analyzer-development

A guide for creating Roslyn analyzers, which inspect C# code and report migration problems, plus optional automatic fixes.

In plain words
What is it for?
It helps detect Web Forms patterns such as event-handler signatures, FindControl calls, and IsPostBack usage, then provide code fixes where appropriate.
Why use it?
It gives migration warnings a consistent design, test structure, diagnostic numbering, and release tracking.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/fritzandfriends/blazorwebformscomponents/analyzer-development
Any agent
npx skills add FritzAndFriends/BlazorWebFormsComponents --skill analyzer-development
Clone the repo
git clone --depth 1 https://github.com/FritzAndFriends/BlazorWebFormsComponents

Made for: Claude Code, Codex.

Per session 84 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,188 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00084 $0.02188
Opus 5 $0.00042 $0.01094
Sonnet 5 $0.00017 $0.00438
Haiku 4.5 $0.00008 $0.00219

Measured 2d ago against content hash 29aa32e7ab00, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

analyzer-development scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/skills/analyzer-development/SKILL.md · 281 lines

How it starts

The opening of the file, as written. The whole thing — 281 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Analyzer Development

This skill covers creating Roslyn analyzers and code-fix providers in the BlazorWebFormsComponents.Analyzers project.

Architecture

The analyzer project ships as a NuGet analyzer package alongside the main BWFC library. Analyzers detect Web Forms patterns in user code and suggest BWFC replacements.

Project Structure

src/BlazorWebFormsComponents.Analyzers/
├── *Analyzer.cs              — DiagnosticAnalyzer implementations
├── *CodeFixProvider.cs       — Optional companion code-fix providers
├── SyntaxExtensions.cs       — Shared Roslyn helper methods
├── AnalyzerReleases.Shipped.md    — Released diagnostic IDs
└── AnalyzerReleases.Unshipped.md  — In-progress diagnostic IDs

src/BlazorWebFormsComponents.Analyzers.Test/
├── *AnalyzerTests.cs         — Analyzer unit tests
├── *CodeFixTests.cs          — Code-fix unit tests
└── AllAnalyzersIntegrationTests.cs — Cross-cutting integration tests

Current Analyzers

Analyzer Diagnostic Detects
EventHandlerSignatureAnalyzer BWFC001+ Web Forms event handler signatures
FindControlUsageAnalyzer BWFC0xx FindControl() calls
IsPostBackUsageAnalyzer BWFC0xx IsPostBack property usage
ViewStateUsageAnalyzer BWFC0xx ViewState["key"] access
ViewStatePropertyPatternAnalyzer BWFC0xx ViewState-backed property patterns
SessionUsageAnalyzer BWFC0xx Session["key"] access
ResponseObjectUsageAnalyzer BWFC0xx Response.Redirect, Response.Write
ResponseRedirectAnalyzer BWFC0xx Response.Redirect specifically
RequestObjectUsageAnalyzer BWFC0xx Request.QueryString, Request.Form
PageClientScriptUsageAnalyzer BWFC0xx ClientScript.Register*
ScriptManagerUsageAnalyzer BWFC0xx ScriptManager usage
RunatServerAnalyzer BWFC0xx runat="server" in markup
NonSerializableViewStateAnalyzer BWFC0xx Non-serializable types in ViewState
MissingParameterAttributeAnalyzer BWFC0xx Missing [Parameter] on public props
RequiredAttributeAnalyzer BWFC0xx Required HTML attributes
IPostBackEventHandlerUsageAnalyzer BWFC0xx IPostBackEventHandler implementation

Read the full file on GitHub · 281 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 281 lines · 84 tokens per session scan A 29aa32e7ab00

Subscribe to this mod's changes

analyzer-development is a skill published in the GitHub repository FritzAndFriends/BlazorWebFormsComponents (449 stars, last pushed 2mo ago), licensed MIT. It adds 84 tokens to every session and 2,188 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

lumeo

Use when building or editing a Blazor UI that uses the Lumeo component library (the Lumeo NuGet package and its satellites Lumeo.Charts / Lumeo.DataGrid / Lumeo.Editor / Lumeo.Scheduler / Lumeo.Gantt / Lumeo.Motion), or when the user mentions Lumeo components (Button, DataGrid, Sheet, Dialog, Tabs, DatePicker, Toast…

Brain2k-0005/Lumeo · 125 tokens

address-pr-feedback

Address unresolved GitHub pull request review feedback in PKMDS-Blazor. Use when asked to handle PR comments, review threads, requested changes, or reviewer follow-up.

codemonkey85/PKMDS-Blazor · 38 tokens

implement-issue

Implement a PKMDS-Blazor GitHub issue end to end. Use when asked to investigate and implement an issue, bug, feature request, or feature-parity item and prepare it for review.

codemonkey85/PKMDS-Blazor · 44 tokens

sync-repos

Synchronize external repositories used by PKMDS-Blazor. Use when asked to sync, get latest, refresh related repos, inspect upstream changes, or prepare work that depends on current PKHeX, PokeAPI, Pokemon Showdown, sprites, or plugin sources.

codemonkey85/PKMDS-Blazor · 58 tokens

blazorbindings-maui-third-party

Integrate third-party .NET MAUI control libraries into BlazorBindings.Maui apps by generating Razor wrappers, registering attached properties, and bridging to native elements for imperative APIs such as popups or bottom sheets. Use when adding, updating, or troubleshooting a MAUI control package in a…

Dreamescaper/BlazorBindings.Maui · 85 tokens

csharp-dotnet

Use when writing, reviewing, testing, or shipping C# / .NET code — ASP.NET Core APIs (minimal APIs vs controllers), EF Core data access, async correctness, solution layout in .cs/.csproj/.sln. NOT a Java/Spring backend (that is spring-boot), NOT a Node/TypeScript backend (that is nestjs), NOT framework-neutral REST…

ericrisco/rsc-harness · 89 tokens