GitHub Actions Docs
devantler-tech/ksail
A skill your agent uses when users ask how to write, explain, customize, migrate, secure, or troubleshoot GitHub Actions workflows, workflow syntax, triggers, matrices, runners, reusable workflows…
Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap nuget-trusted-publishing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nuget-trusted-publishing .claude/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/rodri-oliveira-dev/Dapper-FluentMap/tree/main/.agents/skills/nuget-trusted-publishing into .claude/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rodri-oliveira-dev/Dapper-FluentMap/tree/main/.agents/skills/nuget-trusted-publishingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap nuget-trusted-publishing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/nuget-trusted-publishing .agents/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/rodri-oliveira-dev/Dapper-FluentMap/tree/main/.agents/skills/nuget-trusted-publishing into .agents/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap nuget-trusted-publishing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/nuget-trusted-publishing .cursor/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/rodri-oliveira-dev/Dapper-FluentMap/tree/main/.agents/skills/nuget-trusted-publishing into .cursor/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git --path .agents/skills/nuget-trusted-publishing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap nuget-trusted-publishing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/nuget-trusted-publishing .gemini/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/rodri-oliveira-dev/Dapper-FluentMap/tree/main/.agents/skills/nuget-trusted-publishing into .gemini/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap nuget-trusted-publishingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/nuget-trusted-publishing .github/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/rodri-oliveira-dev/Dapper-FluentMap/tree/main/.agents/skills/nuget-trusted-publishing into .github/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap nuget-trusted-publishing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/nuget-trusted-publishing .opencode/skills/nuget-trusted-publishing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nuget-trusted-publishing" agent skill from https://github.com/rodri-oliveira-dev/Dapper-FluentMap/tree/main/.agents/skills/nuget-trusted-publishing into .opencode/skills/nuget-trusted-publishing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuget-trusted-publishing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nuget-trusted-publishingReview, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.
Nuget Trusted Publishing is an agent skill from rodri-oliveira-dev/Dapper-FluentMap. Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions. USE FOR: NuGet OIDC, keyless NuGet publish, NuGet/login, trusted-publishing policy changes, release authentication, and diagnosing NuGet trusted-publishing failures. DO NOT USE FOR: private feeds that do not support nuget.org trusted publishing.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/package-types.md` and `references/publish-workflow.md`).
It sits in Backend & APIs, covering OAuth and OpenID Connect and CI/CD. It works with GitHub Actions and GitHub. The repository describes itself as: Fluent mapping for Dapper, with conventions, immutable object materialization, analyzers, source generators, DI integration, and Dommel support. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4f5a39f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nuget Trusted Publishing loads about 1.3k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 483 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rodri-oliveira-dev/Dapper-FluentMap at commit 4f5a39f, republished under its MIT licence (© rodri-oliveira-dev). 483 words, ~1,254 tokens.
.claude/skills/nuget-trusted-publishing/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Use NuGet trusted publishing to exchange GitHub OIDC identity for a short-lived NuGet API key instead of storing a long-lived publishing key.
Dapper-FluentMap baseline: trusted publishing is already implemented in
.github/workflows/release.ymlthroughNuGet/login, a protectedreleaseenvironment, and job-scopedid-token: write. Treat that implementation as the baseline to preserve and review, not something to recreate from a generic sample.AGENTS.md,eng/package-catalog.json,eng/publish-package-set.ps1, release recovery, and package immutability rules are authoritative.
NuGet/login, OIDC, policy, environment, or authorization failures.404 proves only that a package/version is not currently present. It does not prove that the publisher is authorized to create that PackageId.Before changing trusted publishing, inspect:
.github/workflows/release.yml and release-recovery-missing-nuget.yml.eng/package-catalog.json for the exact five governed PackageIds.eng/publish-package-set.ps1 for publication/idempotency behavior.eng/validate-release-artifacts.ps1 and consumer-smoke validation.release environment and the exact nuget.org trusted-publishing policy values when external configuration is involved.Current governed package family:
Dapper.FluentMapDapper.FluentMap.DommelFluentMap.DependencyInjectionFluentMap.AnalyzersFluentMap.GeneratorsProject identity, assembly identity, namespace identity, and NuGet PackageId are independent. Do not rename projects/assemblies/namespaces as a side effect of a publishing change.
The NuGet publishing job should retain the equivalent of:
permissions:
contents: read
id-token: write
- name: Exchange GitHub OIDC token for temporary NuGet API key
id: nuget-login
uses: NuGet/login@<approved-pinned-sha>
with:
user: "${{ vars.NUGET_USER }}"The temporary key is then passed only to the governed publication step. Keep NuGet/login SHA-pinned according to repository policy.
The nuget.org trusted-publishing policy is coupled to GitHub identity. Changes to these values may require external policy updates:
Do not claim external policy changes are complete unless they are verified.
For code-only release changes, validate the existing deterministic release pipeline rather than performing a real publish:
A real publish is required only when the user explicitly asks for release execution.
| Problem | Likely cause | Check |
|---|---|---|
NuGet/login 403 | OIDC permission/policy mismatch | id-token: write, policy repo/workflow/environment |
| No matching policy | Workflow/environment identity mismatch | Exact nuget.org policy values |
| Push unauthorized | Package ownership/policy authorization | Package owner/publisher configuration |
| Temporary key expired | Login too early | Move token exchange close to publication |
| Package already exists | Re-run/partial release | Validate existing artifact and publish only missing packages |
© rodri-oliveira-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .agents/skills/nuget-trusted-publishing of rodri-oliveira-dev/Dapper-FluentMap.
Open the folder on GitHubat commit 4f5a39f
Nuget Trusted Publishing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nuget Trusted Publishing this skillrodri-oliveira-dev/Dapper-FluentMap | 454 | — | ~1.3k | Automated safety check: Pass | MIT | |
| GitHub Actions Docsdevantler-tech/ksail | 165 | 2 repos | ~1.3k | Automated safety check: Pass | Custom licence | |
| GitHub Actions Genlaolaoshiren/claude-code-skills-zh | 880 | — | ~1.1k | Automated safety check: Notes | MIT | |
| Releasing Reactivepropertyrunceel/ReactiveProperty | 944 | — | ~2.7k | Automated safety check: Pass | MIT | |
| GitHub Actions Hardeninggithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| AWS GitHub Oidc Scoped Rolemizchi/skills | 360 | — | ~1.6k | Automated safety check: Pass | None |
devantler-tech/ksail
A skill your agent uses when users ask how to write, explain, customize, migrate, secure, or troubleshoot GitHub Actions workflows, workflow syntax, triggers, matrices, runners, reusable workflows…
laolaoshiren/claude-code-skills-zh
分析真实项目并生成或修订安全、可验证的 GitHub Actions workflow;当用户要求创建 CI、测试矩阵、构建、Release、部署、缓存、Secrets、OIDC、PR 自动化或排查 workflow 配置时使用
runceel/ReactiveProperty
Release the ReactiveProperty NuGet package set from this repository.
github/awesome-copilot
Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).
mizchi/skills
OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM.
jeremylongshore/tons-of-skills-marketplace
Validate use when validating GitHub Actions workflows for Google Cloud and Vertex AI deployments.
rodri-oliveira-dev/Dapper-FluentMap
Guide for organizing MSBuild infrastructure with Directory.Build.props, Directory.Build.targets, Directory.Packages.props when present, and related repository build files.
rodri-oliveira-dev/Dapper-FluentMap
Activate when BenchmarkDotNet is involved or when a .NET performance question requires controlled microbenchmark measurement.
rodri-oliveira-dev/Dapper-FluentMap
Pseudo-mutation analysis for behavioral blind spots: determine whether existing tests would catch meaningful caller-visible production changes, identify survivors or untested outcomes, and…
rodri-oliveira-dev/Dapper-FluentMap
Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.
rodri-oliveira-dev/Dapper-FluentMap
Analyze MSBuild binary logs to diagnose build failures. An agent skill from rodri-oliveira-dev/Dapper-FluentMap.
rodri-oliveira-dev/Dapper-FluentMap
A skill your agent uses to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security.
Works with
Categories
Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions. Nuget Trusted Publishing is an agent skill from rodri-oliveira-dev/Dapper-FluentMap. Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.
Nuget Trusted Publishing fits situations like: keyless NuGet publish; trusted-publishing policy changes; release authentication; diagnosing NuGet trusted-publishing failures.
Run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a claude-code`. Or copy the skill folder (.agents/skills/nuget-trusted-publishing in rodri-oliveira-dev/Dapper-FluentMap) into .claude/skills/nuget-trusted-publishing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a codex`. Or copy the skill folder (.agents/skills/nuget-trusted-publishing in rodri-oliveira-dev/Dapper-FluentMap) into .agents/skills/nuget-trusted-publishing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nuget-trusted-publishing, .gemini/skills/nuget-trusted-publishing, .github/skills/nuget-trusted-publishing and .opencode/skills/nuget-trusted-publishing in your project.
SKILL.md names no scripts, command-line tools or credentials: Nuget Trusted Publishing is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nuget Trusted Publishing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 947 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Nuget Trusted Publishing: GitHub Actions Docs (devantler-tech/ksail, 165 stars), GitHub Actions Gen (laolaoshiren/claude-code-skills-zh, 880 stars), Releasing Reactiveproperty (runceel/ReactiveProperty, 944 stars) and GitHub Actions Hardening (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rodri-oliveira-dev (a GitHub user) maintains it in rodri-oliveira-dev/Dapper-FluentMap, which has 454 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.
Source: rodri-oliveira-dev/Dapper-FluentMap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.