Official agent skill

Nuget Trusted Publishing

by dotnet in dotnet/skills

Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.

OfficialMITAuto-check passedDevOps & Cloud

Install Nuget Trusted Publishing

skills CLI
$ npx skills add dotnet/skills --skill nuget-trusted-publishing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dotnet/skills nuget-trusted-publishing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dotnet/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/dotnet-advanced/skills/nuget-trusted-publishing .claude/skills/nuget-trusted-publishing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nuget-trusted-publishing
GitHub stars
5.6k
Used in
2 other repos
Token cost
~2.3k tokens
SKILL.md length
1,003 words
Files
3 (incl. references)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.

  • Works in 4 steps: Assess → Local Verification → nuget.org Policy → …
  • : trusted publishing
  • SKILL.md covers Prerequisites, When to Use This Skill, Safety Rules and Process, plus 2 more sections
  • Calls dotnet and gh; needs NUGET_API_KEY

What it does

Nuget Trusted Publishing is an agent skill from dotnet/skills, published by the product's own GitHub organization. Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens. USE FOR: trusted publishing, NuGet OIDC, keyless NuGet publish, migrate from NuGet API key, NuGet/login, secure NuGet publishing. DO NOT USE FOR: publishing to private feeds or Azure Artifacts (OIDC is nuget.org only). INVOKES: shell (powershell or bash), edit, create, askuser for guided repo setup.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/package-types.md` and `references/publish-workflow.md`).

It sits in DevOps & Cloud, covering OAuth and OpenID Connect and CI/CD. It works with GitHub Actions, .NET, Microsoft Azure and Bash. The repository describes itself as: Repository for skills to assist AI coding agents with .NET and C. The licence is MIT.

When your agent uses it

  • : trusted publishing
  • Keyless NuGet publish
  • Migrate from NuGet API key
  • Secure NuGet publishing

Example prompts

  • “/nuget-trusted-publishing”

Requirements

  • A credential in NUGET_API_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Assess
  2. Local Verification
  3. nuget.org Policy
  4. Workflow Setup

What it can do on your machine

Read from SKILL.md and the folder at commit a660de8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • nuget.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NUGET_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nuget Trusted Publishing loads about 2.3k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 1,003 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dotnet/skills at commit a660de8, republished under its MIT licence (© dotnet). 1,003 words, ~2,317 tokens.

Download SKILL.mdSave it as .claude/skills/nuget-trusted-publishing/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
nuget-trusted-publishing
description
Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens. USE FOR: trusted publishing, NuGet OIDC, keyless NuGet publish, migrate from NuGet API key, NuGet/login, secure NuGet publishing. DO NOT USE FOR: publishing to private feeds or Azure Artifacts (OIDC is nuget.org only). INVOKES: shell (powershell or bash), edit, create, ask_user for guided repo setup.
license
MIT

NuGet Trusted Publishing Setup

Set up NuGet trusted publishing on a GitHub Actions repo. Replaces long-lived API keys with OIDC-based short-lived tokens — no secrets to rotate or leak.

Prerequisites

  • GitHub Actions — this skill covers GitHub Actions setup only
  • nuget.org account — the user needs access to create trusted publishing policies

When to Use This Skill

Use this skill when:

  • Setting up trusted publishing for a NuGet package
  • Migrating from secrets.NUGET_API_KEY to OIDC-based publishing
  • Asked about keyless or secure NuGet publishing
  • Creating a new NuGet publish workflow from scratch
  • Asked to "remove NuGet API key" or "use NuGet/login"
  • Setting up publishing for a dotnet tool, MCP server, or template package
  • Asked about NuGet/login@v1 or id-token: write

Safety Rules

⚠️ Bail-out rule: If any phase fails after one fix attempt on an infrastructure/auth issue, stop and ask the user. Don't loop on environment problems.

⚠️ Never delete or overwrite without confirmation: Removing API key secrets, deleting tags/releases, removing workflow steps, or changing package IDs. NuGet package IDs are permanent — mistakes can't be undone.

Process

Fast-path for greenfield repos: When the user has a simple setup (one packable project, no existing publish workflow), don't gate on multi-turn assessment. Combine phases: create the workflow immediately, include nuget.org policy guidance, local pack recommendation, and filename-matching warning all in one response. The full phased process below is for complex or migration scenarios.

Phase 1: Assess

Inspect the repo and report findings before making any changes.

  1. Find and classify packable projects — check .csproj files and Directory.Build.props (package metadata is often set repo-wide). Classify in this order (earlier matches win):

    • <PackageType>Template</PackageType> → Template
    • <PackageType>McpServer</PackageType> → MCP server (also a dotnet tool)
    • <PackAsTool>true</PackAsTool> → Dotnet tool
    • Class library (IsPackable=true or no OutputType) → Library
    • <OutputType>Exe</OutputType> with <IsPackable>true</IsPackable> → Application package (not a tool, but still publishable)
    • <OutputType>Exe</OutputType> without PackAsTool or IsPackable → Not packable by default (ask user if they intend to publish it)
  2. Validate structure for each project's type:

    TypeRequired
    AllPackageId, Version (in .csproj or Directory.Build.props)
    Dotnet toolPackAsTool (required); ToolCommandName (optional but recommended — defaults to assembly name)
    MCP serverPackageType=McpServer, .mcp/server.json included in package
    TemplatePackageType=Template, .template.config/template.json under content dir
  3. Find existing publish workflows in .github/workflows/ — look for dotnet nuget push, nuget push, or dotnet pack.

  4. Check version consistency — for MCP servers, verify .csproj <Version> matches both server.json version fields (root version and packages[].version). Flag any mismatch.

  5. Report findings to the user: classification, missing properties, version mismatches, existing workflows. For multi-project repos, note whether one workflow or separate workflows per package are needed. Offer to fix gaps — use ask_user before modifying project files.

❌ See references/package-types.md for per-type details and required properties.

Phase 2: Local Verification

Pack and verify locally before touching nuget.org — publishing errors waste a permanent version number.

⚠️ Always mention this step, even if you defer running it. Tell the user: "Before your first publish, run dotnet pack -c Release -o ./artifacts to verify the .nupkg is created correctly."

  1. dotnet pack -c Release -o ./artifacts — verify .nupkg is created
  2. For tools/MCP servers: install from ./artifacts, run --help, uninstall
  3. For libraries: inspect the .nupkg contents (it's a zip)
Phase 3: nuget.org Policy

This phase requires the user to act on nuget.org — guide them with exact values.

  1. Determine the repo owner, repo name, and the workflow filename that will publish.

    ❌ The policy requires the exact workflow filename (e.g., publish.yml or publish.yaml) — just the filename, no path prefix. Matching is case-insensitive. Don't use the workflow name: field.

  2. Guide the user to create the trusted publishing policy:

    Go to nuget.org/account/trustedpublishing → Add policy

    • Repository Owner: {owner}
    • Repository: {repo}
    • Workflow File: {filename}.yml
    • Environment: release (only if the workflow uses environment:; leave blank otherwise)

    Policy ownership: the user chooses individual account or organization. Org-owned policies apply to all packages owned by that org.

    For private repos: policy is "temporarily active" for 7 days — becomes permanent after the first successful publish.

  3. Guide the user to create a GitHub Environment (recommended but optional — provides secret scoping + approval gates):

    Repo Settings → Environments → New environment → release

    Add environment secret: Name = NUGET_USER, Value = nuget.org username (NOT email)

    Optional: add Required reviewers for an approval gate.

⚠️ Wait for the user to confirm they've created the policy before asking them to remove old API keys/secrets or before attempting to run/publish with the workflow. Drafting or showing the workflow file itself is OK before confirmation.

Show full SKILL.md (328 more words)Show less
Phase 4: Workflow Setup

Create or modify the publish workflow. The workflow must always be created or shown in your response — you may draft/show it even if the nuget.org policy is not yet confirmed, but do not guide the user to actually run/publish or remove old secrets until after confirmation.

Greenfield: Create publish.yml from the template in references/publish-workflow.md. Adapt .NET version, project path, and environment name. Ensure your output explicitly mentions id-token: write and NuGet/login@v1.

Migration (existing workflow with API key): Modify in place —

  1. Add OIDC permission and environment to the publishing job:

    yaml
    jobs:
      publish:
        environment: release
        permissions:
          id-token: write     # Required — without this, NuGet/login fails with 403
          contents: read      # Explicit — setting permissions overrides defaults
  2. Add the NuGet login step before push:

    yaml
    - name: NuGet login (OIDC)
      id: login
      uses: NuGet/login@v1
      with:
        user: ${{ secrets.NUGET_USER }}  # nuget.org profile name, NOT email
  3. Replace the API key in the push step:

    yaml
    --api-key ${{ steps.login.outputs.NUGET_API_KEY }} --skip-duplicate
  4. Verify: Ask the user to trigger a publish and confirm the package appears on nuget.org.

❌ Don't delete the old API key secret until trusted publishing is verified. Removing it is a one-way door — wait for confirmation.

Troubleshooting

ProblemCauseFix
NuGet/login 403Missing id-token: writeAdd to job permissions
"no matching policy"Workflow filename mismatchVerify exact filename on nuget.org
Push unauthorizedPackage not owned by policy accountCheck policy owner on nuget.org
Token expiredLogin step >1hr before pushMove NuGet/login closer to push
"temporarily active" policyPrivate repo, first publish pendingPublish within 7 days
already_exists on pushRe-running same versionAdd --skip-duplicate
GitHub Release 422Duplicate release for tagDelete conflicting release (confirm first)
Re-run uses wrong YAMLgh run rerun replays original commit's YAMLDelete obstacle, re-run — never re-tag

⚠️ If any blocker persists after one fix attempt, stop and ask the user.

References

© dotnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in plugins/dotnet-advanced/skills/nuget-trusted-publishing of dotnet/skills.

  • SKILL.md
  • references/package-types.md
  • references/publish-workflow.md

Open the folder on GitHubat commit a660de8

Used in 2 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in dotnet/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Nuget Trusted Publishing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nuget Trusted Publishing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nuget Trusted Publishing this skilldotnet/skills5.6k2 repos~2.3kAutomated safety check: PassMIT
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Managing Workflow Secretsbitwarden/ai-plugins154—~4kAutomated safety check: PassCustom licence
Aspiremicrosoft/aspire.dev1964 repos~1.1kAutomated safety check: PassMIT
GitHub Actions Docsdevantler-tech/ksail1652 repos~1.3kAutomated safety check: PassCustom licence
Azure FunctionsDataDog/dd-trace-dotnet573—~4.7kAutomated safety check: PassApache-2.0

Similar skills

  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    154 GitHub stars~4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Aspire

    microsoft/aspire.dev

    Official

    Orchestrates Aspire distributed applications using the Aspire CLI for running, debugging, and managing distributed apps.

    196 GitHub starsUsed in 4 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • GitHub Actions Docs

    devantler-tech/ksail

    A skill your agent uses when users ask how to write, explain, customize, migrate, secure, or troubleshoot GitHub Actions workflows, workflow syntax, triggers, matrices, runners, reusable workflows…

    165 GitHub starsUsed in 2 repos~1.3k tokens
    DevOps & CloudAuto-check passed
  • Azure Functions

    DataDog/dd-trace-dotnet

    Official

    Dev/test workflow for tracer engineers working on the Datadog .NET tracer — build a local Datadog.AzureFunctions NuGet package, deploy it to a test Azure Function App, trigger it, and analyze…

    573 GitHub stars~4.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Headless Codex CLI Automation

    XiaomiMiMo/MiMo-Code

    Runs OpenAI Codex CLI as a non-interactive worker for CI, Docker, Kubernetes or remote servers, with sandbox modes and JSONL-friendly output.

    14k GitHub stars~2.7k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed

More from dotnet/skills

All 91 skills in this repo
  • Official

    Resolves .NET runtime frames in Apple .ips crash logs to function names, source files and line numbers using dSYM symbols, atos and the Microsoft symbol server.

    5.6k GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Official

    Resolves native crash frames from .NET Android tombstones to function names, source files and line numbers using BuildIds, Microsoft's symbol server and llvm-symbolizer.

    5.6k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Official

    Scans C# and .NET code for about 50 performance anti-patterns and reports prioritized findings with concrete fixes, at a scan depth you choose.

    5.6k GitHub starsUsed in 3 repos~3.1k tokens
    Auto-check passed
  • Official

    Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

    5.6k GitHub starsUsed in 1 repo~3.3k tokens
    Auto-check passed
  • Microbenchmarking

    dotnet/skills

    Official

    Activate this skill when BenchmarkDotNet (BDN) is involved in the task — creating, running, configuring, or reviewing BDN benchmarks.

    5.6k GitHub starsUsed in 3 repos~3.3k tokens
    Auto-check passed
  • Official

    Makes .NET projects compatible with Native AOT and trimming by resolving IL trim and AOT analyzer warnings through annotations rather than suppressions.

    5.6k GitHub starsUsed in 2 repos~4.2k tokens
    Auto-check passed

Questions about Nuget Trusted Publishing

What does Nuget Trusted Publishing do?

Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens. Nuget Trusted Publishing is an agent skill from dotnet/skills, published by the product's own GitHub organization. Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.

When should I use Nuget Trusted Publishing?

Nuget Trusted Publishing fits situations like: : trusted publishing; keyless NuGet publish; migrate from NuGet API key; secure NuGet publishing.

How do I install Nuget Trusted Publishing in Claude Code?

Run `npx skills add dotnet/skills --skill nuget-trusted-publishing -a claude-code`. Or copy the skill folder (plugins/dotnet-advanced/skills/nuget-trusted-publishing in dotnet/skills) into .claude/skills/nuget-trusted-publishing in your project. Claude Code loads it when a task matches its description.

How do I install Nuget Trusted Publishing in Codex?

Run `npx skills add dotnet/skills --skill nuget-trusted-publishing -a codex`. Or copy the skill folder (plugins/dotnet-advanced/skills/nuget-trusted-publishing in dotnet/skills) into .agents/skills/nuget-trusted-publishing in your project. Codex loads it when a task matches its description.

Can I use Nuget Trusted Publishing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dotnet/skills --skill nuget-trusted-publishing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nuget-trusted-publishing, .gemini/skills/nuget-trusted-publishing, .github/skills/nuget-trusted-publishing and .opencode/skills/nuget-trusted-publishing in your project.

What does Nuget Trusted Publishing need to run?

Going by SKILL.md and its folder, Nuget Trusted Publishing needs the command-line tools its instructions call (dotnet and gh) and credentials named NUGET_API_KEY. Our summary lists: A credential in NUGET_API_KEY.

Does Nuget Trusted Publishing access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and nuget.org. This is read from the text; nothing was executed.

Is Nuget Trusted Publishing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nuget Trusted Publishing use?

Nuget Trusted Publishing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nuget Trusted Publishing use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Nuget Trusted Publishing?

Skills that share tags, products or a category with Nuget Trusted Publishing: Azure Bicep Skill (timothywarner-org/claude-code, 224 stars), Managing Workflow Secrets (bitwarden/ai-plugins, 154 stars), Aspire (microsoft/aspire.dev, 196 stars) and GitHub Actions Docs (devantler-tech/ksail, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nuget Trusted Publishing?

dotnet (a GitHub organization, an official publisher) maintains it in dotnet/skills, which has 5,576 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 8, 2026.

Source: dotnet/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.