Official agent skill

Crap Score

by dotnet in dotnet/skills

Calculates CRAP (Change Risk Anti-Patterns) for a named .NET method, class, or file.

OfficialMITAuto-check passed

Install Crap Score

skills CLI
$ npx skills add dotnet/skills --skill crap-score -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dotnet/skills crap-score --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-test/skills/crap-score .claude/skills/crap-score && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crap-score
GitHub stars
5.6k
Used in
1 other repo
Token cost
~3.4k tokens
SKILL.md length
1,698 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Calculates CRAP (Change Risk Anti-Patterns) for a named .NET method, class, or file.

  • Works in 6 steps: Collect code coverage data → Compute cyclomatic complexity → Extract per-method coverage from… → …
  • : explicit CRAP calculation
  • SKILL.md covers Background, When to Use, When Not to Use and Inputs, plus 3 more sections
  • Calls dotnet

What it does

Crap Score is an agent skill from dotnet/skills, published by the product's own GitHub organization. Calculates CRAP (Change Risk Anti-Patterns) for a named .NET method, class, or file. USE FOR: explicit CRAP calculation or coverage-and-complexity risk within that named target, including which tests to prioritize. DO NOT USE FOR: project-wide coverage/CRAP, plateaus, or project-wide blockers/priorities (coverage-analysis); behavioral/pseudo-mutation gaps (test-gap-analysis); writing tests; test runs without CRAP context.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with .NET. The repository describes itself as: Repository for skills to assist AI coding agents with .NET and C. The licence is MIT.

When your agent uses it

  • : explicit CRAP calculation
  • Coverage-and-complexity risk within that named target
  • Including which tests to prioritize
  • : project-wide coverage/CRAP

Example prompts

  • “Use the crap-score skill to calculate CRAP (Change Risk Anti-Patterns) for a named .NET method, class, or file”
  • “/crap-score”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Collect code coverage data
  2. Compute cyclomatic complexity
  3. Extract per-method coverage from Cobertura XML
  4. Calculate CRAP scores
  5. Present results
  6. Provide actionable recommendations

What it can do on your machine

Read from SKILL.md and the folder at commit 8d670fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Crap Score loads about 3.4k tokens when it runs. Until then it costs about 109 tokens; SKILL.md has 1,698 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dotnet/skills at commit 8d670fa, republished under its MIT licence (© dotnet). 1,698 words, ~3,366 tokens.

Download SKILL.mdSave it as .claude/skills/crap-score/SKILL.md (or your agent's skills folder).
name
crap-score
description
Calculates CRAP (Change Risk Anti-Patterns) for a named .NET method, class, or file. USE FOR: explicit CRAP calculation or coverage-and-complexity risk within that named target, including which tests to prioritize. DO NOT USE FOR: project-wide coverage/CRAP, plateaus, or project-wide blockers/priorities (coverage-analysis); behavioral/pseudo-mutation gaps (test-gap-analysis); writing tests; test runs without CRAP context.
license
MIT

CRAP Score Analysis

Calculate CRAP (Change Risk Anti-Patterns) scores for .NET methods to identify code that is both complex and undertested.

Background

The CRAP score combines cyclomatic complexity and code coverage into a single metric:

$$\text{CRAP}(m) = \text{comp}(m)^2 \times (1 - \text{cov}(m))^3 + \text{comp}(m)$$

Where:

  • $\text{comp}(m)$ = cyclomatic complexity of method $m$
  • $\text{cov}(m)$ = code coverage ratio (0.0 to 1.0) of method $m$
CRAP ScoreRisk LevelInterpretation
< 5LowSimple and well-tested
5 to < 15ModerateAcceptable for most code
15 to 30HighNeeds more tests or simplification
> 30CriticalRefactor and add coverage urgently

A method with 100% coverage has CRAP = complexity (the minimum). A method with 0% coverage has CRAP = complexity^2 + complexity.

