Audits ASP.NET Core / .NET Framework applications — Razor Html.Raw and Blazor MarkupString XSS, EF Core FromSqlRaw/SqlQueryRaw and Dapper/ADO string-concat SQL injection, BinaryFormatter/ObjectStateFormatter deserialization RCE, hardcoded machineKey → ViewState RCE, XXE via DtdProcessing.Parse, Newtonsoft TypeNameHandling polymorphic gadgets, AllowAnonymous on sensitive endpoints, antiforgery gaps, CORS AllowAnyOrigin+AllowCredentials, open redirect, Process.Start command injection, hardcoded connection strings, developer exception page in prod. Use when the project has .csproj, .sln, packages.lock.json, packages.config, or web.config.
cp -r cryptoskill/skills/chains/ashrafiucse-dotnet-security .claude/skills/clawhub install ashrafiucse-dotnet-securityCapabilities below are detected automatically by an open-source scanner that reads the skill's text and scripts (see how this is computed). Not measured means the scanner couldn't make a confident call — it is NOT a green check, and you should treat it as a possible red flag until a human or a stronger scanner has measured it.
read_only Phase 1 single-mode classification — multi-mode breakdown deferred to Phase 2.
We did not find any well-known hosted services in this skill's text or scripts. This does NOT mean the skill is local-only — it might use services we don't yet recognize, or talk to them through code paths our scanner can't reach. A complete dependency list (every package, library, and binary, with integrity hashes) is on the roadmap; today we only show recognized hosts.
No one has audited this skill yet. That is different from “audited and clean” — it just means no professional reviewer (a security firm, the CryptoSkill team, or a verified independent researcher) has signed off on it. There are no audit reports to read. How reviewer levels work →
SKILL.md → SOURCE.md → TRUST.auto.yaml → Browse directory →
Auto-generated by cryptoskill/extract-capabilities/0.3.1 · hosted-service list version 2026-09-06 · how this is computed