Official agent skill

Detect Static Dependencies

by dotnet in dotnet/skills

ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill.

OfficialMITAuto-check passedDevelopment

Install Detect Static Dependencies

skills CLI
$ npx skills add dotnet/skills --skill detect-static-dependencies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dotnet/skills detect-static-dependencies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-test/skills/detect-static-dependencies .claude/skills/detect-static-dependencies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detect-static-dependencies
GitHub stars
5.6k
Used in
1 other repo
Token cost
~3.8k tokens
SKILL.md length
1,699 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill.

  • Works in 5 steps: Determine scan scope → Search for static dependency patterns → Aggregate and rank results → …
  • : locating System.DateTime.Now/UtcNow
  • SKILL.md covers When to Use, Response Guidelines, Execution Contract and When Not to Use, plus 4 more sections
  • Calls rg

What it does

Detect Static Dependencies is an agent skill from dotnet/skills, published by the product's own GitHub organization. ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill. USE FOR: locating System.DateTime.Now/UtcNow, System.IO.File/Directory, System.Environment, HttpClient, Console, or Process usage in C; auditing C code for hard-to-test framework dependencies; or verifying those C calls are already abstracted. DO NOT USE FOR: any target lacking the activation prerequisite; generating wrappers (use…

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with C# and .NET. The repository describes itself as: Repository for skills to assist AI coding agents with .NET and C. The licence is MIT.

When your agent uses it

  • : locating System.DateTime.Now/UtcNow
  • System.IO.File/Directory
  • System.Environment
  • Process usage in C

Example prompts

  • “/detect-static-dependencies”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Determine scan scope
  2. Search for static dependency patterns
  3. Aggregate and rank results
  4. Present the report
  5. Suggest next steps

What it can do on your machine

Read from SKILL.md and the folder at commit 8d670fa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detect Static Dependencies loads about 3.8k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 1,699 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~158
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dotnet/skills at commit 8d670fa, republished under its MIT licence (© dotnet). 1,699 words, ~3,813 tokens.

Download SKILL.mdSave it as .claude/skills/detect-static-dependencies/SKILL.md (or your agent's skills folder).
name
detect-static-dependencies
description
ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C#, .NET, `.cs`, or `.csproj`; otherwise stay dormant without invoking this skill. USE FOR: locating System.DateTime.Now/UtcNow, System.IO.File/Directory, System.Environment, HttpClient, Console, or Process usage in C#; auditing C# code for hard-to-test framework dependencies; or verifying those C# calls are already abstracted. DO NOT USE FOR: any target lacking the activation prerequisite; generating wrappers (use generate-testability-wrappers); migrating code (use migrate-static-to-wrapper); or general code review.
license
MIT

Detect Static Dependencies

Scan a C# codebase for calls to hard-to-test static APIs and produce a ranked report showing which statics appear most frequently, which files are most affected, and which abstractions already exist in the .NET ecosystem to replace them.

When to Use

  • Auditing a project's testability before adding unit tests
  • Understanding the scope of static coupling in a legacy codebase
  • Prioritizing which statics to wrap first (highest-frequency wins)
  • Creating a migration plan for incremental testability improvements

Response Guidelines

  • Scale the response to the user's request. A question about a specific category (e.g., "find time statics") should focus on that category with file locations and counts, not produce a full report across all categories.
  • When the user provides a specific file or directory path, scan only that scope — do not expand to the entire solution unless asked.
  • The full structured report format in Step 4 is for comprehensive audit requests. For focused questions, return only the relevant subset (e.g., category summary + affected files for the requested category).

