Agent Skills › btcpayserver/btcpayserver › razor-localization

razor-localization

GitHub

提供Razor视图中参数化本地化字符串的最佳实践,指导根据是否含HTML选择StringLocalizer或ViewLocalizer,并强调动态参数的Html.Encode安全编码。

.agents/skills/razor-localization/SKILL.md btcpayserver/btcpayserver

Trigger Scenarios

编辑包含本地化字符串的Razor .cshtml文件 审查Razor视图中的本地化实现安全性

Install

npx skills add btcpayserver/btcpayserver --skill razor-localization -g -y
More Options

Non-standard path

npx skills add https://github.com/btcpayserver/btcpayserver/tree/master/.agents/skills/razor-localization -g -y

Use without installing

npx skills use btcpayserver/btcpayserver@razor-localization

指定 Agent (Claude Code)

npx skills add btcpayserver/btcpayserver --skill razor-localization -a claude-code -g -y

安装 repo 全部 skill

npx skills add btcpayserver/btcpayserver --all -g -y

预览 repo 内 skill

npx skills add btcpayserver/btcpayserver --list

SKILL.md

Frontmatter
{
    "name": "razor-localization",
    "description": "Use when editing or reviewing Razor `.cshtml` files containing parameterized localized strings. Choose StringLocalizer for plain text and safely encode ViewLocalizer parameters when localized strings contain HTML."
}

Razor Localization

Apply these rules to parameterized localizable strings in Razor views.

Plain Text

Use StringLocalizer when the localized string does not contain HTML. Razor encodes the resulting localized string when rendering it.

@StringLocalizer["{0} has been invited as {1}.", Model.Email, Model.Role]

Do not use ViewLocalizer merely because a string has parameters.

HTML

Use ViewLocalizer only when the localized string intentionally contains HTML. Encode every dynamic parameter with Html.Encode before passing it to ViewLocalizer.

@ViewLocalizer["You have been invited to join <strong>{0}</strong> as {1}.",
    Html.Encode(Model.StoreName), Html.Encode(Model.Role)]

Never pass user-controlled or otherwise dynamic strings directly to ViewLocalizer:

@* Unsafe *@
@ViewLocalizer["Welcome to <strong>{0}</strong>.", Model.StoreName]

Generated HTML values such as Html.ActionLink(...) are intentional HTML and should not be encoded.

Review Checklist

  • Use StringLocalizer for parameterized strings without HTML.
  • Use ViewLocalizer only when the localized resource contains intentional HTML.
  • Wrap every dynamic ViewLocalizer parameter in Html.Encode(...).
  • Do not encode intentional HTML values returned by HTML helpers.
  • Check every added or modified ViewLocalizer call before completing a Razor change.

Version History

  • a305e95 Current 2026-09-23 02:15

Same Skill Collection

.agents/skills/bem-conventions/SKILL.md
.agents/skills/btcpayserver-changelog/SKILL.md
.agents/skills/btcpayserver-configuration/SKILL.md
.agents/skills/btcpayserver-migrations/SKILL.md
.agents/skills/btcpayserver-pr-descriptions/SKILL.md
.agents/skills/playwright-test-patterns/SKILL.md

Metadata

Files
0
Version
51f6cf0
Hash
f31f827a
Indexed
2026-09-23 02:15

ホーム - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-30 20:39
浙ICP备14020137号-1