Atlas / Skills / dotnet / Make Skill

Make SkillSAFE

skills/dotnet/make-skill

EF Core is a modern object-database mapper for .NET. It supports LINQ queries, change tracking, updates, and schema migrations.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
2 documented
License
MIT
Stars
14,800
01

Overview

EF Core is a modern object-database mapper for .NET. It supports LINQ queries, change tracking, updates, and schema migrations.

Read from source at commit 1aecdbaaf9a2OBSERVED · 2026-10-07
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
codexmentioned
copilotmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: make-skill
description: 'Create and evaluate new Agent Skills for GitHub Copilot. Use when asked to create, scaffold, or add a skill. Generates SKILL.md, optional resources, and a paired Vally harness eval.'
---

# Create Skill

This skill helps you scaffold new agent skills that conform to the Agent Skills specification. Agent Skills are a lightweight, open format for extending AI agent capabilities with specialized knowledge and workflows.

## When Not to Use

- Creating custom agents (use the agents/ directory pattern)
- Adding language-specific, framework-specific, or module-specific coding guidelines (use file-based instructions instead)

### Key Principles

- **Frontmatter is critical**: `name` and `description` determine when the skill triggers—be clear and comprehensive
- **Concise is key**: Only include what agents don't already know; context window is shared
- **Useful instructions**: Only include information that's stable, not easily searchable and can be used for any task within the skill's scope
- **No duplication**: Information lives in SKILL.md OR reference files, not both

## Workflow

### Step 1: Investigate the Topic

Build deep understanding of the relevant topics using the repository content, existing documentation, and any linked external resources.

After investigating, verify:
- [ ] Can explain what the skill does in one paragraph
- [ ] Can list 3-5 specific scenarios where the skill is applicable
- [ ] Can identify common pitfalls or misconceptions about the topic
- [ ] Can outline a step-by-step skill workflow with clear validation steps
- [ ] Have search queries for deeper topics
- [ ] Can determine if the skill should be user-invocable or background knowledge only

If there are any ambiguities, gaps in understanding, or multiple valid approaches, ask the user for clarification before proceeding to skill creation. Also, evaluate whether the task might be better handled by a custom agent, agentic workflow, an existing skill or multiple narrower skills, and discuss this with the user if relevant.

### Step 2: Create the skill directory

```
.agents/skills/<skill-name>/
├── SKILL.md          # Required: instructions + metadata
```

### Step 3: Generate SKILL.md with frontmatter

Create the file with required YAML frontmatter:

```yaml
---
name: <skill-name>
description: <description of what the skill does and when to use it>
user-invocable: <Optional, defaults to true. Set to false for background knowledge skills.>
argument-hint: <Optional, guidance for how agents should format arguments when invoking the skill.>
disable-model-invocation: <Optional, set to true to prevent agents from invoking the skill and only allow to be used through manual invocation.>
compatibility: <Optional, specify any environment, tool, or context requirements for the skill.>
metadata: <Optional, key-value mapping for additional metadata that may be relevant for discovery or execution.>
allowed-tools: <Optional, list of pre-approved tools that agents could use when invoking the skill.>
---
```

### Step 4: Add body content sections

Include these recommended sections, following this file's structure:

1. **<Human-readable skill name>**: One paragraph describing the outcome beyond what's already in the description
2. **When Not to Use**: Bullet list of exclusions, optional
3. **Inputs and Outputs**: Example inputs and expected outputs, if applicable
4. **Workflow**: Numbered steps with checkpoints
5. **Testing**: Instructions for how to create automated tests for the skill output, if applicable
6. **Validation**: How to confirm the skill worked correctly
7. **Common Pitfalls**: Known traps and how to avoid them, optional

### Step 5: Add and populate optional directories if needed

```
.agents/skills/<skill-name>/
├── SKILL.md
├── scripts/          # Optional: executable code that agents can run
├── references/       # Optional: REFERENCE.md (Detailed technical reference), FORMS.md (Form templates or structured data formats), domain-specific instruction files
└── assets/           # Optional: templates, resources and other data files that aren't executable or Markdown
```

### Step 6: Write Scripts (Script-driven Only)

- Prefer PowerShell, but can also use Python or JavaScript
- Standard param block with defaults
- Ensure scripts produce clear, structured, and parseable console output (for example, section headers and status lines)
- Emoji status: ✅ green / ⚠️ yellow / 🔴 red
- **Fail-closed error handling** — Unknown ≠ Healthy

> ❌ **NEVER** count API failures as success. Return "Unknown" and exclude from positive counts.

### Step 7: Author and validate the harness evaluation

Create `eng/harness-evaluation/skills/<skill-name>/eval.yaml` and follow the authoring and validation rules in `eng/harness-evaluation/README.md`. Do not add a `skill-invocation` grader; the runner separately requires exact invocation of `<skill-name>` in every treatment trial so control and treatment share the same quality score. The eval must meaningfully distinguish the skilled treatment from the unskilled control.

Also verify:

- [ ] The skill name does not start or end with a hyphen, contain consecutive hyphens, or exceed 64 characters
- [ ] YAML frontmatter name matches the directory name exactly and all frontmatter fields are valid
- [ ] SKILL.md is under 500 lines and 5000 tokens, splitting stable detail into references when needed
- [ ] File references are relative and instructions are actionable and specific
- [ ] Instructions do not duplicate `.github/copilot-instructions.md` or `.github/instructions/`
- [ ] The workflow has numbered steps and observable success criteria
- [ ] No secrets, tokens, or internal URLs are included
- [ ] Optional directories are used appropriately
- [ ] Scripts handle edge cases, fail closed, and return structured, helpful errors
- [ ] The paired Vally comparison demonstrates distinctive value over the unskilled control

### Step 8: Test with Multi-Model Subagents

Fo
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 1aecdbaaf9a2full audit observations/trust-audit/skill/dotnet__make-skill.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-071aecdbaaf9a2SAFEB89first audit
06

Questions

What does the Make Skill skill do?

EF Core is a modern object-database mapper for .NET. It supports LINQ queries, change tracking, updates, and schema migrations.

Is Make Skill safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Make Skill access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Make Skill work with?

Its documentation mentions codex and copilot. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (1aecdbaaf9a2), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement