Agent skill

Code Assessment

by adobe in adobe/skills

Detect, review, and fix code-quality and correctness issues in an AEM as a Cloud Service project — locally, with no external services or network calls.

Apache-2.0Auto-check passedDevelopment

Install Code Assessment

skills CLI
$ npx skills add adobe/skills --skill code-assessment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install adobe/skills code-assessment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/aem/cloud-service/skills/code-assessment .claude/skills/code-assessment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-assessment
GitHub stars
195
Token cost
~2.8k tokens
SKILL.md length
1,180 words
Files
39 (incl. scripts, references)
Skills in repo
105
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detect, review, and fix code-quality and correctness issues in an AEM as a Cloud Service project — locally, with no external services or network calls.

  • Works in 2 steps: User named files / coordinates → run the… → "Scan my repo" / no files named → run…
  • A user wants to check
  • SKILL.md covers Findings sources, Routing, Manual Pattern Hints… and Invocation from the migration…, plus 6 more sections
  • Runs Java and Shell scripts from its folder; calls mvn and npm

What it does

Code Assessment is an agent skill from adobe/skills. Detect, review, and fix code-quality and correctness issues in an AEM as a Cloud Service project — locally, with no external services or network calls. Use whenever a user wants to check, review, assess, audit, scan, modernize, upgrade, or fix AEM Java, Sling Models, OSGi, or Maven code — for example: "check my Sling Models are implemented correctly", "review my @Inject usage", "are my Maven dependencies up to date", "scan this AEM project for issues", "modernize my Sling Models", or "fix code-quality problems"…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 41 other files, including scripts and reference files (for example `README.md`, `references/_template.md` and `references/adding-a-pattern.md`).

It sits in Development, covering Code quality and Runbooks and postmortems. It works with Adobe Experience Manager and Java. The repository describes itself as: Adobe Skills for Agents. The licence is Apache-2.0.

When your agent uses it

  • A user wants to check
  • Maven code — for example: check my Sling Models are implemented correctly
  • Review my @Inject usage
  • Are my Maven dependencies up to date

Example prompts

  • “check my Sling Models are implemented correctly”
  • “review my @Inject usage”
  • “are my Maven dependencies up to date”
  • “/code-assessment”

Requirements

  • A Bash shell

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. User named files / coordinates → run the runbook in with_findings mode against those paths.
  2. "Scan my repo" / no files named → run the runbook in discover mode (per-pattern Discovery, workspace roots only).

What it can do on your machine

Read from SKILL.md and the folder at commit cbc9952. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 5 files in scripts/ (Java and Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • mvn
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Assessment loads about 2.8k tokens when it runs, and up to ~23k if it reads all its reference files. Until then it costs about 205 tokens; SKILL.md has 1,180 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~205
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~23k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from adobe/skills at commit cbc9952, republished under its Apache-2.0 licence (© adobe). 1,180 words, ~2,816 tokens.

Download SKILL.mdSave it as .claude/skills/code-assessment/SKILL.md (or your agent's skills folder). This skill also uses 38 other files; get the full folder from GitHub.
name
code-assessment
description
Detect, review, and fix code-quality and correctness issues in an AEM as a Cloud Service project — locally, with no external services or network calls. Use whenever a user wants to check, review, assess, audit, scan, modernize, upgrade, or fix AEM Java, Sling Models, OSGi, or Maven code — for example: "check my Sling Models are implemented correctly", "review my @Inject usage", "are my Maven dependencies up to date", "scan this AEM project for issues", "modernize my Sling Models", or "fix code-quality problems". Name the files to assess, or ask it to scan the repo; it detects issues, plans, and — only when you ask — applies surgical edits on a branch or in place, then verifies with mvn compile. It recognises the intent and handles each issue type itself, reporting anything it cannot yet fix.
license
Apache-2.0

AEM as a Cloud Service — Code Assessment

Single skill for detecting and fixing AEM CS code-quality issues, entirely against the local workspace — no external services or network calls. Findings reach the runbook from one of two sources; everything downstream is identical.

