Agent skill

Cloud Kms

by Nethereum in Nethereum/Nethereum

Sign Ethereum transactions with AWS KMS or Azure Key Vault HSMs using Nethereum.

MITAuto-check passedBackend & APIs

Install Cloud Kms

skills CLI
$ npx skills add Nethereum/Nethereum --skill cloud-kms -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Nethereum/Nethereum cloud-kms --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Nethereum/Nethereum.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/nethereum-skills/skills/cloud-kms .claude/skills/cloud-kms && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-kms
GitHub stars
2.3k
Token cost
~738 tokens
SKILL.md length
46 words
Files
1
Skills in repo
71
Repo updated
First seen
Licence
MIT

At a glance

Sign Ethereum transactions with AWS KMS or Azure Key Vault HSMs using Nethereum.

  • The user asks about AWS KMS Ethereum signing
  • SKILL.md covers AWS KMS and Azure Key Vault
  • Calls dotnet, aws and az
  • Azure Key Vault signing

What it does

Cloud Kms is an agent skill from Nethereum/Nethereum. Sign Ethereum transactions with AWS KMS or Azure Key Vault HSMs using Nethereum. Use this skill whenever the user asks about AWS KMS Ethereum signing, Azure Key Vault signing, cloud HSM, managed key signing, serverless wallet, key management service, or cloud-based transaction signing in C/.NET.

Its SKILL.md is about 740 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Serverless and Cryptography. It works with Amazon Web Services, Azure Key Vault, Ethereum and C#. The repository describes itself as: Ethereum .Net cross platform integration library. The licence is MIT.

When your agent uses it

  • The user asks about AWS KMS Ethereum signing
  • Azure Key Vault signing
  • Managed key signing
  • Serverless wallet

Example prompts

  • “/cloud-kms”

What it can do on your machine

Read from SKILL.md and the folder at commit 229f278. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dotnet
    • aws
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.nethereum.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Kms loads about 738 tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 46 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~738

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Nethereum/Nethereum at commit 229f278, republished under its MIT licence (© Nethereum). 46 words, ~738 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-kms/SKILL.md (or your agent's skills folder).
name
cloud-kms
description
Sign Ethereum transactions with AWS KMS or Azure Key Vault HSMs using Nethereum. Use this skill whenever the user asks about AWS KMS Ethereum signing, Azure Key Vault signing, cloud HSM, managed key signing, serverless wallet, key management service, or cloud-based transaction signing in C#/.NET.
user-invocable
true

Cloud KMS Signing with Nethereum

Private key generated inside HSM, never exported. Both support Legacy, EIP-1559, EIP-2930, and EIP-7702 transactions.

AWS KMS

NuGet: Nethereum.Signer.AWSKeyManagement

bash
dotnet add package Nethereum.Signer.AWSKeyManagement
Create Key
bash
aws kms create-key --key-spec ECC_SECG_P256K1 --key-usage SIGN_VERIFY
Sign Transactions
csharp
using Nethereum.Signer.AWSKeyManagement;
using Nethereum.Web3;
using Nethereum.Web3.Accounts;

// Uses default AWS credentials chain
var signer = new AWSKeyManagementExternalSigner(keyId: "your-kms-key-id");

var externalAccount = new ExternalAccount(signer, chainId: 1);
await externalAccount.InitialiseAsync();

var web3 = new Web3(externalAccount, "https://your-rpc-url");

var receipt = await web3.Eth.GetEtherTransferService()
    .TransferEtherAndWaitForReceiptAsync(toAddress, 0.1m);
Auth Methods
csharp
// Default credentials (Lambda, ECS, EC2)
var signer = new AWSKeyManagementExternalSigner(keyId);

// Explicit credentials
var signer = new AWSKeyManagementExternalSigner(
    keyId, accessKeyId: "AKIA...", secretAccessKey: "...");

// Specific region
var signer = new AWSKeyManagementExternalSigner(
    keyId, region: Amazon.RegionEndpoint.EUWest1);

Azure Key Vault

NuGet: Nethereum.Signer.AzureKeyVault

bash
dotnet add package Nethereum.Signer.AzureKeyVault
Create Key
bash
az keyvault key create --vault-name my-vault --name ethereum-key --kty EC --curve SECP256K1
Sign Transactions
csharp
using Nethereum.Signer.AzureKeyVault;
using Nethereum.Web3;
using Nethereum.Web3.Accounts;
using Azure.Identity;

var signer = new AzureKeyVaultExternalSigner(
    keyIdentifier: "https://my-vault.vault.azure.net/keys/ethereum-key");

var externalAccount = new ExternalAccount(signer, chainId: 1);
await externalAccount.InitialiseAsync();

var web3 = new Web3(externalAccount, "https://your-rpc-url");

var receipt = await web3.Eth.GetEtherTransferService()
    .TransferEtherAndWaitForReceiptAsync(toAddress, 0.1m);
Auth Methods
csharp
// DefaultAzureCredential (auto-detect)
var signer = new AzureKeyVaultExternalSigner(keyIdentifier);

// Managed identity
var signer = new AzureKeyVaultExternalSigner(
    keyIdentifier, new ManagedIdentityCredential());

// Service principal
var signer = new AzureKeyVaultExternalSigner(
    keyIdentifier, new ClientSecretCredential(tenantId, clientId, clientSecret));

For full documentation, see: https://docs.nethereum.com/docs/signing-and-key-management/guide-cloud-kms

© Nethereum, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/nethereum-skills/skills/cloud-kms of Nethereum/Nethereum.

Open the folder on GitHubat commit 229f278

Compare with similar skills

Cloud Kms next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Kms compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Kms this skillNethereum/Nethereum2.3k—~738Automated safety check: PassMIT
Migrate Dotnet9 To Dotnet10dotnet/skills5.6k2 repos~4.8kAutomated safety check: PassMIT
Azure Security Keyvault Keys Dotnetmicrosoft/skills3.1k5 repos~3.1kAutomated safety check: PassMIT
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
.NET API Compatibility DesignAaronontheweb/dotnet-skills1.2k2 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Official

    Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes.

    5.6k GitHub starsUsed in 2 repos~4.8k tokens
    DevOps & CloudAuto-check passed
  • Official

    Azure Key Vault Keys SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~3.1k tokens
    SecurityAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • .NET API Compatibility Design

    Aaronontheweb/dotnet-skills

    Applies extend-only design rules to NuGet packages and distributed systems, covering source, binary and wire compatibility and how to deprecate members safely.

    1.2k GitHub starsUsed in 2 repos~2.7k tokens
    Backend & APIsAuto-check passed
  • Tsp Csharp

    querylenshq/ef-querylens

    Comprehensive C and .NET development skill for TSP projects.

    225 GitHub stars~1.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from Nethereum/Nethereum

All 71 skills in this repo
  • Aa Batching Paymasters

    Nethereum/Nethereum

    Help users batch multiple calls into a single UserOperation and sponsor gas with paymasters using Nethereum Account Abstraction.

    2.3k GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Aa Bundler

    Nethereum/Nethereum

    Help users run an ERC-4337 bundler using Nethereum — set up in-process or standalone bundlers with mempool, validation, reputation, and JSON-RPC server.

    2.3k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Abi Encoding

    Nethereum/Nethereum

    Encode and decode Ethereum ABI data with Nethereum. An agent skill from Nethereum/Nethereum.

    2.3k GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Abi Retrieval

    Nethereum/Nethereum

    Fetch contract ABIs from Sourcify, Etherscan, and 4Byte Directory using the composite ABIInfoStorage pattern (.NET/C).

    2.3k GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Account Abstraction

    Nethereum/Nethereum

    Help users implement ERC-4337 Account Abstraction with Nethereum — send UserOperations, use smart accounts, route contract calls through a bundler, enable gasless transactions, or work with AA in…

    2.3k GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Address Utils

    Nethereum/Nethereum

    Validate and format Ethereum addresses with Nethereum. An agent skill from Nethereum/Nethereum.

    2.3k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Cloud Kms

What does Cloud Kms do?

Sign Ethereum transactions with AWS KMS or Azure Key Vault HSMs using Nethereum. Cloud Kms is an agent skill from Nethereum/Nethereum. Sign Ethereum transactions with AWS KMS or Azure Key Vault HSMs using Nethereum.

When should I use Cloud Kms?

Cloud Kms fits situations like: the user asks about AWS KMS Ethereum signing; azure Key Vault signing; managed key signing; serverless wallet.

How do I install Cloud Kms in Claude Code?

Run `npx skills add Nethereum/Nethereum --skill cloud-kms -a claude-code`. Or copy the skill folder (plugins/nethereum-skills/skills/cloud-kms in Nethereum/Nethereum) into .claude/skills/cloud-kms in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Kms in Codex?

Run `npx skills add Nethereum/Nethereum --skill cloud-kms -a codex`. Or copy the skill folder (plugins/nethereum-skills/skills/cloud-kms in Nethereum/Nethereum) into .agents/skills/cloud-kms in your project. Codex loads it when a task matches its description.

Can I use Cloud Kms in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Nethereum/Nethereum --skill cloud-kms -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-kms, .gemini/skills/cloud-kms, .github/skills/cloud-kms and .opencode/skills/cloud-kms in your project.

What does Cloud Kms need to run?

Going by SKILL.md and its folder, Cloud Kms needs the command-line tools its instructions call (dotnet, aws and az).

Does Cloud Kms access the network?

SKILL.md names 1 domain. As links in the text: docs.nethereum.com. This is read from the text; nothing was executed.

Is Cloud Kms safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud Kms use?

Cloud Kms is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Kms use?

About 738 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloud Kms?

Skills that share tags, products or a category with Cloud Kms: Migrate Dotnet9 To Dotnet10 (dotnet/skills, 5.6k stars), Azure Security Keyvault Keys Dotnet (microsoft/skills, 3.1k stars), AWS Serverless Eda (zxkane/aws-skills, 367 stars) and Foundatio (FoundatioFx/Foundatio, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Kms?

Nethereum (a GitHub organization) maintains it in Nethereum/Nethereum, which has 2,260 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on October 5, 2026.

Source: Nethereum/Nethereum on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.