.NET / C# source review

SkillSecurity

Lets your agent review code changes for correctness, performance, security, and test gaps.

Use .NET / C# source review in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add .NET / C# source review and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the .NET / C# source review skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

.NET / C# source reviewStart free
About this skill

Review EF Core pull requests or local changes for concrete correctness, compatibility, performance, security, and test-coverage problems. Use when asked to review, critique, or check code changes before merge or submission.

What this skill tells your AI

The instructions your AI receives, as published by dotnet/efcore in .agents/skills/code-review/SKILL.md and read by ahel’s review.

When it applies

Reviewing C#/.NET source (ASP.NET Core, MVC, or legacy WebForms). The headline risks are unsafe deserialization, string-built SQL, XXE, and Razor's raw-output escape hatch.

Why it works

.NET ships powerful-but-dangerous serializers (BinaryFormatter, Json.NET with TypeNameHandling, LosFormatter/ViewState) that instantiate arbitrary types, and several XML APIs resolve DTDs by default on older frameworks. Reviews find where these meet untrusted input.

Sinks & patterns (grep, then trace to user input)

  • Deserialization: BinaryFormatter, LosFormatter, SoapFormatter, NetDataContractSerializer, JsonConvert with TypeNameHandling != None, Js.NET/fastJSON polymorphic types → RCE gadgets.
  • SQLi: string-concatenated SqlCommand/ExecuteReader/FromSqlRaw(EF Core) vs parameters.
  • Command exec: Process.Start with concatenated arguments / UseShellExecute.
  • XXE: XmlDocument/XmlReader/XmlTextReader without DtdProcessing=Prohibit (legacy default resolves entities); XmlSerializer with a user-controlled type.
  • XSS: Razor @Html.Raw(...), MvcHtmlString, WebForms <%= %> with unencoded input; Response.Write.
  • Other: path traversal via Path.Combine(root, input), LdapConnection filter injection, reflection (Type.GetType/Activator.CreateInstance) on input, insecure ViewState (no MAC).

Framework specifics

  • ASP.NET Core: model binding over-posting/mass assignment (bind whole entity), [AllowAnonymous] on sensitive actions, disabled antiforgery on POST APIs, exposed dev endpoints, open redirect via Redirect(returnUrl) without Url.IsLocalUrl.
  • WebForms: ViewState deserialization (machineKey), event-validation off.

Method

  1. Run security-code-scan/CodeQL; treat as leads.
  2. rg 'BinaryFormatter|TypeNameHandling|FromSqlRaw|Html\.Raw|XmlDocument|Process\.Start' → trace to input.
  3. Check controller [Authorize]/antiforgery coverage and model-binding scope.
  4. Confirm with web-deserialization, web-sqli, web-xxe, web-command-injection.

Gotchas

  • Json.NET is safe by default — the bug is an explicit TypeNameHandling.All/Auto.
  • EF Core parameterises LINQ; FromSqlRaw/ExecuteSqlRaw with interpolation is where SQLi returns.
  • ViewState RCE needs the machineKey (leaked/weak) — note the precondition.

References

OWASP .NET security cheat sheet; ysoserial.net gadget research; Microsoft secure-coding guidance.

Signals

GitHub stars
15k
Forks
3k
Last commit
Sep 2026
Advanced
Item type
skill
Key
code-review-dotnet
Source
github.com/dotnet/efcore