Detect Static Dependencies
Scan a C# codebase for calls to hard-to-test static APIs and produce a ranked report showing which statics appear most frequently, which files are most affected, and which abstractions already exist in the .NET ecosystem to replace them.
When to Use
- Auditing a project's testability before adding unit tests
- Understanding the scope of static coupling in a legacy codebase
- Prioritizing which statics to wrap first (highest-frequency wins)
- Creating a migration plan for incremental testability improvements
Response Guidelines
- Scale the response to the user's request. A question about a specific category (e.g., "find time statics") should focus on that category with file locations and counts, not produce a full report across all categories.
- When the user provides a specific file or directory path, scan only that scope — do not expand to the entire solution unless asked.
- The full structured report format in Step 4 is for comprehensive audit requests. For focused questions, return only the relevant subset (e.g., category summary + affected files for the requested category).
Execution Contract
- A relative path named in the prompt is enough to start. Discover it with the
available file-listing tools and scan it immediately; do not ask the user to
provide or re-upload files before both discovery and a content search fail.
- Start with a recursive, line-numbered content search over eligible
.cs
files. Do not search only for the static keyword: ambient calls inside
LINQ expressions, lambdas, callbacks, and interpolated strings usually have
no static modifier.
- If a file-reading tool fails on a path that listing or search proved exists,
classify the failure before retrying. Fall back to another available
mechanism such as
rg -n, grep, or a shell file reader only for confirmed
tool availability, transport, or path-normalization failures and only after
verifying the canonical path remains inside the workspace. Stop on
content-exclusion, permission/policy, workspace-boundary, or unknown failures.
Search output can seed the occurrence ledger; open only the surrounding code
needed to verify receiver provenance.
- Never stop after loading this skill or announcing a scan plan. Return the
completed audit in the same response. If every fallback genuinely fails,
report the verified partial findings and the exact limitation; do not invent
findings or replace the audit with a request to rerun.
When Not to Use
- The user wants wrappers generated (hand off to
generate-testability-wrappers)
- The user wants mechanical migration done (hand off to
migrate-static-to-wrapper)
- The statics are already behind interfaces or
TimeProvider
- The code is not C# / .NET
Inputs
| Input |
Required |
Description |
| Target path |
No |
A file, directory, project (.csproj), or solution (.sln) to scan. Defaults to the current workspace. |
| Exclusion patterns |
No |
Glob patterns to skip (e.g., **/obj/**, **/Migrations/**) |
| Category filter |
No |
Limit to specific categories: time, filesystem, environment, network, console, process |
Workflow
Step 1: Determine scan scope
Resolve the target to a set of .cs files:
- Treat a prompt-named workspace-relative path as the target; locate it rather
than asking the user for an absolute path.
- If omitted, scan every eligible
.cs file under the current workspace; do not
pick one project and silently omit its siblings.
- If a
.cs file, scan that single file.
- If a directory, scan all
.cs files recursively (excluding obj/, bin/).
- If a
.csproj, find its directory and scan .cs files within.
- If a
.sln, parse it, find all project directories, and scan .cs files across all projects.
Always exclude obj/, bin/, and any user-specified exclusion patterns.
Step 2: Search for static dependency patterns
Scan each file for calls matching these categories:
Treat pattern matches as candidates, not findings. Before counting an instance call, trace how its
receiver enters the class. A collaborator supplied through a constructor, parameter, property, or
dependency injection (DI) is already a test seam. In particular, an injected HttpClient is
testable with a controlled HttpMessageHandler; do not count its calls or recommend replacing it
merely because the injected type is concrete.
