Agent skill

Triage Codacy

by netdata in netdata/netdata

Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

GPL-3.0Auto-check: notesDevOps & Cloud

Install Triage Codacy

skills CLI
$ npx skills add netdata/netdata --skill triage-codacy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install netdata/netdata triage-codacy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/triage-codacy .claude/skills/triage-codacy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triage-codacy
GitHub stars
81k
Token cost
~2.2k tokens
SKILL.md length
1,022 words
Files
10 (incl. scripts)
Skills in repo
27
Repo updated
First seen
Licence
GPL-3.0

At a glance

Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

  • Codacy CI failures
  • SKILL.md covers MANDATORY -- keep this skill…, MANDATORY -- live how-tos…, Scope and Required env keys, plus 6 more sections
  • Runs Shell and Python scripts from its folder; calls curl and python3; reaches api.codacy.com; needs CODACY_TOKEN
  • Codacy-analysis-cli

What it does

Triage Codacy is an agent skill from netdata/netdata. Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers. Use for Codacy CI failures, codacy-analysis-cli, PR issue queries, and markdownlint findings. Supplied evidence and source review need no credentials; live queries and local analysis are separate routes. Writes require user authorization.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts (for example `how-tos/INDEX.md`, `how-tos/fetch-large-pr-issue-list.md` and `how-tos/handle-malformed-local-json.md`).

It sits in DevOps & Cloud, covering Failing and flaky tests. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.

When your agent uses it

  • Codacy CI failures
  • Codacy-analysis-cli
  • PR issue queries
  • Markdownlint findings

Example prompts

  • “/triage-codacy”

Requirements

  • Python 3
  • A Bash shell
  • Docker
  • A credential in CODACY_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 2c378f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.codacy.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CODACY_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triage Codacy loads about 2.2k tokens when it runs. Until then it costs about 86 tokens; SKILL.md has 1,022 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~86
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:13
    `scripts/analyze-local.sh`; no token or `.env` needed; select the relevant tool/scope |
  • NoteMentions a .env fileSKILL.md:62
    nly (`analyze-local.sh` does not source `.env`): `CODACY_CLI_VERSION=1.2.3 analyze-local.sh` pins the docker image tag;
  • NoteMentions a .env fileSKILL.md:66
    ept `CODACY_CLI_VERSION` live in `<repo>/.env` (gitignored). See `<repo>/.agents/ENV.md` for setup (where
  • NoteMentions a .env fileSKILL.md:161
    wrappers, run the offline self-test (no `.env` or token setup):

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from netdata/netdata at commit 2c378f0, republished under its GPL-3.0 licence (© netdata). 1,022 words, ~2,241 tokens.

Download SKILL.mdSave it as .claude/skills/triage-codacy/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
triage-codacy
description
Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers. Use for Codacy CI failures, codacy-analysis-cli, PR issue queries, and markdownlint findings. Supplied evidence and source review need no credentials; live queries and local analysis are separate routes. Writes require user authorization.

Codacy audit skill

Use the operation and available evidence to choose a route:

TaskRoute
Review supplied findings or helper changesInspect that evidence and affected helper contracts; no credentials, API fetch or analyzer run solely because this skill loaded
Run local analysisscripts/analyze-local.sh; no token or .env needed; select the relevant tool/scope
Fetch current PR issuesscripts/pr-issues.sh; configured token required by this script; preserve the response and its commit provenance
Diagnose a known CLI/API problemSelect the relevant recipe from ./how-tos/INDEX.md
Validate wrapper changesRun the offline self-test and python3 -B .agents/skills/triage-codacy/tests/test_helpers.py

Loading this skill does not authorize fixes, pushes, remote issue transitions or analysis-policy changes.

This skill is the fourth in the static-analysis triage family in this repo: triage-coverity/, triage-sonarqube/, triage-codeql/, triage-codacy/ share one shape and one set of conventions; each keeps its own .local/audits/<dir>/ (root AGENTS.md, Local-Only Working Directory).

MANDATORY -- keep this skill alive

Capture timing and authorization for operational discoveries follow AGENTS.md#knowledge-capture.

Examples worth capturing:

  • New v3 API endpoint or response-shape detail learned the hard way
  • Codacy-side rate-limit signals
  • A pattern Codacy mismodels for this codebase (so the next assistant can add a path exclusion or mark it FP)
  • A new tool the local CLI gained / lost
  • Auth-failure surface (e.g. token type mismatch, expired token signs)

MANDATORY -- live how-tos catalog

AGENTS.md#knowledge-capture governs this catalog. Authorized Codacy recipes live under how-tos/ and are listed in ./how-tos/INDEX.md.

Scope

In scope:

  • Local pre-push analysis via codacy-analysis-cli (auto-detects local binary, falls back to docker).
  • Read-only PR-issue queries against the v3 API.
  • Token-safe wrappers (sentinel-driven no-leak self-test).

The following need a user-authorized task and applicable project tracking. A GitHub issue or SOW alone is not permission to perform them:

  • Write actions (mark issue as false-positive, mark as fixed, modify ignore-patterns).
  • Repository-wide backlog triage beyond the selected PR or findings.
  • Cross-repo aggregation across the netdata org.

Required env keys

KeyRequired for
CODACY_TOKENAccount API token, header api-token: <value>. Required by pr-issues.sh and any wrapper that calls _codacyaudit_run. NOT required by analyze-local.sh (the CLI runs anonymously).
CODACY_HOSTDefaults to https://api.codacy.com. Override only if Codacy moves the API host.
CODACY_PROVIDERDefaults to gh (GitHub).
CODACY_CLI_VERSIONOptional, not a secret, and read from the process environment only (analyze-local.sh does not source .env): CODACY_CLI_VERSION=1.2.3 analyze-local.sh pins the docker image tag; defaults to latest.
CODACY_ORGDefaults to netdata.
CODACY_REPODefaults to netdata.

All values except CODACY_CLI_VERSION live in <repo>/.env (gitignored). See <repo>/.agents/ENV.md for setup (where each value comes from, sample formats, common mistakes).

Scripts (in scripts/)

ScriptPurpose
_lib.shHelpers (codacyaudit_* prefix). Token-safe; ships codacyaudit_selftest_no_token_leak.
analyze-local.shRun codacy-analysis-cli locally; auto-pick local-binary or docker; write JSON dump under .local/audits/codacy/.
pr-issues.shFetch all Codacy issues for a PR via the v3 API; cluster summary on stdout; full JSON dump on disk.

Workflow -- pre-push prevention

$ .agents/skills/triage-codacy/scripts/analyze-local.sh
[analyze-local] runner=docker format=json dir=<repo>
[analyze-local] wrote 0 finding(s) to <repo>/.local/audits/codacy/local-<ts>.json

For an authorized push, use local analysis to catch relevant findings early. Zero findings establishes only the completed local run's result: CLI versions, selected tools/files and server-side configuration can differ. Check the remote gate for the current head before claiming it is green. Verify findings before applying authorized fixes.

Failed analyses are not clean trees: when the dump is not JSON, is JSON of the wrong shape (not a findings array, an {issues: [...]} object, or a SARIF runs document), or the CLI exits non-zero with zero findings, the script exits 4 and keeps the CLI's stderr in <dump>.log. Treat exit 4 as "no evidence", not as green. If GitHub check-run annotations are empty too, use pr-issues.sh with CODACY_TOKEN; without that token, record the evidence gap and re-check after the next push.

One common local cause is gitignored generated output with restrictive file permissions. For example, if local scratch output under .local/ contains files not readable by the Docker container, Codacy logs Could not read file messages and the saved .json dump is plain text. Fix or move the local generated output before trusting local analyzer output. Preserve unrelated files and permissions when correcting the local cause.

