Agent skill

Diagnostic Dofile

by SepineTam in SepineTam/mcp-for-stata

A skill your agent uses when the user needs to inspect, audit, or diagnose the safety of a Stata do-file.

AGPL-3.0Auto-check passedResearch & Science

Install Diagnostic Dofile

skills CLI
$ npx skills add SepineTam/mcp-for-stata --skill diagnostic-dofile -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SepineTam/mcp-for-stata diagnostic-dofile --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SepineTam/mcp-for-stata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/stata-toolbox/skills/diagnostic-dofile .claude/skills/diagnostic-dofile && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
diagnostic-dofile
GitHub stars
264
Token cost
~1.2k tokens
SKILL.md length
452 words
Files
2
Skills in repo
6
Repo updated
First seen
Licence
AGPL-3.0

At a glance

A skill your agent uses when the user needs to inspect, audit, or diagnose the safety of a Stata do-file.

  • Works in 8 steps: File metadata → Encoding and format → Dangerous commands → …
  • The user needs to inspect
  • SKILL.md covers When to use, How to run, Current checks and Report format, plus 1 more section
  • Runs Python scripts from its folder; calls uv

What it does

Diagnostic Dofile is an agent skill from SepineTam/mcp-for-stata. Use this skill when the user needs to inspect, audit, or diagnose the safety of a Stata do-file. Typical scenarios include: uncertainty about whether a .do file is safe; receiving a complete do-file from an unofficial source (not the Stata website, not a well-known academic institution or professor's official site); asking to check a batch of do-files; or requesting a read-only security/risk/portability diagnostic report. The skill does not modify the original file; it only emits a JSON report. Note that this is…

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `diagnose_dofile.py`).

It sits in Research & Science, covering Econometrics and empirical research and Security review. It works with Model Context Protocol. The repository describes itself as: Stata-MCP: A MCP server for integrating Stata into your agent loop with a safety-first design. The licence is AGPL-3.0.

When your agent uses it

  • The user needs to inspect
  • Diagnose the safety of a Stata do-file

Example prompts

  • “/diagnostic-dofile”

Requirements

  • Python 3

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. File metadata
  2. Encoding and format
  3. Dangerous commands
  4. Data-overwrite risks
  5. Output-file overwrite
  6. External commands / user-written packages
  7. Paths and portability
  8. Macro and parsing risks

What it can do on your machine

Read from SKILL.md and the folder at commit d339615. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • uv

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Diagnostic Dofile loads about 1.2k tokens when it runs. Until then it costs about 156 tokens; SKILL.md has 452 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~156
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SepineTam/mcp-for-stata at commit d339615, republished under its AGPL-3.0 licence (© SepineTam). 452 words, ~1,245 tokens.

Download SKILL.mdSave it as .claude/skills/diagnostic-dofile/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
diagnostic-dofile
description
Use this skill when the user needs to inspect, audit, or diagnose the safety of a Stata do-file. Typical scenarios include: uncertainty about whether a .do file is safe; receiving a complete do-file from an unofficial source (not the Stata website, not a well-known academic institution or professor's official site); asking to check a batch of do-files; or requesting a read-only security/risk/portability diagnostic report. The skill does not modify the original file; it only emits a JSON report. Note that this is not a mandatory step for every do-file; run it only when a security review is warranted.
metadata.version
0.1.0

Diagnostic do-file

This skill inspects a Stata do-file without changing the original file and outputs a JSON diagnostic report. The underlying script reuses stata_mcp.utils.parse_dofile and stata_mcp.guard.blacklist, so it handles Stata command abbreviations, prefixes (capture / quietly), macro expansion, block comments, #delimit ;, and other common constructs.

When to use

Recommended situations:

  • You receive a complete do-file from an unknown or unofficial source, especially one downloaded from outside the Stata website or well-known academic/professor sites.
  • The code arrives as an email attachment, cloud-drive link, forum post, or chat message, and you want to verify that it contains no dangerous commands or data-overwrite risks.
  • Before taking over or reproducing someone else's project, you want to audit the key do-files.
  • You explicitly want a read-only diagnostic report covering security, portability, encoding, and other dimensions.

This skill is not required every time you write a do-file. For analysis code you wrote yourself, understand, and trust, you can run it directly without generating a diagnostic report each time.