Execution Contract

  • A relative path named in the prompt is enough to start. Discover it with the available file-listing tools and scan it immediately; do not ask the user to provide or re-upload files before both discovery and a content search fail.
  • Start with a recursive, line-numbered content search over eligible .cs files. Do not search only for the static keyword: ambient calls inside LINQ expressions, lambdas, callbacks, and interpolated strings usually have no static modifier.
  • If a file-reading tool fails on a path that listing or search proved exists, classify the failure before retrying. Fall back to another available mechanism such as rg -n, grep, or a shell file reader only for confirmed tool availability, transport, or path-normalization failures and only after verifying the canonical path remains inside the workspace. Stop on content-exclusion, permission/policy, workspace-boundary, or unknown failures. Search output can seed the occurrence ledger; open only the surrounding code needed to verify receiver provenance.
  • Never stop after loading this skill or announcing a scan plan. Return the completed audit in the same response. If every fallback genuinely fails, report the verified partial findings and the exact limitation; do not invent findings or replace the audit with a request to rerun.

When Not to Use

  • The user wants wrappers generated (hand off to generate-testability-wrappers)
  • The user wants mechanical migration done (hand off to migrate-static-to-wrapper)
  • The statics are already behind interfaces or TimeProvider
  • The code is not C# / .NET

Inputs

InputRequiredDescription
Target pathNoA file, directory, project (.csproj), or solution (.sln) to scan. Defaults to the current workspace.
Exclusion patternsNoGlob patterns to skip (e.g., **/obj/**, **/Migrations/**)
Category filterNoLimit to specific categories: time, filesystem, environment, network, console, process

Workflow

Step 1: Determine scan scope

Resolve the target to a set of .cs files:

  • Treat a prompt-named workspace-relative path as the target; locate it rather than asking the user for an absolute path.
  • If omitted, scan every eligible .cs file under the current workspace; do not pick one project and silently omit its siblings.
  • If a .cs file, scan that single file.
  • If a directory, scan all .cs files recursively (excluding obj/, bin/).
  • If a .csproj, find its directory and scan .cs files within.
  • If a .sln, parse it, find all project directories, and scan .cs files across all projects.

Always exclude obj/, bin/, and any user-specified exclusion patterns.

Step 2: Search for static dependency patterns

Scan each file for calls matching these categories:

Treat pattern matches as candidates, not findings. Before counting an instance call, trace how its receiver enters the class. A collaborator supplied through a constructor, parameter, property, or dependency injection (DI) is already a test seam. In particular, an injected HttpClient is testable with a controlled HttpMessageHandler; do not count its calls or recommend replacing it merely because the injected type is concrete.

CategoryPatterns to search forRecommended replacement
TimeDateTime.Now, DateTime.UtcNow, DateTime.Today, DateTimeOffset.Now, DateTimeOffset.UtcNow, Task.Delay(, new CancellationTokenSource(TimeSpanTimeProvider (.NET 8+)
File SystemFile.ReadAllText(, File.WriteAllText(, File.Exists(, File.Delete(, File.Copy(, File.Move(, Directory.Exists(, Directory.CreateDirectory(, Directory.GetFiles(, Directory.Delete(, Path.GetTempPath(, and instance members that hit the disk (new FileInfo(...), new DirectoryInfo(...), .LastWriteTimeUtc, new StreamReader(path))IFileSystem (System.IO.Abstractions NuGet)
Randomness / identitynew Random(, Random.Shared, Guid.NewGuid(TimeProvider-style seam: inject Random / an IGuidProvider
Culture / serializationCultureInfo.CurrentCulture, CultureInfo.CurrentUICulture, JsonSerializer.Serialize(, JsonSerializer.Deserialize(Pass culture/options explicitly, or inject a serializer abstraction
EnvironmentEnvironment.GetEnvironmentVariable(, Environment.SetEnvironmentVariable(, Environment.MachineName, Environment.UserName, Environment.CurrentDirectory, Environment.Exit(Custom IEnvironmentProvider
Networknew HttpClient(, .GetAsync(, .PostAsync(, .SendAsync( (confirm the receiver is an HttpClient; exclude calls whose receiver is injected or produced by an injected factory)Inject HttpClient (commonly supplied by IHttpClientFactory)
ConsoleConsole.WriteLine(, Console.ReadLine(, Console.Write(, Console.ReadKey(IConsole wrapper or ILogger
ProcessProcess.Start(, Process.GetCurrentProcess(, Process.GetProcessesByName(Custom IProcessRunner

