Triage Sonarqube
netdata/netdata
Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.
Run a comprehensive 7-phase verification pipeline for .NET projects: build, analyzers, antipattern detection, tests, security, formatting, and diff review.
$ npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install codewithmukesh/dotnet-claude-kit verify --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/verify .claude/skills/verify && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verify" agent skill from https://github.com/codewithmukesh/dotnet-claude-kit/tree/main/skills/verify into .claude/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/codewithmukesh/dotnet-claude-kit/tree/main/skills/verifyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install codewithmukesh/dotnet-claude-kit verify --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/verify .agents/skills/verify && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verify" agent skill from https://github.com/codewithmukesh/dotnet-claude-kit/tree/main/skills/verify into .agents/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install codewithmukesh/dotnet-claude-kit verify --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/verify .cursor/skills/verify && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verify" agent skill from https://github.com/codewithmukesh/dotnet-claude-kit/tree/main/skills/verify into .cursor/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/codewithmukesh/dotnet-claude-kit.git --path skills/verify--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install codewithmukesh/dotnet-claude-kit verify --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/verify .gemini/skills/verify && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/codewithmukesh/dotnet-claude-kit/tree/main/skills/verify into .gemini/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install codewithmukesh/dotnet-claude-kit verifyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/verify .github/skills/verify && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/codewithmukesh/dotnet-claude-kit/tree/main/skills/verify into .github/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install codewithmukesh/dotnet-claude-kit verify --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/verify .opencode/skills/verify && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/codewithmukesh/dotnet-claude-kit/tree/main/skills/verify into .opencode/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verifyRun a comprehensive 7-phase verification pipeline for .NET projects: build, analyzers, antipattern detection, tests, security, formatting, and diff review.
Verify is an agent skill from codewithmukesh/dotnet-claude-kit. Run a comprehensive 7-phase verification pipeline for .NET projects: build, analyzers, antipattern detection, tests, security, formatting, and diff review. Each phase produces PASS/FAIL with actionable output and the pipeline short-circuits on critical failures. Also the authority on verification strategy: which phases to run for a given change, quality gates, and fix-and-retry loops. Use when: "verify", "check everything", "is this ready", "pre-PR check", "run all checks", "quality gate", "verification…
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Testing & QA, covering Quality gates and Refactoring. It works with .NET. The repository describes itself as: Make Claude Code a .NET 10 Expert. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 2330089. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dotnetgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verify loads about 2k tokens when it runs. Until then it costs about 149 tokens; SKILL.md has 777 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
d file changes (`.vs/`, `bin/`, `obj/`, `.env`, secrets)Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from codewithmukesh/dotnet-claude-kit at commit 2330089, republished under its MIT licence (© codewithmukesh). 777 words, ~1,955 tokens.
.claude/skills/verify/SKILL.md (or your agent's skills folder).Runs a sequential, 7-phase verification pipeline that catches issues at every level -- from compiler errors to subtle antipatterns to formatting drift. Each phase produces an explicit PASS, WARN, or FAIL with details. "It looks fine" is not a verification result; a table of statuses is. Critical failures (Phase 1 build, Phase 4 tests) short-circuit the pipeline because later phases cannot produce meaningful results on broken code.
The pipeline answers one question: "Is this code ready for review?"
| Phase | Tool | What It Catches | Critical |
|---|---|---|---|
| 1. Build | dotnet build | Compilation errors, missing references | Yes |
| 2. Diagnostics | get_diagnostics (MCP) | New analyzer warnings, nullability issues | FAIL on new errors |
| 3. Antipatterns | detect_antipatterns (MCP) | async void, sync-over-async, DateTime.Now, more | No |
| 4. Tests | dotnet test | Failing tests, regressions | Yes |
| 5. Security | dotnet list package --vulnerable + scan | Secrets, SQL injection, missing auth, vulnerable packages | FAIL on critical/high |
| 6. Format | dotnet format --verify-no-changes | Style drift, formatting inconsistencies | No |
| 7. Diff Review | git diff analysis | Accidental changes, debug leftovers, TODOs | No |
Full pipeline is the default. For scoped changes, run a subset:
| Scenario | Phases | Notes |
|---|---|---|
| Feature complete / Pre-PR / new endpoint | All 7 | No shortcuts |
| Bug fix | 1, 2, 4 | Add a test first if none covers it |
| After refactor | 1, 2, 3, 4 | Correctness focus; add 5-7 if security-sensitive |
| Dependency update | 1, 4, 5 | Build, tests, vulnerability scan |
| Config or test-only change | 1, 4 | Build and test |
| Formatting only | 6 | Format check is sufficient |
When in doubt, run all 7. Extra phases cost minutes; a missed security issue costs days of incident response. Never cherry-pick phases because a change "looks safe".
