Agent skill

Code Analysis

by managedcode in managedcode/dotnet-skills

Use the free built-in .NET SDK analyzers and analysis levels with gradual Roslyn warning promotion.

MITAuto-check passedAgent Workflows

Install Code Analysis

skills CLI
$ npx skills add managedcode/dotnet-skills --skill code-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install managedcode/dotnet-skills code-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/managedcode/dotnet-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/Tools/Code-Analysis/skills/code-analysis .claude/skills/code-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-analysis
GitHub stars
486
Token cost
~2.1k tokens
SKILL.md length
898 words
Files
5 (incl. references)
Skills in repo
81
Repo updated
First seen
Licence
MIT

At a glance

Use the free built-in .NET SDK analyzers and analysis levels with gradual Roslyn warning promotion.

  • Works in 4 steps: Trivial Hygiene (start here) → Code Quality (ask user which categories) → Security (always promote early) → …
  • : the repo wants first-party .NET analyzers
  • SKILL.md covers Diagnostic Output Budget, Trigger On, Do Not Use For and Inputs, plus 9 more sections
  • Calls dotnet and rg

What it does

Code Analysis is an agent skill from managedcode/dotnet-skills. Use the free built-in .NET SDK analyzers and analysis levels with gradual Roslyn warning promotion. USE FOR: the repo wants first-party .NET analyzers; CI should fail on analyzer warnings; the team needs AnalysisLevel or AnalysisMode guidance. DO NOT USE FOR: third-party analyzer selection by itself; formatting-only work. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `manifest.json`, `references/code-analysis.md` and `references/config.md`). Compatibility notes: Requires a .NET SDK-based repository; respects the repo's AGENTS.md commands first.

It sits in Agent Workflows, covering Codebase knowledge for agents. It works with .NET. The repository describes itself as: Installable .NET skill catalog and CLI for Codex, Claude Code, GitHub Copilot, and Gemini. The licence is MIT.

When your agent uses it

  • : the repo wants first-party .NET analyzers
  • CI should fail on analyzer warnings
  • The team needs AnalysisLevel
  • AnalysisMode guidance

Example prompts

  • “/code-analysis”

Requirements

  • Compatibility (from SKILL.md): Requires a .NET SDK-based repository; respects the repo's `AGENTS.md` commands first.

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Trivial Hygiene (start here)
  2. Code Quality (ask user which categories)
  3. Security (always promote early)
  4. Full Coverage

What it can do on your machine

Read from SKILL.md and the folder at commit 535dd55. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet
    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a .NET SDK-based repository; respects the repo's `AGENTS.md` commands first.

    From compatibility in the SKILL.md frontmatter.

Context cost

Code Analysis loads about 2.1k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 898 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from managedcode/dotnet-skills at commit 535dd55, republished under its MIT licence (© managedcode). 898 words, ~2,136 tokens.

Download SKILL.mdSave it as .claude/skills/code-analysis/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
code-analysis
description
Use the free built-in .NET SDK analyzers and analysis levels with gradual Roslyn warning promotion. USE FOR: the repo wants first-party .NET analyzers; CI should fail on analyzer warnings; the team needs AnalysisLevel or AnalysisMode guidance. DO NOT USE FOR: third-party analyzer selection by itself; formatting-only work. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
compatibility
Requires a .NET SDK-based repository; respects the repo's `AGENTS.md` commands first.

.NET Code Analysis

Diagnostic Output Budget

Keep warnings/errors and a concise result; avoid routine verbose or diagnostic console output. Preserve native progress/ANSI when running tests. On failure, show only the relevant diagnostic and stack frames, deduplicated and capped at 80 lines / 8 KiB per response. Collect extra diagnostics only for an unresolved problem in size-bounded artifacts outside model context; link them and inspect exact bounded excerpts. Never dump full logs/reports or hide the command exit code through filtering.

Trigger On

  • the repo wants first-party .NET analyzers
  • CI should fail on analyzer warnings
  • the team needs AnalysisLevel or AnalysisMode guidance
  • the repo needs a gradual Roslyn warning promotion strategy

Do Not Use For

  • third-party analyzer selection by itself
  • formatting-only work

Inputs

  • the nearest AGENTS.md
  • project files or Directory.Build.props
  • current analyzer severity policy

Hard Rules for AI Agents

Non-negotiable. Violating these undermines the user's explicit intent.

