Agent skill

Product Quality Analysis

by Hack23 in Hack23/cia

Product quality metrics, SonarCloud analysis, technical debt management, code quality gates

Apache-2.0Auto-check passedDevelopment

Install Product Quality Analysis

skills CLI
$ npx skills add Hack23/cia --skill product-quality-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia product-quality-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/product-quality-analysis .claude/skills/product-quality-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
product-quality-analysis
GitHub stars
239
Token cost
~1.9k tokens
SKILL.md length
279 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Product quality metrics, SonarCloud analysis, technical debt management, code quality gates

  • Tasks that involve Technical debt
  • SKILL.md covers Purpose, When to Use This Skill, Quality Gates and SonarCloud Metrics, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Code quality

What it does

Product Quality Analysis is an agent skill from Hack23/cia. Product quality metrics, SonarCloud analysis, technical debt management, code quality gates

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Technical debt, Code quality and Quality gates. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Technical debt
  • Tasks that involve Code quality
  • Tasks that involve Quality gates

Example prompts

  • “/product-quality-analysis”

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java and xml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.sonarcloud.io
    • jacoco.org
    • oreilly.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Product Quality Analysis loads about 1.9k tokens when it runs. Until then it costs about 29 tokens; SKILL.md has 279 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~29
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 279 words, ~1,851 tokens.

Download SKILL.mdSave it as .claude/skills/product-quality-analysis/SKILL.md (or your agent's skills folder).
name
product-quality-analysis
description
Product quality metrics, SonarCloud analysis, technical debt management, code quality gates
license
Apache-2.0

Product Quality Analysis Skill

Purpose

This skill provides guidance for measuring, monitoring, and improving product quality in the CIA platform using SonarCloud analysis, code quality gates, technical debt management, and quality metrics. It ensures the political intelligence platform maintains high reliability and maintainability.

When to Use This Skill

Apply this skill when:

  • ✅ Reviewing SonarCloud analysis results
  • ✅ Assessing technical debt before or after changes
  • ✅ Configuring quality gates for CI/CD pipelines
  • ✅ Prioritizing refactoring efforts
  • ✅ Measuring code quality trends over time
  • ✅ Evaluating pull request quality impact
  • ✅ Planning quality improvement sprints

Do NOT use for:

  • ❌ Security vulnerability analysis (use secure-code-review skill)
  • ❌ Performance benchmarking (use performance-optimization skill)
  • ❌ UI/UX quality assessment (use ui-ux-design-system skill)

Quality Gates

CIA Platform Quality Gate Configuration
Quality Gate: CIA Platform Standard
│
├─ NEW CODE (changes since last version)
│  ├─ Coverage ≥ 80% on new code
│  ├─ Duplicated lines ≤ 3%
│  ├─ Maintainability rating = A
│  ├─ Reliability rating = A
│  ├─ Security rating = A
│  ├─ Security hotspots reviewed = 100%
│  └─ No new blocker or critical issues
│
└─ OVERALL CODE
   ├─ Coverage ≥ 70% (target: 80%)
   ├─ Duplicated lines ≤ 5%
   ├─ Technical debt ratio ≤ 5%
   ├─ Maintainability rating ≥ B
   ├─ Reliability rating ≥ B
   └─ Security rating ≥ B
Quality Gate Decision Flow
Pull Request Quality Check
│
├─→ SonarCloud analysis passes?
│   ├─ YES → Continue
│   └─ NO → Block merge, fix issues
│
├─→ Code coverage meets threshold?
│   ├─ YES → Continue
│   └─ NO → Add missing tests
│
├─→ No new critical/blocker issues?
│   ├─ YES → Continue
│   └─ NO → Fix before merge
│
├─→ Security hotspots reviewed?
│   ├─ YES → Continue
│   └─ NO → Review and classify
│
└─→ Approve PR for merge

SonarCloud Metrics

Key Metrics for CIA Platform
MetricDescriptionTargetAction if Below
BugsReliability issues0 newFix before merge
VulnerabilitiesSecurity flaws0 newFix immediately
Code smellsMaintainability issuesA ratingRefactor in sprint
CoverageTest coverage %≥ 80% newAdd unit tests
DuplicationsCopy-paste code %≤ 3% newExtract shared code
ComplexityCyclomatic complexity< 10/methodDecompose methods
Cognitive complexityReadability measure< 15/methodSimplify logic
Technical debtEffort to fix issues< 5% ratioPlan debt sprints
Interpreting SonarCloud Results
SonarCloud Rating Scale:
  A = 0 issues (excellent)
  B = at least 1 minor issue
  C = at least 1 major issue
  D = at least 1 critical issue
  E = at least 1 blocker issue

