Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Analyze Oss

ASecurity

Analyze an open-source project from What/Why perspective (not how-it's-implemented). Use when the user says "/analyze-oss", "분석해줘 이 오픈소스", "이 레포 뭐하는거야", "analyze this repo", "what does X do", "이거 왜 쓰는거야", "이 라이브러리 분석", provides a GitHub URL and wants understanding, or asks to deeply understand an OSS project's purpose, value, target users, and usage flow. Clones the repo to ~/opensource-analysis/<repo-name>/ (git pull if already exists), dispatches parallel subagents per analysis lens, then s...

174 stars
0 votes
0 copies
3 views
Added 9/9/2026
documentationgobashgitapi

Works with

cliapi

Security Analysis

A100/100

Scanned 9/9/2026

$npx -y skills add team-attention/hoyeon --skill analyze-oss --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Analyze Oss?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Analyze Oss
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/team-attention-analyze-oss/badge)](https://www.skillsdirectory.com/skills/team-attention-analyze-oss)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: analyze-oss
description: |
  Analyze an open-source project from What/Why perspective (not how-it's-implemented).
  Use when the user says "/analyze-oss", "분석해줘 이 오픈소스", "이 레포 뭐하는거야",
  "analyze this repo", "what does X do", "이거 왜 쓰는거야", "이 라이브러리 분석",
  provides a GitHub URL and wants understanding, or asks to deeply understand
  an OSS project's purpose, value, target users, and usage flow.
  Clones the repo to ~/opensource-analysis/<repo-name>/ (git pull if already exists),
  dispatches parallel subagents per analysis lens, then synthesizes a What/Why-focused
  report in chat. Supports optional user-specific follow-up questions.
validate_prompt: |
  Output must contain these sections:
  - What (one-line definition + core capabilities)
  - Why (problem solved, alternatives, differentiator)
  - Who / When (target users, use cases)
  - How it's used (user-perspective flow, not implementation)
  - (If user provided custom questions) Custom Q&A section
  Output must start with "## Analyze OSS:" header.
---

# Analyze OSS — What/Why-focused open source analyzer

Clone an open-source repo locally, analyze it through multiple lenses in parallel
via subagents, and deliver a **What/Why-focused** report in chat.

The goal is **not** to produce an implementation deep-dive. The goal is to help
the user quickly decide "is this what I need, and why would I use it?" and then
answer any custom questions they have about the repo.

## When to use

- User gives a GitHub URL and wants to understand what it is / why it exists
- User asks "what does this repo do?", "이거 뭐하는거야?", "이거 왜 쓰는거야?"
- User is evaluating whether to adopt a library
- User wants a quick intellectual onboarding to an OSS project

## Input

Accept any of:
- GitHub URL: `https://github.com/owner/repo` (or `git@github.com:...`)
- `owner/repo` shorthand
- Optional custom questions appended: `analyze-oss owner/repo "X 대비 어떤지, Y 유스케이스 맞는지"`

If the URL is ambiguous, ask the user to confirm before cloning.

## Execution

### Phase 1 — Fetch repo

Target directory: `~/opensource-analysis/<repo-name>/`

```bash
BASE=~/opensource-analysis
REPO_NAME=<derived from URL>
TARGET=$BASE/$REPO_NAME
mkdir -p $BASE
if [ -d "$TARGET/.git" ]; then
  cd "$TARGET" && git pull --ff-only
else
  git clone --depth 50 <repo-url> "$TARGET"
fi
```

Notes:
- `--depth 50` keeps clone fast; enough for recent commit signals.
- If `git pull` fails (local changes, diverged), warn the user — don't force.
- Capture the absolute path of `$TARGET`; all subagents must use this absolute path.

### Phase 2 — Quick recon (main agent, before dispatch)

Read these in parallel to build dispatch context (don't deep-read, just skim):
- `README*` (pick the most prominent)
- `package.json` / `pyproject.toml` / `Cargo.toml` / `go.mod` (whichever exist)
- Top-level directory listing
- `docs/` top-level listing if present
- Recent 10 commits: `git log --oneline -10`

Extract: repo name, elevator pitch (if README has one), primary language, rough size.

This recon is **only** to brief subagents well — do not write the report yet.

### Phase 3 — Parallel subagent dispatch

Spawn the following subagents in **one message, in parallel**. Each gets:
- Absolute path to the cloned repo
- The recon summary from Phase 2
- Instructions to read only what they need (not the whole repo)
- Instruction to return a structured markdown block

**Subagents (4 default lenses):**

1. **what-lens** — "What is this?"
   - Read: README, top-level docs, package descriptions
   - Produce: one-line definition (≤25 words), 3–5 core capabilities (one sentence each), the repo's own self-description verbatim if useful
   - Avoid implementation detail. Stay at the "capabilities the user gets" layer.

