Agent skill

Nuget Trusted Publishing

by rodri-oliveira-dev in rodri-oliveira-dev/Dapper-FluentMap

Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.

MITAuto-check passedBackend & APIs

Install Nuget Trusted Publishing

skills CLI
$ npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rodri-oliveira-dev/Dapper-FluentMap nuget-trusted-publishing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rodri-oliveira-dev/Dapper-FluentMap.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nuget-trusted-publishing .claude/skills/nuget-trusted-publishing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nuget-trusted-publishing
GitHub stars
454
Token cost
~1.3k tokens
SKILL.md length
483 words
Files
3 (incl. references)
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.

  • Works in 5 steps: .github/workflows/release.yml and… → eng/package-catalog.json for the exact… → eng/publish-package-set.ps1 for… → …
  • Keyless NuGet publish
  • SKILL.md covers When to Use, Safety Rules, Repository Assessment and Trusted Publishing Pattern, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nuget Trusted Publishing is an agent skill from rodri-oliveira-dev/Dapper-FluentMap. Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions. USE FOR: NuGet OIDC, keyless NuGet publish, NuGet/login, trusted-publishing policy changes, release authentication, and diagnosing NuGet trusted-publishing failures. DO NOT USE FOR: private feeds that do not support nuget.org trusted publishing.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/package-types.md` and `references/publish-workflow.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect and CI/CD. It works with GitHub Actions and GitHub. The repository describes itself as: Fluent mapping for Dapper, with conventions, immutable object materialization, analyzers, source generators, DI integration, and Dommel support. The licence is MIT.

When your agent uses it

  • Keyless NuGet publish
  • Trusted-publishing policy changes
  • Release authentication
  • Diagnosing NuGet trusted-publishing failures

Example prompts

  • “/nuget-trusted-publishing”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. .github/workflows/release.yml and release-recovery-missing-nuget.yml.
  2. eng/package-catalog.json for the exact five governed PackageIds.
  3. eng/publish-package-set.ps1 for publication/idempotency behavior.
  4. eng/validate-release-artifacts.ps1 and consumer-smoke validation.
  5. The release environment and the exact nuget.org trusted-publishing policy values when external configuration is involved.

What it can do on your machine

Read from SKILL.md and the folder at commit 4f5a39f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nuget Trusted Publishing loads about 1.3k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 483 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rodri-oliveira-dev/Dapper-FluentMap at commit 4f5a39f, republished under its MIT licence (© rodri-oliveira-dev). 483 words, ~1,254 tokens.

Download SKILL.mdSave it as .claude/skills/nuget-trusted-publishing/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
nuget-trusted-publishing
description
Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions. USE FOR: NuGet OIDC, keyless NuGet publish, NuGet/login, trusted-publishing policy changes, release authentication, and diagnosing NuGet trusted-publishing failures. DO NOT USE FOR: private feeds that do not support nuget.org trusted publishing.
license
MIT

NuGet Trusted Publishing

Use NuGet trusted publishing to exchange GitHub OIDC identity for a short-lived NuGet API key instead of storing a long-lived publishing key.

Dapper-FluentMap baseline: trusted publishing is already implemented in .github/workflows/release.yml through NuGet/login, a protected release environment, and job-scoped id-token: write. Treat that implementation as the baseline to preserve and review, not something to recreate from a generic sample. AGENTS.md, eng/package-catalog.json, eng/publish-package-set.ps1, release recovery, and package immutability rules are authoritative.

When to Use

  • Reviewing or changing the NuGet.org publishing job.
  • Diagnosing NuGet/login, OIDC, policy, environment, or authorization failures.
  • Adding a new package to the governed package family.
  • Changing the release workflow filename or GitHub Environment in a way that may affect the nuget.org trusted-publishing policy.
  • Verifying that release changes preserve short-lived credentials and least privilege.

Safety Rules

  • Never replace OIDC with a long-lived NuGet API key merely to make a release pass.
  • Never publish, tag, create a GitHub Release, or invoke recovery unless the user explicitly requests it.
  • Package IDs and published versions are immutable release identities; validate before publishing.
  • A NuGet.org flat-container 404 proves only that a package/version is not currently present. It does not prove that the publisher is authorized to create that PackageId.
  • Preserve partial-release recovery: validate existing registry artifacts and publish only missing artifacts rather than deleting or overwriting package versions.