Show full SKILL.md (370 more words)Show less

A public Codacy v3 endpoint has exposed PR details without a token when GitHub annotations were empty. Availability is service-dependent; an authorization failure or unavailable response is an evidence gap, not an empty issue list:

curl -fsS \
  "https://api.codacy.com/api/v3/analysis/organizations/gh/netdata/repositories/netdata/pull-requests/<PR>/issues?limit=100"

Filter for .data[] | select(.deltaType == "Added") to inspect added issues, then verify relevance against the current head and gate; this filter alone does not establish which findings block it. Treat commitInfo fields as sensitive operational metadata; do not copy names or email addresses into committed artifacts.

Operational gotcha: Codacy's PR issue API can lag behind the GitHub check-run after a new push. If pr-issues.sh still reports findings but the Codacy check-run for the current head SHA is green, inspect .commitIssue.commitInfo.sha in the dump. Reverify older findings against the current source and current-head gate. An older anchor alone does not prove a finding is stale or resolved; the same defect may still exist.

To restrict to a single tool (matches what Codacy reported on a CI run):

sh
.agents/skills/triage-codacy/scripts/analyze-local.sh --tool markdownlint

Workflow -- PR triage

console
$ .agents/skills/triage-codacy/scripts/pr-issues.sh 22423
[pr-issues] fetching issues for PR #22423 ...
[pr-issues] wrote 0 issue(s) to <repo>/.local/audits/codacy/pr-22423-<ts>.json

No issues on PR #22423.

For a PR with findings, the script emits a clustered TSV summary. Default grouping is --by pattern; switch to --by tool, --by severity, --by file, or --by category for other angles. The JSON dump under .local/audits/codacy/ carries the full issue payload for follow-up jq queries.

Operational note: large Codacy PR issue arrays must be passed to jq via a temporary file and --slurpfile, not --argjson, because shell argument-size limits can fail before jq starts.

Path discipline

This skill follows <repo>/.agents/sensitive-data-discipline.md:

  • Repo files: repo-relative (<repo>/src/...).
  • Codacy account / org / repo identifiers: env-keyed.
  • CODACY_TOKEN: NEVER literal in any committed file; ALWAYS via ${CODACY_TOKEN} and the _lib.sh wrappers.
  • Audit dumps: gitignored under <repo>/.local/audits/codacy/.
  • .agents/skills/triage-coverity/ -- Coverity Scan (same triage shape).
  • .agents/skills/triage-sonarqube/ -- SonarCloud (same triage shape).
  • .agents/skills/triage-codeql/ -- GitHub Code Scanning / CodeQL (same triage shape).

Token-safe self-test

After changing wrappers, run the offline self-test (no .env or token setup):

console
$ source .agents/skills/triage-codacy/scripts/_lib.sh
$ codacyaudit_selftest_no_token_leak
PASS: codacyaudit_selftest_no_token_leak

The self-test uses synthetic configuration and an in-process transport in a subshell. It drives every public HTTP wrapper, checks success and both output streams, and preserves caller state. The focused tests also cover failure status and reflected-secret suppression. This checks local wrapper behavior, not live authentication or service compatibility. Successful API bodies are forwarded unchanged and may contain private data; review before sharing.

© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts) in .agents/skills/triage-codacy of netdata/netdata.

  • SKILL.md
  • how-tos/INDEX.md
  • how-tos/fetch-large-pr-issue-list.md
  • how-tos/handle-malformed-local-json.md
  • how-tos/reproduce-pr-22423-markdownlint.md
  • how-tos/triage-action-required-without-token.md
  • scripts/_lib.sh
  • scripts/analyze-local.sh
  • scripts/pr-issues.sh
  • tests/test_helpers.py

Open the folder on GitHubat commit 2c378f0

Compare with similar skills

Triage Codacy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triage Codacy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triage Codacy this skillnetdata/netdata81k—~2.2kAutomated safety check: NotesGPL-3.0
Azure Pipelines Log Downloaderansible/ansible71k—~825Automated safety check: PassGPL-3.0
CI Failure Triage and RepairChachamaru127/claude-code-harness3.2k1 repos~1.1kAutomated safety check: NotesMIT
CI Watchdoglatitude-dev/latitude-llm4.7k—~1.6kAutomated safety check: PassMIT
Megatron-LM CI Failure TriageNVIDIA/Megatron-LM18k—~1.6kAutomated safety check: PassApache-2.0
CI Triagefair-acc/gnuradio4115—~548Automated safety check: PassLGPL-3.0

Similar skills

  • Downloads Azure Pipelines CI logs for an Ansible pull request or build so the agent can analyze test failures, after asking you first.

