Source profileQuality 94/100

dotnet/skills/plugins/dotnet-test/skills/detect-static-dependencies/SKILL.md

detect-static-dependencies

Scan C# source files for hard-to-test static dependencies — DateTime.Now/UtcNow, File.*, Directory.*, Environment.*, HttpClient, Console.*, Process.*, and other untestable statics. Produces a ranked report of static call sites by frequency. USE FOR: find untestable statics, scan for static dependencies, testability audit, identify hard-to-mock code, find DateTime.Now usage, detect static coupling, testability report, static analysis for testability. DO NOT USE FOR: generating wrappers (use gener

Source repository stars
5,277
Declared platforms
0
Static risk flags
2
Last source update
2026-08-28
Source checked
2026-08-28

Decision brief

What it does: where it fits

Scan a C codebase for calls to hard-to-test static APIs and produce a ranked report showing which statics appear most frequently, which files are most affected, and which abstractions already exist in the .NET ecosystem to replace them.

Best for

  • Auditing a project's testability before adding unit tests
  • Understanding the scope of static coupling in a legacy codebase
  • Prioritizing which statics to wrap first (highest-frequency wins)

Not for

  • The user wants wrappers generated (hand off to generate-testability-wrappers)
  • The user wants mechanical migration done (hand off to migrate-static-to-wrapper)

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeNot declaredNo explicit evidencePortability before use
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/dotnet/skills --skill "plugins/dotnet-test/skills/detect-static-dependencies"
Safe inspection promptEditorial

Inspect the Agent Skill "detect-static-dependencies" from https://github.com/dotnet/skills/blob/2b9056bd9152490cc698c5b3e61c9f9a1c135776/plugins/dotnet-test/skills/detect-static-dependencies/SKILL.md at commit 2b9056bd9152490cc698c5b3e61c9f9a1c135776. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    Workflow

    Resolve the target to a set of .cs files: - If a .cs file, scan that single file. - If a directory, scan all .cs files recursively (excluding obj/, bin/). - If a .csproj, find its directory and scan .cs files within. - If a .sln, parse it, find all project directories, and scan…

    If a .cs file, scan that single file.If a directory, scan all .cs files recursively (excluding obj/, bin/).If a .csproj, find its directory and scan .cs files within.
  2. 02

    Step 1: Determine scan scope

    Resolve the target to a set of .cs files: - If a .cs file, scan that single file. - If a directory, scan all .cs files recursively (excluding obj/, bin/). - If a .csproj, find its directory and scan .cs files within. - If a .sln, parse it, find all project directories, and scan…

    If a .cs file, scan that single file.If a directory, scan all .cs files recursively (excluding obj/, bin/).If a .csproj, find its directory and scan .cs files within.
  3. 03

    Step 2: Search for static dependency patterns

    Scan each file for calls matching these categories:

    Scan each file for calls matching these categories:Treat pattern matches as candidates, not findings. Before counting an instance call, trace how its receiver enters the class. A collaborator supplied through a constructor, parameter, property, or dependency injection (…For time calls, inspect use as well as count. Two ambient clock reads in one logical operation are two call sites and a consistency defect: for example, separate DateTime.UtcNow reads for CreatedAt and ExpiresAt = DateT…
  4. 04

    Step 3: Aggregate and rank results

    Count each call site across the entire scan scope — including the instance-member call sites covered by the rules below, not only static ones.

    Build one occurrence ledger before writing prose. Give each included callKeep the three count domains separate. Files scanned includes everyOne authoritative total. Every call site you found belongs in the category summary and the grand total. Never park real findings in an "additional observations" section that the totals exclude.
  5. 05

    Step 4: Present the report

    Format the output as a structured report:

    Format the output as a structured report:

Permission review

Static risk signals and limitations

Reads files

low · line 4

The documentation asks the agent to read local files, directories, or repositories.

Scan a C# codebase for calls to hard-to-test static APIs and produce a ranked report showing which statics appear most frequently, which files are most affected, and which abstractions already exist in the .NET ecosystem to replace them.

Reads files

low · line 39

The documentation asks the agent to read local files, directories, or repositories.

If a `.cs` file, scan that single file.