| Category |
Patterns to search for |
Recommended replacement |
| Time |
DateTime.Now, DateTime.UtcNow, DateTime.Today, DateTimeOffset.Now, DateTimeOffset.UtcNow, Task.Delay(, new CancellationTokenSource(TimeSpan |
TimeProvider (.NET 8+) |
| File System |
File.ReadAllText(, File.WriteAllText(, File.Exists(, File.Delete(, File.Copy(, File.Move(, Directory.Exists(, Directory.CreateDirectory(, Directory.GetFiles(, Directory.Delete(, Path.GetTempPath(, and instance members that hit the disk (new FileInfo(...), new DirectoryInfo(...), .LastWriteTimeUtc, new StreamReader(path)) |
IFileSystem (System.IO.Abstractions NuGet) |
| Randomness / identity |
new Random(, Random.Shared, Guid.NewGuid( |
TimeProvider-style seam: inject Random / an IGuidProvider |
| Culture / serialization |
CultureInfo.CurrentCulture, CultureInfo.CurrentUICulture, JsonSerializer.Serialize(, JsonSerializer.Deserialize( |
Pass culture/options explicitly, or inject a serializer abstraction |
| Environment |
Environment.GetEnvironmentVariable(, Environment.SetEnvironmentVariable(, Environment.MachineName, Environment.UserName, Environment.CurrentDirectory, Environment.Exit( |
Custom IEnvironmentProvider |
| Network |
new HttpClient(, .GetAsync(, .PostAsync(, .SendAsync( (confirm the receiver is an HttpClient; exclude calls whose receiver is injected or produced by an injected factory) |
Inject HttpClient (commonly supplied by IHttpClientFactory) |
| Console |
Console.WriteLine(, Console.ReadLine(, Console.Write(, Console.ReadKey( |
IConsole wrapper or ILogger |
| Process |
Process.Start(, Process.GetCurrentProcess(, Process.GetProcessesByName( |
Custom IProcessRunner |
For time calls, inspect use as well as count. Two ambient clock reads in one
logical operation are two call sites and a consistency defect: for example,
separate DateTime.UtcNow reads for CreatedAt and
ExpiresAt = DateTime.UtcNow.AddDays(30) can drift. Recommend one captured
instant. With TimeProvider, retain DateTimeOffset where possible; when the
existing member requires UTC DateTime, use GetUtcNow().UtcDateTime, never
.DateTime, which loses the UTC kind. Treat capturing one instant as an
optional behavior-level follow-up: a mechanical wrapper migration must preserve
the original reads one-for-one unless the user separately approves that
semantic change.
Step 3: Aggregate and rank results
Count each call site across the entire scan scope — including the instance-member call sites covered by the rules below, not only static ones.
Counting rules — inaccurate totals are the main way this report loses to an ad-hoc scan:
- Build one occurrence ledger before writing prose. Give each included call
site exactly one row containing category, exact pattern,
file:line, and
recommended seam. Derive every category, pattern, and per-file count by
grouping that same ledger; never recount independently while writing tables.
- Keep the three count domains separate.
Files scanned includes every
eligible source file; affected files includes only files with ledger rows;
call sites is the number of ledger rows. Never substitute one for another.
- One authoritative total. Every call site you found belongs in the category summary and the grand total. Never park real findings in an "additional observations" section that the totals exclude.
- Classify by what the member touches, not by whether it is
static. Instance members that reach the same untestable resource still count and belong in the matching category (new FileInfo(path).LastWriteTimeUtc → File System; new HttpClient().GetAsync(...) → Network). Say "hidden dependency", not "static", when the member is an instance call.
- Check receiver provenance before counting instance calls. Count a resource access only when the code under test acquires or constructs the dependency itself. Exclude constructor-, parameter-, property-, and DI-injected collaborators from the "needs wrapping" total, including concrete
HttpClient instances.
- Exclude deterministic pure helpers from the "needs wrapping" total.
Path.Combine, Path.GetExtension, Path.GetFileName, and Math.*/string.* statics take no ambient input and are trivially testable. List them, if at all, in a separate "no action needed" note — never as testability blockers.
- Cover every category before reporting — time, file system, environment, network, console, process, randomness (
new Random(), Guid.NewGuid()), culture (CultureInfo.CurrentCulture), and serialization/statics such as JsonSerializer. Omitting a category that is present is an under-count.
- Give
file:line for every occurrence so the user can jump straight to it.
- Reconcile before publishing. The category totals, the top-patterns table, and the per-file table must sum to the same grand total.
- Treat exclusions as a scope decision, not a category. Remove
obj/,
bin/, generated, and user-excluded files before building the ledger. Do not
include their files or call sites in any reported count. State the exclusions
once rather than mixing excluded candidates into the arithmetic.
- Label truncated rankings. In a comprehensive audit, list all distinct
patterns when needed for reconciliation. If the user asked only for a top-N
subset, label it as a subset and do not imply that its rows sum to the grand
total.
Produce a summary with:
- Category summary — total call sites per category (time, filesystem, env, etc.)
- Top patterns — the 10 most frequent individual patterns ranked by count
- Most affected files — files with the highest number of static dependencies
- Existing abstractions available — for each category, note the recommended .NET abstraction:
- Time →
TimeProvider (built-in since .NET 8)
- File system →
System.IO.Abstractions (NuGet package)
- HTTP →
IHttpClientFactory (built-in)
- Environment → custom
IEnvironmentProvider
- Console → custom
IConsole or ILogger
- Process → custom
IProcessRunner
Step 4: Present the report
Format the output as a structured report:
## Static Dependency Report
**Scope**: <project/solution name>
**Files scanned**: <count>
**Total static call sites**: <count>
### Category Summary
| Category | Call Sites | Recommended Abstraction |
|-------------|-----------|------------------------|
| Time | 42 | TimeProvider (.NET 8+) |
| File System | 31 | System.IO.Abstractions |
| Environment | 12 | IEnvironmentProvider |
| ... | ... | ... |
### Top 10 Patterns
| # | Pattern | Count | Files |
|---|---------------------|-------|-------|
| 1 | DateTime.UtcNow | 28 | 14 |
| 2 | File.ReadAllText | 18 | 9 |
| ... |
### Most Affected Files
| File | Static Calls | Categories |
|-------------------------------|-------------|---------------------|
| Services/OrderProcessor.cs | 12 | Time, FileSystem |
| ... |
### Migration Priority
1. **Time** (42 sites) — Use `TimeProvider`, zero NuGet dependencies on .NET 8+
2. **File System** (31 sites) — Use `System.IO.Abstractions` NuGet package
3. ...
Step 5: Suggest next steps
Based on the report, recommend which category to tackle first (highest count, best built-in support). Keep this to a few lines.
Mention generate-testability-wrappers or migrate-static-to-wrapper only when the user's next action clearly needs them — a hand-off note, not a sales pitch. Never end an audit with promotional next-steps that dilute the findings.
Validation
Common Pitfalls
| Pitfall |
Solution |
Scanning obj/ or generated code |
Always exclude obj/, bin/, and *.Designer.cs |
| Counting calls on injected collaborators |
Trace the receiver: an injected HttpClient, TimeProvider, interface, or other caller-supplied dependency already has a seam and needs no replacement |
| Missing statics inside lambdas/LINQ |
Search covers all code within .cs files, including lambdas |
Recommending TimeProvider on < .NET 8 |
Check TargetFramework in .csproj — if < net8.0, recommend NodaTime.IClock or custom ISystemClock |
| Ignoring test projects |
Only scan production code — exclude *.Tests.csproj projects from the scan |
| Under-counting by relegating findings |
Real call sites belong in the category totals, not in a trailing "also noticed" paragraph that the totals ignore |
| Calling an instance member a static |
new FileInfo(p).LastWriteTimeUtc is an instance call but still a hidden file-system dependency — count it under File System and describe it accurately |
Recommending a wrapper for Path.Combine |
Pure, deterministic helpers need no seam; listing them as blockers makes the recommendations wrong |
1---2name: detect-static-dependencies3description: ACTIVATION PREREQUISITE: the request or discovered target must explicitly identify C#, .NET, `.cs`, or `.csproj`; otherwise stay dormant without invoking this skill. USE FOR: locating System.DateTime.Now/UtcNow, System.IO.File/Directory, System.Environment, HttpClient, Console, or Process usage in C#; auditing C# code for hard-to-test framework dependencies; or verifying those C# calls are already abstracted. DO NOT USE FOR: any target lacking the activation prerequisite; generating wrappers (use generate-testability-wrappers); migrating code (use migrate-static-to-wrapper); or general code review.4license: MIT5---6
7# Detect Static Dependencies
8
9Scan a C# codebase for calls to hard-to-test static APIs and produce a ranked report showing which statics appear most frequently, which files are most affected, and which abstractions already exist in the .NET ecosystem to replace them.
10
11## When to Use
12
13- Auditing a project's testability before adding unit tests
14- Understanding the scope of static coupling in a legacy codebase
15- Prioritizing which statics to wrap first (highest-frequency wins)
16- Creating a migration plan for incremental testability improvements
17
18## Response Guidelines
19
20- Scale the response to the user's request. A question about a specific category (e.g., "find time statics") should focus on that category with file locations and counts, not produce a full report across all categories.
21- When the user provides a specific file or directory path, scan only that scope — do not expand to the entire solution unless asked.
22- The full structured report format in Step 4 is for comprehensive audit requests. For focused questions, return only the relevant subset (e.g., category summary + affected files for the requested category).
