All skills
openai avatar

/aspnet-core

@c207989 official
by openaiopenai/skills28k stars
1,891

Build, review, refactor, or architect ASP.NET Core web applications using current official guidance for .NET web development. Use when working on Blazor Web Apps, Razor Pages, MVC, Minimal APIs, controller-based Web APIs, SignalR, gRPC, middleware, dependency injection, configuration, authentication, authorization, testing, performance, deployment, or ASP.NET Core upgrades.

Use this Skill: https://skilld.dev/gh/openai/skills/aspnet-core

This session only. Nothing lands on disk.

referencesprogram-and-pipeline.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Program And Pipeline

Primary docs:

Startup Shape

Prefer the modern hosting model:

  1. Create var builder = WebApplication.CreateBuilder(args);
  2. Register services on builder.Services
  3. Build var app = builder.Build();
  4. Configure middleware in the correct order
  5. Map endpoints
  6. Call app.Run();

Use older Startup patterns only when the repository already uses them or the task is migration.

Service Registration

  • Register framework services explicitly: Razor Pages, controllers, Razor components, authentication, authorization, health checks, rate limiting, response compression, output caching, EF Core, and IHttpClientFactory
  • Keep business logic in services instead of controllers, page models, or route handlers
  • Use constructor injection as the default
  • Use options classes for structured configuration
  • Choose lifetimes intentionally:
    • singleton: stateless or shared infrastructure
    • scoped: request-bound work such as DbContext
    • transient: lightweight stateless services

Configuration Defaults

WebApplication.CreateBuilder already loads configuration from common providers such as:

  • appsettings.json
  • environment-specific appsettings.{Environment}.json
  • environment variables
  • command-line arguments

For secrets:

  • use Secret Manager in development
  • use a secure external store in production
  • do not commit secrets to source control

Middleware Order

Middleware order is a frequent source of broken behavior. Favor this shape and adjust only with a concrete reason:

  1. Forwarded headers if behind a proxy or load balancer
  2. Exception handling and HSTS for non-development environments
  3. HTTPS redirection
  4. Static files
  5. Routing when explicit routing middleware is needed
  6. CORS when endpoints require it
  7. Authentication
  8. Authorization
  9. Endpoint-specific middleware such as rate limiting or session as required
  10. Endpoint mapping with MapRazorPages, MapControllers, MapGet, MapHub, or MapGrpcService

Important ordering rules:

  • Call UseAuthentication() before UseAuthorization()
  • Keep proxy/header processing before auth, redirects, and link generation
  • Do not insert custom middleware randomly between auth and authorization without a reason
  • In Minimal API apps, explicit UseRouting() is usually unnecessary unless you need to control order

Routing And Endpoints

  • Prefer endpoint routing everywhere
  • Use route groups for larger Minimal API surfaces
  • Keep MVC and API routes explicit and predictable
  • Use areas only when the application is large enough to benefit from bounded sections
  • Keep endpoint names stable when generating links or integrating with clients

Error Handling

  • Use centralized exception handling instead of scattered try/catch blocks for ordinary request failures
  • Prefer ProblemDetails-style responses for APIs
  • Keep the developer exception page limited to development
  • Separate user-facing failures from internal exception details

Logging And Diagnostics

  • Use ILogger<T> from DI
  • Log structured values, not concatenated strings
  • Put correlation and request diagnostics in middleware or infrastructure, not business logic
  • Enable HTTP logging only when the scenario warrants it and avoid leaking sensitive data

Static Assets And Web Root

  • Keep public assets in wwwroot
  • Treat the web root as publicly readable content
  • Prevent publishing local-only static content through project file rules when needed
  • Use Razor Class Libraries for reusable UI assets across apps

Architectural Defaults

  • Keep Program.cs readable; extract feature registration to extension methods when it starts accumulating unrelated concerns
  • Prefer vertical slices or feature folders over giant "Controllers", "Services", and "Repositories" buckets with weak boundaries
  • Keep framework configuration close to the host and business logic out of it

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive set of guidelines and reference materials for ASP.NET Core development, emphasizing security best practices and official architectural patterns. It does not contain any malicious patterns or unauthorized operations.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    6/16 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at c207989. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Activeupdated 7 months ago
  • Testing
  • aspnet-core
  • dotnet
  • csharp
  • blazor
  • razor-pages
  • mvc
  • minimal-apis
  • ef-core
  • signalr
  • grpc
  • authentication

README badge

README badge for openai/skills/aspnet-core

Instructs Claude on ASP.NET Core application models (Blazor Web Apps, Razor Pages, MVC, Minimal APIs), host and pipeline setup, dependency injection, configuration, authentication, testing, and deployment using current Microsoft documentation. Use for building or refactoring .NET web applications and deciding between framework patterns.

Generated from the current SKILL.md.

Does this skill cover Blazor, Razor Pages, MVC, and Minimal APIs?
Yes. The skill includes dedicated references for each application model (Blazor Web Apps, Razor Pages, MVC, and Minimal/controller-based APIs) and guides you to load only the one you need for your task.
What .NET versions does this skill target?
The skill defaults to .NET 10 / ASP.NET Core 10 for new production work as of March 2026, but adapts to older pinned versions and handles migrations between major versions via the versioning-and-upgrades reference.
Does this skill use third-party libraries or stick to built-in ASP.NET Core features?
The skill prefers built-in features (DI, options, logging, ProblemDetails, OpenAPI, health checks, rate limiting, Identity) before introducing third-party infrastructure.
Can this skill help with authentication, authorization, and data access?
Yes. Cross-cutting references cover security/identity, EF Core, DbContext, and state management, loaded on-demand based on your specific task.
Does this skill guide upgrades from older ASP.NET Core versions?
Yes. The versioning-and-upgrades reference specifically handles breaking changes, obsolete APIs, and migrations between major versions.

Generated from the current SKILL.md. These answers refresh after source changes.