Writes files

medium · line 59

The documentation asks the agent to create, modify, or delete local files.

| **File System** | `File.ReadAllText(`, `File.WriteAllText(`, `File.Exists(`, `File.Delete(`, `File.Copy(`, `File.Move(`, `Directory.Exists(`, `Directory.CreateDirectory(`, `Directory.GetFiles(`, `Directory.Delete(`, `Path.GetTempPath(`, a

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score94/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars5,277SourceRepository attention, not individual Skill quality
Compatibility0 platformsSourceDeclared in the catalog source record
Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
dotnet/skills
Skill path
plugins/dotnet-test/skills/detect-static-dependencies/SKILL.md
Commit
2b9056bd9152490cc698c5b3e61c9f9a1c135776
License
MIT
Collected
2026-08-28
Default branch
main
View the original SKILL.md

Detect Static Dependencies

Scan a C# codebase for calls to hard-to-test static APIs and produce a ranked report showing which statics appear most frequently, which files are most affected, and which abstractions already exist in the .NET ecosystem to replace them.

When to Use

  • Auditing a project's testability before adding unit tests
  • Understanding the scope of static coupling in a legacy codebase
  • Prioritizing which statics to wrap first (highest-frequency wins)
  • Creating a migration plan for incremental testability improvements

Response Guidelines

  • Scale the response to the user's request. A question about a specific category (e.g., "find time statics") should focus on that category with file locations and counts, not produce a full report across all categories.
  • When the user provides a specific file or directory path, scan only that scope — do not expand to the entire solution unless asked.
  • The full structured report format in Step 4 is for comprehensive audit requests. For focused questions, return only the relevant subset (e.g., category summary + affected files for the requested category).

When Not to Use

  • The user wants wrappers generated (hand off to generate-testability-wrappers)
  • The user wants mechanical migration done (hand off to migrate-static-to-wrapper)
  • The statics are already behind interfaces or TimeProvider
  • The code is not C# / .NET

Inputs

InputRequiredDescription
Target pathYesA file, directory, project (.csproj), or solution (.sln) to scan
Exclusion patternsNoGlob patterns to skip (e.g., **/obj/**, **/Migrations/**)
Category filterNoLimit to specific categories: time, filesystem, environment, network, console, process

Workflow

Step 1: Determine scan scope

Resolve the target to a set of .cs files:

  • If a .cs file, scan that single file.
  • If a directory, scan all .cs files recursively (excluding obj/, bin/).
  • If a .csproj, find its directory and scan .cs files within.
  • If a .sln, parse it, find all project directories, and scan .cs files across all projects.

Always exclude obj/, bin/, and any user-specified exclusion patterns.

Step 2: Search for static dependency patterns

Scan each file for calls matching these categories:

Treat pattern matches as candidates, not findings. Before counting an instance call, trace how its receiver enters the class. A collaborator supplied through a constructor, parameter, property, or dependency injection (DI) is already a test seam. In particular, an injected HttpClient is testable with a controlled HttpMessageHandler; do not count its calls or recommend replacing it merely because the injected type is concrete.

CategoryPatterns to search forRecommended replacement
TimeDateTime.Now, DateTime.UtcNow, DateTime.Today, DateTimeOffset.Now, DateTimeOffset.UtcNow, Task.Delay(, new CancellationTokenSource(TimeSpanTimeProvider (.NET 8+)
File SystemFile.ReadAllText(, File.WriteAllText(, File.Exists(, File.Delete(, File.Copy(, File.Move(, Directory.Exists(, Directory.CreateDirectory(, Directory.GetFiles(, Directory.Delete(, Path.GetTempPath(, and instance members that hit the disk (new FileInfo(...), new DirectoryInfo(...), .LastWriteTimeUtc, new StreamReader(path))IFileSystem (System.IO.Abstractions NuGet)
Randomness / identitynew Random(, Random.Shared, Guid.NewGuid(TimeProvider-style seam: inject Random / an IGuidProvider
Culture / serializationCultureInfo.CurrentCulture, CultureInfo.CurrentUICulture, JsonSerializer.Serialize(, JsonSerializer.Deserialize(Pass culture/options explicitly, or inject a serializer abstraction
EnvironmentEnvironment.GetEnvironmentVariable(, Environment.SetEnvironmentVariable(, Environment.MachineName, Environment.UserName, Environment.CurrentDirectory, Environment.Exit(Custom IEnvironmentProvider
Networknew HttpClient(, .GetAsync(, .PostAsync(, .SendAsync( (confirm the receiver is an HttpClient; exclude calls whose receiver is injected or produced by an injected factory)Inject HttpClient (commonly supplied by IHttpClientFactory)
ConsoleConsole.WriteLine(, Console.ReadLine(, Console.Write(, Console.ReadKey(IConsole wrapper or ILogger
ProcessProcess.Start(, Process.GetCurrentProcess(, Process.GetProcessesByName(Custom IProcessRunner

