Official agent skill

Convert To Cpm

by dotnet in dotnet/skills

Convert .NET projects and solutions (.sln, .slnx) to NuGet Central Package Management (CPM) using Directory.Packages.props.

OfficialMITAuto-check passed

Install Convert To Cpm

skills CLI
$ npx skills add dotnet/skills --skill convert-to-cpm -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dotnet/skills convert-to-cpm --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-nuget/skills/convert-to-cpm .claude/skills/convert-to-cpm && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
convert-to-cpm
GitHub stars
5.6k
Used in
1 other repo
Token cost
~3.6k tokens
SKILL.md length
1,719 words
Files
7 (incl. references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Convert .NET projects and solutions (.sln, .slnx) to NuGet Central Package Management (CPM) using Directory.Packages.props.

  • Works in 6 steps: Scope and preflight → Capture the baseline → Audit with a targeted checklist → …
  • : converting to CPM
  • SKILL.md covers Choose a mode first, Inputs, Read references only when needed and Conversion workflow, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Convert To Cpm is an agent skill from dotnet/skills, published by the product's own GitHub organization. Convert .NET projects and solutions (.sln, .slnx) to NuGet Central Package Management (CPM) using Directory.Packages.props. USE FOR: converting to CPM, centralizing or aligning NuGet package versions across multiple projects, inlining MSBuild version properties from Directory.Build.props into Directory.Packages.props, resolving version conflicts or mismatches across a solution or repository, updating or bumping or syncing package versions across projects. Also activate when packages are out of sync, drifting, or…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/audit-complexities.md`, `references/baseline-comparison.md` and `references/directory-packages-props.md`).

It works with .NET. The repository describes itself as: Repository for skills to assist AI coding agents with .NET and C. The licence is MIT.

When your agent uses it

  • : converting to CPM
  • Aligning NuGet package versions across multiple projects
  • Inlining MSBuild version properties from Directory.Build.props into Directory.Packages.props
  • Resolving version conflicts

Example prompts

  • “/convert-to-cpm”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Scope and preflight
  2. Capture the baseline
  3. Audit with a targeted checklist
  4. Create CPM files and update references
  5. Validate and compare
  6. Write the report

What it can do on your machine

Read from SKILL.md and the folder at commit a660de8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Convert To Cpm loads about 3.6k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 216 tokens; SKILL.md has 1,719 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~216
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dotnet/skills at commit a660de8, republished under its MIT licence (© dotnet). 1,719 words, ~3,571 tokens.

Download SKILL.mdSave it as .claude/skills/convert-to-cpm/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
convert-to-cpm
description
Convert .NET projects and solutions (.sln, .slnx) to NuGet Central Package Management (CPM) using Directory.Packages.props. USE FOR: converting to CPM, centralizing or aligning NuGet package versions across multiple projects, inlining MSBuild version properties from Directory.Build.props into Directory.Packages.props, resolving version conflicts or mismatches across a solution or repository, updating or bumping or syncing package versions across projects. Also activate when packages are out of sync, drifting, or inconsistent -- even without the user mentioning CPM. Provides baseline build capture, version conflict resolution, build validation with binlog comparison, and a structured post-conversion report. DO NOT USE FOR: packages.config projects (must migrate to PackageReference first) or repositories that already have CPM fully enabled.
license
MIT

Convert to Central Package Management

Centralize package versions in Directory.Packages.props while preserving project behavior and producing reviewable before/after evidence.

Choose a mode first

Do this before running builds or changing files.

  1. Guard mode -- If any in-scope project uses packages.config, stop. Explain that CPM requires PackageReference and recommend migrating first. Do not create or modify files.
  2. Package-maintenance mode -- A request to update, align, bump, or sync packages authorizes those package edits, not CPM conversion. Audit the named scope, resolve the requested versions, update existing project/shared version declarations, and restore/build every affected CLI target from the directory that establishes its applicable global.json. Ask only when the version or alignment policy is ambiguous. Do not create or modify Directory.Packages.props, remove versions for CPM, or capture conversion artifacts. Complete the package work, then recommend CPM as the durable follow-up.
  3. Conversion mode -- Use only when the user explicitly asks to adopt, enable, or convert to CPM. Follow the workflow below.

If the scope is unclear, ask once before proceeding.

Default execution plan
  • Guard: use a minimal scoped detection pass, then answer and stop.
  • Package maintenance: use a compact audit, edit only the requested package versions in their existing locations, validate affected targets, then recommend CPM. Do not read conversion references or enter the conversion workflow.
  • Conversion: batch the preflight, baseline, audit/mutation, final validation, and report work to avoid redundant turns. Revisit a stage only when new CPM-specific evidence requires a targeted follow-up.

