Agent skill

Aspnet Core

by managedcode in managedcode/dotnet-skills

Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET.

MITAuto-check passedBackend & APIs

Install Aspnet Core

skills CLI
$ npx skills add managedcode/dotnet-skills --skill aspnet-core -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install managedcode/dotnet-skills aspnet-core --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/managedcode/dotnet-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/Frameworks/ASP.NET-Core/skills/aspnet-core .claude/skills/aspnet-core && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aspnet-core
GitHub stars
486
Token cost
~2.1k tokens
SKILL.md length
471 words
Files
4 (incl. references)
Skills in repo
81
Repo updated
First seen
Licence
MIT

At a glance

Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET.

  • Works in 5 steps: Detect the real hosting shape first → Follow the correct middleware order → Use built-in patterns correctly → …
  • : working on ASP.NET Core apps
  • SKILL.md covers Trigger On, Documentation, Workflow and Current Upstream Notes, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Aspnet Core is an agent skill from managedcode/dotnet-skills. Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET. USE FOR: working on ASP.NET Core apps, services, or middleware; changing auth, routing, configuration, hosting, or deployment behavior; deciding between ASP.NET Core sub-stacks. DO NOT USE FOR: unrelated stacks; generic tasks that do not need this specific guidance. INVOKES: inspect the repository context, edit targeted files, and run relevant…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `manifest.json`, `references/anti-patterns.md` and `references/patterns.md`). Compatibility notes: Requires an ASP.NET Core project or solution.

It sits in Backend & APIs, covering Codebase knowledge for agents and Deployment. It works with ASP.NET Core, .NET and Blazor. The repository describes itself as: Installable .NET skill catalog and CLI for Codex, Claude Code, GitHub Copilot, and Gemini. The licence is MIT.

When your agent uses it

  • : working on ASP.NET Core apps
  • Deployment behavior
  • Deciding between ASP.NET Core sub-stacks
  • : unrelated stacks

Example prompts

  • “/aspnet-core”

Requirements

  • Compatibility (from SKILL.md): Requires an ASP.NET Core project or solution.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Detect the real hosting shape first
  2. Follow the correct middleware order
  3. Use built-in patterns correctly
  4. Route specialized work to specific skills
  5. Validate with build, tests, and targeted endpoint checks.

What it can do on your machine

Read from SKILL.md and the folder at commit 535dd55. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are csharp).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires an ASP.NET Core project or solution.

    From compatibility in the SKILL.md frontmatter.

Context cost

Aspnet Core loads about 2.1k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 148 tokens; SKILL.md has 471 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from managedcode/dotnet-skills at commit 535dd55, republished under its MIT licence (© managedcode). 471 words, ~2,083 tokens.

Download SKILL.mdSave it as .claude/skills/aspnet-core/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
aspnet-core
description
Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET. USE FOR: working on ASP.NET Core apps, services, or middleware; changing auth, routing, configuration, hosting, or deployment behavior; deciding between ASP.NET Core sub-stacks. DO NOT USE FOR: unrelated stacks; generic tasks that do not need this specific guidance. INVOKES: inspect the repository context, edit targeted files, and run relevant build, test, lint, or validation commands when changes are made.
compatibility
Requires an ASP.NET Core project or solution.

ASP.NET Core

Trigger On

  • working on ASP.NET Core apps, services, or middleware
  • changing auth, routing, configuration, hosting, or deployment behavior
  • deciding between ASP.NET Core sub-stacks such as Blazor, Minimal APIs, or controller APIs
  • debugging request pipeline issues
  • modernizing legacy ASP.NET to ASP.NET Core

Documentation

References
  • patterns.md - Detailed middleware patterns, security patterns, configuration patterns, DI patterns, error handling patterns, and logging patterns
  • anti-patterns.md - Common ASP.NET Core mistakes including HttpClient misuse, async anti-patterns, configuration errors, DI issues, middleware ordering problems, and security vulnerabilities