23
24## Execution Contract
25
26- A relative path named in the prompt is enough to start. Discover it with the
27 available file-listing tools and scan it immediately; do not ask the user to
28 provide or re-upload files before both discovery and a content search fail.
29- Start with a recursive, line-numbered content search over eligible `.cs`
30 files. Do not search only for the `static` keyword: ambient calls inside
31 LINQ expressions, lambdas, callbacks, and interpolated strings usually have
32 no `static` modifier.
33- If a file-reading tool fails on a path that listing or search proved exists,
34 classify the failure before retrying. Fall back to another available
35 mechanism such as `rg -n`, grep, or a shell file reader only for confirmed
36 tool availability, transport, or path-normalization failures and only after
37 verifying the canonical path remains inside the workspace. Stop on
38 content-exclusion, permission/policy, workspace-boundary, or unknown failures.
39 Search output can seed the occurrence ledger; open only the surrounding code
40 needed to verify receiver provenance.
41- Never stop after loading this skill or announcing a scan plan. Return the
42 completed audit in the same response. If every fallback genuinely fails,
43 report the verified partial findings and the exact limitation; do not invent
44 findings or replace the audit with a request to rerun.
45
46## When Not to Use
47
48- The user wants wrappers generated (hand off to `generate-testability-wrappers`)
49- The user wants mechanical migration done (hand off to `migrate-static-to-wrapper`)
50- The statics are already behind interfaces or `TimeProvider`
51- The code is not C# / .NET
52
53## Inputs
54
55| Input | Required | Description |
56|-------|----------|-------------|
57| Target path | No | A file, directory, project (.csproj), or solution (.sln) to scan. Defaults to the current workspace. |
58| Exclusion patterns | No | Glob patterns to skip (e.g., `**/obj/**`, `**/Migrations/**`) |
59| Category filter | No | Limit to specific categories: `time`, `filesystem`, `environment`, `network`, `console`, `process` |
60
61## Workflow
62
63### Step 1: Determine scan scope
64
65Resolve the target to a set of `.cs` files:
66- Treat a prompt-named workspace-relative path as the target; locate it rather
67 than asking the user for an absolute path.
68- If omitted, scan every eligible `.cs` file under the current workspace; do not
69 pick one project and silently omit its siblings.
70- If a `.cs` file, scan that single file.
71- If a directory, scan all `.cs` files recursively (excluding `obj/`, `bin/`).
72- If a `.csproj`, find its directory and scan `.cs` files within.
73- If a `.sln`, parse it, find all project directories, and scan `.cs` files across all projects.
74
75Always exclude `obj/`, `bin/`, and any user-specified exclusion patterns.
76
77### Step 2: Search for static dependency patterns
78
79Scan each file for calls matching these categories:
80
81Treat pattern matches as candidates, not findings. Before counting an instance call, trace how its
82receiver enters the class. A collaborator supplied through a constructor, parameter, property, or
83dependency injection (DI) is already a test seam. In particular, an injected `HttpClient` is
84testable with a controlled `HttpMessageHandler`; do not count its calls or recommend replacing it
85merely because the injected type is concrete.
