Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add komunite/tezgah --skill saas-authgit clone --depth 1 https://github.com/komunite/tezgahWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/komunite/tezgah/saas-auth)<a href="https://agentmods.dev/skills/komunite/tezgah/saas-auth"><img src="https://agentmods.dev/badge/skills/komunite/tezgah/saas-auth/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/komunite/tezgah/saas-auth"><img src="https://agentmods.dev/badge/skills/komunite/tezgah/saas-auth.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00107 | $0.02627 |
| Opus 5 | $0.00053 | $0.01314 |
| Sonnet 5 | $0.00021 | $0.00525 |
| Haiku 4.5 | $0.00011 | $0.00263 |
Grade A, and why
saas-auth scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 190 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SaaS Auth — Kimlik Doğrulama ve Oturum Yönetimi
Bu skill, bir SaaS uygulamasının kimlik doğrulama katmanını kurar. Auth, uygulamanın diğer tüm katmanlarının temelidir — ödeme sistemi kullanıcı kimliğine, API koruması oturuma, e-posta gönderimi kullanıcı bilgisine bağlıdır.
Bağımlılık: Bu skill saas-launcher orkestratör skill'inin Faz 3'üdür. Bağımsız olarak da kullanılabilir.
Bağlı skill'ler:
- saas-email — Magic Link stratejisi seçildiyse e-posta altyapısının kurulu olması gerekir.
- saas-payments — Auth tamamlandıktan sonra ödeme sistemi kullanıcı kimliğini kullanır.
- saas-api-security — Oturum bilgisi API koruma katmanı tarafından tüketilir.
Auth Stratejisi Seçimi
Kullanıcıyla beraber doğru stratejiyi belirle. Her yöntemin avantaj ve dezavantajlarını açıkla.
Google OAuth
Ne zaman seç: Çoğu SaaS için varsayılan önerimiz. Kullanıcılar yeni bir şifre oluşturmak zorunda kalmaz, güven algısı yüksektir.
Avantajları: Tek tıkla giriş, şifre yönetimi yükü yok, profil bilgisi (isim, fotoğraf) otomatik gelir, güvenilir e-posta adresi garanti.
Dezavantajları: Google Cloud Console'da OAuth uygulama oluşturma ve onay süreci gerekir. Production'da Google'ın app review'u birkaç gün sürebilir. Bazı kurumsal kullanıcılar kişisel Google hesaplarını iş araçlarında kullanmak istemeyebilir.
Kritik adımlar:
- Google Cloud Console'da proje oluştur, OAuth Client ID al
- Callback URL'leri hem development hem production için tanımla
- OAuth Consent Screen'i yapılandır ve yayınla
- Scopes:
emailveprofileneredeyse her zaman yeterli
Dikkat: Google OAuth başvurusunda uygulama adı, logo ve gizlilik politikası URL'si gerekir. Gizlilik politikası sayfası launch'tan önce hazır olmalı.
Magic Link (E-posta ile Giriş)
Ne zaman seç: Şifresiz deneyim isteyenler için. Google'a bağımlı olmak istemeyenler veya Google OAuth'u destekle birlikte ikinci yöntem olarak.
Avantajları: Şifre yok, hesap çalınma riski düşük, e-posta adresi otomatik doğrulanmış olur.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 190 lines · 107 tokens per session scan A 947db027f595
saas-auth is a skill published in the GitHub repository komunite/tezgah (90 stars, last pushed 5mo ago), licensed MIT. It adds 107 tokens to every session and 2,627 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
API Designer
Skill "API Designer" from databayt/hogwarts, covering api design skill, server action pattern and checklist.
Multi-Tenant Validator
Skill "Multi-Tenant Validator" from databayt/hogwarts, covering multi-tenant safety skill, rules and checklist.
copilotkit-upgrade
Use when migrating a CopilotKit v1 application to v2 -- updating package imports, replacing deprecated hooks and components, switching from GraphQL runtime to AG-UI protocol runtime, and resolving breaking API changes.
nextjs-app-router
Full end-to-end tRPC setup for Next.js App Router. Covers route handler with fetchRequestHandler (GET + POST exports), TRPCProvider with QueryClientProvider, createTRPCOptionsProxy for RSC prefetching, HydrateClient/HydrationBoundary for hydration, useSuspenseQuery for Suspense, and server-side callers.
nextjs-pages-router
Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.
subscriptions
Set up real-time event streams with async generator subscriptions using .subscription(async function() { yield }). SSE via httpSubscriptionLink is recommended over WebSocket. Use tracked(id, data) from @trpc/server for reconnection recovery with lastEventId. WebSocket via wsLink and createWSClient from @trpc/client…