dotnet build --no-restore --verbosity quietUse the Roslyn MCP get_diagnostics tool, scoped to changed files/projects
(full solution for cross-cutting changes). Compare against baseline -- flag only
NEW warnings introduced by the current changes. Common findings: CS8600/CS8602
(nullability), CS0219 (unused variable).
Output: PASS (0 new) / WARN (new warnings) / FAIL (new errors). Treat new warnings as work -- today's CS8600 is next month's production NullReferenceException.
Use the Roslyn MCP detect_antipatterns tool on changed files (full project for
broad changes). Catches: async void, sync-over-async (.Result,
.GetAwaiter().GetResult()), new HttpClient(), DateTime.Now/UtcNow instead
of TimeProvider, broad catch (Exception), string interpolation in logging,
missing CancellationToken, EF read queries without AsNoTracking.
Output: PASS (0 findings) / WARN (findings) / FAIL (critical antipatterns)
dotnet test --no-build --verbosity quietOutput: PASS (all green) or FAIL (failing test names + error messages)
dotnet list package --vulnerable --include-transitiveThen review changed files for: hardcoded secrets/connection strings/API keys,
SQL injection (raw SQL without parameterization), missing [Authorize] on
endpoints that need it, permissive CORS, missing input validation, disabled
HTTPS or certificate validation.
Output: PASS / WARN (medium/low findings) / FAIL (critical/high vulnerabilities)
dotnet format --verify-no-changes --verbosity quietReports drift without auto-fixing. To resolve, run dotnet format and include
the changes in the commit. If no .editorconfig exists, note it as a recommendation.
Output: PASS / WARN (with file list)
Analyze git diff --stat and git diff (staged + unstaged) for:
.vs/, bin/, obj/, .env, secrets)Console.WriteLine, #if DEBUG in production paths)Output: PASS (clean, matches intent) / WARN (with findings)
A single pass rarely produces all-green. The loop is the point:
## Verification Results
| Phase | Result | Details |
|-------|--------|---------|
| 1. Build | PASS | 0 errors, 0 warnings |
| 2. Diagnostics | PASS | 0 new diagnostics |
| 3. Antipatterns | WARN | 1 missing CancellationToken |
| 4. Tests | PASS | 47 passed, 0 failed |
| 5. Security | PASS | No findings |
| 6. Format | PASS | Clean |
| 7. Diff Review | WARN | 1 TODO marker found |
**Verdict: READY FOR REVIEW** (with 2 non-blocking warnings)Verdicts: READY FOR REVIEW (all PASS, or only non-blocking WARNs) or NEEDS FIXES (any FAIL, with specific remediation steps). For pre-PR runs, include the verification report in the PR description.
User: /verify
Claude: Running 7-phase verification pipeline...
Phase 1: Build ............ PASS (0 errors)
Phase 2: Diagnostics ...... PASS (0 new warnings)
Phase 3: Antipatterns ..... WARN
- src/Features/Orders/CreateOrder.cs:42 -- DateTime.Now usage, use TimeProvider
Phase 4: Tests ............ PASS (23 passed, 0 failed, 0 skipped)
Phase 5: Security ......... PASS
Phase 6: Format ........... PASS
Phase 7: Diff Review ...... PASS
Verdict: READY FOR REVIEW (1 non-blocking warning)
Recommendation: Replace DateTime.Now with TimeProvider on line 42 before
merging. Not blocking, but it will fail the antipattern check in CI./build-fix -- Auto-fix build errors when Phase 1 fails/code-review -- Multi-dimensional review once verification passes/health-check -- Whole-project graded assessment (beyond this change set)© codewithmukesh, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/verify of codewithmukesh/dotnet-claude-kit.
