Code quality review for WinUI 3 apps — MVVM compliance, x:Bind correctness, accessibility, theming, security, and performance. Use before committing to catch issues that the compiler and UI tests won't find.
npx skills add https://github.com/microsoft/win-dev-skills --skill winui-code-review
Run a code review after the app builds and before committing. This catches quality issues that aren't build errors and aren't visible in UI tests — patterns that compile and run but are wrong, fragile, or slow.
Read through the project's XAML and C# files and check each section below. The Microsoft.WindowsAppSDK.Analyzers Roslyn analyzer ships with the winui-dev-workflow skill and is injected into your build when you compile via the BuildAndRun.ps1 script that ships with that skill — the script drops a temporary Directory.Build.props into the project that loads the analyzer DLL and its .targets, then cleans up after the build. Plain dotnet build (or VS) does not load the analyzer automatically; if you want it to surface as build diagnostics outside the script, add the <Analyzer Include="..." /> and <Import Project="..." /> to your project's own Directory.Build.props (or wait for the planned NuGet package).
The analyzer catches a curated set of WinUI 3 / Windows App SDK issues with categorized 4-digit IDs:
UwpXamlNamespace, Window.Current, CoreDispatcher, GetForCurrentView)TabView content, nested x:Bind without fallback, x:Bind without Mode, null Converter, missing AutomationId, attached-property syntax)[ObservableProperty] field syntax)WebView2 not initialized, removed ONNX Runtime GenAI APIs WUI4101-WUI4103)Every diagnostic ships at Warning severity (no rule is Error) and includes a helpLinkUri. Suppress noise with #pragma warning disable WUIxxxx or <NoWarn> as usual — the analyzer's SuppressionTests verify that pragma suppression round-trips correctly.
ObservableObject, use [ObservableProperty] partial properties (not fields)[RelayCommand] attribute, not manual ICommand implementationsSolidColorBrush, Visibility, BitmapImage) — these belong in converters or XAMLasync Task for async methods, async void only for event handlersObservableCollection<T> — use .Clear() + re-add{x:Bind}, not {Binding}Mode=OneWay or TwoWay set explicitly — OneTime default causes blank UI for dynamic datax:DataType set on every DataTemplate — required for compiled x:BindViewModel.Selected.Name) without FallbackValueMode=OneWay to Command="{x:Bind}"AutomationProperties.AutomationId on every interactive control (Button, TextBox, ComboBox, ToggleSwitch, ListView, NavigationViewItem)AutomationProperties.Name on icon-only buttons and controls without visible textButton, HyperlinkButton) — not clickable Border/TextBlock{ThemeResource} brushes — no hardcoded #FF0000 or Color="Blue"TitleTextBlockStyle, SubtitleTextBlockStyle, BodyTextBlockStyle, CaptionTextBlockStyle) — no raw FontSizeControlCornerRadius / OverlayCornerRadius — not hardcoded values{StaticResource} not {ThemeResource} (except for brush usage sites)Process.Start with unsanitized user inputFile.Delete / File.WriteAllText without validationListView/GridView (virtualized), not StackPanel with foreachx:Load for content that's not always visible (e.g., dialogs, secondary panels)Task.Run or async/await — never block UI.Result / .Wait() / .GetAwaiter().GetResult() — these deadlock the UI threadusing statements on all disposable objects (Model, Tokenizer, InferenceSession, Generator)x:Uid in XAML and ResourceLoader in C# — not hardcodedStrings/en-us/Resources.resw (not .resx)CultureInfo.CurrentCulture — not hardcoded formatsFlowDirection inherited from root, no absolute positioning that breaks in RTL)string.Format or interpolation with resource stringsAfter reviewing, summarize:
For detailed rules with code examples, see references/quality-rules.md — covers performance deep dives (x:Phase, layout optimization), security (PasswordVault, DPAPI, WebView2 hardening), accessibility (keyboard nav, screen readers), code quality (.editorconfig, naming), and globalization (x:Uid patterns, RTL, pluralization).
Execute git commit with conventional commit message analysis, intelligent staging, and message generation. Use when user asks to commit changes, create a git commit, or mentions "/commit". Supports: (1) Auto-detecting type and scope from changes, (2) Generating conventional commit messages from diff, (3) Interactive commit with optional type/scope/description overrides, (4) Intelligent file staging for logical grouping
Comprehensive GitHub code review with AI-powered swarm coordination
Create high-quality git commits: review/stage intended changes, split into logical commits, and write clear commit messages (including Conventional Commits). Use when the user asks to commit, craft a commit message, stage changes, or split work into multiple commits.
Comprehensive truth scoring, code quality verification, and automatic rollback system with 0.95 accuracy threshold for ensuring high-quality agent outputs and codebase reliability.
GitHub CLI (gh) comprehensive reference for repositories, issues, pull requests, Actions, projects, releases, gists, codespaces, organizations, extensions, and all GitHub operations from the command line.
GitHub CLI - manage repositories, issues, pull requests, actions, releases, and more from the command line.
You are a code refactoring expert specializing in clean code principles, SOLID design patterns, and modern software engineering best practices. Analyze and refactor the provided code to improve its quality, maintainability, and performance.
You are a technical debt expert specializing in identifying, quantifying, and prioritizing technical debt in software projects. Analyze the codebase to uncover debt, assess its impact, and create acti
Take microsoft/winui-code-review from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.