When to Use

  • User wants to assess which methods are risky due to low coverage and high complexity
  • User asks for CRAP score of specific methods, classes, or files
  • User wants to prioritize what to test next within a named method, class, or file based on coverage-and-complexity risk
  • User wants to evaluate test quality beyond simple coverage percentages

When Not to Use

  • User just wants to run tests (use run-tests skill)
  • User wants to write new tests (use code-testing-agent)
  • User only wants a coverage percentage without complexity analysis
  • User wants project-wide coverage/CRAP analysis or priorities (use coverage-analysis)

Inputs

InputRequiredDescription
Target scopeYesMethod name, class name, or file path to analyze
Test project pathNoPath to the test project. Defaults to discovering test projects in the solution.
Source project pathNoPath to the source project under analysis

Workflow

Step 1: Collect code coverage data

If the user supplies a valid Cobertura report that contains the requested target, use it directly and do not rerun tests. If the supplied report is malformed, empty, internally contradictory, or missing the target, treat it as failed input: regenerate it with a repository-compatible command when possible, or request a valid report when collection is unavailable. Otherwise invoke run-tests to classify the repository's test platform and confirm the compatible command shape, then require a command that emits Cobertura:

Coverage providerCobertura command
coverlet.collector with VSTestdotnet test <test.csproj> --collect:"XPlat Code Coverage" --results-directory <results-dir>
Microsoft.Testing.Extensions.CodeCoverage with .NET 9 bridged MTPdotnet test <test.csproj> -- --coverage --coverage-output-format cobertura --coverage-output <output-path>
Microsoft.Testing.Extensions.CodeCoverage with .NET 10+ native MTPdotnet test --project <test.csproj> --coverage --coverage-output-format cobertura --coverage-output <output-path>

Use an equivalent repository-owned command when the project defines one. Search the results directory recursively when the collector creates a GUID subfolder. Do not substitute a generic binary .coverage command when no converter is available.

Do not stop at the first restore, compilation, test, or collector failure. Classify the failing layer, inspect every report the command emitted, and exhaust non-persistent retries before asking for input. Safe retries include command-line MSBuild properties that leave source and manifests unchanged and an already-installed or repository-provided alternative collector. A trivial source error is a collection blocker, not the final analysis, when a reversible command-line setting can compile the same source. Never call an empty Cobertura file a successful fallback.

For classic non-SDK projects (ToolsVersion, explicit compile items, or packages.config), use only a repository-provided coverage command that emits Cobertura. If none exists, request Cobertura XML and stop; do not migrate the project or inject an SDK-style provider. CRAP scores always require real coverage data.

Never estimate coverage

Guessed coverage produces wrong CRAP scores, which is worse than no answer. For a classic project with no repository coverage command or existing report, stop here and request Cobertura.

Do not add coverage packages, change project manifests, or install global tools unless the user explicitly authorized dependency/tooling changes. If the repository lacks a usable provider or converter, report that exact prerequisite and the compatible command shape identified through run-tests, then stop. If an existing binary .coverage report is present, convert it only with an already-installed or repository-provided converter; otherwise request authorization or a Cobertura export. If tests execute with failures but still emit valid coverage, continue with that data and note the failures. Report complexity on its own if useful, but never publish a CRAP number derived from assumed coverage.

Before using a report, verify that it parses, contains at least one class and method, and contains the requested target. An empty report or a report that omits the target is failed collection or filtering, not 0% coverage. Regenerate coverage when possible; otherwise stop without publishing a CRAP score.

If the user supplies an existing report, state that it was not regenerated. Do not describe its data as current unless its provenance is established by running the repository's coverage command in this analysis.

Step 2: Compute cyclomatic complexity

Prefer a machine-produced per-method complexity from a repository-provided code metrics report or from the Cobertura method's complexity attribute when that report maps to the current source. Microsoft.CodeAnalysis.Metrics can generate method-level CyclomaticComplexity data through msbuild /t:Metrics, but do not add the package or modify the project without user approval.

If no machine-produced metric exists, analyze the current target source and label the result as a manual complexity count. Count the following decision points (each adds 1 to the base complexity of 1):

ConstructExample
ifif (x > 0)
else ifelse if (y < 0)
case (each)case 1:
forfor (int i = 0; ...)
foreachforeach (var item in list)
whilewhile (running)
do...whiledo { } while (cond)
catch (each)catch (Exception ex)
&&if (a && b)
|| (OR)if (a || b)
??value ?? fallback
?.obj?.Method()
? : (ternary)x > 0 ? a : b
Pattern match armx is > 0 and < 10

Base complexity is 1 for every method. Each decision point adds 1.

When counting manually, read the source file, report the construct-by-construct breakdown, and do not use a source comment as evidence. Count every occurrence, including operators nested inside arguments or return expressions; before declaring a conflict, rescan specifically for &&, ||, ??, ?., ternaries, and switch/pattern arms. If a supplied report maps to the current method and a careful recount agrees, use its metric decisively. If a genuine disagreement remains, label both sources; when the user explicitly asked to use that report, calculate the primary CRAP result from its machine-produced metric and present the manual count as a caveat rather than withholding the requested result.