Open the folder on GitHubat commit 2330089
Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verify this skillcodewithmukesh/dotnet-claude-kit | 751 | — | ~2k | Automated safety check: Notes | MIT | |
| Triage Sonarqubenetdata/netdata | 81k | — | ~2.8k | Automated safety check: Notes | GPL-3.0 | |
| Sonarqube Analysishbmartin/graphviz2drawio | 275 | — | ~508 | Automated safety check: Notes | GPL-3.0 | |
| Ccg Workflowfengshao1227/ccg-workflow | 5.9k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Developing MarchatCod-e-Codes/marchat | 137 | — | ~870 | Automated safety check: Pass | MIT | |
| Verify Tests Catch the Bugdotnet/maui | 23k | — | ~2.7k | Automated safety check: Pass | MIT |
netdata/netdata
Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.
hbmartin/graphviz2drawio
Inspect SonarQube Cloud/SonarCloud findings for this repository using local .env credentials.
fengshao1227/ccg-workflow
How to run a non-trivial change end to end with the CCG role tools (ccganalyze / ccgdesign / ccgbuild / ccgdebug / ccgoptimize / ccgreview / ccgtest) and the verify- quality gates.
Cod-e-Codes/marchat
Implements and refactors marchat Go code with project toolchain and quality gates.
dotnet/maui
Confirms that newly added tests actually fail without the fix, auto-detecting UI, device, unit or XAML tests and running the matching runner.
facioquo/stock-indicators-dotnet
Quality gates for finishing work in this repository — dead-code cleanup, Roslynator and dotnet format fixes, markdownlint, build, unit tests, documentation, and Obsolete migration shims — with the…
codewithmukesh/dotnet-claude-kit
API versioning strategies for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.
codewithmukesh/dotnet-claude-kit
Architecture-aware feature scaffolding for .NET 10 projects.
codewithmukesh/dotnet-claude-kit
Architecture selection advisor for .NET applications. An agent skill from codewithmukesh/dotnet-claude-kit.
codewithmukesh/dotnet-claude-kit
.NET Aspire for cloud-native orchestration. An agent skill from codewithmukesh/dotnet-claude-kit.
codewithmukesh/dotnet-claude-kit
Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.
codewithmukesh/dotnet-claude-kit
Caching strategies for .NET 10 applications. An agent skill from codewithmukesh/dotnet-claude-kit.
Works with
Categories
Run a comprehensive 7-phase verification pipeline for .NET projects: build, analyzers, antipattern detection, tests, security, formatting, and diff review. Verify is an agent skill from codewithmukesh/dotnet-claude-kit.NET projects: build, analyzers, antipattern detection, tests, security, formatting, and diff review.
Verify fits situations like: check everything; verification strategy; which checks should run; after completing a feature.
Run `npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a claude-code`. Or copy the skill folder (skills/verify in codewithmukesh/dotnet-claude-kit) into .claude/skills/verify in your project. Claude Code loads it when a task matches its description.
Run `npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a codex`. Or copy the skill folder (skills/verify in codewithmukesh/dotnet-claude-kit) into .agents/skills/verify in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codewithmukesh/dotnet-claude-kit --skill verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify, .gemini/skills/verify, .github/skills/verify and .opencode/skills/verify in your project.
Going by SKILL.md and its folder, Verify needs the command-line tools its instructions call (dotnet and git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Verify is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verify: Triage Sonarqube (netdata/netdata, 81k stars), Sonarqube Analysis (hbmartin/graphviz2drawio, 275 stars), Ccg Workflow (fengshao1227/ccg-workflow, 5.9k stars) and Developing Marchat (Cod-e-Codes/marchat, 137 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
codewithmukesh (a GitHub organization) maintains it in codewithmukesh/dotnet-claude-kit, which has 751 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on August 7, 2026.
Source: codewithmukesh/dotnet-claude-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.