Findings sources

SourceWhenTarget versions (deps)
User-namedthe user names files or coordinatesuser-supplied
Discoverthe user asks to scan, or names no filesuser-supplied (per the pattern's resolution contract)

Discovery runs through the deterministic analyzer (scripts/analyze.sh): it parses the workspace once and runs the enabled detectors, emitting the shared findings shape. Every ready pattern has an analyzer detector. One detector — remove-deprecated-api — loads its rules dynamically from a preflight-produced cache (remove-deprecated-api/scripts/detect.sh runs the AEM Analyser Maven Plugin and writes the cache TSV before the analyzer is invoked); the detector's shape and integration are otherwise identical. Patterns without a detector are planned only — not yet detectable and not yet built; there is no LLM-scan fallback in this version (see Scope & limitations) — the scan value on planned rows in references/patterns.md marks the intended future detection method, not an active code path.

Routing

  1. User named files / coordinates → run the runbook in with_findings mode against those paths.
  2. "Scan my repo" / no files named → run the runbook in discover mode (per-pattern Discovery, workspace roots only).

Then follow the runbook: references/runbook.md.

Manual Pattern Hints (classification → expert skill)

Route the request to one expert skill. Two pattern families share this skill:

Mechanical fixes (analyzer-driven detection, deterministic edits — follow the runbook flow):

User said / sawExpert skill
"update aem sdk", "upgrade mockito", stale <version> or ${property} in pomoutdated-dependencies/
"fix @Inject", "modernize Sling Models", javax.inject.Inject on @Model fieldsinject-in-sling-model/
"add HTTP timeouts", "outbound/external call has no timeout", HttpClient / HttpClients / OkHttpClient built without a timeoutoutbound-call-timeouts/
"bound my query", "unbounded query", "query causing OOM", p.limit=-1, setLimit(-1)unbounded-query/
"query is slow", "traversal warning", "is my query indexed", "tune oak index", index coverage of a JCR/Oak querytuning-oak-query-indexes/
"remove deprecated API", "fix deprecated imports", "Cloud Manager deprecated API failure", region-deprecated-api / api-regions-check / Import-Package not satisfied pipeline failures, log4j migration, commons-lang/collections upgrades, deprecated Maven deps, unmodifiable OSGi configsremove-deprecated-api/ (analyzer detector with dynamic rules — preflight runs aemanalyser-maven-plugin; hint-driven fixes; see recipe.md)

Architectural migration patterns (guided remediation — full before/after, troubleshooting, modern alternatives; invoked directly or via migration for BPA/CAM-driven discovery):

User said / sawExpert skillBPA pattern ID
org.apache.sling.commons.scheduler.Scheduler or scheduler.schedule( with Runnablescheduler/scheduler
implements ResourceChangeListener, lightweight listener + JobConsumerresource-change-listener/resourceChangeListener
com.day.cq.replication.Replicator, org.apache.sling.replication.*, "publish/preview activation"replication/replication
javax.jcr.observation.EventListener, org.osgi.service.event.EventHandler on non-resource topics (replication, workflow, custom)event-migration/eventListener / eventHandler
com.day.cq.dam.api.AssetManager create/upload/delete APIs, createAssetForBinary, removeAssetForBinaryasset-manager/assetApi
HTL build warning data-sly-test: redundant constant value comparisonreferences/data-sly-test-redundant-constant.mdhtlLint (reference, no expert skill subdirectory)

Broad / correctness-review asks ("check my Sling Models are implemented correctly", "review my code", "is my AEM project healthy", "assess this project") are not a single pattern: run the runbook in discover mode with intent report — the analyzer runs every detector and the report covers all built patterns, explicitly noting aspects not yet supported. Only narrow to one pattern when the user targets a specific fix.

If nothing matches, say the issue is not yet supported and offer to file a request for a new expert skill.

Full catalog (built + planned patterns, with severity / detection / fix): references/patterns.md.

Invocation from the migration skill

migration performs BPA/CAM/MCP discovery and handles batching + one-pattern-per-session workflow. After it has identified (pattern, file) pairs from BPA findings, it hands off here for the actual transformation. When invoked with (pattern, file) from migration:

  • Skip HA/analyzer discovery (caller already identified the pattern + file)
  • Open the pattern's expert skill directly (per the Manual Pattern Hints table above)
  • Apply the steps in the expert skill against the named file(s)
  • Return the result; migration continues with the next finding in its batch

The pattern guides themselves are agnostic about who invoked them — they apply identically whether reached from migration (BPA/CAM) or from the runbook in this skill (HA / analyzer).

