MCAF: .NET CodeQL
Trigger On
- the repo uses or wants CodeQL for .NET security analysis
- GitHub code scanning is part of the CI plan
Value
- produce a concrete project delta: code, docs, config, tests, CI, or review artifact
- reduce ambiguity through explicit planning, verification, and final validation skills
- leave reusable project context so future tasks are faster and safer
Do Not Use For
- teams that need a tool with no private-repo licensing caveat
Inputs
- the nearest
AGENTS.md
- hosting model: open-source repo, private repo, or manual CLI workflow
- current GitHub Actions workflow
Quick Start
- Read the nearest
AGENTS.md and confirm scope and constraints.
- Run this skill's
Workflow through the Ralph Loop until outcomes are acceptable.
- Return the
Required Result Format with concrete artifacts and verification evidence.
Workflow
- Treat CodeQL as a security-analysis tool, not as a style checker.
- Make the licensing and hosting model explicit before proposing it as the default gate.
- Prefer manual build mode for compiled .NET projects when precision matters.
Bootstrap When Missing
If CodeQL is not configured yet:
- Detect current state:
rg -n "codeql-action|security-events|CodeQL" .github/workflows
command -v codeql
- Prefer CI-first setup for repository scanning using
github/codeql-action/init and github/codeql-action/analyze.
- Configure explicit .NET build mode in workflow (
manual when precision matters).
- Add local CLI usage only when the task requires local query work.
- Run the workflow or local analyze path and return
status: configured or status: improved.
- If licensing or hosting constraints reject CodeQL for this repo, return
status: not_applicable with caveat documented.
Deliver
- explicit CodeQL setup or an explicit rejection with caveat documented
- reproducible CI or local commands for running CodeQL in this repo
Validate
- the chosen CodeQL path is allowed for the repo type
- build mode is documented and reproducible
Ralph Loop
Use the Ralph Loop for every task, including docs, architecture, testing, and tooling work.
- Plan first (mandatory):
- analyze current state
- define target outcome, constraints, and risks
- write a detailed execution plan
- list final validation skills to run at the end, with order and reason
- Execute one planned step and produce a concrete delta.
- Review the result and capture findings with actionable next fixes.
- Apply fixes in small batches and rerun the relevant checks or review steps.
- Update the plan after each iteration.
- Repeat until outcomes are acceptable or only explicit exceptions remain.
- If a dependency is missing, bootstrap it or return
status: not_applicable with explicit reason and fallback path.
Required Result Format
status: complete | clean | improved | configured | not_applicable | blocked
plan: concise plan and current iteration step
actions_taken: concrete changes made
validation_skills: final skills run, or skipped with reasons
verification: commands, checks, or review evidence summary
remaining: top unresolved items or none
For setup-only requests with no execution, return status: configured and exact next commands.
Load References
- read
references/codeql.md first
Example Requests
- "Set up CodeQL for this public .NET repo."
- "Explain the CodeQL caveat for private repos."
1---2name: mcaf-dotnet-codeql3description: Use the open-source CodeQL ecosystem for .NET security analysis. Use when a repo needs CodeQL query packs, CLI-based analysis on open source codebases, or GitHub Action setup with explicit licensing caveats for private repositories.4---56# MCAF: .NET CodeQL78## Trigger On910- the repo uses or wants CodeQL for .NET security analysis11- GitHub code scanning is part of the CI plan1213## Value1415- produce a concrete project delta: code, docs, config, tests, CI, or review artifact16- reduce ambiguity through explicit planning, verification, and final validation skills17- leave reusable project context so future tasks are faster and safer1819## Do Not Use For2021- teams that need a tool with no private-repo licensing caveat2223## Inputs2425- the nearest `AGENTS.md`26- hosting model: open-source repo, private repo, or manual CLI workflow27- current GitHub Actions workflow2829## Quick Start30311. Read the nearest `AGENTS.md` and confirm scope and constraints.322. Run this skill's `Workflow` through the `Ralph Loop` until outcomes are acceptable.333. Return the `Required Result Format` with concrete artifacts and verification evidence.3435## Workflow36371. Treat CodeQL as a security-analysis tool, not as a style checker.382. Make the licensing and hosting model explicit before proposing it as the default gate.393. Prefer manual build mode for compiled .NET projects when precision matters.4041## Bootstrap When Missing4243If `CodeQL` is not configured yet:44451. Detect current state:46 - `rg -n "codeql-action|security-events|CodeQL" .github/workflows`47 - `command -v codeql`482. Prefer CI-first setup for repository scanning using `github/codeql-action/init` and `github/codeql-action/analyze`.493. Configure explicit .NET build mode in workflow (`manual` when precision matters).504. Add local CLI usage only when the task requires local query work.515. Run the workflow or local analyze path and return `status: configured` or `status: improved`.526. If licensing or hosting constraints reject CodeQL for this repo, return `status: not_applicable` with caveat documented.535455## Deliver5657- explicit CodeQL setup or an explicit rejection with caveat documented58- reproducible CI or local commands for running CodeQL in this repo5960## Validate6162- the chosen CodeQL path is allowed for the repo type63- build mode is documented and reproducible6465## Ralph Loop6667Use the Ralph Loop for every task, including docs, architecture, testing, and tooling work.68691. Plan first (mandatory):70 - analyze current state71 - define target outcome, constraints, and risks72 - write a detailed execution plan73 - list final validation skills to run at the end, with order and reason742. Execute one planned step and produce a concrete delta.753. Review the result and capture findings with actionable next fixes.764. Apply fixes in small batches and rerun the relevant checks or review steps.775. Update the plan after each iteration.786. Repeat until outcomes are acceptable or only explicit exceptions remain.797. If a dependency is missing, bootstrap it or return `status: not_applicable` with explicit reason and fallback path.8081### Required Result Format8283- `status`: `complete` | `clean` | `improved` | `configured` | `not_applicable` | `blocked`84- `plan`: concise plan and current iteration step85- `actions_taken`: concrete changes made86- `validation_skills`: final skills run, or skipped with reasons87- `verification`: commands, checks, or review evidence summary88- `remaining`: top unresolved items or `none`8990For setup-only requests with no execution, return `status: configured` and exact next commands.9192## Load References9394- read `references/codeql.md` first9596## Example Requests9798- "Set up CodeQL for this public .NET repo."99- "Explain the CodeQL caveat for private repos."