Show full SKILL.md (682 more words)Show less
Step 3: Extract per-method coverage from Cobertura XML

Parse the Cobertura XML to find each method's line-rate attribute under the target <class> element. If line-rate is not available at method level, compute it from the <lines> elements:

$$\text{cov}(m) = \frac{\text{lines with hits} > 0}{\text{total lines}}$$

Method names in Cobertura may differ from source (async methods, lambdas). Match by line ranges when names don't align.

When both line-rate and <lines> exist, recompute the hit ratio and compare them. Allow only normal report rounding (one percentage point); if they differ more, the report contradicts itself. Regenerate it or report the conflict and stop without calculating CRAP. Never silently choose whichever value produces the expected score.

Step 4: Calculate CRAP scores

For each method in scope, apply the formula:

$$\text{CRAP}(m) = \text{comp}(m)^2 \times (1 - \text{cov}(m))^3 + \text{comp}(m)$$

Use a calculator or script for the arithmetic and show the substituted complexity and coverage. Do not calculate the formula mentally. Answer a named method directly; analyze unrelated methods only when the requested scope is a class or file. Once the requested result is established, do not append hypothetical refactor scores or coverage targets unless the user asked for them. Any numeric example must also come from the calculator or script.

Step 5: Present results

Present a sorted table (highest CRAP first):

text
| Method                          | Complexity | Coverage | CRAP Score | Risk     |
|---------------------------------|------------|----------|------------|----------|
| OrderService.ProcessOrder       | 10         | 45%      | 26.6       | High     |
| OrderService.ValidateItems      | 8          | 90%      | 8.1        | Moderate |
| OrderService.CalculateTotal     | 3          | 100%     | 3.0        | Low      |

Include:

  • Summary: total methods analyzed, how many in each risk category
  • Top offenders: methods with CRAP > 30, with specific recommendations
  • Quick wins: methods with high complexity but where small coverage improvements would drop the score significantly
Step 6: Provide actionable recommendations

For high-CRAP methods, suggest one or both:

  1. Add tests -- identify uncovered branches and suggest specific test cases
  2. Reduce complexity -- suggest extract-method refactoring for deeply nested logic

Calculate the coverage needed to bring a method below a CRAP threshold of 15:

$$\text{cov}_{\text{needed}} = 1 - \left(\frac{15 - \text{comp}}{\text{comp}^2}\right)^{1/3}$$

This formula only applies when comp < 15. When comp >= 15, the minimum possible CRAP score (at 100% coverage) is comp itself, which already meets or exceeds the threshold. In that case, coverage alone cannot bring the CRAP score below the threshold -- the method must be refactored to reduce its cyclomatic complexity first.

Report this as: "To bring ProcessOrder (complexity 10) below CRAP 15, increase coverage from 45% to more than 63.2% (at least 64% when reporting whole percentages)." For methods where complexity alone exceeds the threshold, report: "ComplexMethod (complexity 18) cannot reach CRAP < 15 through testing alone -- reduce complexity by extracting sub-methods."

Validation

  • Verify that coverage data was collected successfully (Cobertura XML exists and contains data)
  • Confirm the target method is present; absence is not evidence of 0% coverage
  • Confirm every coverage figure came from that XML — no estimated, assumed, or source-comment-derived values
  • Cross-check method line-rate against its line-hit ratio when both exist
  • Cross-check that method names in coverage data match the source code
  • Confirm CRAP scores with calculator or script output
  • Ensure a 100%-covered method's CRAP equals its complexity exactly

Common Pitfalls

  • Estimating coverage when collection fails: never do it — the resulting CRAP scores are wrong in the direction that matters. Use the repository-compatible Cobertura path confirmed through run-tests, then report the blocker instead.
  • Treating an empty report or missing method as 0% coverage: this is failed collection, filtering, or method mapping; do not manufacture a score.
  • Trusting contradictory Cobertura fields: compare line-rate with the line-hit ratio and stop if they disagree beyond rounding.
  • Trusting a stale complexity comment in the source: compute cyclomatic complexity from the current code; a // complexity: 7 comment left by a previous author is not evidence.
  • Mental CRAP arithmetic: use a calculator or script and show the substituted inputs.
  • Changing tooling to bypass a collector error: report the failed repository-compatible command and missing prerequisite; do not install a global collector or edit manifests without explicit authorization.
  • Stale coverage data: regenerate when the user asks for current results or the source/binaries changed; otherwise disclose that a supplied report was not regenerated.
  • Method name mismatches: Cobertura XML may use mangled/compiler-generated names for async methods, lambdas, or local functions. Match by line ranges when names don't align.
  • Generated code: Exclude auto-generated files (e.g., *.Designer.cs, *.g.cs) from analysis unless explicitly requested.

© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/dotnet-test/skills/crap-score of dotnet/skills.

Open the folder on GitHubat commit 8d670fa

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Crap Score next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crap Score compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crap Score this skilldotnet/skills5.6k1 repos~3.4kAutomated safety check: PassMIT
Minimax DOCXpoco-ai/poco-claw1.4k7 repos~3.9kAutomated safety check: PassMIT
Microsoft Skill CreatorMicrosoftDocs/mcp1.9k3 repos~2.1kAutomated safety check: PassCC-BY-4.0
Speckit ConstitutionWeihanLi/WeihanLi.Common24211 repos~2.1kAutomated safety check: PassApache-2.0
Copilot Session Failure Analysisdotnet/maui23k—~3.4kAutomated safety check: PassMIT
Microsoft Code ReferenceMicrosoftDocs/mcp1.9k4 repos~1.1kAutomated safety check: PassCC-BY-4.0

Similar skills

  • Minimax DOCX

    poco-ai/poco-claw

    Professional DOCX document creation, editing, and formatting using OpenXML SDK (.NET).

    1.4k GitHub starsUsed in 7 repos~3.9k tokens
    Documents & OfficeAuto-check passed
  • Microsoft Skill Creator

    MicrosoftDocs/mcp

    Official

    Create agent skills for Microsoft technologies using official documentation.

    1.9k GitHub starsUsed in 3 repos~2.1k tokens
    Agent WorkflowsAuto-check passed
  • Speckit Constitution

    WeihanLi/WeihanLi.Common

    Create or update the project constitution from interactive or provided principle inputs, ensuring all dependent templates stay in sync.

    242 GitHub starsUsed in 11 repos~2.1k tokens
    DevelopmentAuto-check passed
  • Mines local Copilot CLI session logs for dotnet/maui to rank costly or failing runs, tag recurring failure modes, propose repo edits and emit guard evals.

    23k GitHub stars~3.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Microsoft Code Reference

    MicrosoftDocs/mcp

    Official

    Find working code samples, verify API signatures, and fix Microsoft SDK errors using official docs.

    1.9k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from dotnet/skills

All 91 skills in this repo
  • Official

    Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

    5.6k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Official

    Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.

    5.6k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Official

    Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

    5.6k GitHub starsUsed in 3 repos~3.1k tokens
    Auto-check passed
  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Microbenchmarking

    dotnet/skills

    Official

    Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.

    5.6k GitHub starsUsed in 3 repos~3.3k tokens
    Auto-check passed
  • Official

    Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.

    5.6k GitHub starsUsed in 2 repos~4.2k tokens
    Auto-check passed

Works with

Questions about Crap Score

What does Crap Score do?

Calculates CRAP (Change Risk Anti-Patterns) for a named .NET method, class, or file. Crap Score is an agent skill from dotnet/skills, published by the product's own GitHub organization.NET method, class, or file.

When should I use Crap Score?

Crap Score fits situations like: : explicit CRAP calculation; coverage-and-complexity risk within that named target; including which tests to prioritize; : project-wide coverage/CRAP.

How do I install Crap Score in Claude Code?

Run `npx skills add dotnet/skills --skill crap-score -a claude-code`. Or copy the skill folder (plugins/dotnet-test/skills/crap-score in dotnet/skills) into .claude/skills/crap-score in your project. Claude Code loads it when a task matches its description.

How do I install Crap Score in Codex?

Run `npx skills add dotnet/skills --skill crap-score -a codex`. Or copy the skill folder (plugins/dotnet-test/skills/crap-score in dotnet/skills) into .agents/skills/crap-score in your project. Codex loads it when a task matches its description.

Can I use Crap Score in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill crap-score -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crap-score, .gemini/skills/crap-score, .github/skills/crap-score and .opencode/skills/crap-score in your project.

What does Crap Score need to run?

Going by SKILL.md and its folder, Crap Score needs the command-line tools its instructions call (dotnet).

Does Crap Score access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Crap Score safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Crap Score use?

Crap Score is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crap Score use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Crap Score?

Skills that share tags, products or a category with Crap Score: Minimax DOCX (poco-ai/poco-claw, 1.4k stars), Microsoft Skill Creator (MicrosoftDocs/mcp, 1.9k stars), Speckit Constitution (WeihanLi/WeihanLi.Common, 242 stars) and Copilot Session Failure Analysis (dotnet/maui, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crap Score?

dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,568 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 7, 2026.

Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.