How to run

bash
uv run plugins/stata-toolbox/skills/diagnostic-dofile/diagnose_dofile.py path/to/file.do

Save the report to a file:

bash
uv run plugins/stata-toolbox/skills/diagnostic-dofile/diagnose_dofile.py path/to/file.do -o report.json

Current checks

1. File metadata
  • File path, size, and modification time.
  • UTC timestamp when the report was generated.
  • SHA-256 hash of the file.
2. Encoding and format
  • UTF-8 or UTF-8 with BOM.
  • Non-UTF-8 encodings such as GBK/GB2312.
  • Line ending: LF, CRLF, or mixed.
  • Empty file or comment-only file.
3. Dangerous commands

Based on src/stata_mcp/guard/blacklist.py:

  • Shell / system commands: !, !!, shell, xshell, winexec, unixcmd.
  • File deletion: erase, rm, rmdir.
  • External code execution: do, run, include.
  • Embedded runtimes: python, mata, java, plugin.
  • Package-management commands: ssc, net, github, adoupdate, update.
  • Working-directory changes: cd, chdir.
4. Data-overwrite risks
  • use xxx.dta followed by save xxx.dta, replace pointing to the same file.
  • Memory-clearing operations such as clear all / drop _all.
Show full SKILL.md (170 more words)Show less
5. Output-file overwrite
  • graph export xxx, replace.
  • export xxx, replace.
  • Commands with replace such as outreg2, esttab, estout, putexcel, putdocx, putpdf, logout, texdoc.
  • log using xxx.log, replace.
  • saveold xxx, replace.
6. External commands / user-written packages
  • Recognizes common external commands such as reghdfe, estout, outreg2, esttab, coefplot, ivreg2, rdrobust.
  • Reports them so the caller can run Stata help <command> to verify installation.
7. Paths and portability
  • Absolute paths such as /Users/... or C:\....
  • webuse or network URLs for loading data.
  • cd / chdir working-directory changes.
8. Macro and parsing risks
  • Unresolved macro variables (global macros, local macro expressions, etc.).
  • Unclosed block comments, quotes, or program blocks that may affect parsing reliability.

Report format

The report is a JSON object with the following structure:

json
{
  "schema_version": "0.1.0",
  "generated_at": "2026-09-22T12:34:56.789012Z",
  "file": {
    "path": "/project/analysis.do",
    "size_bytes": 1234,
    "sha256": "abc123...",
    "encoding": "utf-8",
    "has_bom": false,
    "line_ending": "lf"
  },
  "summary": {
    "total_lines": 100,
    "code_lines": 60,
    "comment_lines": 30,
    "blank_lines": 10,
    "error_count": 2,
    "warning_count": 5,
    "info_count": 3
  },
  "findings": [
    {
      "level": "error",
      "line": 12,
      "category": "dangerous_command",
      "message": "Detected dangerous command 'shell'"
    }
  ]
}

Notes

  • The script only reads the original file and never modifies the do-file content.
  • Findings are for reference only; the final execution decision is yours.
  • For Stata-MCP, dangerous commands are automatically blocked by the security guard during stata_do. To disable the guard, configure ~/.statamcp/config.toml, but this is not recommended.

© SepineTam, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/stata-toolbox/skills/diagnostic-dofile of SepineTam/mcp-for-stata.

  • SKILL.md
  • diagnose_dofile.py

Open the folder on GitHubat commit d339615

Compare with similar skills

Diagnostic Dofile next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Diagnostic Dofile compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Diagnostic Dofile this skillSepineTam/mcp-for-stata264—~1.2kAutomated safety check: PassAGPL-3.0
Fin Data Acquisitioncsmar432/finai-research109—~2kAutomated safety check: PassMIT
Fin Generate Ideacsmar432/finai-research109—~2.5kAutomated safety check: PassMIT
Fin Idea Discoverycsmar432/finai-research109—~2.7kAutomated safety check: PassMIT
Fin Novelty Checkcsmar432/finai-research109—~1.4kAutomated safety check: PassMIT
Stata Replicationpedrohcgs/claude-code-my-workflow1.7k—~2.1kAutomated safety check: NotesMIT

Similar skills

  • Fin Data Acquisition

    csmar432/finai-research

    根据REFINEDDESIGN.md中的变量定义,自动获取所需数据并生成可执行的回归分析脚本(Python/Stata)。

    109 GitHub stars~2k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Fin Generate Idea

    csmar432/finai-research

    针对经济金融研究方向的创意生成与评估。生成8-12个可发表的研究idea,过滤后在数据可行的情况下进行小规模实证验证,输出排序后的研究想法报告。

    109 GitHub stars~2.5k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Fin Idea Discovery

    csmar432/finai-research

    经济金融研究的完整想法发现流程。从研究方向出发,经过文献综述、想法生成、新颖性验证、实证方法设计和数据获取,输出经过数据实证验证的可执行研究方案。

    109 GitHub stars~2.7k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Fin Novelty Check

    csmar432/finai-research

    验证经济金融研究想法的新颖性。在JF、JFE、RFS、JME等顶刊及arXiv中搜索近三年文献,输出结构化新颖性报告和定位策略。

    109 GitHub stars~1.4k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed
  • Stata Replication

    pedrohcgs/claude-code-my-workflow

    End-to-end Stata replication pipeline — scaffolds numbered .do files in scripts/stata/, executes them via the stata-mcp MCP server, captures logs and outputs to output/, and produces…

