Azure Security Keyvault Keys Dotnet
microsoft/skills
Azure Key Vault Keys SDK for .NET. An agent skill from microsoft/skills.
Help users own an ERC-4337 smart account whose ECDSA key never lives in the application process — sign UserOperations with AWS KMS, Azure Key Vault, an HSM, a Ledger, or a Trezor instead of an…
$ npx skills add Nethereum/Nethereum --skill external-signer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Nethereum/Nethereum external-signer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Nethereum/Nethereum.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/nethereum-skills/skills/external-signer .claude/skills/external-signer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "external-signer" agent skill from https://github.com/Nethereum/Nethereum/tree/master/plugins/nethereum-skills/skills/external-signer into .claude/skills/external-signer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-signer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Nethereum/Nethereum/tree/master/plugins/nethereum-skills/skills/external-signerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Nethereum/Nethereum --skill external-signer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Nethereum/Nethereum external-signer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Nethereum/Nethereum.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/nethereum-skills/skills/external-signer .agents/skills/external-signer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "external-signer" agent skill from https://github.com/Nethereum/Nethereum/tree/master/plugins/nethereum-skills/skills/external-signer into .agents/skills/external-signer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-signer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Nethereum/Nethereum --skill external-signer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Nethereum/Nethereum external-signer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Nethereum/Nethereum.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/nethereum-skills/skills/external-signer .cursor/skills/external-signer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "external-signer" agent skill from https://github.com/Nethereum/Nethereum/tree/master/plugins/nethereum-skills/skills/external-signer into .cursor/skills/external-signer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-signer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Nethereum/Nethereum.git --path plugins/nethereum-skills/skills/external-signer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Nethereum/Nethereum --skill external-signer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Nethereum/Nethereum external-signer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Nethereum/Nethereum.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/nethereum-skills/skills/external-signer .gemini/skills/external-signer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "external-signer" agent skill from https://github.com/Nethereum/Nethereum/tree/master/plugins/nethereum-skills/skills/external-signer into .gemini/skills/external-signer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-signer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Nethereum/Nethereum external-signerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Nethereum/Nethereum --skill external-signer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Nethereum/Nethereum.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/nethereum-skills/skills/external-signer .github/skills/external-signer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "external-signer" agent skill from https://github.com/Nethereum/Nethereum/tree/master/plugins/nethereum-skills/skills/external-signer into .github/skills/external-signer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-signer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Nethereum/Nethereum --skill external-signer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Nethereum/Nethereum external-signer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Nethereum/Nethereum.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/nethereum-skills/skills/external-signer .opencode/skills/external-signer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "external-signer" agent skill from https://github.com/Nethereum/Nethereum/tree/master/plugins/nethereum-skills/skills/external-signer into .opencode/skills/external-signer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "external-signer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
external-signerHelp users own an ERC-4337 smart account whose ECDSA key never lives in the application process — sign UserOperations with AWS KMS, Azure Key Vault, an HSM, a Ledger, or a Trezor instead of an…
External Signer is an agent skill from Nethereum/Nethereum. Help users own an ERC-4337 smart account whose ECDSA key never lives in the application process — sign UserOperations with AWS KMS, Azure Key Vault, an HSM, a Ledger, or a Trezor instead of an in-memory private key, using Nethereum.AccountAbstraction and IEthExternalSigner. Use whenever the user mentions KMS signing, Azure Key Vault, AWS Key Management Service, HSM-backed wallets, custody, Ledger/Trezor hardware wallet signing for a smart account, MPC signers, or 'the key must never be in memory' requirements, in…
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Cryptography. It works with Amazon Web Services, Azure Key Vault, C# and .NET. The repository describes itself as: Ethereum .Net cross platform integration library. The licence is MIT.
Read from SKILL.md and the folder at commit 229f278. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
dotnetFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.nethereum.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
External Signer loads about 2.3k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 821 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Nethereum/Nethereum at commit 229f278, republished under its MIT licence (© Nethereum). 821 words, ~2,278 tokens.
.claude/skills/external-signer/SKILL.md (or your agent's skills folder).For institutional and custody use cases, an in-memory EthECKey isn't acceptable — the signing key has to live in a cloud Key Management Service, a hardware security module, or a physical device, and must never be readable by the application process itself. IEthExternalSigner is Nethereum's seam for that: signing happens as a remote or hardware operation instead of an in-process ECDSA computation.