86
87| Category | Patterns to search for | Recommended replacement |
88|----------|----------------------|------------------------|
89| **Time** | `DateTime.Now`, `DateTime.UtcNow`, `DateTime.Today`, `DateTimeOffset.Now`, `DateTimeOffset.UtcNow`, `Task.Delay(`, `new CancellationTokenSource(TimeSpan` | `TimeProvider` (.NET 8+) |
90| **File System** | `File.ReadAllText(`, `File.WriteAllText(`, `File.Exists(`, `File.Delete(`, `File.Copy(`, `File.Move(`, `Directory.Exists(`, `Directory.CreateDirectory(`, `Directory.GetFiles(`, `Directory.Delete(`, `Path.GetTempPath(`, and instance members that hit the disk (`new FileInfo(...)`, `new DirectoryInfo(...)`, `.LastWriteTimeUtc`, `new StreamReader(path)`) | `IFileSystem` (System.IO.Abstractions NuGet) |
91| **Randomness / identity** | `new Random(`, `Random.Shared`, `Guid.NewGuid(` | `TimeProvider`-style seam: inject `Random` / an `IGuidProvider` |
92| **Culture / serialization** | `CultureInfo.CurrentCulture`, `CultureInfo.CurrentUICulture`, `JsonSerializer.Serialize(`, `JsonSerializer.Deserialize(` | Pass culture/options explicitly, or inject a serializer abstraction |
93| **Environment** | `Environment.GetEnvironmentVariable(`, `Environment.SetEnvironmentVariable(`, `Environment.MachineName`, `Environment.UserName`, `Environment.CurrentDirectory`, `Environment.Exit(` | Custom `IEnvironmentProvider` |
94| **Network** | `new HttpClient(`, `.GetAsync(`, `.PostAsync(`, `.SendAsync(` (confirm the receiver is an `HttpClient`; exclude calls whose receiver is injected or produced by an injected factory) | Inject `HttpClient` (commonly supplied by `IHttpClientFactory`) |
95| **Console** | `Console.WriteLine(`, `Console.ReadLine(`, `Console.Write(`, `Console.ReadKey(` | `IConsole` wrapper or `ILogger` |
96| **Process** | `Process.Start(`, `Process.GetCurrentProcess(`, `Process.GetProcessesByName(` | Custom `IProcessRunner` |
97
98For time calls, inspect use as well as count. Two ambient clock reads in one
99logical operation are two call sites and a consistency defect: for example,
100separate `DateTime.UtcNow` reads for `CreatedAt` and
101`ExpiresAt = DateTime.UtcNow.AddDays(30)` can drift. Recommend one captured
102instant. With `TimeProvider`, retain `DateTimeOffset` where possible; when the
103existing member requires UTC `DateTime`, use `GetUtcNow().UtcDateTime`, never
104`.DateTime`, which loses the UTC kind. Treat capturing one instant as an
105optional behavior-level follow-up: a mechanical wrapper migration must preserve
106the original reads one-for-one unless the user separately approves that
107semantic change.
108
109### Step 3: Aggregate and rank results
110
111Count each call site across the entire scan scope — including the instance-member call sites covered by the rules below, not only `static` ones.
112
113**Counting rules — inaccurate totals are the main way this report loses to an ad-hoc scan:**
114
115- **Build one occurrence ledger before writing prose.** Give each included call
116 site exactly one row containing category, exact pattern, `file:line`, and
117 recommended seam. Derive every category, pattern, and per-file count by
118 grouping that same ledger; never recount independently while writing tables.
119- **Keep the three count domains separate.** `Files scanned` includes every
120 eligible source file; `affected files` includes only files with ledger rows;
121 `call sites` is the number of ledger rows. Never substitute one for another.
122- **One authoritative total.** Every call site you found belongs in the category summary and the grand total. Never park real findings in an "additional observations" section that the totals exclude.
123- **Classify by what the member touches, not by whether it is `static`.** Instance members that reach the same untestable resource still count and belong in the matching category (`new FileInfo(path).LastWriteTimeUtc` → File System; `new HttpClient().GetAsync(...)` → Network). Say "hidden dependency", not "static", when the member is an instance call.
124- **Check receiver provenance before counting instance calls.** Count a resource access only when the code under test acquires or constructs the dependency itself. Exclude constructor-, parameter-, property-, and DI-injected collaborators from the "needs wrapping" total, including concrete `HttpClient` instances.
125- **Exclude deterministic pure helpers from the "needs wrapping" total.** `Path.Combine`, `Path.GetExtension`, `Path.GetFileName`, and `Math.*`/`string.*` statics take no ambient input and are trivially testable. List them, if at all, in a separate "no action needed" note — never as testability blockers.
126- **Cover every category before reporting** — time, file system, environment, network, console, process, randomness (`new Random()`, `Guid.NewGuid()`), culture (`CultureInfo.CurrentCulture`), and serialization/statics such as `JsonSerializer`. Omitting a category that is present is an under-count.
127- **Give `file:line` for every occurrence** so the user can jump straight to it.
128- **Reconcile before publishing.** The category totals, the top-patterns table, and the per-file table must sum to the same grand total.
129- **Treat exclusions as a scope decision, not a category.** Remove `obj/`,
130 `bin/`, generated, and user-excluded files before building the ledger. Do not
131 include their files or call sites in any reported count. State the exclusions
132 once rather than mixing excluded candidates into the arithmetic.
133- **Label truncated rankings.** In a comprehensive audit, list all distinct
134 patterns when needed for reconciliation. If the user asked only for a top-N
135 subset, label it as a subset and do not imply that its rows sum to the grand
136 total.
