Azure Bicep Skill
timothywarner-org/claude-code
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.
$ npx skills add dotnet/skills --skill nuget-trusted-publishing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dotnet/skills nuget-trusted-publishing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-advanced/skills/nuget-trusted-publishing .claude/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-advanced/skills/nuget-trusted-publishing into .claude/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dotnet/skills/tree/main/plugins/dotnet-advanced/skills/nuget-trusted-publishingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dotnet/skills --skill nuget-trusted-publishing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dotnet/skills nuget-trusted-publishing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/dotnet-advanced/skills/nuget-trusted-publishing .agents/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-advanced/skills/nuget-trusted-publishing into .agents/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dotnet/skills --skill nuget-trusted-publishing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dotnet/skills nuget-trusted-publishing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/dotnet-advanced/skills/nuget-trusted-publishing .cursor/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-advanced/skills/nuget-trusted-publishing into .cursor/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dotnet/skills.git --path plugins/dotnet-advanced/skills/nuget-trusted-publishing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dotnet/skills --skill nuget-trusted-publishing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dotnet/skills nuget-trusted-publishing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/dotnet-advanced/skills/nuget-trusted-publishing .gemini/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-advanced/skills/nuget-trusted-publishing into .gemini/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dotnet/skills nuget-trusted-publishingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dotnet/skills --skill nuget-trusted-publishing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/dotnet-advanced/skills/nuget-trusted-publishing .github/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-advanced/skills/nuget-trusted-publishing into .github/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dotnet/skills --skill nuget-trusted-publishing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dotnet/skills nuget-trusted-publishing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/dotnet-advanced/skills/nuget-trusted-publishing .opencode/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/dotnet/skills/tree/main/plugins/dotnet-advanced/skills/nuget-trusted-publishing into .opencode/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nuget-trusted-publishingSet up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.
Nuget Trusted Publishing is an agent skill from dotnet/skills, published by the product's own GitHub organization. Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens. USE FOR: trusted publishing, NuGet OIDC, keyless NuGet publish, migrate from NuGet API key, NuGet/login, secure NuGet publishing. DO NOT USE FOR: publishing to private feeds or Azure Artifacts (OIDC is nuget.org only). INVOKES: shell (powershell or bash), edit, create, askuser for guided repo setup.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/package-types.md` and `references/publish-workflow.md`).
It sits in DevOps & Cloud, covering OAuth and OpenID Connect and CI/CD. It works with GitHub Actions, .NET, Microsoft Azure and Bash. The repository describes itself as: Repository for skills to assist AI coding agents with .NET and C. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a660de8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dotnetghFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comnuget.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
NUGET_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nuget Trusted Publishing loads about 2.3k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 1,003 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dotnet/skills at commit a660de8, republished under its MIT licence (© dotnet). 1,003 words, ~2,317 tokens.
.claude/skills/nuget-trusted-publishing/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Set up NuGet trusted publishing on a GitHub Actions repo. Replaces long-lived API keys with OIDC-based short-lived tokens — no secrets to rotate or leak.
Use this skill when:
secrets.NUGET_API_KEY to OIDC-based publishingNuGet/login@v1 or id-token: write⚠️ Bail-out rule: If any phase fails after one fix attempt on an infrastructure/auth issue, stop and ask the user. Don't loop on environment problems.
⚠️ Never delete or overwrite without confirmation: Removing API key secrets, deleting tags/releases, removing workflow steps, or changing package IDs. NuGet package IDs are permanent — mistakes can't be undone.
Fast-path for greenfield repos: When the user has a simple setup (one packable project, no existing publish workflow), don't gate on multi-turn assessment. Combine phases: create the workflow immediately, include nuget.org policy guidance, local pack recommendation, and filename-matching warning all in one response. The full phased process below is for complex or migration scenarios.
Inspect the repo and report findings before making any changes.
Find and classify packable projects — check .csproj files and Directory.Build.props (package metadata is often set repo-wide). Classify in this order (earlier matches win):
<PackageType>Template</PackageType> → Template<PackageType>McpServer</PackageType> → MCP server (also a dotnet tool)<PackAsTool>true</PackAsTool> → Dotnet toolIsPackable=true or no OutputType) → Library<OutputType>Exe</OutputType> with <IsPackable>true</IsPackable> → Application package (not a tool, but still publishable)<OutputType>Exe</OutputType> without PackAsTool or IsPackable → Not packable by default (ask user if they intend to publish it)Validate structure for each project's type:
| Type | Required |
|---|---|
| All | PackageId, Version (in .csproj or Directory.Build.props) |
| Dotnet tool | PackAsTool (required); ToolCommandName (optional but recommended — defaults to assembly name) |
| MCP server | PackageType=McpServer, .mcp/server.json included in package |
| Template | PackageType=Template, .template.config/template.json under content dir |
Find existing publish workflows in .github/workflows/ — look for dotnet nuget push, nuget push, or dotnet pack.
Check version consistency — for MCP servers, verify .csproj <Version> matches both server.json version fields (root version and packages[].version). Flag any mismatch.
Report findings to the user: classification, missing properties, version mismatches, existing workflows. For multi-project repos, note whether one workflow or separate workflows per package are needed. Offer to fix gaps — use ask_user before modifying project files.
❌ See references/package-types.md for per-type details and required properties.
Pack and verify locally before touching nuget.org — publishing errors waste a permanent version number.
⚠️ Always mention this step, even if you defer running it. Tell the user: "Before your first publish, run
dotnet pack -c Release -o ./artifactsto verify the .nupkg is created correctly."
dotnet pack -c Release -o ./artifacts — verify .nupkg is created./artifacts, run --help, uninstall.nupkg contents (it's a zip)This phase requires the user to act on nuget.org — guide them with exact values.
Determine the repo owner, repo name, and the workflow filename that will publish.
❌ The policy requires the exact workflow filename (e.g.,
publish.ymlorpublish.yaml) — just the filename, no path prefix. Matching is case-insensitive. Don't use the workflowname:field.
Guide the user to create the trusted publishing policy:
Go to nuget.org/account/trustedpublishing → Add policy
- Repository Owner:
{owner}- Repository:
{repo}- Workflow File:
{filename}.yml- Environment:
release(only if the workflow usesenvironment:; leave blank otherwise)
Policy ownership: the user chooses individual account or organization. Org-owned policies apply to all packages owned by that org.
For private repos: policy is "temporarily active" for 7 days — becomes permanent after the first successful publish.
Guide the user to create a GitHub Environment (recommended but optional — provides secret scoping + approval gates):
Repo Settings → Environments → New environment →
releaseAdd environment secret: Name =
NUGET_USER, Value = nuget.org username (NOT email)
Optional: add Required reviewers for an approval gate.
⚠️ Wait for the user to confirm they've created the policy before asking them to remove old API keys/secrets or before attempting to run/publish with the workflow. Drafting or showing the workflow file itself is OK before confirmation.
Create or modify the publish workflow. The workflow must always be created or shown in your response — you may draft/show it even if the nuget.org policy is not yet confirmed, but do not guide the user to actually run/publish or remove old secrets until after confirmation.
Greenfield: Create publish.yml from the template in references/publish-workflow.md. Adapt .NET version, project path, and environment name. Ensure your output explicitly mentions id-token: write and NuGet/login@v1.
Migration (existing workflow with API key): Modify in place —
Add OIDC permission and environment to the publishing job:
jobs:
publish:
environment: release
permissions:
id-token: write # Required — without this, NuGet/login fails with 403
contents: read # Explicit — setting permissions overrides defaultsAdd the NuGet login step before push:
- name: NuGet login (OIDC)
id: login
uses: NuGet/login@v1
with:
user: ${{ secrets.NUGET_USER }} # nuget.org profile name, NOT emailReplace the API key in the push step:
--api-key ${{ steps.login.outputs.NUGET_API_KEY }} --skip-duplicateVerify: Ask the user to trigger a publish and confirm the package appears on nuget.org.
❌ Don't delete the old API key secret until trusted publishing is verified. Removing it is a one-way door — wait for confirmation.
| Problem | Cause | Fix |
|---|---|---|
NuGet/login 403 | Missing id-token: write | Add to job permissions |
| "no matching policy" | Workflow filename mismatch | Verify exact filename on nuget.org |
| Push unauthorized | Package not owned by policy account | Check policy owner on nuget.org |
| Token expired | Login step >1hr before push | Move NuGet/login closer to push |
| "temporarily active" policy | Private repo, first publish pending | Publish within 7 days |
already_exists on push | Re-running same version | Add --skip-duplicate |
| GitHub Release 422 | Duplicate release for tag | Delete conflicting release (confirm first) |
| Re-run uses wrong YAML | gh run rerun replays original commit's YAML | Delete obstacle, re-run — never re-tag |
⚠️ If any blocker persists after one fix attempt, stop and ask the user.
© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in plugins/dotnet-advanced/skills/nuget-trusted-publishing of dotnet/skills.
Open the folder on GitHubat commit a660de8
We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.
Nuget Trusted Publishing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nuget Trusted Publishing this skilldotnet/skills | 5.6k | 2 repos | ~2.3k | Automated safety check: Pass | MIT | |
| Azure Bicep Skilltimothywarner-org/claude-code | 224 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Managing Workflow Secretsbitwarden/ai-plugins | 154 | — | ~4k | Automated safety check: Pass | Custom licence | |
| Aspiremicrosoft/aspire.dev | 196 | 4 repos | ~1.1k | Automated safety check: Pass | MIT | |
| GitHub Actions Docsdevantler-tech/ksail | 165 | 2 repos | ~1.3k | Automated safety check: Pass | Custom licence | |
| Azure FunctionsDataDog/dd-trace-dotnet | 573 | — | ~4.7k | Automated safety check: Pass | Apache-2.0 |
timothywarner-org/claude-code
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
bitwarden/ai-plugins
Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…
microsoft/aspire.dev
Orchestrates Aspire distributed applications using the Aspire CLI for running, debugging, and managing distributed apps.
devantler-tech/ksail
A skill your agent uses when users ask how to write, explain, customize, migrate, secure, or troubleshoot GitHub Actions workflows, workflow syntax, triggers, matrices, runners, reusable workflows…
DataDog/dd-trace-dotnet
Dev/test workflow for tracer engineers working on the Datadog .NET tracer — build a local Datadog.AzureFunctions NuGet package, deploy it to a test Azure Function App, trigger it, and analyze…
XiaomiMiMo/MiMo-Code
Runs OpenAI Codex CLI as a non-interactive worker for CI, Docker, Kubernetes or remote servers, with sandbox modes and JSONL-friendly output.
dotnet/skills
Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.
dotnet/skills
Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.
dotnet/skills
Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.
dotnet/skills
Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.
dotnet/skills
Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.
dotnet/skills
Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.
Categories
Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens. Nuget Trusted Publishing is an agent skill from dotnet/skills, published by the product's own GitHub organization. Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.
Nuget Trusted Publishing fits situations like: : trusted publishing; keyless NuGet publish; migrate from NuGet API key; secure NuGet publishing.
Run `npx skills add dotnet/skills --skill nuget-trusted-publishing -a claude-code`. Or copy the skill folder (plugins/dotnet-advanced/skills/nuget-trusted-publishing in dotnet/skills) into .claude/skills/nuget-trusted-publishing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dotnet/skills --skill nuget-trusted-publishing -a codex`. Or copy the skill folder (plugins/dotnet-advanced/skills/nuget-trusted-publishing in dotnet/skills) into .agents/skills/nuget-trusted-publishing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill nuget-trusted-publishing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nuget-trusted-publishing, .gemini/skills/nuget-trusted-publishing, .github/skills/nuget-trusted-publishing and .opencode/skills/nuget-trusted-publishing in your project.
Going by SKILL.md and its folder, Nuget Trusted Publishing needs the command-line tools its instructions call (dotnet and gh) and credentials named NUGET_API_KEY. Our summary lists: A credential in NUGET_API_KEY.
SKILL.md names 2 domains. As links in the text: learn.microsoft.com and nuget.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nuget Trusted Publishing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Nuget Trusted Publishing: Azure Bicep Skill (timothywarner-org/claude-code, 224 stars), Managing Workflow Secrets (bitwarden/ai-plugins, 154 stars), Aspire (microsoft/aspire.dev, 196 stars) and GitHub Actions Docs (devantler-tech/ksail, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,576 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 8, 2026.
Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.