Agent skill

Maui Secure Storage

by davidortinau in davidortinau/maui-skills

Add secure storage to .NET MAUI apps using SecureStorage.Default.

MITAuto-check passedMobile

Install Maui Secure Storage

skills CLI
$ npx skills add davidortinau/maui-skills --skill maui-secure-storage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davidortinau/maui-skills maui-secure-storage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davidortinau/maui-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/maui-skills/skills/maui-secure-storage .claude/skills/maui-secure-storage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
maui-secure-storage
GitHub stars
175
Token cost
~1.1k tokens
SKILL.md length
320 words
Files
2 (incl. references)
Skills in repo
41
Repo updated
First seen
Licence
MIT

At a glance

Add secure storage to .NET MAUI apps using SecureStorage.Default.

  • : secure storage
  • SKILL.md covers Critical Platform Pitfalls, Common Mistakes, Decision Framework and Testability: Always Use DI, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Store token securely

What it does

Maui Secure Storage is an agent skill from davidortinau/maui-skills. Add secure storage to .NET MAUI apps using SecureStorage.Default. Covers SetAsync, GetAsync, Remove, RemoveAll, platform setup (Android backup rules, iOS Keychain entitlements, Windows limits), common pitfalls, and a DI wrapper service for testability. USE FOR: "secure storage", "SecureStorage", "store token securely", "Keychain", "Android Keystore", "save secret", "encrypted storage", "store credentials", "sensitive data storage". DO NOT USE FOR: general file storage (use maui-file-handling), SQLite databases…

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/secure-storage-api.md`).

It sits in Mobile, covering Cross-platform mobile apps and File uploads and storage. It works with Android, iOS and SQLite. The repository describes itself as: .NET MAUI skills for GitHub Copilot and Claude Code. The licence is MIT.

When your agent uses it

  • : secure storage
  • Store token securely
  • Android Keystore
  • Encrypted storage

Example prompts

  • “secure storage”
  • “SecureStorage”
  • “store token securely”
  • “/maui-secure-storage”

What it can do on your machine

Read from SKILL.md and the folder at commit 79bb4bf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are csharp).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Maui Secure Storage loads about 1.1k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 154 tokens; SKILL.md has 320 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~154
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davidortinau/maui-skills at commit 79bb4bf, republished under its MIT licence (© davidortinau). 320 words, ~1,150 tokens.

Download SKILL.mdSave it as .claude/skills/maui-secure-storage/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
maui-secure-storage
description
Add secure storage to .NET MAUI apps using SecureStorage.Default. Covers SetAsync, GetAsync, Remove, RemoveAll, platform setup (Android backup rules, iOS Keychain entitlements, Windows limits), common pitfalls, and a DI wrapper service for testability. USE FOR: "secure storage", "SecureStorage", "store token securely", "Keychain", "Android Keystore", "save secret", "encrypted storage", "store credentials", "sensitive data storage". DO NOT USE FOR: general file storage (use maui-file-handling), SQLite databases (use maui-sqlite-database), or authentication flows (use maui-authentication).

Secure Storage — Gotchas & Best Practices

Critical Platform Pitfalls

⚠️ Android: Auto Backup Breaks Encrypted Values

Auto Backup restores encrypted preferences to a new device where the encryption key is invalid — this throws unrecoverable exceptions. You must either disable Auto Backup or exclude secure storage files from backup. See references/secure-storage-api.md for setup options.

⚠️ Android: Always Wrap in try/catch

Corrupted values from backup restoration throw exceptions. Never call GetAsync unprotected:

csharp
// ❌ Unprotected — crashes on corrupted backup data
var value = await SecureStorage.Default.GetAsync("key");

// ✅ Protected — handles corruption gracefully
try
{
    var value = await SecureStorage.Default.GetAsync("key");
}
catch (Exception)
{
    SecureStorage.Default.RemoveAll();
}
⚠️ iOS: Keychain Entitlements on Simulator

Add keychain access groups for Simulator builds, but remove before physical device / App Store builds — they cause signing issues on devices where they aren't needed.

⚠️ iOS: Uninstall Does NOT Clear Keychain

Unlike Android, uninstalling an iOS app does not remove its Keychain entries. Values persist and are available if the app is reinstalled. Design for this — don't assume a fresh install means empty storage.

⚠️ iOS: iCloud Keychain Sync

Values may sync across devices via iCloud Keychain if the user has it enabled. This is platform behavior, not controllable from MAUI. Don't store device-specific tokens that shouldn't roam.

Windows Limits
  • Key name: max 255 characters
  • Value: max 8 KB per setting
  • Composite storage: max 64 KB total

Common Mistakes

csharp
// ❌ Storing large data — SecureStorage is for small secrets only
await SecureStorage.Default.SetAsync("profile_image", base64EncodedImage);

// ✅ Store tokens, passwords, short secrets
await SecureStorage.Default.SetAsync("auth_token", jwtToken);

// ❌ Logging secret values
_logger.LogInformation("Token: {Token}", await SecureStorage.Default.GetAsync("auth_token"));

// ✅ Log existence, not value
_logger.LogInformation("Token exists: {Exists}", token is not null);

// ❌ Storing complex objects without serialization (values are strings only)
await SecureStorage.Default.SetAsync("user", userObject);

// ✅ Serialize to JSON first
await SecureStorage.Default.SetAsync("user", JsonSerializer.Serialize(user));

Decision Framework

QuestionAnswer
Storing a token, password, or API key?✅ Use SecureStorage
Storing user preferences or settings?❌ Use Preferences instead
Storing large files or blobs?❌ Use file system + encryption
Need cross-device sync?⚠️ iOS syncs via iCloud Keychain automatically
Need data cleared on uninstall?⚠️ Only works on Android, not iOS

Testability: Always Use DI

Never call SecureStorage.Default directly from ViewModels — wrap it in an ISecureStorageService interface for testability. See references/secure-storage-api.md for the full DI wrapper pattern with mock examples.

csharp
// ❌ Direct static access — untestable
public class LoginViewModel
{
    public async Task SaveToken(string token)
        => await SecureStorage.Default.SetAsync("auth_token", token);
}

// ✅ Inject interface — testable and mockable
public class LoginViewModel(ISecureStorageService secure)
{
    public async Task SaveToken(string token)
        => await secure.SetAsync("auth_token", token);
}

Checklist

  • Android: Auto Backup disabled or secure storage excluded from backup
  • Android: All GetAsync calls wrapped in try/catch
  • iOS: Keychain entitlements configured (Simulator only — remove for device builds)
  • Values are strings only — complex data serialized to JSON
  • No secret values logged anywhere
  • SecureStorage.Default accessed via DI wrapper, not directly from ViewModels

© davidortinau, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/maui-skills/skills/maui-secure-storage of davidortinau/maui-skills.

  • SKILL.md
  • references/secure-storage-api.md

Open the folder on GitHubat commit 79bb4bf

Compare with similar skills

Maui Secure Storage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Maui Secure Storage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Maui Secure Storage this skilldavidortinau/maui-skills175—~1.1kAutomated safety check: PassMIT
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause
Rnn Codebasewix/react-native-navigation13k—~2kAutomated safety check: PassMIT
Building Native UICherryHQ/cherry-studio-app4k8 repos~2.6kAutomated safety check: PassMIT
Expo Tailwind SetupCherryHQ/cherry-studio-app4k8 repos~3kAutomated safety check: PassMIT
Screenmapaleqsio/screenmap244—~7.2kAutomated safety check: PassMIT

Similar skills

  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • Rnn Codebase

    wix/react-native-navigation

    Official

    Navigate and work with the react-native-navigation (RNN) codebase.

    13k GitHub stars~2k tokensUpdated 4 days ago
    MobileAuto-check passed
  • Building Native UI

    CherryHQ/cherry-studio-app

    Complete guide for building beautiful apps with Expo Router.

    4k GitHub starsUsed in 8 repos~2.6k tokens
    MobileAuto-check passed
  • Expo Tailwind Setup

    CherryHQ/cherry-studio-app

    Set up Tailwind CSS v4 in Expo with react-native-css and NativeWind v5 for universal styling

    4k GitHub starsUsed in 8 repos~3k tokens
    MobileAuto-check passed
  • Screenmap

    aleqsio/screenmap

    Generate a visual navigation map of an Expo / React Native or NativeScript app.

    244 GitHub stars~7.2k tokensUpdated 6 days ago
    MobileAuto-check passed
  • Expo Brownfield Integration

    mweinbach/agent-coworker

    Helps add Expo and React Native to an existing native iOS or Android app, and choose between a prebuilt AAR or XCFramework and a fully integrated build.

    156 GitHub starsUsed in 2 repos~900 tokens
    MobileAuto-check: notes

More from davidortinau/maui-skills

All 41 skills in this repo
  • Maui Hot Reload Diagnostics

    davidortinau/maui-skills

    Diagnose and troubleshoot .NET MAUI Hot Reload issues (C Hot Reload, XAML Hot Reload, Blazor Hybrid).

    175 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed
  • Maui Accessibility

    davidortinau/maui-skills

    Guide for making .NET MAUI apps accessible — screen reader support via SemanticProperties, heading levels, AutomationProperties visibility control, programmatic focus and announcements, and…

    175 GitHub stars~974 tokensUpdated 3 mo ago
    Auto-check passed
  • Maui Animations

    davidortinau/maui-skills

    .NET MAUI view animations, custom animations, easing functions, rotation, scale, translation, and fade effects.

    175 GitHub stars~911 tokensUpdated 3 mo ago
    Auto-check passed
  • Maui App Icons Splash

    davidortinau/maui-skills

    .NET MAUI app icon configuration, splash screen setup, SVG to PNG conversion at build time, composed/adaptive icons, and platform-specific icon and splash screen requirements for Android, iOS, Mac…

    175 GitHub stars~995 tokensUpdated 3 mo ago
    Auto-check passed
  • Maui App Lifecycle

    davidortinau/maui-skills

    .NET MAUI app lifecycle guidance covering the four app states (not running, running, deactivated, stopped), cross-platform Window lifecycle events, backgrounding and resume behaviour…

    175 GitHub stars~947 tokensUpdated 3 mo ago
    Auto-check passed
  • Maui Aspire

    davidortinau/maui-skills

    Guide for .NET MAUI apps consuming .NET Aspire-hosted backend services.

    175 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Maui Secure Storage

What does Maui Secure Storage do?

Add secure storage to .NET MAUI apps using SecureStorage.Default. Maui Secure Storage is an agent skill from davidortinau/maui-skills.Default.

When should I use Maui Secure Storage?

Maui Secure Storage fits situations like: : secure storage; store token securely; android Keystore; encrypted storage.

How do I install Maui Secure Storage in Claude Code?

Run `npx skills add davidortinau/maui-skills --skill maui-secure-storage -a claude-code`. Or copy the skill folder (plugins/maui-skills/skills/maui-secure-storage in davidortinau/maui-skills) into .claude/skills/maui-secure-storage in your project. Claude Code loads it when a task matches its description.

How do I install Maui Secure Storage in Codex?

Run `npx skills add davidortinau/maui-skills --skill maui-secure-storage -a codex`. Or copy the skill folder (plugins/maui-skills/skills/maui-secure-storage in davidortinau/maui-skills) into .agents/skills/maui-secure-storage in your project. Codex loads it when a task matches its description.

Can I use Maui Secure Storage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davidortinau/maui-skills --skill maui-secure-storage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/maui-secure-storage, .gemini/skills/maui-secure-storage, .github/skills/maui-secure-storage and .opencode/skills/maui-secure-storage in your project.

What does Maui Secure Storage need to run?

SKILL.md names no scripts, command-line tools or credentials: Maui Secure Storage is instructions for the agent only.

Does Maui Secure Storage access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Maui Secure Storage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Maui Secure Storage use?

Maui Secure Storage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Maui Secure Storage use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 931 tokens, read only when the agent opens those files.

What are the alternatives to Maui Secure Storage?

Skills that share tags, products or a category with Maui Secure Storage: Engine Whats New (flutter/flutter, 179k stars), Rnn Codebase (wix/react-native-navigation, 13k stars), Building Native UI (CherryHQ/cherry-studio-app, 4k stars) and Expo Tailwind Setup (CherryHQ/cherry-studio-app, 4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Maui Secure Storage?

davidortinau (a GitHub user) maintains it in davidortinau/maui-skills, which has 175 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on July 6, 2026.

Source: davidortinau/maui-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.