137
138Produce a summary with:
139
1401. **Category summary** — total call sites per category (time, filesystem, env, etc.)
1412. **Top patterns** — the 10 most frequent individual patterns ranked by count
1423. **Most affected files** — files with the highest number of static dependencies
1434. **Existing abstractions available** — for each category, note the recommended .NET abstraction:
144 - Time → `TimeProvider` (built-in since .NET 8)
145 - File system → `System.IO.Abstractions` (NuGet package)
146 - HTTP → `IHttpClientFactory` (built-in)
147 - Environment → custom `IEnvironmentProvider`
148 - Console → custom `IConsole` or `ILogger`
149 - Process → custom `IProcessRunner`
150
151### Step 4: Present the report
152
153Format the output as a structured report:
154
155```
156## Static Dependency Report
157
158**Scope**: <project/solution name>
159**Files scanned**: <count>
160**Total static call sites**: <count>
161
162### Category Summary
163| Category | Call Sites | Recommended Abstraction |
164|-------------|-----------|------------------------|
165| Time | 42 | TimeProvider (.NET 8+) |
166| File System | 31 | System.IO.Abstractions |
167| Environment | 12 | IEnvironmentProvider |
168| ... | ... | ... |
169
170### Top 10 Patterns
171| # | Pattern | Count | Files |
172|---|---------------------|-------|-------|
173| 1 | DateTime.UtcNow | 28 | 14 |
174| 2 | File.ReadAllText | 18 | 9 |
175| ... |
176
177### Most Affected Files
178| File | Static Calls | Categories |
179|-------------------------------|-------------|---------------------|
180| Services/OrderProcessor.cs | 12 | Time, FileSystem |
181| ... |
182
183### Migration Priority
1841. **Time** (42 sites) — Use `TimeProvider`, zero NuGet dependencies on .NET 8+
1852. **File System** (31 sites) — Use `System.IO.Abstractions` NuGet package
1863. ...
187```
188
189### Step 5: Suggest next steps
190
191Based on the report, recommend which category to tackle first (highest count, best built-in support). Keep this to a few lines.
192
193Mention `generate-testability-wrappers` or `migrate-static-to-wrapper` only when the user's next action clearly needs them — a hand-off note, not a sales pitch. Never end an audit with promotional next-steps that dilute the findings.
194
195## Validation
196
197- [ ] All `.cs` files in scope were scanned (check count)
198- [ ] Report includes category totals, top patterns, and affected files
199- [ ] Category totals, top patterns, and per-file counts reconcile to the same grand total
200- [ ] Files scanned, affected files, and call sites are reported as different quantities
201- [ ] Every aggregate was derived from one occurrence ledger rather than independently recounted
202- [ ] Every occurrence carries a `file:line` location
203- [ ] No findings are held outside the totals in an "additional" section
204- [ ] Calls on injected collaborators are excluded from the "needs wrapping" total
205- [ ] Deterministic pure helpers (`Path.Combine`, `Math.*`) are not counted as testability blockers
206- [ ] Each detected pattern has a recommended replacement listed
207- [ ] `obj/` and `bin/` directories were excluded
208- [ ] Migration priority is ordered by impact (count × ease of replacement)
209
210## Common Pitfalls
211
212| Pitfall | Solution |
213|---------|----------|
214| Scanning `obj/` or generated code | Always exclude `obj/`, `bin/`, and `*.Designer.cs` |
215| Counting calls on injected collaborators | Trace the receiver: an injected `HttpClient`, `TimeProvider`, interface, or other caller-supplied dependency already has a seam and needs no replacement |
216| Missing statics inside lambdas/LINQ | Search covers all code within `.cs` files, including lambdas |
217| Recommending `TimeProvider` on < .NET 8 | Check `TargetFramework` in `.csproj` — if < net8.0, recommend `NodaTime.IClock` or custom `ISystemClock` |
218| Ignoring test projects | Only scan production code — exclude `*.Tests.csproj` projects from the scan |
219| Under-counting by relegating findings | Real call sites belong in the category totals, not in a trailing "also noticed" paragraph that the totals ignore |
220| Calling an instance member a static | `new FileInfo(p).LastWriteTimeUtc` is an instance call but still a hidden file-system dependency — count it under File System and describe it accurately |
221| Recommending a wrapper for `Path.Combine` | Pure, deterministic helpers need no seam; listing them as blockers makes the recommendations wrong |