Agent skill

Quality Attribute Analyzer

by revfactory in revfactory/harness-100

A specialized skill for systematically analyzing quality attributes in architecture decisions and quantifying tradeoffs.

Apache-2.0Auto-check passedSecurity

Install Quality Attribute Analyzer

skills CLI
$ npx skills add revfactory/harness-100 --skill quality-attribute-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 quality-attribute-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/62-adr-writer/.claude/skills/quality-attribute-analyzer .claude/skills/quality-attribute-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
quality-attribute-analyzer
GitHub stars
1.3k
Token cost
~1.2k tokens
SKILL.md length
230 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

A specialized skill for systematically analyzing quality attributes in architecture decisions and quantifying tradeoffs.

  • Tasks that involve Security review
  • SKILL.md covers Target Agent, Core Quality Attribute…, Quality Attribute Tradeoff… and Weighted Evaluation Matrix…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Quality Attribute Analyzer is an agent skill from revfactory/harness-100. A specialized skill for systematically analyzing quality attributes in architecture decisions and quantifying tradeoffs. Used by the tradeoff-evaluator agent when evaluating tradeoffs between quality attributes such as performance, scalability, and security. Automatically applied in contexts involving 'quality attributes,' 'QA analysis,' '-ility,' 'performance requirements,' 'scalability,' 'security,' or 'CAP theorem.' Note: actual performance test execution and security audits are outside the scope of this skill.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “quality attributes,”
  • “QA analysis,”
  • “-ility,”
  • “/quality-attribute-analyzer”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Quality Attribute Analyzer loads about 1.2k tokens when it runs. Until then it costs about 137 tokens; SKILL.md has 230 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~137
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 230 words, ~1,193 tokens.

Download SKILL.mdSave it as .claude/skills/quality-attribute-analyzer/SKILL.md (or your agent's skills folder).
name
quality-attribute-analyzer
description
A specialized skill for systematically analyzing quality attributes in architecture decisions and quantifying tradeoffs. Used by the tradeoff-evaluator agent when evaluating tradeoffs between quality attributes such as performance, scalability, and security. Automatically applied in contexts involving 'quality attributes,' 'QA analysis,' '-ility,' 'performance requirements,' 'scalability,' 'security,' or 'CAP theorem.' Note: actual performance test execution and security audits are outside the scope of this skill.

Quality Attribute Analyzer — Quality Attribute Analysis Tool

A specialized skill that enhances the tradeoff-evaluator agent's quality attribute analysis capabilities.

Target Agent

  • tradeoff-evaluator — Quality attribute weighted evaluation, risk-reward analysis

Core Quality Attribute (-ility) Dictionary

Runtime Quality Attributes
AttributeDefinitionMeasurement MetricsTypical Targets
PerformanceResponse time, throughputp50/p99 latency, TPSp99 < 200ms
ScalabilityAbility to handle increased loadLinear scaling capabilityLinear at 10x load
AvailabilitySystem uptimeUptime %, MTBF99.9% (Three 9s)
ReliabilityError-free operationFailure rate, MTTRMTTR < 30 min
SecurityProtection from threatsVulnerability count, breach incidentsOWASP Top 10 coverage
Development/Operations Quality Attributes
AttributeDefinitionMeasurement Metrics
MaintainabilityEase of modificationCode complexity, change lead time
TestabilityEase of writing testsCoverage, test execution time
DeployabilityDeployment frequency and safetyDeployment frequency, rollback time
ObservabilitySystem state visibilityLogs, metrics, tracing

Quality Attribute Tradeoff Matrix

Common Tradeoff Relationships
Attribute A (up)Attribute B (down)Reason
PerformanceMaintainabilityOptimized code becomes more complex
SecurityPerformance/UsabilityAuthentication/encryption overhead
ScalabilityConsistencyCAP theorem
AvailabilityConsistencyCAP theorem
FlexibilityPerformanceAbstraction layer overhead
CAP Theorem Decision Making
In distributed systems, only 2 of 3 can be guaranteed:
- Consistency
- Availability
- Partition tolerance

Practical choices:
+----------+----------+----------+
|    CP    |    AP    |    CA    |
| Consist. | Avail. + | Consist. |
| + Part.  | Part.    | + Avail. |
+----------+----------+----------+
| HBase    | Cassandra| Trad.    |
| MongoDB  | DynamoDB | RDBMS    |
| Redis    | CouchDB  | (single) |
+----------+----------+----------+

