All skills
openai avatar

/aspnet-core

@c207989 official
by openaiopenai/skills28k stars
1,891

Build, review, refactor, or architect ASP.NET Core web applications using current official guidance for .NET web development. Use when working on Blazor Web Apps, Razor Pages, MVC, Minimal APIs, controller-based Web APIs, SignalR, gRPC, middleware, dependency injection, configuration, authentication, authorization, testing, performance, deployment, or ASP.NET Core upgrades.

Use this Skill: https://skilld.dev/gh/openai/skills/aspnet-core

This session only. Nothing lands on disk.

referencesapis-minimal-and-controllers.md

≈760 tokens on demand. Your agent reads this file only when SKILL.md points to it.

APIs: Minimal And Controllers

Primary docs:

First Decision

Choose between:

  • Minimal APIs for focused, low-ceremony HTTP endpoints
  • controller-based APIs for richer MVC conventions and attribute-driven behavior

Do not mix both styles in the same feature unless that split is genuinely useful.

Minimal API Guidance

Prefer Minimal APIs when the surface is small to medium and you want concise endpoint definitions.

Good defaults:

  • organize endpoints with route groups
  • keep route handlers thin
  • move business logic into services
  • prefer TypedResults over untyped results
  • use endpoint filters when cross-cutting behavior belongs at the endpoint layer
  • use built-in validation support on supported target frameworks

Minimal API reminders:

  • handler parameters can be bound from route, query, headers, body, form, or DI
  • authorization can be applied with RequireAuthorization
  • return IResult or TypedResults when response shape matters
  • use OpenAPI support for discoverable contracts

On .NET 10, Minimal APIs support built-in validation with AddValidation(). Use that instead of inventing parallel validation infrastructure when the target framework supports it.

Controller API Guidance

Prefer controllers when the API needs:

  • [ApiController] behaviors
  • attribute routing and conventions
  • filters
  • custom formatters
  • mature controller organization in an existing codebase

Controller defaults:

  • derive API controllers from ControllerBase
  • annotate with [ApiController]
  • use attribute routing
  • return ProblemDetails-compatible failures
  • let automatic model validation handle invalid requests unless there is a concrete override requirement

Key [ApiController] behaviors:

  • attribute routing is required
  • invalid model state automatically becomes HTTP 400
  • binding source inference applies
  • error responses use ProblemDetails patterns

Shared API Practices

  • Keep request and response DTOs separate from persistence models
  • Use version-stable route and payload contracts
  • Use CreatedAt... patterns for resource creation
  • Prefer explicit status codes and typed results over implicit behavior
  • Apply authorization at the endpoint or controller boundary, not only inside service methods
  • Use ProblemDetails for errors instead of ad hoc JSON shapes

Browser-Facing Notes

  • Be careful with cookie-authenticated API endpoints and CORS
  • For browser-based form or file upload endpoints, account for antiforgery requirements
  • In ASP.NET Core 10, known API endpoints no longer use cookie-login redirects by default; rely on API-appropriate unauthorized responses instead

Native AOT

Use dotnet new webapiaot only when native AOT is an explicit deployment requirement. Treat it as a constraint that affects library choice, reflection, JSON patterns, and compatibility.

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive set of guidelines and reference materials for ASP.NET Core development, emphasizing security best practices and official architectural patterns. It does not contain any malicious patterns or unauthorized operations.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    6/16 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at c207989. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Activeupdated 7 months ago
  • Testing
  • aspnet-core
  • dotnet
  • csharp
  • blazor
  • razor-pages
  • mvc
  • minimal-apis
  • ef-core
  • signalr
  • grpc
  • authentication

README badge

README badge for openai/skills/aspnet-core

Instructs Claude on ASP.NET Core application models (Blazor Web Apps, Razor Pages, MVC, Minimal APIs), host and pipeline setup, dependency injection, configuration, authentication, testing, and deployment using current Microsoft documentation. Use for building or refactoring .NET web applications and deciding between framework patterns.

Generated from the current SKILL.md.

Does this skill cover Blazor, Razor Pages, MVC, and Minimal APIs?
Yes. The skill includes dedicated references for each application model (Blazor Web Apps, Razor Pages, MVC, and Minimal/controller-based APIs) and guides you to load only the one you need for your task.
What .NET versions does this skill target?
The skill defaults to .NET 10 / ASP.NET Core 10 for new production work as of March 2026, but adapts to older pinned versions and handles migrations between major versions via the versioning-and-upgrades reference.
Does this skill use third-party libraries or stick to built-in ASP.NET Core features?
The skill prefers built-in features (DI, options, logging, ProblemDetails, OpenAPI, health checks, rate limiting, Identity) before introducing third-party infrastructure.
Can this skill help with authentication, authorization, and data access?
Yes. Cross-cutting references cover security/identity, EF Core, DbContext, and state management, loaded on-demand based on your specific task.
Does this skill guide upgrades from older ASP.NET Core versions?
Yes. The versioning-and-upgrades reference specifically handles breaking changes, obsolete APIs, and migrations between major versions.

Generated from the current SKILL.md. These answers refresh after source changes.