Agent skill

Code Quality Gate

by fengshao1227 in fengshao1227/ccg-workflow

Scans code for complexity, long functions, duplicated blocks, naming problems and code smells with a Node script, then reports and suggests refactors.

MITAuto-check: notesDevelopment

SKILL.md written in Chinese; this summary is our English description.

Install Code Quality Gate

skills CLI
$ npx skills add fengshao1227/ccg-workflow --skill verify-quality -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fengshao1227/ccg-workflow verify-quality --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fengshao1227/ccg-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/dsh-ccg/skills/verify-quality .claude/skills/verify-quality && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-quality
GitHub stars
5.9k
Token cost
~593 tokens
SKILL.md length
91 words
Files
2 (incl. scripts)
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Scans code for complexity, long functions, duplicated blocks, naming problems and code smells with a Node script, then reports and suggests refactors.

  • Checking a module for complexity and code smells after a refactor
  • SKILL.md covers 核心原则, 自动检查, 检测指标 and 自动触发时机, plus 3 more sections
  • Runs JavaScript scripts from its folder; calls node
  • Running a quality gate during pull request review

What it does

Written in Chinese, this skill is a code quality gate built on the idea that readability, maintainability and testability define quality. A bundled Node script scans a path, with a verbose option, and measures cyclomatic complexity, function length, file length, parameter count, nesting depth and line length, each against a threshold that produces a warning or a hint.

It also checks naming conventions, with PascalCase for classes, snake_case for functions and variables and upper snake case for constants, and flags code smells: duplicated blocks, long parameter lists, magic numbers, dead code and commented-out code, each with a severity. The report lists passes and failures, and the skill includes before-and-after examples for lowering complexity and removing duplication.

It is meant to run automatically on large modules, after a refactor, during code review and before a commit, and it requires Node 18 or later. The report shows a pass or fail summary for the scanned code.

When your agent uses it

  • Checking a module for complexity and code smells after a refactor
  • Running a quality gate during pull request review
  • Finding long functions, deep nesting or duplicated blocks
  • Checking naming conventions before committing

Example prompts

  • “Run the quality check on ./src and list every function that is too complex.”
  • “Check this refactor for duplicated blocks and magic numbers before I commit.”
  • “Give me a code quality report for the payments module with refactoring suggestions.”

Requirements

  • Node.js 18 or later
  • Compatibility (from SKILL.md): node>=18
  • Pre-approved tools (allowed-tools): Bash, Read, Glob

What it can do on your machine

Read from SKILL.md and the folder at commit f349e3d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    node>=18

    From compatibility in the SKILL.md frontmatter.

Context cost

Code Quality Gate loads about 593 tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 91 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~593

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from fengshao1227/ccg-workflow at commit f349e3d, republished under its MIT licence (© fengshao1227). 91 words, ~593 tokens.

Download SKILL.mdSave it as .claude/skills/verify-quality/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
verify-quality
description
代码质量校验关卡。检测复杂度、重复代码、命名规范、函数长度等质量指标。当用户提到代码质量、复杂度检查、代码异味、重构建议、lint检查、代码规范时使用。在复杂模块、重构完成时自动触发。
allowed-tools
Bash, Read, Glob
compatibility
node>=18
license
MIT
user-invocable
true
disable-model-invocation
false
argument-hint
<扫描路径>

⚖ 校验关卡 · 代码质量

核心原则

代码质量 = 可读性 + 可维护性 + 可测试性
劣质代码是技术债,技术债是道基裂痕
复杂度是 bug 的温床

自动检查

运行质量检查脚本(跨平台):

bash
# 在 skill 目录下运行
node scripts/quality_checker.js <扫描路径>
node scripts/quality_checker.js <扫描路径> -v      # 详细模式
node scripts/quality_checker.js <扫描路径> --json  # JSON 输出

