对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。

No licenceAuto-check passedDatabases

Install Do Analyze

skills CLI
$ npx skills add jar-analyzer/jar-analyzer-claude --skill do-analyze -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jar-analyzer/jar-analyzer-claude do-analyze --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jar-analyzer/jar-analyzer-claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/jar-analyzer-plugin/skills/do-analyze .claude/skills/do-analyze && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
do-analyze
GitHub stars
140
Token cost
~2.5k tokens
SKILL.md length
287 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
None found

At a glance

对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。

  • Works in 10 steps: 项目概览 — 了解分析目标的基本信息 → 方法调用搜索 — 查找谁调用了某个方法 → 方法定义搜索 — 查找某个方法定义在哪里 → …
  • Tasks that involve Security review
  • SKILL.md covers 概述, 前提条件, 数据库表结构 and 重要约定, plus 3 more sections
  • Calls sqlite3 and java

What it does

Do Analyze is an agent skill from jar-analyzer/jar-analyzer-claude. 对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases, covering Security review. It works with SQLite and SQL. The repository describes itself as: Claude Code plugin for Java JAR security audit — 基于 jar-analyzer 的 Claude Code 安全审计插件,构建数据库,AI 深入分析.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/do-analyze”

Requirements

  • Python 3

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. 项目概览 — 了解分析目标的基本信息
  2. 方法调用搜索 — 查找谁调用了某个方法
  3. 方法定义搜索 — 查找某个方法定义在哪里
  4. 反向调用链追踪 — 从 sink 回溯到 entry
  5. Spring 入口分析
  6. Java Web 组件分析
  7. 字符串搜索 — 敏感信息检测
  8. 继承关系分析
  9. 注解分析
  10. 漏洞 Sink 检测

What it can do on your machine

Read from SKILL.md and the folder at commit 6bd7845. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sqlite3
    • java

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Do Analyze loads about 2.5k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 287 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 287 words (~2,451 tokens).

“在 build-db skill 构建好 jar-analyzer.db 后,使用本 skill 对数据库进行各类安全分析查询。 通过 SQL 查询 + 反编译验证的方式,实现方法调用搜索、调用链追踪、漏洞模式检测等功能。”

— opening of SKILL.md by jar-analyzer
name
do-analyze

Read the full SKILL.md on GitHub

Files

Just SKILL.md in plugins/jar-analyzer-plugin/skills/do-analyze of jar-analyzer/jar-analyzer-claude.

Open the folder on GitHubat commit 6bd7845

Compare with similar skills

Do Analyze next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Do Analyze compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Do Analyze this skilljar-analyzer/jar-analyzer-claude140—~2.5kAutomated safety check: PassNone
SQL Database Support for pRESTprest/prest4.6k—~1.6kAutomated safety check: PassMIT
Cursor BYOK Database Schemaleookun/cursor-byok3.2k—~1.3kAutomated safety check: PassMIT
Squixeduardofuncao/squix273—~784Automated safety check: PassMIT
Drizzle Migrationsbretzel-app/crumbs1271 repos~2.6kAutomated safety check: PassMIT
Golang Databaseunxed/f42402 repos~2.9kAutomated safety check: PassMIT

Similar skills

  • Guides classifying, gap-analyzing and scaffolding support for a new SQL database in pREST, from Postgres-compatible variants to entirely new dialects.

    4.6k GitHub stars~1.6k tokensUpdated 2 days ago
    DatabasesAuto-check passed
  • Cursor BYOK Database Schema

    leookun/cursor-byok

    Guides SQLite schema changes in the Cursor BYOK server, keeping SQLx migrations, the Rust store, API contracts and fixtures aligned.

    3.2k GitHub stars~1.3k tokensUpdated 9 days ago
    DatabasesAuto-check passed
  • Squix

    eduardofuncao/squix

    Run SQL queries across databases (Postgres, MySQL, SQLite, etc.) via the squix CLI.

    273 GitHub stars~784 tokensUpdated 15 days ago
    DatabasesAuto-check passed
  • Drizzle Migrations

    bretzel-app/crumbs

    Drizzle ORM schema management and SQLite migrations — adding tables, modifying columns, creating indexes, generating and running migrations, Drizzle query patterns.

    127 GitHub starsUsed in 1 repo~2.6k tokens
    DatabasesAuto-check passed
  • Comprehensive guide for Go database access — parameterized queries, struct scanning, NULLable columns, transactions, isolation levels, SELECT FOR UPDATE, connection pool, batch processing, context…

    240 GitHub starsUsed in 2 repos~2.9k tokens
    DatabasesAuto-check passed
  • Import Export

    AHS12/thoth-blueprint

    Change SQL, SQLite worker, DBML, JSON, Mermaid, SVG, or database export/import flows while preserving diagram semantics and round trips.

    626 GitHub stars~499 tokensUpdated 1 mo ago
    DatabasesAuto-check passed

More from jar-analyzer/jar-analyzer-claude

  • Build DB

    jar-analyzer/jar-analyzer-claude

    使用 jar-analyzer-engine 从 JAR/WAR/Class 文件构建 SQLite 分析数据库。这是进行 Java 代码安全审计、方法调用分析的第一步。

    140 GitHub stars~898 tokensUpdated 6 mo ago
    Auto-check passed

Works with

Questions about Do Analyze

What does Do Analyze do?

对 jar-analyzer-engine 构建的 SQLite 数据库执行安全审计分析查询。支持方法调用搜索、调用链追踪、Spring 组件分析、字符串搜索、漏洞模式检测等。. Do Analyze is an agent skill from jar-analyzer/jar-analyzer-claude.

When should I use Do Analyze?

Do Analyze fits situations like: tasks that involve Security review.

How do I install Do Analyze in Claude Code?

Run `npx skills add jar-analyzer/jar-analyzer-claude --skill do-analyze -a claude-code`. Or copy the skill folder (plugins/jar-analyzer-plugin/skills/do-analyze in jar-analyzer/jar-analyzer-claude) into .claude/skills/do-analyze in your project. Claude Code loads it when a task matches its description.

How do I install Do Analyze in Codex?

Run `npx skills add jar-analyzer/jar-analyzer-claude --skill do-analyze -a codex`. Or copy the skill folder (plugins/jar-analyzer-plugin/skills/do-analyze in jar-analyzer/jar-analyzer-claude) into .agents/skills/do-analyze in your project. Codex loads it when a task matches its description.

Can I use Do Analyze in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jar-analyzer/jar-analyzer-claude --skill do-analyze -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/do-analyze, .gemini/skills/do-analyze, .github/skills/do-analyze and .opencode/skills/do-analyze in your project.

What does Do Analyze need to run?

Going by SKILL.md and its folder, Do Analyze needs the command-line tools its instructions call (sqlite3 and java). Our summary lists: Python 3.

Does Do Analyze access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Do Analyze safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Do Analyze use?

No licence was found for Do Analyze or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Do Analyze use?

About 2.5k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Do Analyze?

Skills that share tags, products or a category with Do Analyze: SQL Database Support for pREST (prest/prest, 4.6k stars), Cursor BYOK Database Schema (leookun/cursor-byok, 3.2k stars), Squix (eduardofuncao/squix, 273 stars) and Drizzle Migrations (bretzel-app/crumbs, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Do Analyze?

jar-analyzer (a GitHub organization) maintains it in jar-analyzer/jar-analyzer-claude, which has 140 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on March 20, 2026.

Source: jar-analyzer/jar-analyzer-claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.