2. **why-lens** — "Why does this exist?"
   - Read: README motivation/intro sections, CHANGELOG for origin context, any `MOTIVATION.md` / `docs/why*`
   - Produce: the problem it solves (in plain language), what you'd have to do without it, 2–3 named alternatives and how this differs, the distinct value proposition
   - If motivation is not explicit, infer from the examples and features — but mark inferences as "[inferred]".

3. **who-when-lens** — "Who uses this, and when?"
   - Read: README use-cases/examples, `examples/`, showcase/users sections, issues labeled "question" or similar for real-world usage signals
   - Produce: target user personas (2–4), concrete use cases (with short scenarios), situations where you'd *not* use this / known limitations

4. **how-used-lens** — "How does a user actually use this?" (user-perspective, not implementation)
   - Read: Quickstart in README, `examples/`, minimal usage snippets
   - Produce: install step, minimal "hello world", typical usage flow from zero → first success (as a narrative, not code walkthrough), main interaction touchpoints (CLI? API? config file? SDK?)
   - Explicitly exclude internal architecture, source-level design, class diagrams.

**If the user provided custom questions**, spawn one more subagent per distinct question:

5. **custom-Q{n}-lens** — answer one specific user question
   - Brief it with the full question verbatim and the recon summary
   - Tell it to read whatever files it needs (grep liberally) to answer, and to cite file paths in its answer
   - If it cannot answer from the repo alone, say so — don't fabricate

### Phase 4 — Synthesize

Main agent takes all subagent outputs and composes the final report in chat.

**Output template** (strict):

```markdown
## Analyze OSS: <repo-name>

**Repo:** <url>  ·  **Language:** <lang>  ·  **Cloned at:** <abs path>

### What
<one-line definition>

**Core capabilities:**
- …
- …

### Why
**Problem:** <plain language>
**Without it:** <what you'd do otherwise>
**Alternatives & differentiator:** <named alternatives, 1 line each, then what makes this different>

### Who / When
**Target users:** …
**Use cases:** …
**Not a good fit when:** …

### How it's used (user perspective)
**Install:** `…`
**Minimal example:** <short snippet or description — keep brief>
**Typical flow:** <zero-to-first-success narrative, 3–6 steps>
**Interaction surface:** <CLI / HTTP API / SDK / config / etc.>

### Custom Q&A   ← only if user provided questions
**Q: <question>**
A: <answer with file path citations>

### Notes
- [inferred] markers if any
- Anything surprising / red flags / caveats worth surfacing
```

### Phase 5 — Offer follow-ups

After delivering the report, ask:
> "Anything you want me to dig into further? (e.g. compare with X, how auth works, licensing details, etc.)"

For follow-ups, dispatch additional subagents with the same pattern — one question, one subagent — and extend the Custom Q&A section.

## Principles

- **What/Why over How.** The user does not want an architecture lecture. Unless they explicitly ask "how is X implemented", stay at the user-facing layer.
- **Parallel by default.** All independent lenses go in one message. Sequential dispatch wastes wall-clock time.
- **Cite file paths** when claiming something about the repo. "README says X" is better than just "X".
- **Mark inferences.** If something isn't stated in the repo, say `[inferred]`.
- **Don't overclaim popularity or quality.** You have shallow clone + local info; avoid "this is widely used" unless README/shields show it.
- **Chat output only.** Do not write a report file unless the user explicitly asks.

## Edge cases

- **Private or 404 repo:** git clone will fail — surface the error and ask the user.
- **Huge repo (>500MB):** `--depth 50` already helps; if still slow, warn the user and proceed.
- **Monorepo:** if the repo contains multiple packages, ask the user which sub-package to focus on before dispatching subagents (or offer an overview of all packages).
- **Non-code repos (awesome-lists, docs):** adapt — the "how it's used" lens becomes "how do you navigate/consume this".
- **Stale clone with local changes:** don't overwrite. Report to user, ask whether to re-clone fresh into a sibling directory.

Attribution

team-attentionteam-attention
View sourceSee grades on GitHubMore from team-attention →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Context Fundamentals

Understand the components, mechanics, and constraints of context in agent systems. Use when designing agent architectures, debugging context-related failures, or optimizing context usage.

179001 votes

Architecture Diagram Creator

Create comprehensive HTML architecture diagrams with data flows, business context, and system architecture.

6661 votes

release-notes

Draft release notes and changelog entries from git history or merged PRs between two refs (tags/SHAs/branches), including breaking changes, migrations, and upgrade steps. Use when the user asks for release notes, changelog updates, or a GitHub Release draft.

1301 votes

docs-style-guide

Documentation style guide enforcer by @planetabhi. Applies and reviews the writing style guide when authoring or editing product documentation and tutorials. Use to check prose for voice, tense, word choice, inclusive language, formatting, code block, UI, Markdown, and number/date conventions.

11 votes

Docx

Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in W...

1789400 votes
View all in documentation →