Weighted Evaluation Matrix (Weighted Scoring)

Evaluation Procedure
1. Set weights per quality attribute (totaling 100%)
2. Score each alternative 1-5 per attribute
3. Weighted score = Weight x Score
4. Rank alternatives by total score
Template
markdown
| Quality Attribute | Weight | Alt A | Wtd A | Alt B | Wtd B | Alt C | Wtd C |
|-------------------|--------|-------|-------|-------|-------|-------|-------|
| Performance | 25% | 4 | 1.00 | 3 | 0.75 | 5 | 1.25 |
| Scalability | 20% | 5 | 1.00 | 4 | 0.80 | 3 | 0.60 |
| Security | 20% | 3 | 0.60 | 4 | 0.80 | 4 | 0.80 |
| Maintainability | 15% | 2 | 0.30 | 4 | 0.60 | 3 | 0.45 |
| Cost | 10% | 3 | 0.30 | 5 | 0.50 | 2 | 0.20 |
| Learning Curve | 10% | 4 | 0.40 | 3 | 0.30 | 2 | 0.20 |
| **Total** | **100%** | | **3.60** | | **3.75** | | **3.50** |
Weight Determination Guidelines
Project TypePerformanceScalabilitySecurityMaintainabilityCost
Startup MVP10%15%10%25%25%
Fintech20%15%30%15%10%
Social Platform25%30%10%15%10%
Enterprise Internal System10%10%20%25%25%

Simplified ATAM (Architecture Tradeoff Analysis Method)

6-Step Analysis
1. Identify Architecture Drivers
   -> Core business goals + quality attribute scenarios

2. Create Utility Tree
   -> Quality attributes -> Sub-items -> Scenarios -> Priority (H/M/L)

3. Analyze Architecture Approaches
   -> Impact of each approach on scenarios

4. Identify Sensitivity Points / Tradeoffs
   -> Which decisions are sensitive to which attributes

5. Classify Risks / Non-risks
   -> Resolved tradeoffs vs. unresolved risks

6. Compile Results
   -> List of key tradeoffs to reflect in the ADR

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/62-adr-writer/.claude/skills/quality-attribute-analyzer of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Quality Attribute Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Quality Attribute Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Quality Attribute Analyzer this skillrevfactory/harness-1001.3k—~1.2kAutomated safety check: PassApache-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Skillward AuditFangcun-AI/SkillWard143—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 7 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Quality Attribute Analyzer

What does Quality Attribute Analyzer do?

A specialized skill for systematically analyzing quality attributes in architecture decisions and quantifying tradeoffs. Quality Attribute Analyzer is an agent skill from revfactory/harness-100. A specialized skill for systematically analyzing quality attributes in architecture decisions and quantifying tradeoffs.

When should I use Quality Attribute Analyzer?

Quality Attribute Analyzer fits situations like: tasks that involve Security review.

How do I install Quality Attribute Analyzer in Claude Code?

Run `npx skills add revfactory/harness-100 --skill quality-attribute-analyzer -a claude-code`. Or copy the skill folder (en/62-adr-writer/.claude/skills/quality-attribute-analyzer in revfactory/harness-100) into .claude/skills/quality-attribute-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Quality Attribute Analyzer in Codex?

Run `npx skills add revfactory/harness-100 --skill quality-attribute-analyzer -a codex`. Or copy the skill folder (en/62-adr-writer/.claude/skills/quality-attribute-analyzer in revfactory/harness-100) into .agents/skills/quality-attribute-analyzer in your project. Codex loads it when a task matches its description.

Can I use Quality Attribute Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill quality-attribute-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/quality-attribute-analyzer, .gemini/skills/quality-attribute-analyzer, .github/skills/quality-attribute-analyzer and .opencode/skills/quality-attribute-analyzer in your project.

What does Quality Attribute Analyzer need to run?

SKILL.md names no scripts, command-line tools or credentials: Quality Attribute Analyzer is instructions for the agent only.

Does Quality Attribute Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Quality Attribute Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Quality Attribute Analyzer use?

Quality Attribute Analyzer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Quality Attribute Analyzer use?

About 1.2k tokens (SKILL.md is roughly 4.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Quality Attribute Analyzer?

Skills that share tags, products or a category with Quality Attribute Analyzer: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Quality Attribute Analyzer?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.