For time calls, inspect use as well as count. Two ambient clock reads in one logical operation are two call sites and a consistency defect: for example, separate DateTime.UtcNow reads for CreatedAt and ExpiresAt = DateTime.UtcNow.AddDays(30) can drift. Recommend one captured instant. With TimeProvider, retain DateTimeOffset where possible; when the existing member requires UTC DateTime, use GetUtcNow().UtcDateTime, never .DateTime, which loses the UTC kind. Treat capturing one instant as an optional behavior-level follow-up: a mechanical wrapper migration must preserve the original reads one-for-one unless the user separately approves that semantic change.

Show full SKILL.md (840 more words)Show less
Step 3: Aggregate and rank results

Count each call site across the entire scan scope — including the instance-member call sites covered by the rules below, not only static ones.

Counting rules — inaccurate totals are the main way this report loses to an ad-hoc scan:

  • Build one occurrence ledger before writing prose. Give each included call site exactly one row containing category, exact pattern, file:line, and recommended seam. Derive every category, pattern, and per-file count by grouping that same ledger; never recount independently while writing tables.
  • Keep the three count domains separate. Files scanned includes every eligible source file; affected files includes only files with ledger rows; call sites is the number of ledger rows. Never substitute one for another.
  • One authoritative total. Every call site you found belongs in the category summary and the grand total. Never park real findings in an "additional observations" section that the totals exclude.
  • Classify by what the member touches, not by whether it is static. Instance members that reach the same untestable resource still count and belong in the matching category (new FileInfo(path).LastWriteTimeUtc → File System; new HttpClient().GetAsync(...) → Network). Say "hidden dependency", not "static", when the member is an instance call.
  • Check receiver provenance before counting instance calls. Count a resource access only when the code under test acquires or constructs the dependency itself. Exclude constructor-, parameter-, property-, and DI-injected collaborators from the "needs wrapping" total, including concrete HttpClient instances.
  • Exclude deterministic pure helpers from the "needs wrapping" total. Path.Combine, Path.GetExtension, Path.GetFileName, and Math.*/string.* statics take no ambient input and are trivially testable. List them, if at all, in a separate "no action needed" note — never as testability blockers.
  • Cover every category before reporting — time, file system, environment, network, console, process, randomness (new Random(), Guid.NewGuid()), culture (CultureInfo.CurrentCulture), and serialization/statics such as JsonSerializer. Omitting a category that is present is an under-count.
  • Give file:line for every occurrence so the user can jump straight to it.
  • Reconcile before publishing. The category totals, the top-patterns table, and the per-file table must sum to the same grand total.
  • Treat exclusions as a scope decision, not a category. Remove obj/, bin/, generated, and user-excluded files before building the ledger. Do not include their files or call sites in any reported count. State the exclusions once rather than mixing excluded candidates into the arithmetic.
  • Label truncated rankings. In a comprehensive audit, list all distinct patterns when needed for reconciliation. If the user asked only for a top-N subset, label it as a subset and do not imply that its rows sum to the grand total.

Produce a summary with:

  1. Category summary — total call sites per category (time, filesystem, env, etc.)
  2. Top patterns — the 10 most frequent individual patterns ranked by count
  3. Most affected files — files with the highest number of static dependencies
  4. Existing abstractions available — for each category, note the recommended .NET abstraction:
    • Time → TimeProvider (built-in since .NET 8)
    • File system → System.IO.Abstractions (NuGet package)
    • HTTP → IHttpClientFactory (built-in)
    • Environment → custom IEnvironmentProvider
    • Console → custom IConsole or ILogger
    • Process → custom IProcessRunner
Step 4: Present the report

Format the output as a structured report:

## Static Dependency Report

**Scope**: <project/solution name>
**Files scanned**: <count>
**Total static call sites**: <count>

### Category Summary
| Category     | Call Sites | Recommended Abstraction |
|-------------|-----------|------------------------|
| Time         | 42        | TimeProvider (.NET 8+) |
| File System  | 31        | System.IO.Abstractions |
| Environment  | 12        | IEnvironmentProvider   |
| ...          | ...       | ...                    |

