Install
$ agentstack add skill-ngxtm-devkit-blazor ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Blazor
Priority: P1 (OPERATIONAL)
Blazor component patterns for interactive web UIs.
Implementation Guidelines
- Components: Keep components focused. Split large components into smaller ones.
- Parameters: Use
[Parameter]for one-way,EventCallbackfor two-way binding. - Cascading Values: Use for app-wide state (theme, user context).
- State Management: Component state for local, Fluxor/custom service for global.
- Forms:
EditFormwithDataAnnotationsValidatoror FluentValidation. - JS Interop: Use
IJSRuntimesparingly. Prefer Blazor bindings. - Render Modes: Choose based on requirements (Server, WASM, Auto in .NET 8+).
- Streaming: Use
[StreamRendering]for long-loading components.
Anti-Patterns
- No direct DOM manipulation: Use Blazor bindings and refs.
- No
StateHasChanged()in lifecycle: Called automatically after lifecycle methods. - No heavy computation in render: Move to
OnInitializedor background task. - No sync JS interop in Server mode: Causes UI blocking.
Code
@* UserList.razor *@
@page "/users"
@attribute [StreamRendering]
@inject IUserService UserService
Users
Users
@if (_users is null)
{
Loading...
}
else if (_users.Count == 0)
{
No users found.
}
else
{
@foreach (var user in _users)
{
}
}
@code {
private List? _users;
protected override async Task OnInitializedAsync()
{
_users = await UserService.GetAllAsync();
}
private async Task HandleDelete(int userId)
{
await UserService.DeleteAsync(userId);
_users = await UserService.GetAllAsync();
}
}
@* UserCard.razor - Reusable component *@
@User.Name
@User.Email
OnDelete.InvokeAsync(User.Id)">Delete
@code {
[Parameter, EditorRequired]
public User User { get; set; } = default!;
[Parameter]
public EventCallback OnDelete { get; set; }
}
@* EditForm with validation *@
Name
_model.Name)" />
Email
_model.Email)" />
@if (_isSubmitting)
{
}
Submit
@code {
private CreateUserModel _model = new();
private bool _isSubmitting;
private async Task HandleSubmit()
{
_isSubmitting = true;
await UserService.CreateAsync(_model);
_isSubmitting = false;
NavigationManager.NavigateTo("/users");
}
}
Reference & Examples
For lifecycle, state management, and JS interop: See [references/REFERENCE.md](references/REFERENCE.md).
Related Topics
aspnet-core | razor-pages | security
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ngxtm
- Source: ngxtm/devkit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.