CIA Platform Minimum: B for overall, A for new code

Technical Debt Management

Debt Classification
Technical Debt Categories
│
├─ DESIGN DEBT
│  ├─ Circular dependencies between modules
│  ├─ Missing abstraction layers
│  └─ Tight coupling between services
│
├─ CODE DEBT
│  ├─ Duplicated code across modules
│  ├─ Complex methods (high cyclomatic complexity)
│  ├─ Missing or outdated documentation
│  └─ Inconsistent naming conventions
│
├─ TEST DEBT
│  ├─ Missing unit tests for critical paths
│  ├─ Flaky integration tests
│  ├─ No E2E tests for user flows
│  └─ Low branch coverage in complex logic
│
└─ DEPENDENCY DEBT
   ├─ Outdated library versions
   ├─ Unused dependencies in POMs
   ├─ Known vulnerability in dependencies
   └─ License compatibility issues
Debt Prioritization Matrix
ImpactEffort: LowEffort: MediumEffort: High
HighFix immediatelyPlan for next sprintSchedule dedicated sprint
MediumFix during feature workAdd to backlogEvaluate ROI
LowBoy scout ruleTrack in backlogDefer
Debt Reduction Patterns
java
// ✅ Boy Scout Rule: Leave code cleaner than you found it
// When modifying a method, also:
// - Add missing tests
// - Fix adjacent code smells
// - Update outdated JavaDoc
// - Remove unused imports

// ✅ Extract Method for complex logic
// BEFORE: Method with cyclomatic complexity > 10
public String analyzeVotingPattern(List<Vote> votes) {
    // 50+ lines of complex logic
}

// AFTER: Decomposed into focused methods
public String analyzeVotingPattern(List<Vote> votes) {
    VoteStatistics stats = calculateStatistics(votes);
    String trend = identifyTrend(stats);
    return formatAnalysis(stats, trend);
}

Code Quality Patterns

Module Quality Standards
CIA Platform Module Quality Targets:
│
├─ model.* modules
│  ├─ Coverage: ≥ 70% (generated code excluded)
│  ├─ Complexity: Low (POJOs, entities)
│  └─ Focus: Correct JPA annotations, equals/hashCode
│
├─ service.* modules
│  ├─ Coverage: ≥ 85% (business logic)
│  ├─ Complexity: Medium (application logic)
│  └─ Focus: Transaction boundaries, error handling
│
├─ web-widgets module
│  ├─ Coverage: ≥ 75% (UI logic)
│  ├─ Complexity: Medium (view logic)
│  └─ Focus: Accessibility, responsive design
│
└─ citizen-intelligence-agency module
   ├─ Coverage: ≥ 80% (integration)
   ├─ Complexity: Low (configuration, wiring)
   └─ Focus: Security configuration, startup
Maven Quality Plugins
xml
<!-- JaCoCo coverage enforcement -->
<plugin>
    <groupId>org.jacoco</groupId>
    <artifactId>jacoco-maven-plugin</artifactId>
    <configuration>
        <rules>
            <rule>
                <element>BUNDLE</element>
                <limits>
                    <limit>
                        <counter>LINE</counter>
                        <value>COVEREDRATIO</value>
                        <minimum>0.80</minimum>
                    </limit>
                    <limit>
                        <counter>BRANCH</counter>
                        <value>COVEREDRATIO</value>
                        <minimum>0.70</minimum>
                    </limit>
                </limits>
            </rule>
        </rules>
    </configuration>
</plugin>

Quality Review Checklist

Per Pull Request
Code Quality Review:
□ SonarCloud quality gate passes
□ No new bugs or vulnerabilities
□ Code coverage ≥ 80% on new code
□ No duplicated blocks > 10 lines
□ Cyclomatic complexity < 10 per method
□ Cognitive complexity < 15 per method
□ JavaDoc on public APIs
□ Consistent naming conventions
□ No TODO/FIXME without linked issue
Per Release
Release Quality Assessment:
□ Overall coverage trending upward
□ Technical debt ratio ≤ 5%
□ Zero blocker or critical issues
□ All security hotspots reviewed
□ Dependency updates applied
□ Performance regression tests pass
□ E2E test suite passes