  1. Never disable or remove TreatWarningsAsErrors or WarningsAsErrors if the project has set them. Do not comment them out, set to false, wrap in a condition, or add <TreatWarningsAsErrors>false</TreatWarningsAsErrors> to make the build pass.
  2. Never add <NoWarn> or #pragma warning disable for warnings the user chose to treat as errors, unless the user explicitly approves the suppression.
  3. Never silently downgrade severity in .editorconfig (e.g. error to warning or none) to make a build succeed.
  4. If warnings-as-errors breaks the build — fix the code. If the fix is too large, ask the user whether to defer that warning ID.
  5. If warning volume is too large to fix in one pass — report count and categories to the user and ask which to tackle first. Do not unilaterally disable the policy.

Workflow

mermaid
flowchart TD
    A[Start] --> B{New or legacy project?}
    B -->|New| C[TreatWarningsAsErrors=true immediately]
    B -->|Legacy| D[dotnet build, count warnings by ID]
    D --> E{"< 30 warnings?"}
    E -->|Yes| F[Fix all, then enable TreatWarningsAsErrors]
    E -->|No| G[Report counts to user, ask which batch first]
    G --> H[Add selected IDs to WarningsAsErrors]
    H --> I[Fix that batch, verify build]
    I --> J{More batches?}
    J -->|Yes| G
    J -->|No| F
    C --> K[Set AnalysisLevel latest-recommended]
    F --> K
    K --> L[Promote security CA3xxx/CA5xxx to error in .editorconfig]
    L --> M[Validate: build + CI green]
  1. Start with SDK analyzers before third-party packages.
  2. Detect project maturity: new or existing/legacy.
  3. Enable EnableNETAnalyzers, AnalysisLevel, AnalysisMode in Directory.Build.props.
  4. Apply the right warning promotion strategy (see below).
  5. Per-rule severity goes in repo-root .editorconfig.
  6. dotnet build is the analyzer gate in CI.

Warning Promotion Strategy

New Projects

Set these in Directory.Build.props immediately:

  • TreatWarningsAsErrors = true
  • AnalysisLevel = latest-recommended
  • Security category = error in .editorconfig

Fix all warnings before merging.

Legacy Projects — Gradual Promotion

Blanket TreatWarningsAsErrors on a legacy codebase produces hundreds/thousands of errors. An agent cannot fix them all at once — context floods, fix quality drops. Promote in batches.

Phase 1: Trivial Hygiene (start here)

Mechanical fixes, lowest effort:

  • CS8019 — unnecessary using directive (remove it)
  • CS0219 — variable assigned but never used (remove it)
  • CS0168 — variable declared but never used (remove it)
  • CS1591 — missing XML comment for public member (add comment or disable for internal code)
  • CS0612 — obsolete member used, no message (replace with non-obsolete API)
  • CS0618 — obsolete member used, with message (follow migration guidance)

Add to WarningsAsErrors: CS8019;CS0219;CS0168. Fix all, then Phase 2.

Phase 2: Code Quality (ask user which categories)
  • CA2000 — dispose objects before losing scope (Reliability)
  • CA1062 — validate public method arguments (Design)
  • CA1822 — mark members as static (Performance)
  • CA1860 — avoid Enumerable.Any() for length check (Performance)
  • CA1861 — avoid constant arrays as arguments (Performance)
  • CA2007 — consider calling ConfigureAwait (Reliability)
  • CS8600–CS8610 — nullable reference type warnings (Nullability)

Ask: "Which categories next — Nullability, Performance, or Reliability?" Add selected IDs to WarningsAsErrors, fix, repeat.

Phase 3: Security (always promote early)

Set in .editorconfig regardless of project maturity:

editorconfig
[*.cs]
dotnet_analyzer_diagnostic.category-Security.severity = error

Covers CA3001 (SQL injection), CA3002 (XSS), CA3003 (path injection), CA3075 (insecure DTD), CA5350/CA5351 (weak crypto), CA5394 (insecure randomness).

Show full SKILL.md (349 more words)Show less
Phase 4: Full Coverage

Once all batches pass, transition to:

xml
<TreatWarningsAsErrors>true</TreatWarningsAsErrors>
<WarningsNotAsErrors>CA1707</WarningsNotAsErrors> <!-- explicit exceptions only -->
Interaction Protocol (legacy codebases)
  1. Run dotnet build, count warnings by ID.
  2. Report summary: "Found 47 CS8019, 23 CA1822, 12 CA2000, 8 CS8600."
  3. Ask which batch to tackle. Recommend starting with Phase 1.
  4. Fix selected batch, verify build.
  5. Add those IDs to WarningsAsErrors.
  6. Report back, ask about next batch.

Never skip the ask step. The user decides the pace.

Bootstrap When Missing

  1. Detect current state:
    • dotnet --info
    • rg -n "EnableNETAnalyzers|AnalysisLevel|AnalysisMode|TreatWarningsAsErrors|WarningsAsErrors" -g '*.csproj' -g 'Directory.Build.*' .
    • dotnet build SOLUTION_OR_PROJECT 2>&1 — count warnings by ID
  2. Classify: new (few/zero warnings) vs legacy (many warnings).
  3. Enable EnableNETAnalyzers, AnalysisLevel, AnalysisMode in MSBuild config.
  4. Apply promotion strategy matching project maturity.
  5. Per-rule severity in repo-root .editorconfig.
  6. Run dotnet build, return status: configured or status: improved.
  7. If repo defers analyzer policy to another build layer, return status: not_applicable.

Deliver

  • explicit, reviewable first-party analyzer policy
  • build-time analyzer execution for CI
  • warning promotion plan matching project maturity

Validate

  • analyzer behavior driven by repo config, not IDE defaults
  • CI reproduces same warnings/errors locally
  • no TreatWarningsAsErrors, WarningsAsErrors, or severity settings removed/weakened without user approval
  • promoted warnings produce build errors, not just IDE hints

Ralph Loop

  1. Plan: analyze state, define target, constraints, risks, execution plan, validation steps.
  2. Execute one step, produce concrete delta.
  3. Review result, capture findings.
  4. Apply fixes in small batches, rerun checks.
  5. Update plan after each iteration.
  6. Repeat until acceptable or only explicit exceptions remain.
  7. Missing dependency: bootstrap or return status: not_applicable.
Required Result Format
  • status: complete | clean | improved | configured | not_applicable | blocked
  • plan: concise plan and current step
  • actions_taken: concrete changes
  • validation_skills: final skills run or skipped with reasons
  • verification: commands, checks, or review evidence
  • remaining: unresolved items or none

Load References

Example Requests

  • "Turn on built-in .NET analyzers."
  • "Make analyzer warnings fail the build."
  • "Set the right AnalysisLevel for this repo."
  • "Start treating unused usings and unused variables as errors."
  • "Help me gradually promote Roslyn warnings in my legacy project."
  • "Which warnings should I promote to errors next?"

© managedcode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in catalog/Tools/Code-Analysis/skills/code-analysis of managedcode/dotnet-skills.

  • SKILL.md
  • manifest.json
  • references/code-analysis.md
  • references/config.md
  • references/rules.md

Open the folder on GitHubat commit 535dd55

Compare with similar skills

Code Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Analysis this skillmanagedcode/dotnet-skills486—~2.1kAutomated safety check: PassMIT
ccc Semantic Code Searchcocoindex-io/cocoindex-code2.7k—~938Automated safety check: PassApache-2.0
Repomix Codebase Packeryamadashy/repomix29k—~1.3kAutomated safety check: NotesMIT
Codebase Handbook BuilderRuhan-Wang/Harness_Handbook331—~2.2kAutomated safety check: PassApache-2.0
CodemapJordanCoin/codemap704—~1.8kAutomated safety check: PassMIT
MCP Code Search Tool SelectionContext-Engine-AI/Context-Engine402—~1.3kAutomated safety check: PassMIT

Similar skills

  • ccc Semantic Code Search

    cocoindex-io/cocoindex-code

    Semantic code search and index management with the ccc CLI: the agent initializes, indexes and queries the project by concept, filtering by language or path.

    2.7k GitHub stars~938 tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Repomix Codebase Packer

    yamadashy/repomix

    Packs a local directory or remote GitHub repository into one AI-friendly file with Repomix, then searches it to explore structure, find patterns and count tokens.

    29k GitHub stars~1.3k tokensUpdated 3 days ago
    Agent WorkflowsAuto-check: notes
  • Codebase Handbook Builder

    Ruhan-Wang/Harness_Handbook

    Generates, refreshes, validates and uses a compact handbook that maps where a change touches in a repository, using the active Codex session and no external LLM API.

