DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Redmond desk5 min

Using Skills in Microsoft Agent Framework with C#

A practical C# guide to Microsoft Agent Framework skills: how the four skill sources work, when to use workflows instead, and how to manage approval and script-execution risks.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use an Agent Skill when you want a model to apply focused instructions flexibly; use a workflow when your application must enforce the steps and their order. In Microsoft Agent Framework for C#, skills can come from files, inline code, a class, or an MCP server. The right source depends on where the skill’s instructions and resources belong—and whether you trust any scripts it may run.

What an Agent Skill does

Microsoft describes Agent Skills as portable packages of instructions, scripts, and resources that give agents specialized capabilities and domain expertise. A skill provides the model with guidance for a task; it does not, by itself, prescribe a guaranteed execution path. The model decides how to apply the guidance.

Skills use progressive disclosure: the agent can discover a skill before loading its full instructions, then consult resources or run scripts only as needed. Microsoft documents four stages:

  1. Advertise: make the skill available for the agent to discover.
  2. Load instructions: provide the skill’s instructions when it is relevant.
  3. Read resources: let the agent consult supporting material when needed.
  4. Run scripts: execute a skill script when the task calls for it and the setup allows it.

This design is intended to limit how much context the agent needs at once. Microsoft’s documentation does not publish a measured context-savings figure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a skill or a workflow

The key difference is who controls the execution path: a skill leaves the approach to the AI, while a workflow lets the developer define it.

Need Skill Workflow
Execution control The model chooses how to use the instructions. The developer specifies the path and order.
Recovery A retry may repeat work from the turn; there is no workflow checkpointing implied by a skill. Can support checkpointing and resuming after failures.
Side effects Less suitable when repeating an action would cause harm or cost. Preferable when actions such as sending email or charging a payment must not be repeated on retry.
Coordination Fits focused tasks where the AI can choose its approach. Fits complex coordination, including multiple agents or human approvals.

Use a skill when the agent should figure out how to accomplish a focused task. Use a workflow when you need to guarantee which steps run and in what order.

Pick a C# skill source

The documented C# API supports file-based, inline, class-based, and MCP-based skills. You can combine sources using AgentSkillsProviderBuilder; Microsoft’s documentation describes this builder as a place to compose sources and configure filtering, aggregation, deduplication, caching, or a script runner.

Source Where it lives Useful when Scripts and resources Trust boundary
File-based Skill folders on the filesystem, each with a SKILL.md. Instructions are maintained as files and organized into directories. Resources and scripts are supplied by the skill folder. Configure an appropriate script runner if scripts need to run. Review the folder’s contents and execution permissions. Without a runner, attempting script execution causes an error.
Inline C# code using AgentInlineSkill. Definitions are generated dynamically, belong alongside application code, or need access to call-site state. The API supports adding resources and scripts; delegates can receive IServiceProvider when the agent is constructed with services. Application code controls what the delegates expose or execute.
Class-based A class derived from AgentClassSkill<TSelf>. You want skill components bundled in a C# class with discovery through annotations. Use [AgentSkillResource] and [AgentSkillScript] to mark resources and scripts; dependency injection is supported as documented. Review the annotated methods and their dependencies as executable application code.
MCP-based An MCP server, using UseMcpSkills. Skills are provided through an MCP integration rather than local definitions. The documented API can fetch skill-md entries on demand and download and unpack archive entries locally. The MCP skills API is experimental and may change. Scripts bundled in archive skills are never executed.

Microsoft’s Agent Skills documentation is marked last updated September 18, 2026. API names, experimental features, and defaults can vary by release, so check the documentation for the version of Microsoft Agent Framework you use rather than assuming examples work unchanged.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Attach file-based skills

For filesystem skills, point an AgentSkillsProvider at a directory containing skill folders with SKILL.md files, then attach the provider through ChatClientAgentOptions.AIContextProviders. If you are composing sources, the builder also provides UseFileSkill(...).

A file skill’s scripts need an appropriate script runner to execute. If no runner is configured, the error occurs when execution is attempted—not merely because the skill is discovered. Decide whether the agent should be able to run scripts before enabling that capability.

Define skills in C# code

Inline skills

Use AgentInlineSkill when the skill’s instructions or resources are created dynamically, should live with the application code, or need to capture call-site state. The API supports adding both resources and scripts. If the agent is constructed with services, resource and script delegates can receive IServiceProvider for dependency injection.

Class-based skills

For a class-oriented design, derive a skill type from AgentClassSkill<TSelf> and annotate members with [AgentSkillResource] or [AgentSkillScript] so the framework can discover them. This keeps a skill’s components together in a C# class and can use dependency injection as documented.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

These API patterns are version-sensitive. Verify the current API surface for your installed package before adopting a code sample from documentation for a different release.

Connect MCP-based skills

The documented C# integration uses the Microsoft.Agents.AI.Mcp package and UseMcpSkills. The API is explicitly experimental, so its behavior and signatures may change. Microsoft describes two kinds of content: skill-md entries fetched on demand, and archive entries downloaded and unpacked locally. Scripts bundled in archive skills are never executed—a deliberate security restriction.

Treat an MCP source as an external trust boundary: understand who controls the server and what instructions or resources it supplies before making those skills available to an agent.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Require approval and constrain execution

In Microsoft’s documented Harness setup, all three skill tools require approval by default. The documentation provides AgentSkillsProvider.ReadOnlyToolsAutoApprovalRule and AllToolsAutoApprovalRule as ways to allow automatic approval. Microsoft cautions against using automatic approval except with trusted skill sources. The default described here is specific to that Harness setup; do not assume it applies identically to every host or framework version.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For production script execution, Microsoft recommends considering safeguards such as:

  • Sandboxing the execution environment.
  • CPU, memory, and time limits.
  • Input validation and an allow-list of executable scripts.
  • Structured logs and audit trails.

These controls matter because instructions and scripts can come from different places, and a script may have effects beyond what a skill’s description suggests. Keep approval and execution permissions aligned with the source’s trustworthiness.

Choose credentials deliberately

The documented example uses DefaultAzureCredential. Microsoft cautions that production applications should consider a specific credential, such as ManagedIdentityCredential, to avoid latency, unintended credential probing, and fallback risks. Choose the credential strategy for the deployment environment rather than carrying a broad development convenience into production by default.

A practical decision checklist

  • Choose a skill if the task is focused and the model should decide how to apply its instructions.
  • Choose a workflow if step order, checkpointing, safe retries, or coordination must be explicit.
  • Choose files for directory-based skill content, inline definitions for dynamic or state-aware code, a class for bundled C# components, or MCP when skills are supplied through that integration.
  • Configure a script runner only when script execution is needed, and define limits and approvals before enabling it.
  • Check the current Microsoft documentation against your installed package version, especially for experimental MCP support and approval defaults.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.