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/product-quality-analysis of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Product Quality Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Product Quality Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Product Quality Analysis this skillHack23/cia239—~1.9kAutomated safety check: PassApache-2.0
Systematic Code Refactoringluongnv89/claude-howto42k—~3kAutomated safety check: PassMIT
Constraint-Driven Developmentaddyosmani/agent-skills102k2 repos~5.2kAutomated safety check: PassMIT
Code Refactoring Workflowluongnv89/claude-howto42k—~3.1kAutomated safety check: PassMIT
Tech Debt Analyzerailabs-393/ai-labs-claude-skills4542 repos~3.9kAutomated safety check: PassMIT
FIXME Resolvertailcallhq/forgecode7.6k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Systematic Code Refactoring

    luongnv89/claude-howto

    Guides refactoring in phases based on Martin Fowler's method: research, test coverage check, planning and small tested steps, with your approval at each phase.

    42k GitHub stars~3k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Constraint-Driven Development

    addyosmani/agent-skills

    Records a project's quality bar in CONSTRAINTS.md and watches diffs for signs an agent quietly weakened it, such as suppressions, skipped tests or lowered thresholds.

    102k GitHub starsUsed in 2 repos~5.2k tokens
    DevelopmentAuto-check passed
  • Code Refactoring Workflow

    luongnv89/claude-howto

    Guides systematic, test-backed refactoring in the style of Martin Fowler, moving through research, planning and small incremental changes with your approval at each phase.

    42k GitHub stars~3.1k tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Tech Debt Analyzer

    ailabs-393/ai-labs-claude-skills

    This skill should be used when analyzing technical debt in a codebase, documenting code quality issues, creating technical debt registers, or assessing code maintainability.

    454 GitHub starsUsed in 2 repos~3.9k tokens
    DevelopmentAuto-check passed
  • FIXME Resolver

    tailcallhq/forgecode

    Finds every FIXME comment in a codebase, groups related ones across files into one task, implements the work they describe and removes the comments once it is done.

    7.6k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Desloppify

    Git-on-my-level/codex-autorunner

    Codebase health scanner and technical debt tracker. An agent skill from Git-on-my-level/codex-autorunner.

    875 GitHub stars~3.4k tokensUpdated 6 days ago
    DevelopmentAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Product Quality Analysis

What does Product Quality Analysis do?

Product quality metrics, SonarCloud analysis, technical debt management, code quality gates. Product Quality Analysis is an agent skill from Hack23/cia.

When should I use Product Quality Analysis?

Product Quality Analysis fits situations like: tasks that involve Technical debt; tasks that involve Code quality; tasks that involve Quality gates.

How do I install Product Quality Analysis in Claude Code?

Run `npx skills add Hack23/cia --skill product-quality-analysis -a claude-code`. Or copy the skill folder (.github/skills/product-quality-analysis in Hack23/cia) into .claude/skills/product-quality-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Product Quality Analysis in Codex?

Run `npx skills add Hack23/cia --skill product-quality-analysis -a codex`. Or copy the skill folder (.github/skills/product-quality-analysis in Hack23/cia) into .agents/skills/product-quality-analysis in your project. Codex loads it when a task matches its description.

Can I use Product Quality Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill product-quality-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/product-quality-analysis, .gemini/skills/product-quality-analysis, .github/skills/product-quality-analysis and .opencode/skills/product-quality-analysis in your project.

What does Product Quality Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Product Quality Analysis is instructions for the agent only.

Does Product Quality Analysis access the network?

SKILL.md names 4 domains. As links in the text: docs.sonarcloud.io, jacoco.org, oreilly.com and github.com. This is read from the text; nothing was executed.

Is Product Quality Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Product Quality Analysis use?

Product Quality Analysis is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Product Quality Analysis use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Product Quality Analysis?

Skills that share tags, products or a category with Product Quality Analysis: Systematic Code Refactoring (luongnv89/claude-howto, 42k stars), Constraint-Driven Development (addyosmani/agent-skills, 102k stars), Code Refactoring Workflow (luongnv89/claude-howto, 42k stars) and Tech Debt Analyzer (ailabs-393/ai-labs-claude-skills, 454 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Product Quality Analysis?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.