检测指标

复杂度指标
指标阈值超标后果
圈复杂度≤ 10🟠 警告,建议拆分
函数长度≤ 50 行🟠 警告,建议拆分
文件长度≤ 500 行🟡 提示,考虑拆分
参数数量≤ 5🟠 警告,考虑封装
嵌套深度≤ 4🟠 警告,建议重构
行长度≤ 120🔵 提示
命名规范
类型规范示例
类名PascalCaseUserService, HttpClient
函数名snake_caseget_user, process_data
常量UPPER_SNAKEMAX_RETRY, DEFAULT_TIMEOUT
变量snake_caseuser_id, total_count
代码异味
异味说明严重度
重复代码相似代码块 > 10 行🟠 High
过长参数列表参数 > 5 个🟡 Medium
魔法数字未命名的常量🟡 Medium
死代码未使用的函数/变量🔵 Low
注释代码被注释的代码块🔵 Low

自动触发时机

场景触发条件
复杂模块代码行数 > 200
重构完成重构任务完成时
代码审查PR/MR 审查时
提交前代码提交前检查

校验流程

1. 扫描代码文件
2. 计算复杂度指标
3. 检测代码异味
4. 验证命名规范
5. 输出质量校验报告

校验报告格式

## 代码质量校验报告

✓ 通过 | ✗ 未通过

### 复杂度指标
- 平均函数复杂度: N
- 超标函数数: N
- 最大文件行数: N

### 代码异味
- 🟠 High: N
- 🟡 Medium: N
- 🔵 Low: N

### 问题清单

| 文件 | 行号 | 类型 | 严重度 | 描述 |
|------|------|------|--------|------|
| ... | ... | ... | ... | ... |

### 结论
可交付 / 需重构后交付

重构建议

降低复杂度
python
# 🔴 高复杂度 - 道基不稳
def process(data):
    if condition1:
        if condition2:
            if condition3:
                # 深层嵌套
                pass

# ✅ 低复杂度 - 道基稳固
def process(data):
    if not condition1:
        return
    if not condition2:
        return
    if not condition3:
        return
    # 主逻辑
消除重复
python
# 🔴 重复代码 - 异端
def func1():
    # 10行相同逻辑
    pass

def func2():
    # 10行相同逻辑
    pass

# ✅ 提取公共函数 - 正道
def common_logic():
    # 公共逻辑
    pass

def func1():
    common_logic()

def func2():
    common_logic()

© fengshao1227, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in dsh-ccg/skills/verify-quality of fengshao1227/ccg-workflow.

  • SKILL.md
  • scripts/quality_checker.js

Open the folder on GitHubat commit f349e3d

Compare with similar skills

Code Quality Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Quality Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Quality Gate this skillfengshao1227/ccg-workflow5.9k—~593Automated safety check: NotesMIT
Systematic Code Refactoringluongnv89/claude-howto42k—~3kAutomated safety check: PassMIT
Code Refactoring Workflowluongnv89/claude-howto42k—~3.1kAutomated safety check: PassMIT
FIXME Resolvertailcallhq/forgecode7.6k—~1.1kAutomated safety check: PassApache-2.0
DesloppifyGit-on-my-level/codex-autorunner875—~3.4kAutomated safety check: PassMIT
Tech Debt Analyzerailabs-393/ai-labs-claude-skills4551 repos~3.9kAutomated safety check: PassMIT

Similar skills

  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • Code Refactoring Workflow

    luongnv89/claude-howto

    Guides systematic, test-backed refactoring in the style of Martin Fowler, moving through research, planning and small incremental changes with your approval at each phase.

    42k GitHub stars~3.1k tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • FIXME Resolver

    tailcallhq/forgecode

    Finds every FIXME comment in a codebase, groups related ones across files into one task, implements the work they describe and removes the comments once it is done.

    7.6k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Desloppify

    Git-on-my-level/codex-autorunner

    Codebase health scanner and technical debt tracker. An agent skill from Git-on-my-level/codex-autorunner.

    875 GitHub stars~3.4k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Tech Debt Analyzer

    ailabs-393/ai-labs-claude-skills

    This skill should be used when analyzing technical debt in a codebase, documenting code quality issues, creating technical debt registers, or assessing code maintainability.

