Speckit Constitution
WeihanLi/WeihanLi.Common
Create or update the project constitution from interactive or provided principle inputs, ensuring all dependent templates stay in sync.
ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill.
$ npx skills add dotnet/skills --skill detect-static-dependencies -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dotnet/skills detect-static-dependencies --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-test/skills/detect-static-dependencies .claude/skills/detect-static-dependencies && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "detect-static-dependencies" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-test/skills/detect-static-dependencies into .claude/skills/detect-static-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-static-dependencies", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dotnet/skills/tree/main/plugins/dotnet-test/skills/detect-static-dependenciesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dotnet/skills --skill detect-static-dependencies -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dotnet/skills detect-static-dependencies --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/dotnet-test/skills/detect-static-dependencies .agents/skills/detect-static-dependencies && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "detect-static-dependencies" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-test/skills/detect-static-dependencies into .agents/skills/detect-static-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-static-dependencies", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dotnet/skills --skill detect-static-dependencies -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dotnet/skills detect-static-dependencies --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/dotnet-test/skills/detect-static-dependencies .cursor/skills/detect-static-dependencies && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "detect-static-dependencies" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-test/skills/detect-static-dependencies into .cursor/skills/detect-static-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-static-dependencies", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dotnet/skills.git --path plugins/dotnet-test/skills/detect-static-dependencies--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dotnet/skills --skill detect-static-dependencies -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dotnet/skills detect-static-dependencies --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/dotnet-test/skills/detect-static-dependencies .gemini/skills/detect-static-dependencies && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "detect-static-dependencies" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-test/skills/detect-static-dependencies into .gemini/skills/detect-static-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-static-dependencies", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dotnet/skills detect-static-dependenciesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dotnet/skills --skill detect-static-dependencies -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/dotnet-test/skills/detect-static-dependencies .github/skills/detect-static-dependencies && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "detect-static-dependencies" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-test/skills/detect-static-dependencies into .github/skills/detect-static-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-static-dependencies", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dotnet/skills --skill detect-static-dependencies -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dotnet/skills detect-static-dependencies --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/dotnet-test/skills/detect-static-dependencies .opencode/skills/detect-static-dependencies && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "detect-static-dependencies" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-test/skills/detect-static-dependencies into .opencode/skills/detect-static-dependencies/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "detect-static-dependencies", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
detect-static-dependenciesACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill.
Detect Static Dependencies is an agent skill from dotnet/skills, published by the product's own GitHub organization. ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill. USE FOR: locating System.DateTime.Now/UtcNow, System.IO.File/Directory, System.Environment, HttpClient, Console, or Process usage in C; auditing C code for hard-to-test framework dependencies; or verifying those C calls are already abstracted. DO NOT USE FOR: any target lacking the activation prerequisite; generating wrappers (use…
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with C# and .NET. The repository describes itself as: Repository for skills to assist AI coding agents with .NET and C. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8d670fa. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Detect Static Dependencies loads about 3.8k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 1,699 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dotnet/skills at commit 8d670fa, republished under its MIT licence (© dotnet). 1,699 words, ~3,813 tokens.
.claude/skills/detect-static-dependencies/SKILL.md (or your agent's skills folder).Scan a C# codebase for calls to hard-to-test static APIs and produce a ranked report showing which statics appear most frequently, which files are most affected, and which abstractions already exist in the .NET ecosystem to replace them.
.cs
files. Do not search only for the static keyword: ambient calls inside
LINQ expressions, lambdas, callbacks, and interpolated strings usually have
no static modifier.rg -n, grep, or a shell file reader only for confirmed
tool availability, transport, or path-normalization failures and only after
verifying the canonical path remains inside the workspace. Stop on
content-exclusion, permission/policy, workspace-boundary, or unknown failures.
Search output can seed the occurrence ledger; open only the surrounding code
needed to verify receiver provenance.generate-testability-wrappers)migrate-static-to-wrapper)TimeProvider| Input | Required | Description |
|---|---|---|
| Target path | No | A file, directory, project (.csproj), or solution (.sln) to scan. Defaults to the current workspace. |
| Exclusion patterns | No | Glob patterns to skip (e.g., **/obj/**, **/Migrations/**) |
| Category filter | No | Limit to specific categories: time, filesystem, environment, network, console, process |
Resolve the target to a set of .cs files:
.cs file under the current workspace; do not
pick one project and silently omit its siblings..cs file, scan that single file..cs files recursively (excluding obj/, bin/)..csproj, find its directory and scan .cs files within..sln, parse it, find all project directories, and scan .cs files across all projects.Always exclude obj/, bin/, and any user-specified exclusion patterns.
