Token导航 LogoToken导航TokenDH.com
前端设计external-servicegithub未标认证来源可访问许可证需确认审计通过

tech-stack-evaluator技术堆栈评估器

Agent Skill

tech-stack-evaluator 用于处理 GitHub 仓库、Issue、Pull Request 和代码协作信息,适合在 Codex、Claude、Cursor、Gemini CLI 中需要围绕仓库状态、代码变更或协作事项进行整理时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

2,305

周安装

98

GitHub Stars

103

下载量

808
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:tech-stack-evaluator(技术堆栈评估器)
来源仓库:https://github.com/borghei/claude-skills
仓库路径:skills/tech-stack-evaluator
安装命令:
npx skills add https://github.com/borghei/claude-skills --skill tech-stack-evaluator
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/borghei/claude-skills --skill tech-stack-evaluator

简介

用于技术选型对比与 TCO 分析,提供数据驱动的框架评估建议。

  • 支持生态系统健康度、安全合规性与迁移成本估算等多维度评估。
  • 输出包含加权得分与改进路线图的综合分析报告。
  • 适用于新项目技术决策或现有栈升级规划场景,需明确比较对象列表。
  • tech-stack-evaluator 属于前端设计类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Technology Stack Evaluator

Evaluate and compare technologies, frameworks, and cloud providers with data-driven analysis and actionable recommendations.

Table of Contents


Capabilities

CapabilityDescription
Technology ComparisonCompare frameworks and libraries with weighted scoring
TCO AnalysisCalculate 5-year total cost including hidden costs
Ecosystem HealthAssess GitHub metrics, npm adoption, community strength
Security AssessmentEvaluate vulnerabilities and compliance readiness
Migration AnalysisEstimate effort, risks, and timeline for migrations
Cloud ComparisonCompare AWS, Azure, GCP for specific workloads

Quick Start

Compare Two Technologies

Compare React vs Vue for a SaaS dashboard.
Priorities: developer productivity (40%), ecosystem (30%), performance (30%).

Calculate TCO

Calculate 5-year TCO for Next.js on Vercel.
Team: 8 developers. Hosting: $2500/month. Growth: 40%/year.

Assess Migration

Evaluate migrating from Angular.js to React.
Codebase: 50,000 lines, 200 components. Team: 6 developers.

Input Formats

The evaluator accepts three input formats:

Text - Natural language queries

Compare PostgreSQL vs MongoDB for our e-commerce platform.

YAML - Structured input for automation

comparison:
  technologies: ["React", "Vue"]
  use_case: "SaaS dashboard"
  weights:
    ecosystem: 30
    performance: 25
    developer_experience: 45

JSON - Programmatic integration

{
  "technologies": ["React", "Vue"],
  "use_case": "SaaS dashboard"
}

Analysis Types

Quick Comparison (200-300 tokens)

  • Weighted scores and recommendation
  • Top 3 decision factors
  • Confidence level

Standard Analysis (500-800 tokens)

  • Comparison matrix
  • TCO overview
  • Security summary

Full Report (1200-1500 tokens)

  • All metrics and calculations
  • Migration analysis
  • Detailed recommendations

Scripts

stack_comparator.py

Compare technologies with customizable weighted criteria.

python scripts/stack_comparator.py --help

tco_calculator.py

Calculate total cost of ownership over multi-year projections.

python scripts/tco_calculator.py --input assets/sample_input_tco.json

ecosystem_analyzer.py

Analyze ecosystem health from GitHub, npm, and community metrics.

python scripts/ecosystem_analyzer.py --technology react

security_assessor.py

Evaluate security posture and compliance readiness.

python scripts/security_assessor.py --technology express --compliance soc2,gdpr

migration_analyzer.py

Estimate migration complexity, effort, and risks.

python scripts/migration_analyzer.py --from angular-1.x --to react

References

DocumentContent
references/metrics.mdDetailed scoring algorithms and calculation formulas
references/examples.mdInput/output examples for all analysis types
references/workflows.mdStep-by-step evaluation workflows

Confidence Levels

LevelScoreInterpretation
High80-100%Clear winner, strong data
Medium50-79%Trade-offs present, moderate uncertainty
Low< 50%Close call, limited data

When to Use

  • Comparing frontend/backend frameworks for new projects
  • Evaluating cloud providers for specific workloads
  • Planning technology migrations with risk assessment
  • Calculating build vs. buy decisions with TCO
  • Assessing open-source library viability

When NOT to Use

  • Trivial decisions between similar tools (use team preference)
  • Mandated technology choices (decision already made)
  • Emergency production issues (use monitoring tools)

Troubleshooting

ProblemCauseSolution
Weighted scores all return 50.0Technology data dictionaries missing score keys under each categoryEnsure each category dict contains a score key on a 0-100 scale (e.g., {"performance": {"score": 85}})
TCO projections look unrealistically lowDefault cost parameters used when operational_costs or initial_costs are emptyPopulate monthly_hosting, annual_licensing, developer_hourly_rate, and maintenance_hours_per_dev_monthly with real figures
Ecosystem health score stuck at 50 for npmnpm_data dict is empty or not providedPass npm metrics (weekly_downloads, version, dependencies_count, days_since_last_publish); 50 is the neutral fallback when npm data is absent
Security compliance returns "Unknown standard"Unsupported standard name passed to assess_compliance()Use one of the supported keys: GDPR, SOC2, HIPAA, PCI_DSS (case-sensitive)
Migration complexity always shows moderatearchitecture_change_level defaults to moderate when not specifiedSet architecture_change_level explicitly to minimal, moderate, significant, or complete in codebase_stats
Report renders ASCII tables instead of markdownReportGenerator auto-detects CLI context when stdout is a TTYPass output_context='desktop' to force rich markdown output
Format detector misclassifies YAML as textFewer than 50% of lines match YAML key-value patternsEnsure input uses standard YAML syntax with key: value pairs and proper indentation

Success Criteria

  • TCO variance under 15%: Calculated TCO deviates less than 15% from actual costs when validated against real-world spending data over the projection period.
  • Security score above 80/100: Technologies recommended for production use achieve a minimum overall security score of 80, corresponding to grade B or higher.
  • Ecosystem health score above 65/100: Recommended technologies demonstrate viable long-term ecosystem health with a risk level no worse than "Low-Medium."
  • Migration effort estimate within 20%: Person-hours and timeline estimates land within 20% of actual migration effort when measured post-completion.
  • Comparison confidence above 70%: Final technology recommendations carry a confidence score of 70% or higher, indicating a meaningful score gap between top candidates.
  • Compliance readiness at "Mostly Ready" or above: Technologies targeting regulated environments achieve at least 70% feature coverage against required compliance standards (GDPR, SOC2, HIPAA, PCI-DSS).
  • Report generation under 5 seconds: All report types (executive summary, full report) render within 5 seconds for evaluations comparing up to 5 technologies.

Scope & Limitations

Covers:

  • Weighted multi-criteria comparison of frameworks, libraries, and cloud providers
  • Multi-year TCO projections including hidden costs (technical debt, vendor lock-in, turnover)
  • Ecosystem viability assessment using GitHub, npm, and community metrics
  • Security posture scoring and compliance readiness for GDPR, SOC2, HIPAA, PCI-DSS

Does NOT cover:

  • Live data fetching from GitHub API, npm registry, or vulnerability databases (all data must be provided as input dictionaries)
  • Performance benchmarking or load testing (use engineering/senior-qa for test execution)
  • Licensing legal review or contract negotiation (use ra-qm-team compliance skills for regulatory guidance)
  • Team hiring or organizational design decisions (use hr-operations/talent-acquisition for staffing analysis)

Integration Points

SkillIntegrationData Flow
engineering/senior-securityFeed security assessor output into deeper vulnerability analysisSecurityAssessor results → security review input
engineering/senior-devopsUse TCO hosting projections to inform infrastructure planningTCOCalculator hosting/scaling data → DevOps capacity models
engineering/senior-qaMigration test coverage scores inform QA test planningMigrationAnalyzer testing_requirements → QA test strategy
ra-qm-team/compliance-auditorCompliance readiness gaps feed into formal audit preparationSecurityAssessor.assess_compliance() missing features → audit checklist
c-level-advisor/cto-advisorExecutive summaries and TCO reports support CTO decision-makingReportGenerator executive summary → strategic technology decisions
product-team/product-managerEcosystem viability and migration timelines inform product roadmapsEcosystemAnalyzer + MigrationAnalyzer → roadmap planning

Tool Reference

stack_comparator.py

Purpose: Compare technologies with customizable weighted criteria across 8 evaluation categories: performance, scalability, developer experience, ecosystem, learning curve, documentation, community support, and enterprise readiness.

