Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add neverinfamous/memory-journal-mcp --skill auth-identitygit clone --depth 1 https://github.com/neverinfamous/memory-journal-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/neverinfamous/memory-journal-mcp/auth-identity)<a href="https://agentmods.dev/skills/neverinfamous/memory-journal-mcp/auth-identity"><img src="https://agentmods.dev/badge/skills/neverinfamous/memory-journal-mcp/auth-identity.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00065 | $0.00794 |
| Opus 5 | $0.00032 | $0.00397 |
| Sonnet 5 | $0.00013 | $0.00159 |
| Haiku 4.5 | $0.00006 | $0.00079 |
Grade A, and why
auth-identity scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 49 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Authentication & Identity
This skill outlines the strict security requirements and architectural patterns for implementing Authentication and Identity (AuthN/AuthZ) in modern applications.
Security Gates (CRITICAL)
CRITICAL HITL GATE: You MUST stop and ask the user for explicit confirmation before modifying authentication flows, updating token expiration times, changing cookie settings (
httpOnly,Secure), or adding new OAuth providers. Auth changes carry high risk of introducing vulnerabilities. Never silently commit auth logic.
1. OAuth & OIDC (OpenID Connect)
- Standard Flow: Always use the Authorization Code flow with PKCE (Proof Key for Code Exchange) for SPAs and mobile apps. Never use the Implicit Flow (it is deprecated and insecure).
- State Parameter: Always implement and validate the
stateparameter to prevent CSRF (Cross-Site Request Forgery) attacks during the OAuth callback. - Provider Scopes: Request the minimum necessary scopes. Never request
offline_access(refresh tokens) unless explicitly required and approved by the user.
2. JWT (JSON Web Tokens)
- Signing Algorithms: Always use asymmetric algorithms (e.g.,
RS256,EdDSA) if the token needs to be verified by multiple services. UseHS256only if the issuer and verifier are the exact same service. NEVER allow thenonealgorithm. - Payload Data: Never put sensitive data (PII, passwords, internal IDs) inside a JWT payload. JWTs are Base64 encoded, not encrypted.
- Expiration: Keep short-lived access tokens (e.g., 15-60 minutes). Use Refresh Tokens for extending sessions.
- Validation: Always strictly validate the
exp(expiration),iss(issuer), andaud(audience) claims on every request.
3. Session & Storage Management
- Web Storage: Never store JWTs or session IDs in
localStorageorsessionStoragewhere they are vulnerable to XSS (Cross-Site Scripting) attacks. - Cookies: Always store session tokens in cookies with strict attributes:
HttpOnly: True (prevents JavaScript access)Secure: True (requires HTTPS)SameSite:LaxorStrict(prevents CSRF)
- Invalidation: Ensure sessions can be revoked on the server side (e.g., via a Redis blocklist or database
sessionstable).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 49 lines · 65 tokens per session scan A aac4164abc3f
auth-identity is a skill published in the GitHub repository neverinfamous/memory-journal-mcp (20 stars, last pushed 1mo ago), licensed MIT. It adds 65 tokens to every session and 794 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
tech-writing
Write professional technical documents — requirements/PRD, tech spec/design doc, low-level design, decision records, and trade-off analysis — at a formality tier matched to the task. Grounds every claim in real code or a cited source, marks what it could not verify, and refuses to pad. Use when asked to write/update a…
perf-profiling
Systematic performance profiling and optimization across frontend (Core Web Vitals, code splitting, lazy loading), backend (N+1 queries, async), and database (EXPLAIN ANALYZE, indexing) layers. Use when the user reports slow code, latency, memory leaks, needs to benchmark, or wants to speed up an application. Measure…
plan-orchestrator
Route hierarchical-planning intents to the correct backing script. Use when the user invokes /aura-frog:plan (with or without subcommand), mentions plan verbs (expand/next/replan/promote/archive/freeze/thaw/undo/status/conflicts), or types a plan-vocabulary bare word with .claude/plans/active.json present. Owns verb…
skill-creator
Generate a new skill from a plain-language description — decides invocation control, arguments, and context cost, then scaffolds, validates, and tests it.
tree-of-thoughts
Structured reasoning — branch/evaluate/prune/expand search over solution space (tree), or a single ordered chain when the path is linear. Use for architecture with multi-step decisions, refactor planning, complex debug hypothesis trees, or step-by-step structured thinking. Papers: Yao et al. 2023 (ToT)…
chain-of-verification
Draft → generate verification questions → answer independently via tools → revise. Catches hallucinated facts in reports and reviews. MANDATORY for Phase 4 security/test claims. Paper: Dhuliawala et al. 2023.