### Top 10 Patterns
| # | Pattern             | Count | Files |
|---|---------------------|-------|-------|
| 1 | DateTime.UtcNow     | 28    | 14    |
| 2 | File.ReadAllText    | 18    | 9     |
| ...                                      |

### Most Affected Files
| File                          | Static Calls | Categories          |
|-------------------------------|-------------|---------------------|
| Services/OrderProcessor.cs    | 12          | Time, FileSystem    |
| ...                                                               |

### Migration Priority
1. **Time** (42 sites) — Use `TimeProvider`, zero NuGet dependencies on .NET 8+
2. **File System** (31 sites) — Use `System.IO.Abstractions` NuGet package
3. ...
Step 5: Suggest next steps

Based on the report, recommend which category to tackle first (highest count, best built-in support). Keep this to a few lines.

Mention generate-testability-wrappers or migrate-static-to-wrapper only when the user's next action clearly needs them — a hand-off note, not a sales pitch. Never end an audit with promotional next-steps that dilute the findings.

Validation

  • All .cs files in scope were scanned (check count)
  • Report includes category totals, top patterns, and affected files
  • Category totals, top patterns, and per-file counts reconcile to the same grand total
  • Files scanned, affected files, and call sites are reported as different quantities
  • Every aggregate was derived from one occurrence ledger rather than independently recounted
  • Every occurrence carries a file:line location
  • No findings are held outside the totals in an "additional" section
  • Calls on injected collaborators are excluded from the "needs wrapping" total
  • Deterministic pure helpers (Path.Combine, Math.*) are not counted as testability blockers
  • Each detected pattern has a recommended replacement listed
  • obj/ and bin/ directories were excluded
  • Migration priority is ordered by impact (count × ease of replacement)

Common Pitfalls

PitfallSolution
Scanning obj/ or generated codeAlways exclude obj/, bin/, and *.Designer.cs
Counting calls on injected collaboratorsTrace the receiver: an injected HttpClient, TimeProvider, interface, or other caller-supplied dependency already has a seam and needs no replacement
Missing statics inside lambdas/LINQSearch covers all code within .cs files, including lambdas
Recommending TimeProvider on < .NET 8Check TargetFramework in .csproj — if < net8.0, recommend NodaTime.IClock or custom ISystemClock
Ignoring test projectsOnly scan production code — exclude *.Tests.csproj projects from the scan
Under-counting by relegating findingsReal call sites belong in the category totals, not in a trailing "also noticed" paragraph that the totals ignore
Calling an instance member a staticnew FileInfo(p).LastWriteTimeUtc is an instance call but still a hidden file-system dependency — count it under File System and describe it accurately
Recommending a wrapper for Path.CombinePure, deterministic helpers need no seam; listing them as blockers makes the recommendations wrong

© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/dotnet-test/skills/detect-static-dependencies of dotnet/skills.

Open the folder on GitHubat commit 8d670fa

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Detect Static Dependencies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detect Static Dependencies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detect Static Dependencies this skilldotnet/skills5.6k1 repos~3.8kAutomated safety check: PassMIT
Speckit ConstitutionWeihanLi/WeihanLi.Common24211 repos~2.1kAutomated safety check: PassApache-2.0
Add Analyzerdotnet/roslynator3.5k—~1.3kAutomated safety check: PassCustom licence
GitVersion .NET DevelopmentGitTools/GitVersion3.1k—~1.7kAutomated safety check: PassMIT
Code Reviewdotnet/macios2.9k—~1.7kAutomated safety check: PassCustom licence
Add Compiler Diagnostic Fixdotnet/roslynator3.5k—~1kAutomated safety check: PassCustom licence

Similar skills

  • Speckit Constitution

    WeihanLi/WeihanLi.Common

    Create or update the project constitution from interactive or provided principle inputs, ensuring all dependent templates stay in sync.