Usage:

from stack_comparator import StackComparator

comparator = StackComparator({
    "technologies": ["React", "Vue"],
    "use_case": "SaaS dashboard",
    "weights": {"developer_experience": 40, "performance": 30, "ecosystem": 30}
})

results = comparator.compare_technologies(tech_data_list)

Constructor Parameters (comparison_data dict):

KeyTypeDefaultDescription
technologieslist[]Names of technologies to compare
use_casestr"general"Use case context (supports real-time, enterprise, startup bonuses)
prioritiesdict{}Priority overrides
weightsdictDEFAULT_WEIGHTSCategory weights (auto-normalized to 100)

Default Weights: performance 15, scalability 15, developer_experience 20, ecosystem 15, learning_curve 10, documentation 10, community_support 10, enterprise_readiness 5.

Key Methods:

  • compare_technologies(tech_data_list) -- Full comparison with scores, recommendation, confidence, and decision factors
  • score_technology(tech_name, tech_data) -- Score a single technology across all categories
  • calculate_weighted_score(category_scores) -- Calculate weighted total from category scores
  • generate_pros_cons(tech_name, tech_scores) -- Generate pros/cons lists from scores

Example Output:

{
  "technologies": {"React": {"weighted_total": 78.5, "strengths": [...], "weaknesses": [...]}},
  "recommendation": "React",
  "confidence": 72.0,
  "decision_factors": [{"category": "developer_experience", "importance": "40.0%", "best_performer": "React"}],
  "comparison_matrix": [{"category": "performance", "weight": "15.0%", "scores": {"React": "82.0", "Vue": "79.0"}}]
}

Output Format: Python dictionary (serialize with json.dumps() for JSON output).


tco_calculator.py

Purpose: Calculate comprehensive Total Cost of Ownership over multi-year projections, including initial costs, operational costs, scaling costs, hidden costs (technical debt, vendor lock-in, security incidents, downtime, turnover), and developer productivity impact.

Usage:

from tco_calculator import TCOCalculator

calculator = TCOCalculator({
    "technology": "Next.js",
    "team_size": 8,
    "timeline_years": 5,
    "initial_costs": {"licensing": 0, "migration": 15000, "developer_hourly_rate": 100},
    "operational_costs": {"monthly_hosting": 2500, "annual_licensing": 0, "maintenance_hours_per_dev_monthly": 20},
    "scaling_params": {"annual_growth_rate": 0.40, "initial_users": 5000}
})

tco = calculator.calculate_total_tco()
summary = calculator.generate_tco_summary()

Constructor Parameters (tco_data dict):

KeyTypeDefaultDescription
technologystr"Unknown"Technology name
team_sizeint5Number of developers
timeline_yearsint5Projection period in years
initial_costsdict{}One-time costs: licensing, migration, setup, tooling, training_hours_per_dev, developer_hourly_rate, training_materials
operational_costsdict{}Recurring costs: monthly_hosting, annual_licensing, annual_support, maintenance_hours_per_dev_monthly
scaling_paramsdict{}Growth params: annual_growth_rate, initial_users, initial_servers, cost_per_server_monthly
productivity_factorsdict{}Productivity: productivity_multiplier, time_to_market_reduction_days, avg_feature_time_days, avg_feature_value, technical_debt_percentage, vendor_lock_in_risk, security_incidents_per_year, avg_security_incident_cost, downtime_hours_per_year, downtime_cost_per_hour, annual_turnover_rate, cost_per_new_hire

Key Methods:

  • calculate_total_tco() -- Complete TCO with all cost components
  • generate_tco_summary() -- Executive summary with formatted dollar amounts
  • calculate_initial_costs() -- One-time cost breakdown
  • calculate_operational_costs() -- Year-by-year operational costs
  • calculate_scaling_costs() -- User projections and cost-per-user analysis
  • calculate_hidden_costs() -- Technical debt, vendor lock-in, security, downtime, turnover
  • calculate_productivity_impact() -- Productivity gains and feature velocity

Output Format: Python dictionary (all monetary values as floats; generate_tco_summary() returns pre-formatted dollar strings).


ecosystem_analyzer.py

Purpose: Analyze technology ecosystem health and long-term viability by scoring GitHub activity, npm adoption, community strength, corporate backing, and maintenance responsiveness on a 0-100 scale.

