npx skills add ...
npx skills add dotnet/skills --skill crap-score
Calculates CRAP (Change Risk Anti-Patterns) for a named .NET method, class, or file. USE FOR: explicit CRAP calculation or coverage-and-complexity risk within that named target, including which tests to prioritize. DO NOT USE FOR: project-wide coverage/CRAP, plateaus, or project-wide blockers/priorities (coverage-analysis); behavioral/pseudo-mutation gaps (test-gap-analysis); writing tests; test runs without CRAP context.
npx skills add dotnet/skills --skill crap-score
Calculate CRAP (Change Risk Anti-Patterns) scores for .NET methods to identify code that is both complex and undertested.
The CRAP score combines cyclomatic complexity and code coverage into a single metric:
$$\text{CRAP}(m) = \text{comp}(m)^2 \times (1 - \text{cov}(m))^3 + \text{comp}(m)$$
Where:
| CRAP Score | Risk Level | Interpretation |
|---|---|---|
| < 5 | Low | Simple and well-tested |
| 5 to < 15 | Moderate | Acceptable for most code |
| 15 to 30 | High | Needs more tests or simplification |
| > 30 | Critical | Refactor and add coverage urgently |
A method with 100% coverage has CRAP = complexity (the minimum). A method with 0% coverage has CRAP = complexity^2 + complexity.
run-tests skill)code-testing-agent)coverage-analysis)| Input | Required | Description |
|---|---|---|
| Target scope | Yes | Method name, class name, or file path to analyze |
| Test project path | No | Path to the test project. Defaults to discovering test projects in the solution. |
| Source project path | No | Path to the source project under analysis |
If no coverage data exists yet, classify the test project first. For SDK-style
projects, run dotnet test with coverage collection. For classic non-SDK
projects (ToolsVersion, explicit compile items, or packages.config), use only
a repository-provided coverage command that emits Cobertura. If none exists,
ask for Cobertura XML and stop; do not migrate the project or inject an SDK-style
coverage package. CRAP scores always require real coverage data.
Check the test project's .csproj for the coverage package, then run the appropriate command:
| Coverage Package | Command | Output Location |
|---|---|---|
coverlet.collector | dotnet test --collect:"XPlat Code Coverage" --results-directory ./TestResults | Typically under TestResults/<guid>/coverage.cobertura.xml. Search recursively under the results directory (for example, TestResults/**/coverage.cobertura.xml) or use any explicit coverage path the user provides. |
Microsoft.Testing.Extensions.CodeCoverage (.NET 9) | dotnet test -- --coverage --coverage-output-format cobertura --coverage-output ./TestResults | --coverage-output path |
Microsoft.Testing.Extensions.CodeCoverage (.NET 10+) | dotnet test --coverage --coverage-output-format cobertura --coverage-output ./TestResults | --coverage-output path |
Guessed coverage produces wrong CRAP scores, which is worse than no answer. For a classic project with no repository coverage command or existing report, stop here and request Cobertura; do not use any collection fallback below.
For SDK-style projects, if the first command yields no Cobertura XML, work down this collection list before giving up:
dotnet add <test.csproj> package coverlet.collector, then re-run. Never use
this fallback for packages.config or classic non-SDK projects.dotnet tool install --global dotnet-coverage then
dotnet-coverage collect -f cobertura -o coverage.cobertura.xml "dotnet test <test.csproj>".For any project type, if a real binary .coverage report already exists, convert
or summarize that existing data with ReportGenerator:
dotnet tool install --global dotnet-reportgenerator-globaltool then
reportgenerator -reports:<file> -targetdir:cov -reporttypes:Cobertura.If every path fails, report that coverage could not be collected, show the commands you tried and their errors, and stop. Report complexity on its own if useful, but never publish a CRAP number derived from an assumed coverage percentage.
Before using a report, verify that it parses, contains at least one class and method, and contains the requested target. An empty report or a report that omits the target is failed collection or filtering, not 0% coverage. Regenerate coverage when possible; otherwise stop without publishing a CRAP score.
If the user supplies an existing report, state that it was not regenerated. Do not describe its data as current unless its provenance is established by running the repository's coverage command in this analysis.
Prefer a machine-produced per-method complexity from a repository-provided code
metrics report or from the Cobertura method's complexity attribute when that
report maps to the current source. Microsoft.CodeAnalysis.Metrics can generate
method-level CyclomaticComplexity data through msbuild /t:Metrics, but do
not add the package or modify the project without user approval.
If no machine-produced metric exists, analyze the current target source and label the result as a manual complexity count. Count the following decision points (each adds 1 to the base complexity of 1):
| Construct | Example |
|---|---|
if | if (x > 0) |
else if | else if (y < 0) |
case (each) | case 1: |
for | for (int i = 0; ...) |
foreach | foreach (var item in list) |
while | while (running) |
do...while | do { } while (cond) |
catch (each) | catch (Exception ex) |
&& | if (a && b) |
|| (OR) | if (a || b) |
?? | value ?? fallback |
?. | obj?.Method() |
? : (ternary) | x > 0 ? a : b |
| Pattern match arm | x is > 0 and < 10 |
Base complexity is 1 for every method. Each decision point adds 1.
When counting manually, read the source file, report the construct-by-construct breakdown, and do not use a source comment as evidence. If the report's complexity attribute disagrees with the current-source count, report the conflict and do not present either resulting CRAP score as authoritative.
Parse the Cobertura XML to find each method's line-rate attribute under the target <class> element. If line-rate is not available at method level, compute it from the <lines> elements:
$$\text{cov}(m) = \frac{\text{lines with hits} > 0}{\text{total lines}}$$
Method names in Cobertura may differ from source (async methods, lambdas). Match by line ranges when names don't align.
When both line-rate and <lines> exist, recompute the hit ratio and compare
them. Allow only normal report rounding (one percentage point); if they differ
more, the report contradicts itself. Regenerate it or report the conflict and
stop without calculating CRAP. Never silently choose whichever value produces
the expected score.
For each method in scope, apply the formula:
$$\text{CRAP}(m) = \text{comp}(m)^2 \times (1 - \text{cov}(m))^3 + \text{comp}(m)$$
Use a calculator or script for the arithmetic and show the substituted complexity and coverage. Do not calculate the formula mentally.
Present a sorted table (highest CRAP first):
Include:
For high-CRAP methods, suggest one or both:
Calculate the coverage needed to bring a method below a CRAP threshold of 15:
$$\text{cov}_{\text{needed}} = 1 - \left(\frac{15 - \text{comp}}{\text{comp}^2}\right)^{1/3}$$
This formula only applies when comp < 15. When comp >= 15, the minimum possible CRAP score (at 100% coverage) is comp itself, which already meets or exceeds the threshold. In that case, coverage alone cannot bring the CRAP score below the threshold -- the method must be refactored to reduce its cyclomatic complexity first.
Report this as: "To bring ProcessOrder (complexity 10) below CRAP 15, increase coverage from 45% to more than 63.2% (at least 64% when reporting whole percentages)." For methods where complexity alone exceeds the threshold, report: "ComplexMethod (complexity 18) cannot reach CRAP < 15 through testing alone -- reduce complexity by extracting sub-methods."
line-rate against its line-hit ratio when both existline-rate with the line-hit ratio and stop if they disagree beyond rounding.// complexity: 7 comment left by a previous author is not evidence.dotnet-coverage collect runs out of process and usually succeeds where the in-proc collector fails.*.Designer.cs, *.g.cs) from analysis unless explicitly requested.