Workflow

  1. Detect the real hosting shape first:

    • top-level Program.cs structure
    • middleware order and registration
    • auth model (Identity, JWT, OAuth, cookies)
    • endpoint registrations and routing
  2. Follow the correct middleware order:

    ExceptionHandler → HttpsRedirection → Static Files → Routing
    → CORS → Authentication → Authorization → Rate Limiting
    → Response Caching → Custom Middleware → Endpoints
  3. Use built-in patterns correctly:

    • Prefer IOptions<T> / IOptionsSnapshot<T> for configuration
    • Use ILogger<T> for structured logging
    • Use IHttpClientFactory for HTTP clients (never new HttpClient())
    • Use IHostedService / BackgroundService for background work
  4. Route specialized work to specific skills:

    • UI and components → blazor
    • Real-time → signalr
    • RPC → grpc
    • New HTTP APIs → minimal-apis (prefer unless controllers needed)
    • Controller APIs → web-api
  5. Validate with build, tests, and targeted endpoint checks.

Current Upstream Notes

  • ASP.NET Core v10.0.11 is a servicing release rather than a new programming model. It updates OpenAPI to 2.7.5, fixes restoration of expired client-persisted Blazor circuit state, and refreshes servicing dependencies. Keep the existing middleware and endpoint architecture, then rerun focused OpenAPI, interactive-rendering, auth, and startup tests.
  • The August 2026 Microsoft Learn overview for aspnetcore-10.0 remains the routing entry point for choosing between Blazor, Minimal APIs, controller APIs, SignalR, and gRPC; the refresh does not justify changing an existing app model by itself.
Show full SKILL.md (193 more words)Show less

Middleware Patterns

Correct Order Matters
csharp
var app = builder.Build();

app.UseExceptionHandler("/error");      // 1. Catch all exceptions
app.UseHsts();                          // 2. Security headers
app.UseHttpsRedirection();              // 3. HTTPS redirect
app.UseStaticFiles();                   // 4. Serve static files
app.UseRouting();                       // 5. Route matching
app.UseCors();                          // 6. CORS policy
app.UseAuthentication();                // 7. Who are you?
app.UseAuthorization();                 // 8. Can you access?
app.UseRateLimiter();                   // 9. Rate limiting
app.UseResponseCaching();               // 10. Response cache
app.MapControllers();                   // 11. Endpoints
Custom Middleware Pattern
csharp
public class RequestTimingMiddleware
{
    private readonly RequestDelegate _next;
    private readonly ILogger<RequestTimingMiddleware> _logger;

    public RequestTimingMiddleware(RequestDelegate next, ILogger<RequestTimingMiddleware> logger)
    {
        _next = next;
        _logger = logger;
    }

    public async Task InvokeAsync(HttpContext context)
    {
        var sw = Stopwatch.StartNew();
        await _next(context);
        _logger.LogInformation("Request {Path} completed in {Elapsed}ms",
            context.Request.Path, sw.ElapsedMilliseconds);
    }
}

Configuration Patterns

Strongly-Typed Options
csharp
// appsettings.json
{
  "EmailSettings": {
    "SmtpServer": "smtp.example.com",
    "Port": 587
  }
}

// Registration
builder.Services.Configure<EmailSettings>(
    builder.Configuration.GetSection("EmailSettings"));

// Usage
public class EmailService(IOptions<EmailSettings> options)
{
    private readonly EmailSettings _settings = options.Value;
}
Environment-Based Configuration
csharp
builder.Configuration
    .AddJsonFile("appsettings.json", optional: false)
    .AddJsonFile($"appsettings.{builder.Environment.EnvironmentName}.json", optional: true)
    .AddEnvironmentVariables()
    .AddUserSecrets<Program>(optional: true);

Security Patterns

Authentication Setup
csharp
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddJwtBearer(options =>
    {
        options.TokenValidationParameters = new TokenValidationParameters
        {
            ValidateIssuer = true,
            ValidateAudience = true,
            ValidateLifetime = true,
            ValidateIssuerSigningKey = true,
            ValidIssuer = builder.Configuration["Jwt:Issuer"],
            ValidAudience = builder.Configuration["Jwt:Audience"],
            IssuerSigningKey = new SymmetricSecurityKey(
                Encoding.UTF8.GetBytes(builder.Configuration["Jwt:Key"]!))
        };
    });
Authorization Policies
csharp
builder.Services.AddAuthorization(options =>
{
    options.AddPolicy("AdminOnly", policy =>
        policy.RequireRole("Admin"));
    options.AddPolicy("MinAge18", policy =>
        policy.RequireClaim("Age", "18", "19", "20")); // simplified
});

Anti-Patterns to Avoid

Anti-PatternWhy It's BadBetter Approach
new HttpClient()Socket exhaustionIHttpClientFactory
Sync-over-async (Task.Result)Thread pool starvationawait properly
Storing secrets in appsettings.jsonSecurity riskUser Secrets, Key Vault
Catching all exceptions silentlyHides bugsUse IExceptionHandler
async void in middlewareCrashes processasync Task
Missing HTTPS redirectSecurity riskUseHttpsRedirection()

Performance Best Practices

  1. Use async/await everywhere — avoid sync blocking calls
  2. Pool DbContext properly — use scoped lifetime
  3. Enable response compression — UseResponseCompression()
  4. Use output caching — UseOutputCache() for .NET 7+
  5. Profile with diagnostic tools — Visual Studio Diagnostic Tools, PerfView
  6. Avoid allocations in hot paths — use Span<T>, pooling

Deliver

  • production-credible ASP.NET Core code and config
  • a clear request pipeline and hosting story
  • verification that matches the affected endpoints and middleware
  • security headers and HTTPS configured correctly

Validate

  • middleware order is intentional and documented
  • security and configuration changes are explicit
  • endpoint behavior is covered by tests or smoke checks
  • no blocking calls in async context
  • secrets are not committed to source control
  • health checks are implemented for production readiness

© managedcode, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in catalog/Frameworks/ASP.NET-Core/skills/aspnet-core of managedcode/dotnet-skills.

  • SKILL.md
  • manifest.json
  • references/anti-patterns.md
  • references/patterns.md

Open the folder on GitHubat commit 535dd55

Compare with similar skills

Aspnet Core next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aspnet Core compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aspnet Core this skillmanagedcode/dotnet-skills486—~2.1kAutomated safety check: PassMIT
Using Dotnetnovotnyllc/dotnet-artisan233—~2.3kAutomated safety check: WarnMIT
C# and .NET DeveloperJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Aspnet Corefanslead/ReverseProxy.Store1632 repos~1.4kAutomated safety check: PassApache-2.0
Dotnet Webapidotnet/skills5.6k2 repos~5.5kAutomated safety check: PassMIT
Create Datadriven Aspnetcoredotnet/skills5.6k1 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • Using Dotnet

    novotnyllc/dotnet-artisan

    Detects .NET intent for any C, ASP.NET Core, EF Core, Blazor, MAUI, Uno Platform, WPF, WinUI, SignalR, gRPC, xUnit, NuGet, or MSBuild request from prompt keywords and repository signals (.sln…

    233 GitHub stars~2.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: warnings
  • C# and .NET Developer

    Jeffallan/claude-skills

    Guides C# work on .NET 8+: ASP.NET Core APIs, Entity Framework Core data access, Blazor apps and CQRS with MediatR, following a five-step build workflow.

    12k GitHub stars~1.3k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Aspnet Core

    fanslead/ReverseProxy.Store

    Build, review, refactor, or architect ASP.NET Core web applications using current official guidance for .NET web development.

    163 GitHub starsUsed in 2 repos~1.4k tokens
    Backend & APIsAuto-check passed
  • Dotnet Webapi

    dotnet/skills

    Official

    Guides creation and modification of ASP.NET Core Web API endpoints with correct HTTP semantics, OpenAPI metadata, and error handling.

    5.6k GitHub starsUsed in 2 repos~5.5k tokens
    Backend & APIsAuto-check passed
  • Official

    Generate or scaffold ASP.NET Core code — Razor Pages, Blazor components, MVC controllers, views, and Minimal API endpoints — without using ASP.NET Core CLI scaffolding/code-generation tools.

    5.6k GitHub starsUsed in 1 repo~3.2k tokens
    DevelopmentAuto-check passed
  • Siwe

    Nethereum/Nethereum

    Help users implement Sign-In with Ethereum (EIP-4361) authentication using Nethereum (.NET).

    2.3k GitHub stars~1.3k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from managedcode/dotnet-skills

All 81 skills in this repo
  • Analyzer Config

    managedcode/dotnet-skills

    Use a repo-root .editorconfig to configure free .NET analyzer and style rules.

    486 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Archunitnet

    managedcode/dotnet-skills

    Use the open-source free ArchUnitNET library for architecture rules in .NET tests.

    486 GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Aspire

    managedcode/dotnet-skills

    Build, upgrade, and operate Aspire 13.5.x C or TypeScript application hosts with the current CLI, AppHost, ServiceDefaults, integrations, dashboard, testing, MCP, and deployment patterns for…

    486 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Asynkron Profiler

    managedcode/dotnet-skills

    Use the open-source free Asynkron.Profiler dotnet tool for CLI-first CPU, allocation, exception, contention, and heap profiling of .NET commands or existing trace artifacts.

    486 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Azure Functions

    managedcode/dotnet-skills

    Build, review, or migrate Azure Functions in .NET with correct execution model, isolated worker setup, bindings, DI, and Durable Functions patterns.

    486 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Blazor

    managedcode/dotnet-skills

    Build and review Blazor applications across server, WebAssembly, web app, and hybrid scenarios with correct component design, state flow, rendering, and hosting choices.

    486 GitHub stars~2.1k tokensUpdated today
    Auto-check passed

Questions about Aspnet Core

What does Aspnet Core do?

Build, debug, modernize, or review ASP.NET Core applications with correct hosting, middleware, security, configuration, logging, and deployment patterns on current .NET. Aspnet Core is an agent skill from managedcode/dotnet-skills.NET.

When should I use Aspnet Core?

Aspnet Core fits situations like: : working on ASP.NET Core apps; deployment behavior; deciding between ASP.NET Core sub-stacks; : unrelated stacks.

How do I install Aspnet Core in Claude Code?

Run `npx skills add managedcode/dotnet-skills --skill aspnet-core -a claude-code`. Or copy the skill folder (catalog/Frameworks/ASP.NET-Core/skills/aspnet-core in managedcode/dotnet-skills) into .claude/skills/aspnet-core in your project. Claude Code loads it when a task matches its description.

How do I install Aspnet Core in Codex?

Run `npx skills add managedcode/dotnet-skills --skill aspnet-core -a codex`. Or copy the skill folder (catalog/Frameworks/ASP.NET-Core/skills/aspnet-core in managedcode/dotnet-skills) into .agents/skills/aspnet-core in your project. Codex loads it when a task matches its description.

Can I use Aspnet Core in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add managedcode/dotnet-skills --skill aspnet-core -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aspnet-core, .gemini/skills/aspnet-core, .github/skills/aspnet-core and .opencode/skills/aspnet-core in your project.

What does Aspnet Core need to run?

SKILL.md names no scripts, command-line tools or credentials: Aspnet Core is instructions for the agent only. Compatibility (from SKILL.md): Requires an ASP.NET Core project or solution..

Does Aspnet Core access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Aspnet Core safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aspnet Core use?

Aspnet Core is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aspnet Core use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Aspnet Core?

Skills that share tags, products or a category with Aspnet Core: Using Dotnet (novotnyllc/dotnet-artisan, 233 stars), C# and .NET Developer (Jeffallan/claude-skills, 12k stars), Aspnet Core (fanslead/ReverseProxy.Store, 163 stars) and Dotnet Webapi (dotnet/skills, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aspnet Core?

managedcode (a GitHub organization) maintains it in managedcode/dotnet-skills, which has 486 GitHub stars. The repository holds 81 skills in this directory. The repository was last updated on October 7, 2026.

Source: managedcode/dotnet-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.