    331 GitHub stars~2.2k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Codemap

    JordanCoin/codemap

    Gives an agent a quick map of a codebase's structure, dependencies, changes and handoffs, and tunes per-project config so the output stays code-first.

    704 GitHub stars~1.8k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • MCP Code Search Tool Selection

    Context-Engine-AI/Context-Engine

    Rules for choosing Qdrant-Indexer semantic search over grep or file reads when exploring code, debugging or asking where and why questions.

    402 GitHub stars~1.3k tokensUpdated 3 mo ago
    Agent WorkflowsAuto-check passed
  • Repo Context Ledger

    gviiisen/repo-context-ledger

    Record every behavior-changing feature addition, fix, and adjustment as durable, evidence-based repository knowledge, then use that ledger to continue accurately across AI windows, tools, Git…

    105 GitHub stars~2.8k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed

More from managedcode/dotnet-skills

All 81 skills in this repo
  • Analyzer Config

    managedcode/dotnet-skills

    Use a repo-root .editorconfig to configure free .NET analyzer and style rules.

    486 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Archunitnet

    managedcode/dotnet-skills

    Use the open-source free ArchUnitNET library for architecture rules in .NET tests.

    486 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Aspire

    managedcode/dotnet-skills

    Build, upgrade, and operate Aspire 13.5.x C or TypeScript application hosts with the current CLI, AppHost, ServiceDefaults, integrations, dashboard, testing, MCP, and deployment patterns for…

    486 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Aspnet Core

    managedcode/dotnet-skills

    Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET.

    486 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Asynkron Profiler

    managedcode/dotnet-skills

    Use the open-source free Asynkron.Profiler dotnet tool for CLI-first CPU, allocation, exception, contention, and heap profiling of .NET commands or existing trace artifacts.

    486 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Azure Functions

    managedcode/dotnet-skills

    Build, review, or migrate Azure Functions in .NET with correct execution model, isolated worker setup, bindings, DI, and Durable Functions patterns.

    486 GitHub stars~2.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Code Analysis

What does Code Analysis do?

Use the free built-in .NET SDK analyzers and analysis levels with gradual Roslyn warning promotion. Code Analysis is an agent skill from managedcode/dotnet-skills.NET SDK analyzers and analysis levels with gradual Roslyn warning promotion.

When should I use Code Analysis?

Code Analysis fits situations like: : the repo wants first-party .NET analyzers; CI should fail on analyzer warnings; the team needs AnalysisLevel; analysisMode guidance.

How do I install Code Analysis in Claude Code?

Run `npx skills add managedcode/dotnet-skills --skill code-analysis -a claude-code`. Or copy the skill folder (catalog/Tools/Code-Analysis/skills/code-analysis in managedcode/dotnet-skills) into .claude/skills/code-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Code Analysis in Codex?

Run `npx skills add managedcode/dotnet-skills --skill code-analysis -a codex`. Or copy the skill folder (catalog/Tools/Code-Analysis/skills/code-analysis in managedcode/dotnet-skills) into .agents/skills/code-analysis in your project. Codex loads it when a task matches its description.

Can I use Code Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add managedcode/dotnet-skills --skill code-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-analysis, .gemini/skills/code-analysis, .github/skills/code-analysis and .opencode/skills/code-analysis in your project.

What does Code Analysis need to run?

Going by SKILL.md and its folder, Code Analysis needs the command-line tools its instructions call (dotnet and rg). Compatibility (from SKILL.md): Requires a .NET SDK-based repository; respects the repo's `AGENTS.md` commands first..

Does Code Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Analysis use?

Code Analysis is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Analysis use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.

What are the alternatives to Code Analysis?

Skills that share tags, products or a category with Code Analysis: ccc Semantic Code Search (cocoindex-io/cocoindex-code, 2.7k stars), Repomix Codebase Packer (yamadashy/repomix, 29k stars), Codebase Handbook Builder (Ruhan-Wang/Harness_Handbook, 331 stars) and Codemap (JordanCoin/codemap, 704 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Analysis?

managedcode (a GitHub organization) maintains it in managedcode/dotnet-skills, which has 486 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 7, 2026.

Source: managedcode/dotnet-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.