dotnet-mcaf

dotnet-mcaf is a skill for Claude Code, Codex from Postpartum-genushyacinthus29/dotnet-skills. It costs 57 tokens per session (994 once invoked), scanned A, a copy of dotnet-mcaf, MIT.

A setup guide for adding MCAF governance to a .NET code repository. It covers repository instructions, project documentation, and the skills needed for development work.

In plain words
What is it for?
Use it when starting MCAF in a .NET repository, updating AGENTS.md files, choosing governance and implementation skills, or organizing architecture, testing, and operations documentation.
Why use it?
It gives a team a shared way to organize work and repository rules, so important guidance is not scattered or guessed.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: mentions AGENTS.md.

Good fit Use it when starting MCAF in a .NET repository, updating AGENTS.md files, choosing governance and implementation skills, or organizing architecture, testing, and operations documentation.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/postpartum-genushyacinthus29/dotnet-skills/dotnet-mcaf
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add Postpartum-genushyacinthus29/dotnet-skills --skill dotnet-mcaf
Clone the repo
git clone --depth 1 https://github.com/Postpartum-genushyacinthus29/dotnet-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for dotnet-mcaf

README.md
[![agentmods](https://agentmods.dev/badge/skills/postpartum-genushyacinthus29/dotnet-skills/dotnet-mcaf/github.svg)](https://agentmods.dev/skills/postpartum-genushyacinthus29/dotnet-skills/dotnet-mcaf)
Your own site
<a href="https://agentmods.dev/skills/postpartum-genushyacinthus29/dotnet-skills/dotnet-mcaf"><img src="https://agentmods.dev/badge/skills/postpartum-genushyacinthus29/dotnet-skills/dotnet-mcaf/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for dotnet-mcaf

Your own site · 80×15
<a href="https://agentmods.dev/skills/postpartum-genushyacinthus29/dotnet-skills/dotnet-mcaf"><img src="https://agentmods.dev/badge/skills/postpartum-genushyacinthus29/dotnet-skills/dotnet-mcaf.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 57 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 994 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 98% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00057 $0.00994
Opus 5 $0.00028 $0.00497
Sonnet 5 $0.00011 $0.00199
Haiku 4.5 $0.00006 $0.00099

Measured 11d ago against content hash 46a7d1af5147, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

dotnet-mcaf scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

98% identical to dotnet-mcaf — 2 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

skills/dotnet-mcaf/SKILL.md · 90 lines

How it starts

The opening of the file, as written. The whole thing — 90 lines — stays where its author put it; the contents beside it link to each section on GitHub.

MCAF Adoption

Trigger On

  • bootstrapping MCAF in a new or existing repository that also contains .NET work
  • updating root or project-local AGENTS.md files to follow a durable repo workflow
  • deciding which MCAF governance skills and dotnet-* implementation skills to install together
  • organizing repo-native docs for architecture, features, ADRs, testing, development, and operations

Workflow

  1. Start from the canonical bootstrap surface:

    • tutorial: https://mcaf.managed-code.com/tutorial
    • concepts: https://mcaf.managed-code.com/
    • public MCAF skills: https://mcaf.managed-code.com/skills
  2. Place root AGENTS.md at the repository or solution root.

  3. Add project-local AGENTS.md only when the solution has multiple projects with genuinely different local rules.

  4. Install MCAF governance skills (dotnet-mcaf-*) for process areas and dotnet-* implementation skills for framework work. Check references/skill-map.md for overlap before adding duplicate surfaces.

  5. Route to the narrowest MCAF skill once the governance concern is clear:

    Concern Skill
    Delivery workflow and feedback loops dotnet-mcaf-agile-delivery
    Developer onboarding and local inner loop dotnet-mcaf-devex
    Durable docs structure and source-of-truth placement dotnet-mcaf-documentation
    Executable feature behaviour docs dotnet-mcaf-feature-spec
    Human review for large AI-generated drops dotnet-mcaf-human-review-planning
    ML/AI product delivery process dotnet-mcaf-ml-ai-delivery
    Explicit quality attributes and trade-offs dotnet-mcaf-nfr
    Branch, merge, and release hygiene dotnet-mcaf-source-control
    Design-system, accessibility, front-end direction dotnet-mcaf-ui-ux
  6. Scaffold repo-native documentation:

    docs/
    ├── Architecture.md
    ├── Features/
    ├── ADR/
    ├── Testing/
    ├── Development/
    └── Operations/
    
  7. Encode the non-trivial task flow in AGENTS.md: <slug>.brainstorm.md then <slug>.plan.md then implementation and validation.

  8. Treat verification as part of done: tests, analyzers, formatters, coverage, and any architecture or security gates the repo configured.

Read the full file on GitHub · 90 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 11d ago First seen · 90 lines · 57 tokens per session scan A 46a7d1af5147

Subscribe to this mod's changes

dotnet-mcaf is a skill published in the GitHub repository Postpartum-genushyacinthus29/dotnet-skills (10 stars, last pushed yesterday), licensed MIT. It adds 57 tokens to every session and 994 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 98% identical to dotnet-mcaf, differing in 2 lines, and is treated as a copy.

Related

Other skills, from other repositories

dotnet-techne-cross-repo-impact

Use when reviewing a .NET pull request for breaking changes that may affect other microservice repositories. Detects cross-repo API, DTO, endpoint, EF entity, and NuGet-package breaks, and checks whether a compatible downstream PR already exists. Keywords: cross-repo impact, breaking change, microservice…

Metalnib/dotnet-episteme-skills · 95 tokens

dotnet-techne-csharp-type-design-performance

Use when designing types and collections for hot paths and low-allocation .NET code. Keywords: readonly struct, sealed class, ValueTask, Span, FrozenDictionary, FrozenSet, allocation optimisation.

Metalnib/dotnet-episteme-skills · 49 tokens

dotnet-techne-csharp-api-design

Use when designing or changing public C#/.NET APIs with compatibility and versioning constraints. Keywords: breaking change, API design, backward compatibility, binary compatibility, deprecation strategy, versioning.

Metalnib/dotnet-episteme-skills · 48 tokens

dotnet-techne-csharp-concurrency-patterns

Use when choosing .NET concurrency patterns for async I/O, queues, pipelines, or thread safety. Keywords: async/await, channels, dataflow, Rx, lock contention, producer consumer, parallel processing.

Metalnib/dotnet-episteme-skills · 53 tokens

dotnet-techne-synopsis

Use when you need blast-radius analysis, dependency graphs, cross-repo impact, breaking-change diff, or architectural overview of .NET workspaces. Keywords: blast radius, dependency graph, impact analysis, cross-repo, call graph, endpoint map, EF Core lineage, breaking change, daemon, reindex.

Metalnib/dotnet-episteme-skills · 70 tokens

dotnet-techne-inspect

Use when you need to inspect NuGet package APIs, list public types, or decompile method/property signatures. Keywords: inspect package API, list types, decompile type, method signatures, NuGet interface.

Metalnib/dotnet-episteme-skills · 49 tokens