Runbook

All detection, planning, edits, verification, git/in-place handling, and the run log live in references/runbook.md. The runbook is the sole owner of repo-environment detection (edit_mode, git snapshot) — this control plane does not duplicate it.

One pattern per session

Report may span every pattern found; apply touches one pattern per session (atomic revert, single-story diff). Refuse "fix everything" for the apply phase. Rationale: references/shared-principles.md.

Show full SKILL.md (469 more words)Show less

Critical rules

  • Local only — no network calls or external services; operate solely on the workspace. Documented exception: remove-deprecated-api is plugin-driven and needs Maven Central (to resolve aemanalyser-maven-plugin and, transitively, the AEM SDK's api-regions data) plus optionally Adobe Experience League as a fallback source for successor guidance. If offline, that one pattern is skipped with a clear message; all other patterns remain local-only.
  • Requires a local JDK (Java 11+) for detection — the analyzer compiles/runs in memory; no install beyond the JDK, no network. If absent, detection stops with a clear message.
  • The analyzer is detection — never substitute external tooling. Do not run mvn versions:display-dependency-updates / mvn versions:display-property-updates, npm outdated, or Maven Central / registry lookups in place of analyzer discovery. Those answer "what is the latest on the network" — outside this skill's local-only contract. If the user explicitly wants a live registry comparison, say it needs network and offer it as a separate step after delivering the skill report. remove-deprecated-api's preflight (remove-deprecated-api/scripts/detect.sh) is the one documented exception: it invokes the AEM Analyser Maven Plugin against the project to populate its rules cache, then hands off to the shared analyzer.
  • Never commit, push, or open a PR — branch (git) or in-place edits only; the developer reviews and commits.
  • Surgical edits — no reformatting / re-serialization.
  • Skip with a reason — record un-applicable findings as skipped with an exact reason; never silently drop.
  • One pattern per session for apply.

Full rationale: references/shared-principles.md.

Scope & limitations

Local static detection and remediation only — no external services, no network, no live AEM instance. Issues that require runtime or live-repository state, telemetry, or history across runs are out of scope for this skill. Detection requires a local JDK (Java 11+); there is no remote or LLM-scan fallback in this version. A large apply (e.g. an @Inject migration across 100+ files) is processed in resumable batches: the run checkpoints each file to .autofix/last-run.json and pauses at a per-pass cap, so it survives context limits — reply apply <pattern> to continue (see references/git-workflow.md).

Adding a new pattern

Full end-to-end procedure — detector → fixtures/tests → catalog + routing → expert skill → verify: references/adding-a-pattern.md. The [wiring] test keeps the detector, catalog row, and expert-skill directory in sync.

Triggering scales without touching the description. The description above is intentionally broad (intent verbs + AEM domain), so it already fires on "check / review / fix my <AEM thing>"; a new pattern is reached by its Manual Pattern Hints + patterns.md rows, not by editing the description. Update the description only if the new pattern introduces a domain keyword it does not already cover (a new subsystem or file type). The [wiring] test keeps the detector, catalog row, and expert-skill directory in sync.

  • migration — drives BPA/CAM/MCP-based legacy-AEM migration workflow. Discovers findings, batches them, enforces one-pattern-per-session, and hands off (pattern, file) pairs to this skill for transformation. See the "Invocation from the migration skill" section above.

© adobe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 38 other files (scripts, references) in plugins/aem/cloud-service/skills/code-assessment of adobe/skills.

  • SKILL.md
  • README.md
  • references/_template.md
  • references/adding-a-pattern.md
  • references/aem-cloud-service-pattern-prerequisites.md
  • references/data-sly-test-redundant-constant.md
  • references/git-workflow.md
  • references/patterns.md
  • references/resource-resolver-logging.md
  • references/runbook.md
  • references/scr-to-osgi-ds.md
  • references/shared-principles.md
  • references/troubleshooting.md
  • scripts/README.md
  • scripts/analyze.sh
  • scripts/analyzer/Analyze.java
  • scripts/analyzer/Corpus.java
  • scripts/analyzer/Detector.java
  • … and 21 more

Open the folder on GitHubat commit cbc9952

Compare with similar skills

Code Assessment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Assessment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Assessment this skilladobe/skills195—~2.8kAutomated safety check: PassApache-2.0
Coding Standardtestdouble/han279—~8.6kAutomated safety check: PassMIT
Project Documentationtestdouble/han279—~3.5kAutomated safety check: PassMIT
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
New Rule for sonar-javaSonarSource/sonar-java1.2k—~833Automated safety check: PassCustom licence
Cross-Language Coding Standardszereight/gitlab-mcp2k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Coding Standard

    testdouble/han

    Creates and updates coding standards, conventions, rules, and guidelines for the current project.

