Dependency health report for .NET solutions: outdated NuGet packages, vulnerable versions, and commercial-license traps (MediatR, MassTransit, FluentAssertions, AutoMapper) — powered by the…

MITAuto-check passedAgent Workflows

Install Outdated

skills CLI
$ npx skills add codewithmukesh/dotnet-claude-kit --skill outdated -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install codewithmukesh/dotnet-claude-kit outdated --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/codewithmukesh/dotnet-claude-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/outdated .claude/skills/outdated && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
outdated
GitHub stars
751
Token cost
~1.2k tokens
SKILL.md length
418 words
Files
1
Skills in repo
47
Repo updated
First seen
Licence
MIT

At a glance

Dependency health report for .NET solutions: outdated NuGet packages, vulnerable versions, and commercial-license traps (MediatR, MassTransit, FluentAssertions, AutoMapper) — powered by the…

  • Works in 3 steps: Inventory — every PackageReference per… → Staleness + vulnerabilities — current vs… → License screen — flags packages that…
  • Tasks that involve MCP servers
  • SKILL.md covers What, When, How and Example, plus 1 more section
  • Calls dotnet

What it does

Outdated is an agent skill from codewithmukesh/dotnet-claude-kit. Dependency health report for .NET solutions: outdated NuGet packages, vulnerable versions, and commercial-license traps (MediatR, MassTransit, FluentAssertions, AutoMapper) — powered by the getnugetpackages MCP tool. Invoke when: "outdated packages", "check dependencies", "stale packages", "package audit", "dependency health", "are my packages up to date", "license check", "vulnerable packages", "nuget audit".

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with .NET. The repository describes itself as: Make Claude Code a .NET 10 Expert. The licence is MIT.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “outdated packages”
  • “check dependencies”
  • “stale packages”
  • “/outdated”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Inventory — every PackageReference per project, with TFMs and central
  2. Staleness + vulnerabilities — current vs latest stable, and known CVEs,
  3. License screen — flags packages that moved to commercial licenses so an

What it can do on your machine

Read from SKILL.md and the folder at commit 2330089. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Outdated loads about 1.2k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 418 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from codewithmukesh/dotnet-claude-kit at commit 2330089, republished under its MIT licence (© codewithmukesh). 418 words, ~1,237 tokens.

Download SKILL.mdSave it as .claude/skills/outdated/SKILL.md (or your agent's skills folder).
name
outdated
description
Dependency health report for .NET solutions: outdated NuGet packages, vulnerable versions, and commercial-license traps (MediatR, MassTransit, FluentAssertions, AutoMapper) — powered by the get_nuget_packages MCP tool. Invoke when: "outdated packages", "check dependencies", "stale packages", "package audit", "dependency health", "are my packages up to date", "license check", "vulnerable packages", "nuget audit".

/outdated

What

A three-layer dependency health report:

  1. Inventory — every PackageReference per project, with TFMs and central package management awareness, via the get_nuget_packages MCP tool (no network, token-cheap).
  2. Staleness + vulnerabilities — current vs latest stable, and known CVEs, via the dotnet CLI.
  3. License screen — flags packages that moved to commercial licenses so an innocent dotnet outdated --upgrade doesn't silently change your legal position.

The output is a single prioritized table — vulnerabilities first, license traps second, staleness last — with a recommended action per row.

When

  • "check for outdated packages", "package audit", "dependency health"
  • Before a .NET version upgrade (pairs with /migrate Flow B)
  • After inheriting an unfamiliar codebase
  • Dependabot/NuGet audit warnings appeared and you want the full picture
  • Periodically on long-lived projects — quarterly is a good cadence

How

Step 1: Inventory (MCP, no network)

get_nuget_packages()                          -- whole solution
get_nuget_packages(projectFilter: "Api")      -- or one project

Returns per-project {Name, TargetFramework, Cpm, Packages: [{Id, Version}]}. Note Cpm: true — updates then belong in Directory.Packages.props, not the csproj. Flag mixed TFMs across projects while you're here.

Step 2: Staleness and vulnerabilities (CLI)

bash
dotnet list package --outdated
dotnet list package --vulnerable --include-transitive

Both need a successful restore first. If restore fails, fix that before auditing — a broken lock state makes version output unreliable.

Step 3: License screen

Check the inventory against the known commercial moves (full rationale in knowledge/package-recommendations.md):

PackageCommercial fromFree alternative
MediatR13+ (Lucky Penny, RPL)Mediator (martinothamar) — source-generated, MIT
MassTransit9+ (v8 Apache, patches end 2026 then EOL)Wolverine 6.x, or stay on v8 short-term
FluentAssertions8+ (v7 stays Apache, frozen)xUnit built-in Assert (kit default), Shouldly, AwesomeAssertions
AutoMapper15+ (Lucky Penny)Manual mapping (kit default) or Mapperly (MIT)
Show full SKILL.md (160 more words)Show less

A license flag fires when the project is on the free major and a naive "update all" would cross the boundary — that is the trap this step exists for.

Step 4: Report

One table, priority-ordered:

PriorityMeaningAction
VULNERABLEKnown CVE in current versionUpdate now, test, deploy
LICENSENext major crosses a commercial boundaryPin below boundary or plan migration
MAJORBehind a major (breaking changes likely)One at a time, release notes first
MINOR/PATCHRoutine driftBatch patches; minors one at a time

Step 5: Act (optional)

Offer to execute updates via /migrate Flow C — one package at a time, dotnet build && dotnet test between each. Never batch major updates: batched failures are unattributable.

MCP Tools Used
  • get_nuget_packages — inventory, CPM detection, TFM audit
  • get_diagnostics — verify the solution still compiles clean after updates

Example

User: /outdated

Claude: Inventorying packages (get_nuget_packages)...
  3 projects, CPM enabled (Directory.Packages.props), all net10.0.

  Checking versions and CVEs...

  | Package                  | Current | Latest  | Priority   | Action                          |
  |--------------------------|---------|---------|------------|---------------------------------|
  | System.Text.Json (trans.)| 10.0.2  | 10.0.10 | VULNERABLE | Update now (CVE-2026-XXXX)      |
  | MassTransit              | 8.3.0   | 9.1.2   | LICENSE    | v9 is commercial. Stay on v8    |
  |                          |         |         |            | (EOL end 2026) or plan Wolverine|
  | Serilog.AspNetCore       | 9.0.0   | 10.0.0  | MAJOR      | Update alone, check sink compat |
  | FluentValidation         | 12.0.1  | 12.1.1  | PATCH      | Batch with other patches        |

  1 vulnerability, 1 license trap, 1 major, 1 patch.
  Want me to apply these via /migrate Flow C?
  • /migrate — Flow C executes the updates this report recommends
  • knowledge/package-recommendations.md — vetted packages + licensing detail
  • knowledge/mediatr-to-mediator-migration.md — step-by-step MediatR exit
  • /verify — full pipeline after applying updates

© codewithmukesh, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/outdated of codewithmukesh/dotnet-claude-kit.

Open the folder on GitHubat commit 2330089

Compare with similar skills

Outdated next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Outdated compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Outdated this skillcodewithmukesh/dotnet-claude-kit751—~1.2kAutomated safety check: PassMIT
Microsoft Skill CreatorMicrosoftDocs/mcp1.9k3 repos~2.1kAutomated safety check: PassCC-BY-4.0
MCP Csharpatherio-danp/cde-dotnetcc109—~1.2kAutomated safety check: NotesNone
Creating Dotnet MCP ServersSebastienDegodez/copilot-instructions197—~1.3kAutomated safety check: PassApache-2.0
Csharp MCP Server GeneratorILoveDotNet/ilovedotnet155—~560Automated safety check: PassCC0-1.0
Dotnet MCP Builderboshi-xixixi/TraeSkill274—~1.7kAutomated safety check: PassMIT

Similar skills

  • Microsoft Skill Creator

    MicrosoftDocs/mcp

    Official

    Create agent skills for Microsoft technologies using official documentation.

    1.9k GitHub starsUsed in 3 repos~2.1k tokens
    Agent WorkflowsAuto-check passed
  • MCP Csharp

    atherio-danp/cde-dotnetcc

    Create, debug, test, and publish MCP (Model Context Protocol) servers in C using the official ModelContextProtocol SDK — tools/prompts/resources, stdio vs HTTP transport, MapMcp hosting.

    109 GitHub stars~1.2k tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check: notes
  • Creating Dotnet MCP Servers

    SebastienDegodez/copilot-instructions

    A skill your agent uses when building Model Context Protocol (MCP) servers in .NET, configuring tools, transports (SSE/stdio), JSON serialization for AOT, or testing MCP endpoints

    197 GitHub stars~1.3k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Csharp MCP Server Generator

    ILoveDotNet/ilovedotnet

    Generate a complete MCP server project in C with tools, prompts, and proper configuration

    155 GitHub stars~560 tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Dotnet MCP Builder

    boshi-xixixi/TraeSkill

    Build Model Context Protocol (MCP) servers in C/.NET against the current ModelContextProtocol 1.x NuGet packages.

    274 GitHub stars~1.7k tokensUpdated 4 mo ago
    Agent WorkflowsAuto-check passed
  • Dotnet MCP Builder

    github/awesome-copilot

    Official

    Build Model Context Protocol (MCP) servers in C/.NET against the current ModelContextProtocol 2.x NuGet packages.

    40k GitHub stars~2.1k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from codewithmukesh/dotnet-claude-kit

All 47 skills in this repo
  • API Versioning

    codewithmukesh/dotnet-claude-kit

    API versioning strategies for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Scaffold

    codewithmukesh/dotnet-claude-kit

    Architecture-aware feature scaffolding for .NET 10 projects.

    751 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Architecture Advisor

    codewithmukesh/dotnet-claude-kit

    Architecture selection advisor for .NET applications. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Aspire

    codewithmukesh/dotnet-claude-kit

    .NET Aspire for cloud-native orchestration. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Authentication

    codewithmukesh/dotnet-claude-kit

    Authentication and authorization for ASP.NET Core. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Caching

    codewithmukesh/dotnet-claude-kit

    Caching strategies for .NET 10 applications. An agent skill from codewithmukesh/dotnet-claude-kit.

    751 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed

Works with

Categories

Questions about Outdated

What does Outdated do?

Dependency health report for .NET solutions: outdated NuGet packages, vulnerable versions, and commercial-license traps (MediatR, MassTransit, FluentAssertions, AutoMapper) — powered by the…. Outdated is an agent skill from codewithmukesh/dotnet-claude-kit.NET solutions: outdated NuGet packages, vulnerable versions, and commercial-license traps (MediatR, MassTransit, FluentAssertions, AutoMapper) — powered by the getnugetpackages MCP tool.

When should I use Outdated?

Outdated fits situations like: tasks that involve MCP servers.

How do I install Outdated in Claude Code?

Run `npx skills add codewithmukesh/dotnet-claude-kit --skill outdated -a claude-code`. Or copy the skill folder (skills/outdated in codewithmukesh/dotnet-claude-kit) into .claude/skills/outdated in your project. Claude Code loads it when a task matches its description.

How do I install Outdated in Codex?

Run `npx skills add codewithmukesh/dotnet-claude-kit --skill outdated -a codex`. Or copy the skill folder (skills/outdated in codewithmukesh/dotnet-claude-kit) into .agents/skills/outdated in your project. Codex loads it when a task matches its description.

Can I use Outdated in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add codewithmukesh/dotnet-claude-kit --skill outdated -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/outdated, .gemini/skills/outdated, .github/skills/outdated and .opencode/skills/outdated in your project.

What does Outdated need to run?

Going by SKILL.md and its folder, Outdated needs the command-line tools its instructions call (dotnet).

Does Outdated access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Outdated safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Outdated use?

Outdated is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Outdated use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Outdated?

Skills that share tags, products or a category with Outdated: Microsoft Skill Creator (MicrosoftDocs/mcp, 1.9k stars), MCP Csharp (atherio-danp/cde-dotnetcc, 109 stars), Creating Dotnet MCP Servers (SebastienDegodez/copilot-instructions, 197 stars) and Csharp MCP Server Generator (ILoveDotNet/ilovedotnet, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Outdated?

codewithmukesh (a GitHub organization) maintains it in codewithmukesh/dotnet-claude-kit, which has 751 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on August 7, 2026.

Source: codewithmukesh/dotnet-claude-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.