    71k GitHub stars~825 tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI Failure Triage and Repair

    Chachamaru127/claude-code-harness

    Diagnoses failing CI pipelines and tests, deciding first whether the test or the implementation is at fault, and hands hard cases to a dedicated fixer subagent.

    3.2k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check: notes
  • CI Watchdog

    latitude-dev/latitude-llm

    Continuously monitor GitHub PR CI checks and automatically fix failures until all checks pass.

    4.7k GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Investigates a failing GitHub Actions run or job for Megatron-LM, finds the root cause plus the PR and test author involved, and files a structured bug issue.

    18k GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI Triage

    fair-acc/gnuradio4

    Fetch and classify a failed GitHub Actions job for this repo — distinguish out-of-memory kills, six-hour timeouts, configure errors and genuine test failures, and identify what was in flight.

    115 GitHub stars~548 tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI Failure Triage

    n1m21n/Infinite

    Diagnose a failed GitHub Actions run (Windows MSVC crash, Linux clang/sanitizer, link errors) from the logs in one pass, and fix every candidate at once instead of one CI round-trip at a time.

    264 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from netdata/netdata

All 27 skills in this repo
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Triage Agent Events

    netdata/netdata

    Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.

    81k GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Triage Coverity

    netdata/netdata

    Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

    81k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes
  • Create, review or validate Netdata Prometheus chart profiles, exporter dashboard design, collection policy and stock semantic proofs.

    81k GitHub stars~4.7k tokensUpdated today
    Auto-check passed

Questions about Triage Codacy

What does Triage Codacy do?

Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers. Triage Codacy is an agent skill from netdata/netdata. Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

When should I use Triage Codacy?

Triage Codacy fits situations like: codacy CI failures; codacy-analysis-cli; PR issue queries; markdownlint findings.

How do I install Triage Codacy in Claude Code?

Run `npx skills add netdata/netdata --skill triage-codacy -a claude-code`. Or copy the skill folder (.agents/skills/triage-codacy in netdata/netdata) into .claude/skills/triage-codacy in your project. Claude Code loads it when a task matches its description.

How do I install Triage Codacy in Codex?

Run `npx skills add netdata/netdata --skill triage-codacy -a codex`. Or copy the skill folder (.agents/skills/triage-codacy in netdata/netdata) into .agents/skills/triage-codacy in your project. Codex loads it when a task matches its description.

Can I use Triage Codacy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill triage-codacy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-codacy, .gemini/skills/triage-codacy, .github/skills/triage-codacy and .opencode/skills/triage-codacy in your project.

What does Triage Codacy need to run?

Going by SKILL.md and its folder, Triage Codacy needs a shell and Python for the scripts in its folder, the command-line tools its instructions call (curl and python3) and credentials named CODACY_TOKEN. Our summary lists: Python 3; A Bash shell; Docker; A credential in CODACY_TOKEN.

Does Triage Codacy access the network?

SKILL.md names 1 domain. In commands or code: api.codacy.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Triage Codacy safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Triage Codacy use?

Triage Codacy is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triage Codacy use?

About 2.2k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Triage Codacy?

Skills that share tags, products or a category with Triage Codacy: Azure Pipelines Log Downloader (ansible/ansible, 71k stars), CI Failure Triage and Repair (Chachamaru127/claude-code-harness, 3.2k stars), CI Watchdog (latitude-dev/latitude-llm, 4.7k stars) and Megatron-LM CI Failure Triage (NVIDIA/Megatron-LM, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triage Codacy?

netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,838 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 8, 2026.

Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.