This plan is an efficiency default, not a hard cap. Never omit an in-scope project, imported .props/.targets file, detected complexity, required validation, or deliverable to save a turn. Batch complete work where practical.

Inputs

InputRequiredRule
ScopeYesProject, solution, or directory containing the projects to inspect or convert
Conflict strategyFor package maintenance or conversion with conflictsIf the user already supplied a strategy such as "use the highest version," apply it without asking again and record its impact. Otherwise stop after the audit and ask before editing.

Read references only when needed

Never preload all references.

ConditionRead
Entering conversion baseline or producing the package diffbaseline-comparison.md
A conflict, conditional reference, shared import, security concern, or VersionOverride is detectedaudit-complexities.md
Placement is unclear or conditional PackageVersion/VersionOverride is requireddirectory-packages-props.md
A package version uses an MSBuild propertymsbuild-property-handling.md
Restore or build fails after conversionvalidation-and-errors.md
Writing the final reportreport-template.md

Conversion workflow

1. Scope and preflight
  • Resolve the project/solution scope. For a solution, list its projects. For a directory, search only beneath that directory and create an explicit target set that covers the full scope: use each applicable .sln/.slnx, then add each project not covered by a solution. Verify that every in-scope project is covered and avoid duplicate work for projects that occur in more than one target. Ask only when overlapping targets or repository boundaries make the intended coverage ambiguous; never ask the user to select one target when that would omit in-scope projects.
  • Determine CPM management scopes separately from CLI targets. Group projects that will share one central version policy and place one Directory.Packages.props at each group's first common ancestor, while respecting existing nearest-file boundaries. Multiple CLI targets can share one CPM file; independent project groups can require separate files.
  • Check for packages.config; if found, switch to Guard mode and stop.
  • Check the scope and ancestors for Directory.Packages.props. If CPM is already fully enabled, report that and stop. If a partial file exists, preserve it and ask only when its intended scope is ambiguous.
  • Choose one common artifact directory within the resolved scope, normally the targets' first common ancestor. Use explicit paths into it for every binlog, package snapshot, and the report.
  • Run each target's .NET commands from its solution/project directory or another directory that establishes its applicable global.json, not from an unrelated parent workspace.
  • Do not inspect unrelated projects or host-tool configuration when the user supplied a scope.
2. Capture the baseline

Read baseline-comparison.md. For each target, determine the active SDK once from that target's command directory and select the documented command syntax for that version. If SDK resolution fails or the SDK cannot process the requested solution format, stop and report the prerequisite; do not alter the host SDK or repository SDK policy unless the user asks.

Then use one command batch to:

  1. Clean, restore, and build every explicit target. Use baseline.binlog for one target or a unique baseline-<target-key>.binlog for each of multiple targets.
  2. Write resolved packages for every target without restoring again. Use baseline-packages.json for one target or a matching baseline-packages-<target-key>.json for each of multiple targets.
  3. Keep normal command output concise. Save full output to artifacts when useful; inspect only errors on failure and never read the binlog as text.

Finish every baseline before editing. If any baseline build fails, stop without modifying files and preserve all artifacts already produced.

3. Audit with a targeted checklist

Use all baseline snapshots plus one targeted scan of in-scope project, .props, and .targets files. Identify:

  • Package IDs, resolved versions, and consuming projects
  • Version conflicts
  • MSBuild property-based versions and their definitions
  • Conditional PackageReference items
  • Imported files containing package references
  • Existing VersionOverride usage

For a complex scope, complete every applicable item above across all projects and imported files; do not stop after finding the first conflict.

Do not run broad --outdated or --deprecated scans by default. Before editing, attempt a scoped --vulnerable --include-transitive query when the user requested security information, a known advisory must be verified, or conflict resolution will move a project across a major package version. Record the compact findings, "no advisories found," or why the check could not run. If a high-risk check is unavailable because of authentication, package-source, or offline constraints, surface the uncertainty and confirm the user's strategy rather than silently treating it as safe. Do not upgrade beyond the highest version already in scope as part of a CPM conversion.

Present conflicts and their impact. Explicitly classify major-version alignment as high risk and minor/patch alignment as moderate risk without performing an extra online scan. If the user supplied a conflict strategy, proceed. Otherwise ask for the unresolved decisions and stop before editing.

Show full SKILL.md (706 more words)Show less
4. Create CPM files and update references
  • Create or update each required Directory.Packages.props at its computed management scope with ManagePackageVersionsCentrally set to true.
  • Add one alphabetically sorted PackageVersion per package, preserving required target-framework conditions.
  • Remove only Version from managed PackageReference items in projects and imported files.
  • Preserve conditions, whitespace, and all other metadata such as PrivateAssets, IncludeAssets, ExcludeAssets, GeneratePathProperty, and Aliases.
  • Use VersionOverride only when the chosen strategy requires it.

For MSBuild version properties, follow msbuild-property-handling.md. When the user directs inlining, include both the literal PackageVersion and removal of the obsolete property definition in the same mutation batch. Before final validation, verify separately that:

  1. No $(PropertyName) references remain in scoped project, .props, or .targets files.
  2. No <PropertyName>...</PropertyName> definition remains for each property chosen for removal.

Do not rely on a $() reference scan to prove that the XML property definition was removed.

5. Validate and compare

Using baseline-comparison.md, validate the final on-disk state after all project, shared-file, and property edits. Use one command batch to:

  1. Clean, restore, and build every explicit target after all CPM edits. Use after-cpm.binlog for one target or a matching after-cpm-<target-key>.binlog for each of multiple targets.
  2. Write resolved packages for every target without restoring again. Use after-cpm-packages.json for one target or a matching after-cpm-packages-<target-key>.json for each of multiple targets.
  3. Produce a compact per-project changes/unchanged comparison without printing or rereading the full JSON files.
  4. If resolved versions changed and the repository exposes a routine, scoped test command for affected projects, run it with --no-build --no-restore and record the result. If tests require substantial setup, broad infrastructure, or user approval, recommend the exact scoped command instead. A version-neutral conversion does not require an automatic test run.

If restore or build fails with a CPM-related error, read validation-and-errors.md, inspect only the relevant error lines, make a targeted correction, and rerun the affected validation. For SDK, authentication, package-source, file-lock, test-host, or other environmental failures, report the blocker instead of changing the machine or expanding the investigation.

If a test run fails after a successful build, inspect only enough output to determine whether CPM package resolution caused it. Apply a targeted correction only when the evidence clearly identifies a CPM defect; otherwise record the failure and recommended user action without expanding into test-host, SDK, output-directory, or dependency-copy debugging.

6. Write the report

Read report-template.md now, not earlier. Create convert-to-cpm.md beside the other artifacts. It must include the six required sections, every explicit target and CPM management scope, concrete conflict impacts, the aggregate package comparison, risk level, follow-ups, artifact usage, and the name of every shared .props/.targets file inspected or changed. In the final response, mention those shared files, the risk level, and how any conditional references and target frameworks were preserved. Avoid rewriting the report after validation unless verification finds an omission or incorrect evidence.

Required conversion artifacts

Preserve the report and every target's four evidence files; they are not temporary files. For one target, the five deliverables are:

  • baseline.binlog
  • after-cpm.binlog
  • baseline-packages.json
  • after-cpm-packages.json
  • convert-to-cpm.md

For multiple targets, replace the four fixed evidence names with unique target-keyed pairs such as baseline-api.binlog, after-cpm-api.binlog, baseline-packages-api.json, and after-cpm-packages-api.json. Keep one aggregate convert-to-cpm.md.

Efficiency rules

  • Batch independent reads and edits when supported.
  • Keep full build logs and package JSON out of the conversation; return compact summaries and artifact paths.
  • Do not repeat successful commands or reread successful output.
  • In conversion mode, do not perform package upgrades, broad outdated/deprecated scans, repeated tests, or unrelated repository exploration. The single conditional vulnerability query and test run defined above are part of complete high-risk conversion validation. Package maintenance can perform the requested upgrades and one scoped version-discovery query needed to resolve them.
  • Do not install or remove an SDK, create a temporary SDK selector, change roll-forward policy, invoke SDK-internal assemblies, kill unrelated processes, or clean host tooling/temp infrastructure. Report an environment prerequisite and stop.

Validation

  • Baseline and converted builds succeeded for every explicit target and all target binlogs exist
  • Every managed PackageReference has no Version, or intentionally uses VersionOverride
  • Every managed package has the correct central PackageVersion
  • Conditions and non-version metadata were preserved
  • Before/after package comparison contains no unexplained changes
  • Inlined version properties have neither remaining $() references nor obsolete XML definitions
  • The report and all per-target baseline and converted artifacts exist

© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/dotnet-nuget/skills/convert-to-cpm of dotnet/skills.

  • SKILL.md
  • references/audit-complexities.md
  • references/baseline-comparison.md
  • references/directory-packages-props.md
  • references/msbuild-property-handling.md
  • references/report-template.md
  • references/validation-and-errors.md

Open the folder on GitHubat commit a660de8

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Convert To Cpm next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Convert To Cpm compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Convert To Cpm this skilldotnet/skills5.6k1 repos~3.6kAutomated safety check: PassMIT
Minimax DOCXpoco-ai/poco-claw1.4k7 repos~3.9kAutomated safety check: PassMIT
Microsoft Skill CreatorMicrosoftDocs/mcp1.9k3 repos~2.1kAutomated safety check: PassCC-BY-4.0
Speckit ConstitutionWeihanLi/WeihanLi.Common24211 repos~2.1kAutomated safety check: PassApache-2.0
Copilot Session Failure Analysisdotnet/maui23k—~3.4kAutomated safety check: PassMIT
Microsoft Code ReferenceMicrosoftDocs/mcp1.9k4 repos~1.1kAutomated safety check: PassCC-BY-4.0

Similar skills

  • Minimax DOCX

    poco-ai/poco-claw

    Professional DOCX document creation, editing, and formatting using OpenXML SDK (.NET).

    1.4k GitHub starsUsed in 7 repos~3.9k tokens
    Documents & OfficeAuto-check passed
  • Microsoft Skill Creator

    MicrosoftDocs/mcp

    Official

    Create agent skills for Microsoft technologies using official documentation.

    1.9k GitHub starsUsed in 3 repos~2.1k tokens
    Agent WorkflowsAuto-check passed
  • Speckit Constitution

    WeihanLi/WeihanLi.Common

    Create or update the project constitution from interactive or provided principle inputs, ensuring all dependent templates stay in sync.

    242 GitHub starsUsed in 11 repos~2.1k tokens
    DevelopmentAuto-check passed
  • Mines local Copilot CLI session logs for dotnet/maui to rank costly or failing runs, tag recurring failure modes, propose repo edits and emit guard evals.

    23k GitHub stars~3.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Microsoft Code Reference

    MicrosoftDocs/mcp

    Official

    Find working code samples, verify API signatures, and fix Microsoft SDK errors using official docs.

    1.9k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Official

    Audits and updates os-packages.json files listing the Linux packages each .NET release needs per distro, then regenerates the Markdown from the JSON.

    22k GitHub stars~2.3k tokensUpdated today
    DevelopmentAuto-check passed

More from dotnet/skills

All 91 skills in this repo
  • Official

    Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

    5.6k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Official

    Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.

    5.6k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Official

    Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

    5.6k GitHub starsUsed in 3 repos~3.1k tokens
    Auto-check passed
  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Microbenchmarking

    dotnet/skills

    Official

    Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.

    5.6k GitHub starsUsed in 3 repos~3.3k tokens
    Auto-check passed
  • Official

    Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.

    5.6k GitHub starsUsed in 2 repos~4.2k tokens
    Auto-check passed

Works with

Questions about Convert To Cpm

What does Convert To Cpm do?

Convert .NET projects and solutions (.sln, .slnx) to NuGet Central Package Management (CPM) using Directory.Packages.props. Convert To Cpm is an agent skill from dotnet/skills, published by the product's own GitHub organization.props.

When should I use Convert To Cpm?

Convert To Cpm fits situations like: : converting to CPM; aligning NuGet package versions across multiple projects; inlining MSBuild version properties from Directory.Build.props into Directory.Packages.props; resolving version conflicts.

How do I install Convert To Cpm in Claude Code?

Run `npx skills add dotnet/skills --skill convert-to-cpm -a claude-code`. Or copy the skill folder (plugins/dotnet-nuget/skills/convert-to-cpm in dotnet/skills) into .claude/skills/convert-to-cpm in your project. Claude Code loads it when a task matches its description.

How do I install Convert To Cpm in Codex?

Run `npx skills add dotnet/skills --skill convert-to-cpm -a codex`. Or copy the skill folder (plugins/dotnet-nuget/skills/convert-to-cpm in dotnet/skills) into .agents/skills/convert-to-cpm in your project. Codex loads it when a task matches its description.

Can I use Convert To Cpm in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill convert-to-cpm -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/convert-to-cpm, .gemini/skills/convert-to-cpm, .github/skills/convert-to-cpm and .opencode/skills/convert-to-cpm in your project.

What does Convert To Cpm need to run?

SKILL.md names no scripts, command-line tools or credentials: Convert To Cpm is instructions for the agent only.

Does Convert To Cpm access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Convert To Cpm safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Convert To Cpm use?

Convert To Cpm is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Convert To Cpm use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.8k tokens, read only when the agent opens those files.

What are the alternatives to Convert To Cpm?

Skills that share tags, products or a category with Convert To Cpm: Minimax DOCX (poco-ai/poco-claw, 1.4k stars), Microsoft Skill Creator (MicrosoftDocs/mcp, 1.9k stars), Speckit Constitution (WeihanLi/WeihanLi.Common, 242 stars) and Copilot Session Failure Analysis (dotnet/maui, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Convert To Cpm?

dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,576 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 8, 2026.

Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.