    1.7k GitHub stars~2.1k tokensUpdated 13 days ago
    Research & ScienceAuto-check: notes
  • Aer Statspai

    brycewang-stanford/Auto-Empirical-Research-Skills

    A skill your agent uses when aer-identification has fixed the design, after methodology choice and before aer-robustness or aer-tables-figures, to run an AER-track analysis with StatsPAI — the…

    4.6k GitHub stars~3k tokensUpdated 5 days ago
    Research & ScienceAuto-check passed

More from SepineTam/mcp-for-stata

  • Stata Audit

    SepineTam/mcp-for-stata

    Inspect, validate, summarize, and render local Stata-MCP audit evidence under .statamcp.

    264 GitHub stars~1.2k tokensUpdated 5 days ago
    Auto-check passed
  • MCP Smoke Test

    SepineTam/mcp-for-stata

    Run a local smoke test for the Stata-MCP server. An agent skill from SepineTam/mcp-for-stata.

    264 GitHub stars~1.4k tokensUpdated 5 days ago
    Auto-check passed
  • Stata Discover

    SepineTam/mcp-for-stata

    A skill your agent uses when you need to find Stata on the user's machine or configure stata-mcp to use it.

    264 GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Rfc Impl Generator

    SepineTam/mcp-for-stata

    Generate RFC and IMPL documents from a user-provided feature/fix description.

    264 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check passed
  • Stata Skill

    SepineTam/mcp-for-stata

    A packaged Stata Runner skill via official MCP-for-Stata server including statado, adopackageinstall, help, readlog and getdatainfo tools.

    264 GitHub stars~2.7k tokensUpdated 5 days ago
    Auto-check passed

Questions about Diagnostic Dofile

What does Diagnostic Dofile do?

A skill your agent uses when the user needs to inspect, audit, or diagnose the safety of a Stata do-file. Diagnostic Dofile is an agent skill from SepineTam/mcp-for-stata. Use this skill when the user needs to inspect, audit, or diagnose the safety of a Stata do-file.

When should I use Diagnostic Dofile?

Diagnostic Dofile fits situations like: the user needs to inspect; diagnose the safety of a Stata do-file.

How do I install Diagnostic Dofile in Claude Code?

Run `npx skills add SepineTam/mcp-for-stata --skill diagnostic-dofile -a claude-code`. Or copy the skill folder (plugins/stata-toolbox/skills/diagnostic-dofile in SepineTam/mcp-for-stata) into .claude/skills/diagnostic-dofile in your project. Claude Code loads it when a task matches its description.

How do I install Diagnostic Dofile in Codex?

Run `npx skills add SepineTam/mcp-for-stata --skill diagnostic-dofile -a codex`. Or copy the skill folder (plugins/stata-toolbox/skills/diagnostic-dofile in SepineTam/mcp-for-stata) into .agents/skills/diagnostic-dofile in your project. Codex loads it when a task matches its description.

Can I use Diagnostic Dofile in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SepineTam/mcp-for-stata --skill diagnostic-dofile -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/diagnostic-dofile, .gemini/skills/diagnostic-dofile, .github/skills/diagnostic-dofile and .opencode/skills/diagnostic-dofile in your project.

What does Diagnostic Dofile need to run?

Going by SKILL.md and its folder, Diagnostic Dofile needs Python for the scripts in its folder and the command-line tools its instructions call (uv). Our summary lists: Python 3.

Does Diagnostic Dofile access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Diagnostic Dofile safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Diagnostic Dofile use?

Diagnostic Dofile is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Diagnostic Dofile use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Diagnostic Dofile?

Skills that share tags, products or a category with Diagnostic Dofile: Fin Data Acquisition (csmar432/finai-research, 109 stars), Fin Generate Idea (csmar432/finai-research, 109 stars), Fin Idea Discovery (csmar432/finai-research, 109 stars) and Fin Novelty Check (csmar432/finai-research, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Diagnostic Dofile?

SepineTam (a GitHub user) maintains it in SepineTam/mcp-for-stata, which has 264 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 6, 2026.

Source: SepineTam/mcp-for-stata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.