Repository Assessment

Before changing trusted publishing, inspect:

  1. .github/workflows/release.yml and release-recovery-missing-nuget.yml.
  2. eng/package-catalog.json for the exact five governed PackageIds.
  3. eng/publish-package-set.ps1 for publication/idempotency behavior.
  4. eng/validate-release-artifacts.ps1 and consumer-smoke validation.
  5. The release environment and the exact nuget.org trusted-publishing policy values when external configuration is involved.

Current governed package family:

  • Dapper.FluentMap
  • Dapper.FluentMap.Dommel
  • FluentMap.DependencyInjection
  • FluentMap.Analyzers
  • FluentMap.Generators

Project identity, assembly identity, namespace identity, and NuGet PackageId are independent. Do not rename projects/assemblies/namespaces as a side effect of a publishing change.

Show full SKILL.md (188 more words)Show less

Trusted Publishing Pattern

The NuGet publishing job should retain the equivalent of:

yaml
permissions:
  contents: read
  id-token: write

- name: Exchange GitHub OIDC token for temporary NuGet API key
  id: nuget-login
  uses: NuGet/login@<approved-pinned-sha>
  with:
    user: "${{ vars.NUGET_USER }}"

The temporary key is then passed only to the governed publication step. Keep NuGet/login SHA-pinned according to repository policy.

Policy Coupling

The nuget.org trusted-publishing policy is coupled to GitHub identity. Changes to these values may require external policy updates:

  • repository owner/name;
  • publishing workflow filename;
  • GitHub Environment name;
  • nuget.org account/package ownership.

Do not claim external policy changes are complete unless they are verified.

Validation

For code-only release changes, validate the existing deterministic release pipeline rather than performing a real publish:

  • workflow schema/actionlint where applicable;
  • restore/build/test/pack;
  • package metadata and artifact-manifest validation;
  • consumer-smoke tests;
  • package catalog consistency;
  • least-privilege permissions and OIDC path.

A real publish is required only when the user explicitly asks for release execution.

Troubleshooting

ProblemLikely causeCheck
NuGet/login 403OIDC permission/policy mismatchid-token: write, policy repo/workflow/environment
No matching policyWorkflow/environment identity mismatchExact nuget.org policy values
Push unauthorizedPackage ownership/policy authorizationPackage owner/publisher configuration
Temporary key expiredLogin too earlyMove token exchange close to publication
Package already existsRe-run/partial releaseValidate existing artifact and publish only missing packages

References

© rodri-oliveira-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .agents/skills/nuget-trusted-publishing of rodri-oliveira-dev/Dapper-FluentMap.

  • SKILL.md
  • references/package-types.md
  • references/publish-workflow.md

Open the folder on GitHubat commit 4f5a39f

Compare with similar skills

Nuget Trusted Publishing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nuget Trusted Publishing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nuget Trusted Publishing this skillrodri-oliveira-dev/Dapper-FluentMap454—~1.3kAutomated safety check: PassMIT
GitHub Actions Docsdevantler-tech/ksail1652 repos~1.3kAutomated safety check: PassCustom licence
GitHub Actions Genlaolaoshiren/claude-code-skills-zh880—~1.1kAutomated safety check: NotesMIT
Releasing Reactivepropertyrunceel/ReactiveProperty944—~2.7kAutomated safety check: PassMIT
GitHub Actions Hardeninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
AWS GitHub Oidc Scoped Rolemizchi/skills360—~1.6kAutomated safety check: PassNone

Similar skills

  • GitHub Actions Docs

    devantler-tech/ksail

    A skill your agent uses when users ask how to write, explain, customize, migrate, secure, or troubleshoot GitHub Actions workflows, workflow syntax, triggers, matrices, runners, reusable workflows…

    165 GitHub starsUsed in 2 repos~1.3k tokens
    DevOps & CloudAuto-check passed
  • GitHub Actions Gen

    laolaoshiren/claude-code-skills-zh

    分析真实项目并生成或修订安全、可验证的 GitHub Actions workflow;当用户要求创建 CI、测试矩阵、构建、Release、部署、缓存、Secrets、OIDC、PR 自动化或排查 workflow 配置时使用

    880 GitHub stars~1.1k tokensUpdated 5 days ago
    DevOps & CloudAuto-check: notes
  • Releasing Reactiveproperty

    runceel/ReactiveProperty

    Release the ReactiveProperty NuGet package set from this repository.

    944 GitHub stars~2.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • GitHub Actions Hardening

    github/awesome-copilot

    Official

    Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM.

    360 GitHub stars~1.6k tokensUpdated 8 days ago
    DevOps & CloudAuto-check passed
  • Gh Actions Validator

    jeremylongshore/tons-of-skills-marketplace

    Validate use when validating GitHub Actions workflows for Google Cloud and Vertex AI deployments.

    2.8k GitHub stars~713 tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from rodri-oliveira-dev/Dapper-FluentMap

All 11 skills in this repo
  • Directory Build Organization

    rodri-oliveira-dev/Dapper-FluentMap

    Guide for organizing MSBuild infrastructure with Directory.Build.props, Directory.Build.targets, Directory.Packages.props when present, and related repository build files.

    454 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Microbenchmarking

    rodri-oliveira-dev/Dapper-FluentMap

    Activate when BenchmarkDotNet is involved or when a .NET performance question requires controlled microbenchmark measurement.

    454 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Test Gap Analysis

    rodri-oliveira-dev/Dapper-FluentMap

    Pseudo-mutation analysis for behavioral blind spots: determine whether existing tests would catch meaningful caller-visible production changes, identify survivors or untested outcomes, and…

    454 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Authoring GitHub Workflows

    rodri-oliveira-dev/Dapper-FluentMap

    Author and review GitHub Actions workflow YAML safely so syntactically-valid YAML can't ship a workflow that GitHub Actions refuses to run.

    454 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Binlog Failure Analysis

    rodri-oliveira-dev/Dapper-FluentMap

    Analyze MSBuild binary logs to diagnose build failures. An agent skill from rodri-oliveira-dev/Dapper-FluentMap.

    454 GitHub stars~750 tokensUpdated 2 days ago
    Auto-check passed
  • CI Release Governance

    rodri-oliveira-dev/Dapper-FluentMap

    A skill your agent uses to review or adjust Dapper-FluentMap GitHub Actions, packaging, NuGet publishing, versioning, release, rollback, recovery, provenance, and automation security.

    454 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed

Questions about Nuget Trusted Publishing

What does Nuget Trusted Publishing do?

Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions. Nuget Trusted Publishing is an agent skill from rodri-oliveira-dev/Dapper-FluentMap. Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.

When should I use Nuget Trusted Publishing?

Nuget Trusted Publishing fits situations like: keyless NuGet publish; trusted-publishing policy changes; release authentication; diagnosing NuGet trusted-publishing failures.

How do I install Nuget Trusted Publishing in Claude Code?

Run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a claude-code`. Or copy the skill folder (.agents/skills/nuget-trusted-publishing in rodri-oliveira-dev/Dapper-FluentMap) into .claude/skills/nuget-trusted-publishing in your project. Claude Code loads it when a task matches its description.

How do I install Nuget Trusted Publishing in Codex?

Run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a codex`. Or copy the skill folder (.agents/skills/nuget-trusted-publishing in rodri-oliveira-dev/Dapper-FluentMap) into .agents/skills/nuget-trusted-publishing in your project. Codex loads it when a task matches its description.

Can I use Nuget Trusted Publishing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rodri-oliveira-dev/Dapper-FluentMap --skill nuget-trusted-publishing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nuget-trusted-publishing, .gemini/skills/nuget-trusted-publishing, .github/skills/nuget-trusted-publishing and .opencode/skills/nuget-trusted-publishing in your project.

What does Nuget Trusted Publishing need to run?

SKILL.md names no scripts, command-line tools or credentials: Nuget Trusted Publishing is instructions for the agent only.

Does Nuget Trusted Publishing access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Nuget Trusted Publishing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nuget Trusted Publishing use?

Nuget Trusted Publishing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nuget Trusted Publishing use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 947 tokens, read only when the agent opens those files.

What are the alternatives to Nuget Trusted Publishing?

Skills that share tags, products or a category with Nuget Trusted Publishing: GitHub Actions Docs (devantler-tech/ksail, 165 stars), GitHub Actions Gen (laolaoshiren/claude-code-skills-zh, 880 stars), Releasing Reactiveproperty (runceel/ReactiveProperty, 944 stars) and GitHub Actions Hardening (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nuget Trusted Publishing?

rodri-oliveira-dev (a GitHub user) maintains it in rodri-oliveira-dev/Dapper-FluentMap, which has 454 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 8, 2026.

Source: rodri-oliveira-dev/Dapper-FluentMap on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.