Usage:

from ecosystem_analyzer import EcosystemAnalyzer

analyzer = EcosystemAnalyzer({
    "technology": "React",
    "github": {"stars": 220000, "forks": 45000, "contributors": 1500, "commits_last_month": 120},
    "npm": {"weekly_downloads": 20000000, "version": "18.2.0", "dependencies_count": 3},
    "community": {"stackoverflow_questions": 400000, "job_postings": 15000},
    "corporate_backing": {"type": "major_tech_company"}
})

report = analyzer.generate_ecosystem_report()
viability = analyzer.assess_viability()

Constructor Parameters (ecosystem_data dict):

KeyTypeDefaultDescription
technologystr"Unknown"Technology name
githubdict{}GitHub metrics: stars, forks, contributors, commits_last_month, avg_issue_response_hours, issue_resolution_rate, releases_per_year, active_maintainers, open_issues
npmdict{}npm metrics: weekly_downloads, version, dependencies_count, days_since_last_publish
communitydict{}Community metrics: stackoverflow_questions, job_postings, tutorials_count, forum_members
corporate_backingdict{}Backing info: type (one of major_tech_company, established_company, startup_backed, community_led, none), funding_millions

Health Score Weights: github_health 25%, npm_health 20%, community_health 20%, corporate_backing 15%, maintenance_health 20%.

Key Methods:

  • generate_ecosystem_report() -- Complete report with health scores, viability, and formatted metrics
  • calculate_health_score() -- Component scores and weighted overall score
  • assess_viability() -- Viability level, risk assessment, strengths, and recommendation

Output Format: Python dictionary with nested health scores, viability assessment, and formatted metrics.


security_assessor.py

Purpose: Evaluate security posture and compliance readiness for technology stacks. Scores vulnerabilities, patch responsiveness, built-in security features, and track record. Assesses compliance against GDPR, SOC2, HIPAA, and PCI-DSS.

Usage:

from security_assessor import SecurityAssessor

assessor = SecurityAssessor({
    "technology": "Express",
    "vulnerabilities": {
        "critical_last_12m": 0, "high_last_12m": 2,
        "avg_critical_patch_days": 7, "has_security_team": True
    },
    "security_features": {
        "encryption_in_transit": True, "authentication": True,
        "input_validation": True, "csrf_protection": True
    },
    "compliance_requirements": ["SOC2", "GDPR"]
})

report = assessor.generate_security_report()
compliance = assessor.assess_compliance(["SOC2", "GDPR"])

Constructor Parameters (security_data dict):

KeyTypeDefaultDescription
technologystr"Unknown"Technology name
vulnerabilitiesdict{}Vulnerability data: critical_last_12m, high_last_12m, medium_last_12m, low_last_12m, critical_last_3y, high_last_3y, medium_last_3y, low_last_3y, avg_critical_patch_days, avg_high_patch_days, has_security_team, years_since_major_incident, has_security_certifications, has_bug_bounty_program, security_audits_per_year, common_vulnerability_types
security_featuresdict{}Boolean feature flags: encryption_at_rest, encryption_in_transit, authentication, authorization, input_validation, rate_limiting, csrf_protection, xss_protection, sql_injection_protection, audit_logging, mfa_support, rbac, secrets_management, security_headers, cors_configuration
compliance_requirementslist[]Standards to assess: GDPR, SOC2, HIPAA, PCI_DSS

Security Score Weights: vulnerability_score 30%, patch_responsiveness 25%, security_features 30%, track_record 15%.

Key Methods:

  • generate_security_report() -- Full report with score, compliance, vulnerabilities, and recommendations
  • calculate_security_score() -- Component scores with letter grade (A-F)
  • assess_compliance(standards) -- Per-standard readiness with missing features list
  • identify_vulnerabilities() -- Categorized vulnerability report with trend analysis

Output Format: Python dictionary with security scores, compliance assessments, and risk level.


migration_analyzer.py

Purpose: Analyze migration complexity, estimate effort in person-hours and calendar months, assess technical/business/team risks, and recommend a migration approach (direct, phased, or strangler pattern) based on complexity scoring.