    455 GitHub starsUsed in 1 repo~3.9k tokens
    DevelopmentAuto-check passed
  • Run a deep DRY + code-hygiene audit of the Rust workspace and turn the findings into verified, deduplicated, hierarchical GitHub tech-debt issues.

    577 GitHub stars~1.5k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from fengshao1227/ccg-workflow

  • Change Verification Gate

    fengshao1227/ccg-workflow

    Analyzes a code diff for documentation sync, test coverage and impact scope, warning when docs or tests lag behind a design-level change or a large edit.

    5.9k GitHub stars~511 tokensUpdated 25 days ago
    Auto-check: notes
  • Module Completeness Check

    fengshao1227/ccg-workflow

    Scans a module directory for the required README.md and DESIGN.md plus recommended files and reports what is missing, so a module is not delivered incomplete.

    5.9k GitHub stars~473 tokensUpdated 25 days ago
    Auto-check: notes
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 25 days ago
    Auto-check: notes
  • README and DESIGN Generator

    fengshao1227/ccg-workflow

    Generates README.md and DESIGN.md skeletons for a module by scanning its structure with a Node script, then lists what to fill in by hand.

    5.9k GitHub stars~410 tokensUpdated 25 days ago
    Auto-check: notes
  • Ccg Workflow

    fengshao1227/ccg-workflow

    How to run a non-trivial change end to end with the CCG role tools (ccganalyze / ccgdesign / ccgbuild / ccgdebug / ccgoptimize / ccgreview / ccgtest) and the verify- quality gates.

    5.9k GitHub stars~2.3k tokensUpdated 25 days ago
    Auto-check passed

Categories

Questions about Code Quality Gate

What does Code Quality Gate do?

Scans code for complexity, long functions, duplicated blocks, naming problems and code smells with a Node script, then reports and suggests refactors. Written in Chinese, this skill is a code quality gate built on the idea that readability, maintainability and testability define quality. A bundled Node script scans a path, with a verbose option, and measures cyclomatic complexity, function length, file length, parameter count, nesting depth and line length, each against a threshold that produces a warning or a hint.

When should I use Code Quality Gate?

Code Quality Gate fits situations like: checking a module for complexity and code smells after a refactor; running a quality gate during pull request review; finding long functions, deep nesting or duplicated blocks; checking naming conventions before committing.

How do I install Code Quality Gate in Claude Code?

Run `npx skills add fengshao1227/ccg-workflow --skill verify-quality -a claude-code`. Or copy the skill folder (dsh-ccg/skills/verify-quality in fengshao1227/ccg-workflow) into .claude/skills/verify-quality in your project. Claude Code loads it when a task matches its description.

How do I install Code Quality Gate in Codex?

Run `npx skills add fengshao1227/ccg-workflow --skill verify-quality -a codex`. Or copy the skill folder (dsh-ccg/skills/verify-quality in fengshao1227/ccg-workflow) into .agents/skills/verify-quality in your project. Codex loads it when a task matches its description.

Can I use Code Quality Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fengshao1227/ccg-workflow --skill verify-quality -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-quality, .gemini/skills/verify-quality, .github/skills/verify-quality and .opencode/skills/verify-quality in your project.

What does Code Quality Gate need to run?

Going by SKILL.md and its folder, Code Quality Gate needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js 18 or later. Its frontmatter pre-approves these tools: Bash, Read, Glob. Compatibility (from SKILL.md): node>=18.

Does Code Quality Gate access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Quality Gate safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Code Quality Gate use?

Code Quality Gate is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Quality Gate use?

About 593 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Quality Gate?

Skills that share tags, products or a category with Code Quality Gate: Systematic Code Refactoring (luongnv89/claude-howto, 42k stars), Code Refactoring Workflow (luongnv89/claude-howto, 42k stars), FIXME Resolver (tailcallhq/forgecode, 7.6k stars) and Desloppify (Git-on-my-level/codex-autorunner, 875 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Quality Gate?

fengshao1227 (a GitHub user) maintains it in fengshao1227/ccg-workflow, which has 5,935 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 15, 2026.

Source: fengshao1227/ccg-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.