dotnet-quality
.NET code quality with Roslyn analyzers, StyleCop, and dotnet format. Covers linting, formatting, and best practices for C#/.NET. USE WHEN: user works with "C#", ".NET", "ASP.NET Core", asks about "Roslyn analyzers", "StyleCop", "dotnet format", ".NET linting", "C# best practices" DO NOT USE FOR: SonarQube - use `sonarqube` skill, testing - use .NET test skills, security - use `dotnet-security` skill
What this skill does
# .NET Quality - Quick Reference
## When NOT to Use This Skill
- **SonarQube setup** - Use `sonarqube` skill
- **Security scanning** - Use `dotnet-security` skill
- **Testing** - Use .NET test skills
> **Deep Knowledge**: Use `mcp__documentation__fetch_docs` with technology: `dotnet` for comprehensive documentation.
## Tool Overview
| Tool | Focus | Installation |
|------|-------|--------------|
| **dotnet format** | Formatting + analyzers | Built-in |
| **Roslyn Analyzers** | Code analysis | NuGet |
| **StyleCop.Analyzers** | Style rules | NuGet |
| **Roslynator** | Refactoring | NuGet |
| **SonarAnalyzer.CSharp** | SonarQube rules | NuGet |
## Roslyn Analyzers Setup
### Install Analyzers
```xml
<!-- Directory.Build.props (solution-wide) -->
<Project>
<PropertyGroup>
<AnalysisLevel>latest-all</AnalysisLevel>
<EnforceCodeStyleInBuild>true</EnforceCodeStyleInBuild>
<TreatWarningsAsErrors>true</TreatWarningsAsErrors>
</PropertyGroup>
<ItemGroup>
<PackageReference Include="Microsoft.CodeAnalysis.NetAnalyzers" Version="8.0.0">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
<PackageReference Include="StyleCop.Analyzers" Version="1.2.0-beta.556">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
<PackageReference Include="Roslynator.Analyzers" Version="4.10.0">
<PrivateAssets>all</PrivateAssets>
<IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
</ItemGroup>
</Project>
```
### .editorconfig
```ini
# .editorconfig
root = true
[*]
indent_style = space
indent_size = 4
end_of_line = lf
charset = utf-8
trim_trailing_whitespace = true
insert_final_newline = true
[*.cs]
# Organize usings
dotnet_sort_system_directives_first = true
dotnet_separate_import_directive_groups = false
# this. qualification
dotnet_style_qualification_for_field = false:warning
dotnet_style_qualification_for_property = false:warning
dotnet_style_qualification_for_method = false:warning
dotnet_style_qualification_for_event = false:warning
# Language keywords vs BCL types
dotnet_style_predefined_type_for_locals_parameters_members = true:warning
dotnet_style_predefined_type_for_member_access = true:warning
# var preferences
csharp_style_var_for_built_in_types = true:suggestion
csharp_style_var_when_type_is_apparent = true:suggestion
csharp_style_var_elsewhere = true:suggestion
# Expression-bodied members
csharp_style_expression_bodied_methods = when_on_single_line:suggestion
csharp_style_expression_bodied_constructors = false:suggestion
csharp_style_expression_bodied_properties = true:suggestion
csharp_style_expression_bodied_accessors = true:suggestion
csharp_style_expression_bodied_lambdas = true:suggestion
# Pattern matching
csharp_style_pattern_matching_over_is_with_cast_check = true:warning
csharp_style_pattern_matching_over_as_with_null_check = true:warning
# Null checking
csharp_style_throw_expression = true:suggestion
csharp_style_conditional_delegate_call = true:warning
dotnet_style_coalesce_expression = true:warning
dotnet_style_null_propagation = true:warning
# Code style
csharp_prefer_braces = true:warning
csharp_prefer_simple_using_statement = true:suggestion
csharp_style_prefer_switch_expression = true:suggestion
# Naming conventions
dotnet_naming_rule.interface_should_be_begins_with_i.severity = warning
dotnet_naming_rule.interface_should_be_begins_with_i.symbols = interface
dotnet_naming_rule.interface_should_be_begins_with_i.style = begins_with_i
dotnet_naming_symbols.interface.applicable_kinds = interface
dotnet_naming_symbols.interface.applicable_accessibilities = public, internal, private, protected
dotnet_naming_style.begins_with_i.required_prefix = I
dotnet_naming_style.begins_with_i.capitalization = pascal_case
dotnet_naming_rule.private_field_should_be_camel_case_with_underscore.severity = warning
dotnet_naming_rule.private_field_should_be_camel_case_with_underscore.symbols = private_field
dotnet_naming_rule.private_field_should_be_camel_case_with_underscore.style = camel_case_underscore
dotnet_naming_symbols.private_field.applicable_kinds = field
dotnet_naming_symbols.private_field.applicable_accessibilities = private
dotnet_naming_style.camel_case_underscore.required_prefix = _
dotnet_naming_style.camel_case_underscore.capitalization = camel_case
# Analyzer severity
dotnet_diagnostic.CA1062.severity = warning # Validate arguments
dotnet_diagnostic.CA1307.severity = warning # Specify StringComparison
dotnet_diagnostic.CA1310.severity = warning # Specify StringComparison for correctness
dotnet_diagnostic.CA2007.severity = none # ConfigureAwait (not needed in ASP.NET Core)
dotnet_diagnostic.IDE0058.severity = none # Expression value never used
# StyleCop
dotnet_diagnostic.SA1101.severity = none # Prefix local calls with this
dotnet_diagnostic.SA1309.severity = none # Field names must not begin with underscore
dotnet_diagnostic.SA1600.severity = none # Elements should be documented
dotnet_diagnostic.SA1633.severity = none # File should have header
```
## dotnet format
### Commands
```bash
# Check formatting
dotnet format --verify-no-changes
# Fix formatting
dotnet format
# Specific project
dotnet format ./src/MyProject
# Analyzers only
dotnet format analyzers
# Style only
dotnet format style
# Whitespace only
dotnet format whitespace
# With severity
dotnet format --severity warn
```
## Common Analyzer Warnings
### CA1062 - Validate Arguments
```csharp
// BAD - No null check
public void Process(string input)
{
Console.WriteLine(input.Length); // CA1062
}
// GOOD - Null check
public void Process(string input)
{
ArgumentNullException.ThrowIfNull(input);
Console.WriteLine(input.Length);
}
// GOOD - Nullable reference type
public void Process(string? input)
{
if (input is null) return;
Console.WriteLine(input.Length);
}
```
### CA1307/CA1310 - StringComparison
```csharp
// BAD - Culture-dependent
if (name.Equals("admin")) // CA1307
// GOOD - Explicit comparison
if (name.Equals("admin", StringComparison.OrdinalIgnoreCase))
// GOOD - For user-facing
if (name.Equals(otherName, StringComparison.CurrentCultureIgnoreCase))
```
### CA2000 - Dispose Objects
```csharp
// BAD - Not disposed
public void Process()
{
var stream = new FileStream("file.txt", FileMode.Open); // CA2000
// forgot to dispose
}
// GOOD - Using statement
public void Process()
{
using var stream = new FileStream("file.txt", FileMode.Open);
// automatically disposed
}
```
### IDE0090 - Use Target-typed new
```csharp
// Before
List<string> items = new List<string>();
// After
List<string> items = new();
// Or with var
var items = new List<string>();
```
## Common Code Smells & Fixes
### 1. God Class
```csharp
// BAD - Does too much
public class OrderProcessor
{
public void CreateOrder() { ... }
public void SendEmail() { ... }
public void GeneratePdf() { ... }
public void CalculateTax() { ... }
}
// GOOD - Single responsibility
public class OrderService
{
private readonly IEmailService _emailService;
private readonly IPdfGenerator _pdfGenerator;
private readonly ITaxCalculator _taxCalculator;
public OrderService(
IEmailService emailService,
IPdfGenerator pdfGenerator,
ITaxCalculator taxCalculator)
{
_emailService = emailService;
_pdfGenerator = pdfGenerator;
_taxCalculator = taxCalculator;
}
public async Task<Order> CreateOrderAsync(OrderRequest request)
{
var order = BuildOrder(request);
order.Tax = _taxCalculator.Calculate(order);
return order;
}
}
```
### 2. Async/Await Pitfalls
```csharp
// BAD - Blocking async
public void Process()
{
var result = GetDataAsync().Result; /Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.