All skills
openai avatar

/aspnet-core

@c207989 official
by openaiopenai/skills28k stars
1,891

Build, review, refactor, or architect ASP.NET Core web applications using current official guidance for .NET web development. Use when working on Blazor Web Apps, Razor Pages, MVC, Minimal APIs, controller-based Web APIs, SignalR, gRPC, middleware, dependency injection, configuration, authentication, authorization, testing, performance, deployment, or ASP.NET Core upgrades.

Use this Skill: https://skilld.dev/gh/openai/skills/aspnet-core

This session only. Nothing lands on disk.

referencessecurity-and-identity.md

≈736 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security And Identity

Primary docs:

Security Defaults

  • Use the most secure authentication flow available
  • Keep secrets out of source code and plain configuration files
  • Use Secret Manager in development
  • Use a secure production secret store
  • Enforce HTTPS
  • Apply least privilege to users, services, and data access

Authentication And Authorization

Authentication answers who the user or caller is. Authorization answers what they can do.

Default pipeline order:

  1. UseAuthentication()
  2. UseAuthorization()

Apply authorization at boundaries:

  • [Authorize] on controllers, actions, page models, or hubs
  • RequireAuthorization() on endpoints and route groups
  • policies for reusable rules
  • roles only when role-based checks are actually the right abstraction

Use AllowAnonymous sparingly and intentionally.

Identity

Use ASP.NET Core Identity when the app needs first-party user accounts, login flows, password management, email confirmation, MFA, or related account management.

Useful starting points:

  • dotnet new webapp -au Individual
  • dotnet new mvc -au Individual

Identity guidance:

  • scaffold only the pages you truly need to customize
  • keep Identity UI updates maintainable; full scaffolding increases merge and upgrade cost
  • use policies and claims for authorization rather than encoding all decisions in page logic
  • persist data-protection keys appropriately in multi-instance deployments

On ASP.NET Core 10, Identity metrics are available for observing auth-related behavior. Use them when the app has meaningful authentication traffic or security monitoring requirements.

CSRF, CORS, And Browser Security

  • Use antiforgery protection for cookie-based interactive apps and form posts
  • Do not confuse CORS with authentication or authorization
  • Avoid permissive AllowAnyOrigin plus credentials combinations
  • Treat browser-side state as untrusted

HTTPS, HSTS, And Forwarded Headers

  • redirect HTTP to HTTPS
  • enable HSTS outside development when appropriate
  • configure forwarded headers correctly when behind proxies or load balancers
  • do not generate links or evaluate scheme-sensitive behavior before proxy headers are processed

Data Protection And Secrets

  • persist data-protection keys outside ephemeral local storage when the app runs on multiple instances
  • do not use environment variables as the preferred long-term home for production secrets when a stronger secret store is available
  • never check production credentials into source control

Blazor Note

For Blazor apps, read the general ASP.NET Core security guidance first and then the Blazor-specific security docs. Some Blazor security guidance adds to or supersedes the general guidance.

Source: SKILL.md on GitHub

1 warning17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides a comprehensive set of guidelines and reference materials for ASP.NET Core development, emphasizing security best practices and official architectural patterns. It does not contain any malicious patterns or unauthorized operations.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    6/16 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at c207989. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Activeupdated 7 months ago
  • Testing
  • aspnet-core
  • dotnet
  • csharp
  • blazor
  • razor-pages
  • mvc
  • minimal-apis
  • ef-core
  • signalr
  • grpc
  • authentication

README badge

README badge for openai/skills/aspnet-core

Instructs Claude on ASP.NET Core application models (Blazor Web Apps, Razor Pages, MVC, Minimal APIs), host and pipeline setup, dependency injection, configuration, authentication, testing, and deployment using current Microsoft documentation. Use for building or refactoring .NET web applications and deciding between framework patterns.

Generated from the current SKILL.md.

Does this skill cover Blazor, Razor Pages, MVC, and Minimal APIs?
Yes. The skill includes dedicated references for each application model (Blazor Web Apps, Razor Pages, MVC, and Minimal/controller-based APIs) and guides you to load only the one you need for your task.
What .NET versions does this skill target?
The skill defaults to .NET 10 / ASP.NET Core 10 for new production work as of March 2026, but adapts to older pinned versions and handles migrations between major versions via the versioning-and-upgrades reference.
Does this skill use third-party libraries or stick to built-in ASP.NET Core features?
The skill prefers built-in features (DI, options, logging, ProblemDetails, OpenAPI, health checks, rate limiting, Identity) before introducing third-party infrastructure.
Can this skill help with authentication, authorization, and data access?
Yes. Cross-cutting references cover security/identity, EF Core, DbContext, and state management, loaded on-demand based on your specific task.
Does this skill guide upgrades from older ASP.NET Core versions?
Yes. The versioning-and-upgrades reference specifically handles breaking changes, obsolete APIs, and migrations between major versions.

Generated from the current SKILL.md. These answers refresh after source changes.