.).

    400 GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check: notes
  • Pre Push

    artcc/freelingo

    A skill your agent uses when the user asks to check before pushing, pre-push, verificar antes de pushear, run all checks, or quiere validar que todo pasa antes de hacer push.

    158 GitHub stars~732 tokensUpdated today
    EducationAuto-check passed
  • Kedro Babysit

    kedro-org/kedro

    Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…

    11k GitHub stars~4k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from aAAaqwq/AGI-Super-Team

All 161 skills in this repo
  • Content Creator

    aAAaqwq/AGI-Super-Team

    Create SEO-optimized marketing content with consistent brand voice.

    105 GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • Financial Calculator

    aAAaqwq/AGI-Super-Team

    Advanced financial calculator with future value tables, present value, discount calculations, markup pricing, and compound interest.

    105 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Performing Security Code Review

    aAAaqwq/AGI-Super-Team

    This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    105 GitHub starsUsed in 1 repo~920 tokens
    Auto-check passed
  • Frontend Design Ultimate

    aAAaqwq/AGI-Super-Team

    Create distinctive, production-grade static sites with React, Tailwind CSS, and shadcn/ui — no mockups needed.

    105 GitHub starsUsed in 2 repos~2.7k tokens
    Auto-check passed
  • Sysadmin Toolbox

    aAAaqwq/AGI-Super-Team

    Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks.

    105 GitHub starsUsed in 2 repos~775 tokens
    Auto-check passed
  • Zsxq Smart Publish

    aAAaqwq/AGI-Super-Team

    Publish and manage content on 知识星球 (zsxq.com). An agent skill from aAAaqwq/AGI-Super-Team.

    105 GitHub stars~1.5k tokensUpdated 10 days ago
    Auto-check passed

Works with

Categories

Questions about Static Code Analysis

What does Static Code Analysis do?

Implement static code analysis with linters, formatters, and security scanners to catch bugs early. Static Code Analysis is an agent skill from aAAaqwq/AGI-Super-Team. Implement static code analysis with linters, formatters, and security scanners to catch bugs early.

When should I use Static Code Analysis?

Static Code Analysis fits situations like: enforcing code standards; detecting security vulnerabilities; automating code review.

How do I install Static Code Analysis in Claude Code?

Run `npx skills add aAAaqwq/AGI-Super-Team --skill static-code-analysis -a claude-code`. Or copy the skill folder (skills/static-code-analysis in aAAaqwq/AGI-Super-Team) into .claude/skills/static-code-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Static Code Analysis in Codex?

Run `npx skills add aAAaqwq/AGI-Super-Team --skill static-code-analysis -a codex`. Or copy the skill folder (skills/static-code-analysis in aAAaqwq/AGI-Super-Team) into .agents/skills/static-code-analysis in your project. Codex loads it when a task matches its description.

Can I use Static Code Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aAAaqwq/AGI-Super-Team --skill static-code-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/static-code-analysis, .gemini/skills/static-code-analysis, .github/skills/static-code-analysis and .opencode/skills/static-code-analysis in your project.

What does Static Code Analysis need to run?

Going by SKILL.md and its folder, Static Code Analysis needs a shell for the scripts in its folder. Our summary lists: Python 3; A Bash shell.

Does Static Code Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Static Code Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Static Code Analysis use?

Static Code Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Static Code Analysis use?

About 664 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Static Code Analysis?

Skills that share tags, products or a category with Static Code Analysis: Ha Code Quality (FutureTense/keymaster, 349 stars), Cb Code Quality (BlkLeg/CircuitBreaker, 201 stars), Mozlint (BrowserWorks/waterfox-android, 376 stars) and Fix Security Issue (hardisgroupcom/sfdx-hardis, 400 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Static Code Analysis?

aAAaqwq (a GitHub user) maintains it in aAAaqwq/AGI-Super-Team, which has 105 GitHub stars. The repository holds 161 skills in this directory. The repository was last updated on September 27, 2026.

Source: aAAaqwq/AGI-Super-Team on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.