    279 GitHub stars~8.6k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Project Documentation

    testdouble/han

    Creates and maintains project documentation for features, systems, and components.

    279 GitHub stars~3.5k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • New Rule for sonar-java

    SonarSource/sonar-java

    Official

    Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

    1.2k GitHub stars~833 tokensUpdated today
    DevelopmentAuto-check passed
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Code Quality

    piomin/claude-ai-spring-boot

    Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance.

    1.3k GitHub stars~2.2k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed

More from adobe/skills

All 105 skills in this repo
  • Scaffolds, implements, deploys and debugs Adobe Runtime actions in App Builder projects, with templates for webhooks, events, database CRUD, sequences and Asset Compute workers.

    195 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Launches Chrome with an unpacked extension over CDP, opens its sidepanel, popup or options page, and hands over to cdp-connect for clicks, typing and screenshots.

    195 GitHub stars~952 tokensUpdated today
    Auto-check passed
  • Extracts icons, metadata, text, forms, videos and social links from any web page with playwright-cli, with SVG icon classification and cleanup.

    195 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Page Langs

    adobe/skills

    Detect all languages used on a webpage — both declared (html@lang, hreflang alternate links, nested lang= attributes, meta content-language) and actually present in the body text (Google CLD3 via…

    195 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Page Prep

    adobe/skills

    Prepare any webpage for clean interaction by detecting and removing disruptive overlays (cookie banners, GDPR consent, modals, popups, newsletter signups, paywalls, login walls).

    195 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Page Reduce

    adobe/skills

    Reduce a webpage to a structural skeleton with semantic tokens.

    195 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Questions about Code Assessment

What does Code Assessment do?

Detect, review, and fix code-quality and correctness issues in an AEM as a Cloud Service project — locally, with no external services or network calls. Code Assessment is an agent skill from adobe/skills. Detect, review, and fix code-quality and correctness issues in an AEM as a Cloud Service project — locally, with no external services or network calls.

When should I use Code Assessment?

Code Assessment fits situations like: A user wants to check; maven code — for example: check my Sling Models are implemented correctly; review my @Inject usage; are my Maven dependencies up to date.

How do I install Code Assessment in Claude Code?

Run `npx skills add adobe/skills --skill code-assessment -a claude-code`. Or copy the skill folder (plugins/aem/cloud-service/skills/code-assessment in adobe/skills) into .claude/skills/code-assessment in your project. Claude Code loads it when a task matches its description.

How do I install Code Assessment in Codex?

Run `npx skills add adobe/skills --skill code-assessment -a codex`. Or copy the skill folder (plugins/aem/cloud-service/skills/code-assessment in adobe/skills) into .agents/skills/code-assessment in your project. Codex loads it when a task matches its description.

Can I use Code Assessment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add adobe/skills --skill code-assessment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-assessment, .gemini/skills/code-assessment, .github/skills/code-assessment and .opencode/skills/code-assessment in your project.

What does Code Assessment need to run?

Going by SKILL.md and its folder, Code Assessment needs Java and a shell for the scripts in its folder and the command-line tools its instructions call (mvn and npm). Our summary lists: A Bash shell.

Does Code Assessment access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Assessment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Code Assessment use?

Code Assessment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Assessment use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 20k tokens, read only when the agent opens those files.

What are the alternatives to Code Assessment?

Skills that share tags, products or a category with Code Assessment: Coding Standard (testdouble/han, 279 stars), Project Documentation (testdouble/han, 279 stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars) and New Rule for sonar-java (SonarSource/sonar-java, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Assessment?

adobe (a GitHub organization) maintains it in adobe/skills, which has 195 GitHub stars. The repository holds 105 skills in this directory. The repository was last updated on October 6, 2026.

Source: adobe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.