Usage:

from migration_analyzer import MigrationAnalyzer

analyzer = MigrationAnalyzer({
    "source_technology": "Angular 1.x",
    "target_technology": "React",
    "codebase_stats": {
        "lines_of_code": 50000, "num_components": 200,
        "architecture_change_level": "significant",
        "current_test_coverage": 0.6
    },
    "team": {"team_size": 6, "target_tech_experience": "low"},
    "constraints": {"downtime_tolerance": "low"}
})

plan = analyzer.generate_migration_plan()
effort = analyzer.estimate_effort()
risks = analyzer.assess_risks()

Constructor Parameters (migration_data dict):

KeyTypeDefaultDescription
source_technologystr"Unknown"Current technology
target_technologystr"Unknown"Target technology
codebase_statsdict{}Codebase metrics: lines_of_code, num_files, num_components, architecture_change_level (minimal/moderate/significant/complete), has_database, database_size_gb, schema_changes_required, data_transformation_required, breaking_api_changes (none/minimal/some/many/complete), num_dependencies, dependencies_to_replace, current_test_coverage (0-1), num_tests
teamdict{}Team info: team_size, hours_per_week, target_tech_experience (none/low/medium/high)
constraintsdict{}Constraints: downtime_tolerance (none/low/medium/high)

Complexity Score Weights: code_volume 20%, architecture_changes 25%, data_migration 20%, api_compatibility 15%, dependency_changes 10%, testing_requirements 10%.

Key Methods:

  • generate_migration_plan() -- Complete plan with complexity, effort, risks, approach, and success criteria
  • calculate_complexity_score() -- Per-factor complexity scores (1-10 scale)
  • estimate_effort() -- Person-hours, person-months, phase breakdown, and calendar timeline
  • assess_risks() -- Technical, business, and team risks with severity and mitigation strategies

Output Format: Python dictionary with nested complexity analysis, effort estimation, risk assessment, and recommended approach.


report_generator.py

Purpose: Generate context-aware evaluation reports with progressive disclosure. Auto-detects output context (Claude Desktop vs CLI) and renders rich markdown tables or ASCII-formatted output accordingly. Supports selective section generation.

Usage:

from report_generator import ReportGenerator

generator = ReportGenerator(report_data, output_context="desktop")

executive_summary = generator.generate_executive_summary(max_tokens=300)
full_report = generator.generate_full_report(sections=["executive_summary", "comparison_matrix", "tco_analysis"])
generator.export_to_file("evaluation_report.md")

Constructor Parameters:

ParameterTypeDefaultDescription
report_datadict(required)Complete evaluation data containing any combination of: technologies, recommendation, decision_factors, comparison_matrix, tco_analysis, ecosystem_health, security_assessment, migration_analysis, performance_benchmarks, use_case
output_contextstrNone (auto-detect)Output format: "desktop" for rich markdown, "cli" for ASCII tables. Auto-detects via CLAUDE_DESKTOP env var and TTY check

Available Report Sections: executive_summary, comparison_matrix, tco_analysis, ecosystem_health, security_assessment, migration_analysis, performance_benchmarks.

Key Methods:

  • generate_executive_summary(max_tokens=300) -- Concise summary with recommendation, strengths, concerns, and decision factors
  • generate_full_report(sections=None) -- Complete report with selected sections (all if None)
  • export_to_file(filename, sections=None) -- Write report to file, returns file path

Output Format: Markdown string (desktop context) or ASCII-formatted string (CLI context).


format_detector.py

Purpose: Automatically detect and parse input format (JSON, YAML, URL, or natural language text) for technology evaluation requests. Extracts technology names, use cases, priorities, and analysis types from unstructured text input.

Usage:

from format_detector import FormatDetector

detector = FormatDetector('Compare React vs Vue for a SaaS dashboard. Priorities: performance, ecosystem.')

format_type = detector.detect_format()   # Returns: "text"
parsed = detector.parse()                # Returns normalized dict
info = detector.get_format_info()        # Returns detection metadata

Constructor Parameters:

ParameterTypeDefaultDescription
input_datastr(required)Raw input string in any supported format

Supported Formats:

  • JSON -- Valid JSON objects are detected and parsed directly
  • YAML -- Detected when >50% of lines match key-value or list patterns (simplified parser, no PyYAML dependency)
  • URL -- Detected when input contains http:// or https:// URLs; categorizes GitHub, npm, and other URLs
  • Text -- Natural language fallback; extracts technologies from 30+ known keywords, identifies use cases, priorities, and analysis types

Key Methods:

  • detect_format() -- Returns format string: "json", "yaml", "url", or "text"
  • parse() -- Parse input and return normalized dictionary with standard keys: technologies, use_case, priorities, analysis_type, format
  • get_format_info() -- Detection metadata: detected_format, input_length, line_count, parsing_successful

Output Format: Python dictionary normalized to a standard structure with keys: technologies (list), use_case (str), priorities (list), analysis_type (str), format (str).

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.66%
按下载量换算296

Claude

30.97%
按下载量换算250

Cursor

18.7%
按下载量换算151

Gemini CLI

10.46%
按下载量换算85

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills