Install
$ agentstack add skill-ngxtm-devkit-aspnet-core ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
ASP.NET Core Web API
Priority: P1 (OPERATIONAL)
Modern ASP.NET Core patterns for building RESTful APIs.
Implementation Guidelines
- Minimal APIs: Use for simple endpoints.
app.MapGet(), route groups, endpoint filters. - Controllers: Use
[ApiController]for automatic model validation and binding. - Middleware: Order matters. Custom middleware with
app.Use(). - Filters: Action filters for cross-cutting concerns. Exception filters for error handling.
- Validation: FluentValidation or DataAnnotations. Return
ProblemDetailson errors. - Versioning: URL-based (
/api/v1/) or header-based versioning. - OpenAPI: Always configure Swagger for API documentation.
- Response Types: Use
TypedResultsfor compile-time safety.
Anti-Patterns
- No
HttpClientwithoutIHttpClientFactory: Socket exhaustion risk. - No blocking async: Never
.Resultor.Wait()in controllers. - No business logic in controllers: Controllers should only orchestrate.
- No returning
Taskwithoutasync: Useasynckeyword or return directly.
Code
// Minimal API with route groups
var app = WebApplication.CreateBuilder(args).Build();
var users = app.MapGroup("/api/users")
.WithTags("Users")
.RequireAuthorization();
users.MapGet("/", async (IUserService service) =>
TypedResults.Ok(await service.GetAllAsync()));
users.MapGet("/{id:int}", async (int id, IUserService service) =>
await service.GetByIdAsync(id) is { } user
? TypedResults.Ok(user)
: TypedResults.NotFound());
users.MapPost("/", async (CreateUserDto dto, IUserService service) =>
{
var user = await service.CreateAsync(dto);
return TypedResults.Created($"/api/users/{user.Id}", user);
}).AddEndpointFilter>();
// Controller with proper patterns
[ApiController]
[Route("api/[controller]")]
[Produces("application/json")]
public class OrdersController(IOrderService orderService) : ControllerBase
{
[HttpGet("{id:int}")]
[ProducesResponseType(StatusCodes.Status200OK)]
[ProducesResponseType(StatusCodes.Status404NotFound)]
public async Task GetOrder(int id, CancellationToken ct)
{
var order = await orderService.GetByIdAsync(id, ct);
return order is null ? NotFound() : Ok(order);
}
[HttpPost]
[ProducesResponseType(StatusCodes.Status201Created)]
[ProducesResponseType(StatusCodes.Status400BadRequest)]
public async Task CreateOrder(CreateOrderDto dto, CancellationToken ct)
{
var order = await orderService.CreateAsync(dto, ct);
return CreatedAtAction(nameof(GetOrder), new { id = order.Id }, order);
}
}
Reference & Examples
For middleware, exception handling, and HttpClientFactory: See [references/REFERENCE.md](references/REFERENCE.md).
Related Topics
security | razor-pages | blazor
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ngxtm
- Source: ngxtm/devkit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.