The account itself doesn't change. It is still a plain ECDSA-owned NethereumSmartAccount, installed with the same EcdsaValidatorModule used everywhere else in Account Abstraction. Only where the key lives and who computes the signature changes — the generic on-ramp doesn't care which IAccountSigningService you hand it, so wiring an external signer in is exactly the same shape as wiring a raw key, one level removed.
dotnet add package Nethereum.Web3
dotnet add package Nethereum.AccountAbstractionPlus whichever signer package matches the backend:
| Backend | Package | Type |
|---|---|---|
| AWS Key Management Service | Nethereum.Signer.AWSKeyManagement | Nethereum.Signer.AWSKeyManagement.AWSKeyManagementExternalSigner |
| Azure Key Vault | Nethereum.Signer.AzureKeyVault | Nethereum.Signer.AzureKeyVault.AzureKeyVaultExternalSigner |
| Ledger hardware wallet | Nethereum.Signer.Ledger | Nethereum.Ledger.LedgerExternalSigner |
| Trezor hardware wallet | Nethereum.Signer.Trezor | Nethereum.Signer.Trezor.TrezorExternalSigner |
Each derives from Nethereum.Signer.EthExternalSignerBase. You also need IAAClient registered (the standard AddNethereumAccountAbstraction setup) and the same NethereumAccountFactory + ECDSAValidator pair deployed on the target chain that any ECDSA-owned account uses — an external signer installs the identical validator, so there's nothing extra to deploy on-chain for it.
Wrap any IEthExternalSigner in AccountSigningExternalService, then drive it through the same generic on-ramp as any other signer:
using Nethereum.Accounts.AccountMessageSigning;
using Nethereum.AccountAbstraction;
using Nethereum.AccountAbstraction.Client;
using Nethereum.AccountAbstraction.ERC7579.Modules;
using Nethereum.AccountAbstraction.Signing;
using Nethereum.Signer;
// externalSigner is any IEthExternalSigner - a KMS, HSM, or hardware-wallet signer whose private
// key never lives in this process.
IEthExternalSigner externalSigner = /* your KMS/HSM/hardware-wallet signer */;
var ownerAddress = await externalSigner.GetAddressAsync();
var signingService = new AccountSigningExternalService(externalSigner);
var validator = new EcdsaValidatorModule(deploymentAddresses.EcdsaValidatorAddress);
var initData = AccountInitDataBuilder.BuildEcdsa(deploymentAddresses.EcdsaValidatorAddress, ownerAddress);
var account = await aaClient.CreateAccountAsync(signingService, validator, initData); // NethereumSmartAccount
myToken.UseAccountAbstraction(account, aaClient);
var receipt = (AATransactionReceipt)await myToken.TransferRequestAndWaitForReceiptAsync(recipient, amount);
Console.WriteLine($"UserOp success: {receipt.UserOpSuccess}, sender: {receipt.Sender}");That's it — no code downstream of CreateAccountAsync knows or cares that the owner key lives in a KMS instead of memory. Every signature over a UserOperation hash is produced by a call out to externalSigner, never by an in-process private key.
An external-signer account is not a distinct account type — it's an ordinary ECDSA-owned NethereumSmartAccount with the same EcdsaValidatorModule and AccountInitDataBuilder.BuildEcdsa init data as a raw-key account. On-chain, the deployed ECDSAValidator reports the external signer's address as owner — indistinguishable from an account owned by an in-process key, because it's the same signature scheme (secp256k1/ECDSA) either way.
What changes is entirely client-side: AccountSigningExternalService wraps an IEthExternalSigner instead of an EthECKey, and its SignTypedDataV4/PersonalSign are delegated out to that signer — SignTypedDataJsonAsync for typed data, SignEthereumMessageAsync for personal-sign — as a KMS API call or HSM operation rather than an in-memory computation. Contrast this with a WebAuthn passkey (see the webauthn-passkeys skill): a passkey is a different signature scheme (P-256), whereas an external signer is still plain secp256k1 ECDSA — just computed somewhere else.
using Amazon;
using Nethereum.Signer.AWSKeyManagement;
// keyId identifies an asymmetric ECC_SECG_P256K1 key already created in AWS KMS.
IEthExternalSigner externalSigner = new AWSKeyManagementExternalSigner(
keyId: "arn:aws:kms:...:key/...", region: RegionEndpoint.EUWest1);using Azure.Identity; // DefaultAzureCredential - add the Azure.Identity NuGet package
using Nethereum.Signer.AzureKeyVault;
// keyName identifies an EC-secp256k1 key already created in the given Key Vault.
IEthExternalSigner externalSigner = new AzureKeyVaultExternalSigner(
keyName: "my-signing-key", vaultUri: "https://my-vault.vault.azure.net/", credential: new DefaultAzureCredential());An MPC (multi-party computation) signer isn't shipped out of the box, but plugs in the exact same way: implement IEthExternalSigner (or derive from EthExternalSignerBase) against the MPC network's signing API, and hand it to AccountSigningExternalService unchanged.
The hardware-wallet signers (LedgerExternalSigner, TrezorExternalSigner) implement the same IEthExternalSigner, need a connected device, and are typically used from a desktop app rather than a server process — see each package's README for device-transport setup. Signing a UserOperation's EIP-712 typed data through a Ledger specifically is not covered by an automated test in this codebase; verify on a real device before relying on it for AA (Ledger does not override the base typed-data signing path, so confirm the produced signature recovers to the owner under ECDSAValidator).
IAAClient.ConfigureEip7702 takes an EthECKey ownerKey directly, because the 7702 authorisation tuple's secp256k1 signature has to be produced by the same key path Nethereum's transaction signing uses, not through the generic IAccountSigningService seam. An external signer can own a CREATE2-deployed modular account, but it cannot drive the 7702 upgrade-in-place tier — use the CREATE2 on-ramp shown above instead.SignAsync/SignTypedDataJsonAsync surfaces as an exception before a UserOperation is ever sent, not as a bundler rejection.AccountSigningExternalService only calls GetAddressAsync() once (to build init data) plus the two signing methods.| Scenario | Approach |
|---|---|
| Signing key must live in a cloud KMS | AWSKeyManagementExternalSigner or AzureKeyVaultExternalSigner |
| Signing key must live on a physical device | LedgerExternalSigner / TrezorExternalSigner |
| Custom custody backend (MPC network, internal HSM API) | Implement IEthExternalSigner yourself |
| Device-native biometric passkey instead of ECDSA | Use the webauthn-passkeys skill instead — different signature scheme |
| Upgrading an existing EOA in place (EIP-7702) | Needs a raw EthECKey — external signers can't drive this tier |
For full documentation, see: https://docs.nethereum.com/docs/account-abstraction/guide-external-signer
© Nethereum, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/nethereum-skills/skills/external-signer of Nethereum/Nethereum.
Open the folder on GitHubat commit 229f278
External Signer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| External Signer this skillNethereum/Nethereum | 2.3k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Azure Security Keyvault Keys Dotnetmicrosoft/skills | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Migrate Dotnet9 To Dotnet10dotnet/skills | 5.6k | 2 repos | ~4.8k | Automated safety check: Pass | MIT | |
| Nes Decompilejonathanpeppers/dotnes | 780 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Azure Keyvault Keys TSmicrosoft/skills | 3.1k | 5 repos | ~1.7k | Automated safety check: Pass | MIT | |
| Azure Security Keyvault Keys Javamicrosoft/skills | 3.1k | 5 repos | ~2.9k | Automated safety check: Pass | MIT |
microsoft/skills
Azure Key Vault Keys SDK for .NET. An agent skill from microsoft/skills.
dotnet/skills
Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes.
jonathanpeppers/dotnes
Decompile NES ROM files (.nes) into C projects that can be rebuilt with dotnes.
microsoft/skills
Manage cryptographic keys using Azure Key Vault Keys SDK for JavaScript (@azure/keyvault-keys).
microsoft/skills
Azure Key Vault Keys Java SDK for cryptographic key management.
richlander/dotnet-inspect
Reconstruct a method or type as C and IL — decompiled source, annotated source with hidden facts, raw IL, fidelity levels, and IL-offset lookup.
Nethereum/Nethereum
Help users batch multiple calls into a single UserOperation and sponsor gas with paymasters using Nethereum Account Abstraction.
Nethereum/Nethereum
Help users run an ERC-4337 bundler using Nethereum — set up in-process or standalone bundlers with mempool, validation, reputation, and JSON-RPC server.
Nethereum/Nethereum
Encode and decode Ethereum ABI data with Nethereum. An agent skill from Nethereum/Nethereum.
Nethereum/Nethereum
Fetch contract ABIs from Sourcify, Etherscan, and 4Byte Directory using the composite ABIInfoStorage pattern (.NET/C).
Nethereum/Nethereum
Help users implement ERC-4337 Account Abstraction with Nethereum — send UserOperations, use smart accounts, route contract calls through a bundler, enable gasless transactions, or work with AA in…
Nethereum/Nethereum
Validate and format Ethereum addresses with Nethereum. An agent skill from Nethereum/Nethereum.
Works with
Categories
Help users own an ERC-4337 smart account whose ECDSA key never lives in the application process — sign UserOperations with AWS KMS, Azure Key Vault, an HSM, a Ledger, or a Trezor instead of an…. External Signer is an agent skill from Nethereum/Nethereum.AccountAbstraction and IEthExternalSigner.
External Signer fits situations like: the user mentions KMS signing; azure Key Vault; AWS Key Management Service; HSM-backed wallets.
Run `npx skills add Nethereum/Nethereum --skill external-signer -a claude-code`. Or copy the skill folder (plugins/nethereum-skills/skills/external-signer in Nethereum/Nethereum) into .claude/skills/external-signer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Nethereum/Nethereum --skill external-signer -a codex`. Or copy the skill folder (plugins/nethereum-skills/skills/external-signer in Nethereum/Nethereum) into .agents/skills/external-signer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Nethereum/Nethereum --skill external-signer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/external-signer, .gemini/skills/external-signer, .github/skills/external-signer and .opencode/skills/external-signer in your project.
Going by SKILL.md and its folder, External Signer needs the command-line tools its instructions call (dotnet).
SKILL.md names 1 domain. As links in the text: docs.nethereum.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
External Signer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with External Signer: Azure Security Keyvault Keys Dotnet (microsoft/skills, 3.1k stars), Migrate Dotnet9 To Dotnet10 (dotnet/skills, 5.6k stars), Nes Decompile (jonathanpeppers/dotnes, 780 stars) and Azure Keyvault Keys TS (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Nethereum (a GitHub organization) maintains it in Nethereum/Nethereum, which has 2,260 GitHub stars. The repository holds 71 skills in this directory. The repository was last updated on October 5, 2026.
Source: Nethereum/Nethereum on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.