Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Use the open-source CodeQL ecosystem for .NET security analysis. Use when a repo needs CodeQL query packs, CLI-based analysis on open source codebases, or GitHub Action setup with explicit licensing caveats. USE FOR: the repo uses or wants CodeQL for .NET security analysis; GitHub code scanning is part of the CI plan. DO NOT USE FOR: teams that need a tool with no private-repo licensing caveat. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or v
.claude/skills/managedcode-codeql/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-19 | ✗→✓ | ▲ Improved | 95% | 0% |
| case-01 | ✓→✗ | ▼ Worse | -32% | 0% |
| case-02 | ✓→✗ | ▼ Worse | -56% | 0% |
| case-14 | ✓→✗ | ▼ Worse | -6% | 0% |
| case-03 | ✓→✓ | = Same ✓ | -26% | 0% |
AGENTS.mdAGENTS.md and confirm scope and constraints.Workflow through the Ralph Loop until outcomes are acceptable.Required Result Format with concrete artifacts and verification evidence.If CodeQL is not configured yet:
rg -n "codeql-action|security-events|CodeQL" .github/workflowscommand -v codeqlgithub/codeql-action/init and github/codeql-action/analyze.manual when precision matters).status: configured or status: improved.status: not_applicable with caveat documented.Use the Ralph Loop for every task, including docs, architecture, testing, and tooling work.
status: not_applicable with explicit reason and fallback path.status: complete | clean | improved | configured | not_applicable | blockedplan: concise plan and current iteration stepactions_taken: concrete changes madevalidation_skills: final skills run, or skipped with reasonsverification: commands, checks, or review evidence summaryremaining: top unresolved items or noneFor setup-only requests with no execution, return status: configured and exact next commands.
Other measured skills in the registry, with their headline benchmark lift.