    242 GitHub starsUsed in 11 repos~2.1k tokens
    DevelopmentAuto-check passed
  • Add Analyzer

    dotnet/roslynator

    Official

    A skill your agent uses when adding a new RCS diagnostic in roslynator (RCS0 formatting, RCS1 general, RCS9 code-analysis), wiring roslynator EditorConfig options, or when docs say CHANGELOG.md…

    3.5k GitHub stars~1.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • GitVersion .NET Development

    GitTools/GitVersion

    Gives repository-specific .NET guidance for GitVersion: build and test commands, central package management, project layout and coding conventions.

    3.1k GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review

    dotnet/macios

    Official

    Review dotnet/macios PRs against established rules. An agent skill from dotnet/macios.

    2.9k GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    A skill your agent uses when adding a Roslynator code fix for C compiler error CS or RCF, editing Diagnostics.xml or CodeFixes.xml, or when compiler-diagnostic-fixes-testing.md shows…

    3.5k GitHub stars~1k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Add Refactoring

    dotnet/roslynator

    Official

    A skill your agent uses when adding a new RR refactoring in roslynator, editing Refactorings.xml, registering in RefactoringContext, or when refactorings-testing.md shows XunitRefactoringVerifier —…

    3.5k GitHub stars~946 tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from dotnet/skills

All 91 skills in this repo
  • Official

    Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

    5.6k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Official

    Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.

    5.6k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Official

    Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

    5.6k GitHub starsUsed in 3 repos~3.1k tokens
    Auto-check passed
  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Microbenchmarking

    dotnet/skills

    Official

    Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.

    5.6k GitHub starsUsed in 3 repos~3.3k tokens
    Auto-check passed
  • Official

    Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.

    5.6k GitHub starsUsed in 2 repos~4.2k tokens
    Auto-check passed

Works with

Categories

Questions about Detect Static Dependencies

What does Detect Static Dependencies do?

ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C, .NET, .cs, or .csproj; otherwise stay dormant without invoking this skill. Detect Static Dependencies is an agent skill from dotnet/skills, published by the product's own GitHub organization.csproj; otherwise stay dormant without invoking this skill.

When should I use Detect Static Dependencies?

Detect Static Dependencies fits situations like: : locating System.DateTime.Now/UtcNow; system.IO.File/Directory; system.Environment; process usage in C.

How do I install Detect Static Dependencies in Claude Code?

Run `npx skills add dotnet/skills --skill detect-static-dependencies -a claude-code`. Or copy the skill folder (plugins/dotnet-test/skills/detect-static-dependencies in dotnet/skills) into .claude/skills/detect-static-dependencies in your project. Claude Code loads it when a task matches its description.

How do I install Detect Static Dependencies in Codex?

Run `npx skills add dotnet/skills --skill detect-static-dependencies -a codex`. Or copy the skill folder (plugins/dotnet-test/skills/detect-static-dependencies in dotnet/skills) into .agents/skills/detect-static-dependencies in your project. Codex loads it when a task matches its description.

Can I use Detect Static Dependencies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill detect-static-dependencies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detect-static-dependencies, .gemini/skills/detect-static-dependencies, .github/skills/detect-static-dependencies and .opencode/skills/detect-static-dependencies in your project.

What does Detect Static Dependencies need to run?

Going by SKILL.md and its folder, Detect Static Dependencies needs the command-line tools its instructions call (rg).

Does Detect Static Dependencies access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Detect Static Dependencies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Detect Static Dependencies use?

Detect Static Dependencies is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detect Static Dependencies use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Detect Static Dependencies?

Skills that share tags, products or a category with Detect Static Dependencies: Speckit Constitution (WeihanLi/WeihanLi.Common, 242 stars), Add Analyzer (dotnet/roslynator, 3.5k stars), GitVersion .NET Development (GitTools/GitVersion, 3.1k stars) and Code Review (dotnet/macios, 2.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detect Static Dependencies?

dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,568 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 7, 2026.

Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.