Can AI agents automate NuGet?
Microsoft · hybrid · developer-tools
NuGet is automatable today through the NuGet V3 HTTP API. This record is NuGet package feeds and the NuGet MCP server shipped as NuGet.Mcp.Server. It is not JFrog Artifactory, GitHub Packages, or npm. The nuget.org service index is https://api.nuget.org/v3/index.json. Microsoft Learn documents resources for package content, metadata, search, and publish. On nuget.org, only the PackagePublish resource requires authentication, and it uses the X-NuGet-ApiKey header for push, unlist, and relist. Reads of public packages do not use that header. nuget.exe installs, creates, publishes, and manages packages. The pack, restore, delete, locals, and push commands are also available on macOS and Linux through the dotnet CLI. Some nuget.exe commands are limited under Mono. The MCP server is local stdio through dnx. Microsoft Learn requires the .NET 10 SDK or later. NuGet.Mcp.Server 1.4.16 lists fix_vulnerable_packages, upgrade_packages_to_latest, get_latest_package_version, get_package_context, update_package_version, and review_supply_chain_security. Visual Studio 2026 includes the server and it must be enabled. Visual Studio 2022 17.14 or later uses a manual stdio config aimed at the nuget.org service index. The package page for 1.4.16 still says .NET 10 Preview 6 or later. Webhooks and an llms.txt index were not established. iPaaS catalogs were not opened. Computer-use viability is unassessed. The API scores 8, the CLI scores 7, and MCP scores 7. API is the best path because an HTTP client can search, download, and publish without the .NET 10 SDK.
Best path today: api · Overall automatability: 8/10
Modalities
| Modality | Status | Detail |
|---|---|---|
| API | yes | restapi-key coverage: partial · docs |
| SDK | unknown | official: unknown |
| MCP | yes | verdict: official |
| Integrations | unknown | |
| CLI | yes | |
| Extensibility | unknown | webhooks: unknown |
| Data access | export: nupkg · import: nupkg | |
| RPA / UI automation | unknown | web-dom No repeatable UI probe was run. The NuGet V3 API, nuget.exe, the dotnet CLI, and the local NuGet MCP server cover package lookup and publish without browser control of nuget.org.
|
| Computer use | unknown | measured verdicts only — "unknown" means not yet probed by us |
Scores
| api | mcp | integrations | cli | rpa | computer use | overall |
|---|---|---|---|---|---|---|
| 8 | 7 | — | 7 | — | — | 8 |
Evidence
| Fact | Tier | Source | Date |
|---|---|---|---|
homepage | declared | source | 2026-09-30 |
license | declared | source | 2026-09-30 |
deployment | declared | source | 2026-09-30 |
platforms | declared | source | 2026-09-30 |
modalities.rpa.ui_stack[0] | declared | source | 2026-09-30 |
modalities.api.exists | declared | source | 2026-09-30 |
modalities.api.kinds[0] | declared | source | 2026-09-30 |
modalities.api.auth[0] | declared | source | 2026-09-30 |
modalities.api.coverage | declared | source | 2026-09-30 |
modalities.api.docs | declared | source | 2026-09-30 |
modalities.data_access.export[0] | declared | source | 2026-09-30 |
modalities.data_access.import[0] | declared | source | 2026-09-30 |
modalities.mcp.first_party | declared | source | 2026-09-30 |
modalities.mcp.verdict | declared | source | 2026-09-30 |
modalities.cli.exists | declared | source | 2026-09-30 |
verdict.scores.api | declared | source | 2026-09-30 |
verdict.scores.mcp | declared | source | 2026-09-30 |
verdict.scores.cli | declared | source | 2026-09-30 |
freshness.watch[0].url | declared | source | 2026-09-30 |
freshness.watch[1].url | declared | source | 2026-09-30 |
freshness.watch[2].url | declared | source | 2026-09-30 |
freshness.watch[3].url | declared | source | 2026-09-30 |
Related tools
Other products in this database that share a category with NuGet.
Last verified 2026-09-30 · volatility medium · JSON record