For time calls, inspect use as well as count. Two ambient clock reads in one logical operation are two call sites and a consistency defect: for example, separate DateTime.UtcNow reads for CreatedAt and ExpiresAt = DateTime.UtcNow.AddDays(30) can drift. Recommend one captured instant. With TimeProvider, retain DateTimeOffset where possible; when the existing member requires UTC DateTime, use GetUtcNow().UtcDateTime, never .DateTime, which loses the UTC kind. Treat capturing one instant as an optional behavior-level follow-up: a mechanical wrapper migration must preserve the original reads one-for-one unless the user separately approves that semantic change.

Step 3: Aggregate and rank results

Count each call site across the entire scan scope — including the instance-member call sites covered by the rules below, not only static ones.

Counting rules — inaccurate totals are the main way this report loses to an ad-hoc scan:

  • Build one occurrence ledger before writing prose. Give each included call site exactly one row containing category, exact pattern, file:line, and recommended seam. Derive every category, pattern, and per-file count by grouping that same ledger; never recount independently while writing tables.
  • Keep the three count domains separate. Files scanned includes every eligible source file; affected files includes only files with ledger rows; call sites is the number of ledger rows. Never substitute one for another.
  • One authoritative total. Every call site you found belongs in the category summary and the grand total. Never park real findings in an "additional observations" section that the totals exclude.
  • Classify by what the member touches, not by whether it is static. Instance members that reach the same untestable resource still count and belong in the matching category (new FileInfo(path).LastWriteTimeUtc → File System; new HttpClient().GetAsync(...) → Network). Say "hidden dependency", not "static", when the member is an instance call.
  • Check receiver provenance before counting instance calls. Count a resource access only when the code under test acquires or constructs the dependency itself. Exclude constructor-, parameter-, property-, and DI-injected collaborators from the "needs wrapping" total, including concrete HttpClient instances.
  • Exclude deterministic pure helpers from the "needs wrapping" total. Path.Combine, Path.GetExtension, Path.GetFileName, and Math.*/string.* statics take no ambient input and are trivially testable. List them, if at all, in a separate "no action needed" note — never as testability blockers.
  • Cover every category before reporting — time, file system, environment, network, console, process, randomness (new Random(), Guid.NewGuid()), culture (CultureInfo.CurrentCulture), and serialization/statics such as JsonSerializer. Omitting a category that is present is an under-count.
  • Give file:line for every occurrence so the user can jump straight to it.
  • Reconcile before publishing. The category totals, the top-patterns table, and the per-file table must sum to the same grand total.
  • Treat exclusions as a scope decision, not a category. Remove obj/, bin/, generated, and user-excluded files before building the ledger. Do not include their files or call sites in any reported count. State the exclusions once rather than mixing excluded candidates into the arithmetic.
  • Label truncated rankings. In a comprehensive audit, list all distinct patterns when needed for reconciliation. If the user asked only for a top-N subset, label it as a subset and do not imply that its rows sum to the grand total.

Produce a summary with:

  1. Category summary — total call sites per category (time, filesystem, env, etc.)
  2. Top patterns — the 10 most frequent individual patterns ranked by count
  3. Most affected files — files with the highest number of static dependencies
  4. Existing abstractions available — for each category, note the recommended .NET abstraction:
    • Time → TimeProvider (built-in since .NET 8)
    • File system → System.IO.Abstractions (NuGet package)
    • HTTP → IHttpClientFactory (built-in)
    • Environment → custom IEnvironmentProvider
    • Console → custom IConsole or ILogger
    • Process → custom IProcessRunner

Step 4: Present the report

Format the output as a structured report:

## Static Dependency Report

**Scope**: <project/solution name>
**Files scanned**: <count>
**Total static call sites**: <count>

### Category Summary
| Category     | Call Sites | Recommended Abstraction |
|-------------|-----------|------------------------|
| Time         | 42        | TimeProvider (.NET 8+) |
| File System  | 31        | System.IO.Abstractions |
| Environment  | 12        | IEnvironmentProvider   |
| ...          | ...       | ...                    |

### Top 10 Patterns
| # | Pattern             | Count | Files |
|---|---------------------|-------|-------|
| 1 | DateTime.UtcNow     | 28    | 14    |
| 2 | File.ReadAllText    | 18    | 9     |
| ...                                      |

### Most Affected Files
| File                          | Static Calls | Categories          |
|-------------------------------|-------------|---------------------|
| Services/OrderProcessor.cs    | 12          | Time, FileSystem    |
| ...                                                               |

### Migration Priority
1. **Time** (42 sites) — Use `TimeProvider`, zero NuGet dependencies on .NET 8+
2. **File System** (31 sites) — Use `System.IO.Abstractions` NuGet package
3. ...