Scan each file for calls matching these categories:
Treat pattern matches as candidates, not findings. Before counting an instance call, trace how its
receiver enters the class. A collaborator supplied through a constructor, parameter, property, or
dependency injection (DI) is already a test seam. In particular, an injected HttpClient is
testable with a controlled HttpMessageHandler; do not count its calls or recommend replacing it
merely because the injected type is concrete.
| Category | Patterns to search for | Recommended replacement |
|---|---|---|
| Time | DateTime.Now, DateTime.UtcNow, DateTime.Today, DateTimeOffset.Now, DateTimeOffset.UtcNow, Task.Delay(, new CancellationTokenSource(TimeSpan | TimeProvider (.NET 8+) |
| File System | File.ReadAllText(, File.WriteAllText(, File.Exists(, File.Delete(, File.Copy(, File.Move(, Directory.Exists(, Directory.CreateDirectory(, Directory.GetFiles(, Directory.Delete(, Path.GetTempPath(, and instance members that hit the disk (new FileInfo(...), new DirectoryInfo(...), .LastWriteTimeUtc, new StreamReader(path)) | IFileSystem (System.IO.Abstractions NuGet) |
| Randomness / identity | new Random(, Random.Shared, Guid.NewGuid( | TimeProvider-style seam: inject Random / an IGuidProvider |
| Culture / serialization | CultureInfo.CurrentCulture, CultureInfo.CurrentUICulture, JsonSerializer.Serialize(, JsonSerializer.Deserialize( | Pass culture/options explicitly, or inject a serializer abstraction |
| Environment | Environment.GetEnvironmentVariable(, Environment.SetEnvironmentVariable(, Environment.MachineName, Environment.UserName, Environment.CurrentDirectory, Environment.Exit( | Custom IEnvironmentProvider |
| Network | new HttpClient(, .GetAsync(, .PostAsync(, .SendAsync( (confirm the receiver is an HttpClient; exclude calls whose receiver is injected or produced by an injected factory) | Inject HttpClient (commonly supplied by IHttpClientFactory) |
| Console | Console.WriteLine(, Console.ReadLine(, Console.Write(, Console.ReadKey( | IConsole wrapper or ILogger |
| Process | Process.Start(, Process.GetCurrentProcess(, Process.GetProcessesByName( | Custom IProcessRunner |
For time calls, inspect use as well as count. Two ambient clock reads in one
logical operation are two call sites and a consistency defect: for example,
separate DateTime.UtcNow reads for CreatedAt and
ExpiresAt = DateTime.UtcNow.AddDays(30) can drift. Recommend one captured
instant. With TimeProvider, retain DateTimeOffset where possible; when the
existing member requires UTC DateTime, use GetUtcNow().UtcDateTime, never
.DateTime, which loses the UTC kind. Treat capturing one instant as an
optional behavior-level follow-up: a mechanical wrapper migration must preserve
the original reads one-for-one unless the user separately approves that
semantic change.
Count each call site across the entire scan scope — including the instance-member call sites covered by the rules below, not only static ones.
Counting rules — inaccurate totals are the main way this report loses to an ad-hoc scan:
file:line, and
recommended seam. Derive every category, pattern, and per-file count by
grouping that same ledger; never recount independently while writing tables.Files scanned includes every
eligible source file; affected files includes only files with ledger rows;
call sites is the number of ledger rows. Never substitute one for another.static. Instance members that reach the same untestable resource still count and belong in the matching category (new FileInfo(path).LastWriteTimeUtc → File System; new HttpClient().GetAsync(...) → Network). Say "hidden dependency", not "static", when the member is an instance call.HttpClient instances.Path.Combine, Path.GetExtension, Path.GetFileName, and Math.*/string.* statics take no ambient input and are trivially testable. List them, if at all, in a separate "no action needed" note — never as testability blockers.new Random(), Guid.NewGuid()), culture (CultureInfo.CurrentCulture), and serialization/statics such as JsonSerializer. Omitting a category that is present is an under-count.file:line for every occurrence so the user can jump straight to it.obj/,
bin/, generated, and user-excluded files before building the ledger. Do not
include their files or call sites in any reported count. State the exclusions
once rather than mixing excluded candidates into the arithmetic.Produce a summary with:
TimeProvider (built-in since .NET 8)System.IO.Abstractions (NuGet package)IHttpClientFactory (built-in)IEnvironmentProviderIConsole or ILoggerIProcessRunnerFormat the output as a structured report:
## Static Dependency Report
**Scope**: <project/solution name>
**Files scanned**: <count>
**Total static call sites**: <count>
### Category Summary
| Category | Call Sites | Recommended Abstraction |
|-------------|-----------|------------------------|
| Time | 42 | TimeProvider (.NET 8+) |
| File System | 31 | System.IO.Abstractions |
| Environment | 12 | IEnvironmentProvider |
| ... | ... | ... |
### Top 10 Patterns
| # | Pattern | Count | Files |
|---|---------------------|-------|-------|
| 1 | DateTime.UtcNow | 28 | 14 |
| 2 | File.ReadAllText | 18 | 9 |
| ... |
### Most Affected Files
| File | Static Calls | Categories |
|-------------------------------|-------------|---------------------|
| Services/OrderProcessor.cs | 12 | Time, FileSystem |
| ... |
### Migration Priority
1. **Time** (42 sites) — Use `TimeProvider`, zero NuGet dependencies on .NET 8+
2. **File System** (31 sites) — Use `System.IO.Abstractions` NuGet package
3. ...Based on the report, recommend which category to tackle first (highest count, best built-in support). Keep this to a few lines.