Step 5: Suggest next steps

Based on the report, recommend which category to tackle first (highest count, best built-in support). Keep this to a few lines.

Mention generate-testability-wrappers or migrate-static-to-wrapper only when the user's next action clearly needs them — a hand-off note, not a sales pitch. Never end an audit with promotional next-steps that dilute the findings.

Validation

  • All .cs files in scope were scanned (check count)
  • Report includes category totals, top patterns, and affected files
  • Category totals, top patterns, and per-file counts reconcile to the same grand total
  • Files scanned, affected files, and call sites are reported as different quantities
  • Every aggregate was derived from one occurrence ledger rather than independently recounted
  • Every occurrence carries a file:line location
  • No findings are held outside the totals in an "additional" section
  • Calls on injected collaborators are excluded from the "needs wrapping" total
  • Deterministic pure helpers (Path.Combine, Math.*) are not counted as testability blockers
  • Each detected pattern has a recommended replacement listed
  • obj/ and bin/ directories were excluded
  • Migration priority is ordered by impact (count × ease of replacement)

Common Pitfalls

PitfallSolution
Scanning obj/ or generated codeAlways exclude obj/, bin/, and *.Designer.cs
Counting calls on injected collaboratorsTrace the receiver: an injected HttpClient, TimeProvider, interface, or other caller-supplied dependency already has a seam and needs no replacement
Missing statics inside lambdas/LINQSearch covers all code within .cs files, including lambdas
Recommending TimeProvider on < .NET 8Check TargetFramework in .csproj — if < net8.0, recommend NodaTime.IClock or custom ISystemClock
Ignoring test projectsOnly scan production code — exclude *.Tests.csproj projects from the scan
Under-counting by relegating findingsReal call sites belong in the category totals, not in a trailing "also noticed" paragraph that the totals ignore
Calling an instance member a staticnew FileInfo(p).LastWriteTimeUtc is an instance call but still a hidden file-system dependency — count it under File System and describe it accurately
Recommending a wrapper for Path.CombinePure, deterministic helpers need no seam; listing them as blockers makes the recommendations wrong

Frequently asked questions

What to verify before installation and use

What does the detect-static-dependencies source document cover?

Scan a C codebase for calls to hard-to-test static APIs and produce a ranked report showing which statics appear most frequently, which files are most affected, and which abstractions already exist in the .NET ecosystem to replace them.

How do I install detect-static-dependencies?

The source record exposes this install command: npx skills add https://github.com/dotnet/skills --skill "plugins/dotnet-test/skills/detect-static-dependencies". Inspect the command and pinned source before running it.

Which permission-related actions were detected?

Static rules flagged read-files, write-files in the source; the page lists the matching lines and excerpts.

Alternatives

Compare before choosing

Computed 10025,136

alirezarezvani/claude-skills

app-store-optimization

App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist

Computed 975,277

dotnet/skills

migrate-static-to-wrapper

Migrate C# static calls to a wrapper or built-in abstraction the user already named, within named files/projects, including affected fake-based test updates. USE FOR explicit DateTime.UtcNow/Now to TimeProvider, File.* to IFileSystem, existing IEnvironmentReader/ITextFileStore, scoped migrations, constructor injection, or a static API seam that keeps callers compiling and DateTimeKind unchanged. DO NOT USE when the user asks for behavior tests but leaves seam selection open (testability-obstacle

Computed 975,277

dotnet/skills

test-tagging

Classifies existing tests by standard traits and reports their distribution. MUST USE to categorize/tag/label tests, compare happy vs error paths, audit the test mix, or describe coverage shape by test type. Read bodies when names mislead. Apply canonical attributes; otherwise report only. DO NOT USE for test-quality audits, executed coverage or CRAP, behavioral gaps, writing tests, or migration.

Computed 97224

yonatangross/orchestkit

verify

Grade work that already exists and decide whether it can merge. Runs the project's current unit, integration, and E2E suites plus security scanning and type checking, scores every dimension 0-10, and returns a merge verdict with a VERIFIED-vs-CLAIMED evidence manifest. Writes no test files and edits no source. Use when verifying changes are ready to merge. Use /ork:cover instead when the tests still have to be written.