Mention generate-testability-wrappers or migrate-static-to-wrapper only when the user's next action clearly needs them — a hand-off note, not a sales pitch. Never end an audit with promotional next-steps that dilute the findings.
.cs files in scope were scanned (check count)file:line locationPath.Combine, Math.*) are not counted as testability blockersobj/ and bin/ directories were excluded| Pitfall | Solution |
|---|---|
Scanning obj/ or generated code | Always exclude obj/, bin/, and *.Designer.cs |
| Counting calls on injected collaborators | Trace the receiver: an injected HttpClient, TimeProvider, interface, or other caller-supplied dependency already has a seam and needs no replacement |
| Missing statics inside lambdas/LINQ | Search covers all code within .cs files, including lambdas |
Recommending TimeProvider on < .NET 8 | Check TargetFramework in .csproj — if < net8.0, recommend NodaTime.IClock or custom ISystemClock |
| Ignoring test projects | Only scan production code — exclude *.Tests.csproj projects from the scan |
| Under-counting by relegating findings | Real call sites belong in the category totals, not in a trailing "also noticed" paragraph that the totals ignore |
| Calling an instance member a static | new FileInfo(p).LastWriteTimeUtc is an instance call but still a hidden file-system dependency — count it under File System and describe it accurately |
Recommending a wrapper for Path.Combine | Pure, deterministic helpers need no seam; listing them as blockers makes the recommendations wrong |
© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/dotnet-test/skills/detect-static-dependencies of dotnet/skills.
Open the folder on GitHubat commit 8d670fa
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.
Detect Static Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Detect Static Dependencies this skilldotnet/skills | 5.6k | 1 repos | ~3.8k | Automated safety check: Pass | MIT | |
| Speckit ConstitutionWeihanLi/WeihanLi.Common | 242 | 11 repos | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Add Analyzerdotnet/roslynator | 3.5k | — | ~1.3k | Automated safety check: Pass | Custom licence | |
| GitVersion .NET DevelopmentGitTools/GitVersion | 3.1k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Code Reviewdotnet/macios | 2.9k | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| Add Compiler Diagnostic Fixdotnet/roslynator | 3.5k | — | ~1k | Automated safety check: Pass | Custom licence |
WeihanLi/WeihanLi.Common
Create or update the project constitution from interactive or provided principle inputs, ensuring all dependent templates stay in sync.
dotnet/roslynator
A skill your agent uses when adding a new RCS diagnostic in roslynator (RCS0 formatting, RCS1 general, RCS9 code-analysis), wiring roslynator EditorConfig options, or when docs say CHANGELOG.md…
GitTools/GitVersion
Gives repository-specific .NET guidance for GitVersion: build and test commands, central package management, project layout and coding conventions.
dotnet/macios
Review dotnet/macios PRs against established rules. An agent skill from dotnet/macios.
dotnet/roslynator
A skill your agent uses when adding a Roslynator code fix for C compiler error CS or RCF, editing Diagnostics.xml or CodeFixes.xml, or when compiler-diagnostic-fixes-testing.md shows…
dotnet/roslynator
A skill your agent uses when adding a new RR refactoring in roslynator, editing Refactorings.xml, registering in RefactoringContext, or when refactorings-testing.md shows XunitRefactoringVerifier —…
dotnet/skills
Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.
dotnet/skills
Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.
dotnet/skills
Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.
dotnet/skills
Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.
dotnet/skills
Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.
dotnet/skills
Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.
Categories
ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill. Detect Static Dependencies is an agent skill from dotnet/skills, published by the product's own GitHub organization.csproj; otherwise stay dormant without invoking this skill.
Detect Static Dependencies fits situations like: : locating System.DateTime.Now/UtcNow; system.IO.File/Directory; system.Environment; process usage in C.
Run `npx skills add dotnet/skills --skill detect-static-dependencies -a claude-code`. Or copy the skill folder (plugins/dotnet-test/skills/detect-static-dependencies in dotnet/skills) into .claude/skills/detect-static-dependencies in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dotnet/skills --skill detect-static-dependencies -a codex`. Or copy the skill folder (plugins/dotnet-test/skills/detect-static-dependencies in dotnet/skills) into .agents/skills/detect-static-dependencies in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill detect-static-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detect-static-dependencies, .gemini/skills/detect-static-dependencies, .github/skills/detect-static-dependencies and .opencode/skills/detect-static-dependencies in your project.
Going by SKILL.md and its folder, Detect Static Dependencies needs the command-line tools its instructions call (rg).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Detect Static Dependencies is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Detect Static Dependencies: Speckit Constitution (WeihanLi/WeihanLi.Common, 242 stars), Add Analyzer (dotnet/roslynator, 3.5k stars), GitVersion .NET Development (GitTools/GitVersion, 3.1k stars) and Code Review (dotnet/macios, 2.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,568 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 7, 2026.
Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.