Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/shipwithai/shipwithai-plugins/auth-setupnpx skills add ShipWithAI/shipwithai-plugins --skill auth-setupgit clone --depth 1 https://github.com/ShipWithAI/shipwithai-pluginsWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00053 | $0.08126 |
| Opus 5 | $0.00026 | $0.04063 |
| Sonnet 5 | $0.00011 | $0.01625 |
| Haiku 4.5 | $0.00005 | $0.00813 |
Grade C, and why
auth-setup scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Recursive force deletehighDestructive command
rm -rf with a variable or a broad path is one typo away from removing the wrong tree.
cp -a "$SCAFFOLD_DIR"/. . && rm -rf "$SCAFFOLD_DIR" How it starts
The opening of the file, as written. The whole thing — 499 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Auth Setup
Production-ready authentication for any web app in under 45 minutes. 2 auth providers (Better Auth & Firebase), Google OAuth, copy-paste UI components, and a verification script. GitHub & Apple OAuth coming soon.
When to Use
- Starting a new project needing user authentication
- Adding auth to an existing app (auto-detects and adapts to existing theme)
- Migrating between auth providers
- Setting up OAuth social login (Google, GitHub, Apple)
- Need login/register page components
CRITICAL — New Project Scaffolding
If scaffolding a new Next.js project, never run create-next-app . in the current directory.
Claude Code plugins (OMC, gstack) create dotfiles (.omc/, .claude/) that conflict with
create-next-app, which requires a completely empty directory. The dotfiles are recreated
by hooks between deletion and scaffolding, causing an infinite failure loop.
Correct pattern — scaffold in /tmp, pin to Next.js 14:
SCAFFOLD_DIR=/tmp/nextjs-scaffold-$RANDOM && \
npx create-next-app@14 "$SCAFFOLD_DIR" \
--typescript --tailwind --eslint --app --src-dir \
--import-alias "@/*" --use-npm --no-turbopack && \
cp -a "$SCAFFOLD_DIR"/. . && rm -rf "$SCAFFOLD_DIR"
Why @14 not @latest? Next.js 16 deprecated middleware.ts in favor of proxy.ts.
All templates, guides, and middleware examples in this plugin use the middleware.ts convention
(Next.js 14/15). Using @latest will install Next.js 16+ and the build will fail.
See pitfall #37 for details.
Or scaffold into a named subdirectory, then move files up.
shadcn/ui: Use npx [email protected] init -d (NOT shadcn@2 or shadcn@latest).
[email protected]+ expects Tailwind v4's CSS-based config and fails with Next.js 14's tailwind.config.ts.
After shadcn init, you MUST install tailwindcss-animate — shadcn adds it to tailwind.config.ts but does NOT auto-install it: {pm} install tailwindcss-animate (use package manager detected in Step 0).
See pitfall #44.
Provider Decision Framework
What ships with it
60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- assets/components/better-auth/auth-provider-buttons.tsx 4.4 KB
- assets/components/better-auth/dashboard-client.tsx 852 B
- assets/components/better-auth/forgot-password.tsx 3.6 KB
- assets/components/better-auth/login-page.tsx 5.9 KB
- assets/components/better-auth/protected-layout.tsx 359 B
- assets/components/better-auth/register-page.tsx 6.3 KB
- assets/components/better-auth/reset-password.tsx 4.7 KB
- assets/components/better-auth/user-profile.tsx 5.0 KB
- assets/components/firebase/auth-provider-buttons.tsx 5.0 KB
- assets/components/firebase/dashboard-client.tsx 873 B
- assets/components/firebase/forgot-password.tsx 3.5 KB
- assets/components/firebase/login-page.tsx 5.5 KB
- assets/components/firebase/protected-layout.tsx 295 B
- assets/components/firebase/register-page.tsx 6.5 KB
- assets/components/firebase/reset-password.tsx 1.4 KB
- assets/components/firebase/user-profile.tsx 5.5 KB
- assets/components/shared/dashboard-page.tsx 1.0 KB
- assets/components/shared/globals.css 1.9 KB
- assets/components/shared/icons.tsx 1.9 KB
- assets/config/authjs.config.ts 4.0 KB runs code
- assets/config/better-auth.config.ts 4.9 KB runs code
- assets/config/better-auth.env.example 970 B
- assets/config/clerk.config.ts 3.5 KB runs code
- assets/config/drizzle.config.ts 633 B runs code
- assets/config/email.ts 1.8 KB runs code
- assets/config/env.example 1.8 KB
- assets/config/firebase.config.ts 11 KB runs code
- assets/config/next.config.ts 3.2 KB runs code
- assets/config/supabase.config.ts 5.3 KB runs code
- assets/db/better-auth-db.ts 1.5 KB runs code
- assets/db/better-auth-schema.ts 2.4 KB runs code
- assets/middleware/better-auth/express-middleware.ts 2.1 KB runs code
- assets/middleware/better-auth/hono-middleware.ts 1.9 KB runs code
- assets/middleware/better-auth/nextjs-middleware.ts 4.4 KB runs code
- assets/middleware/express-middleware.ts 5.2 KB runs code
- assets/middleware/firebase/express-middleware.ts 2.2 KB runs code
- assets/middleware/firebase/hono-middleware.ts 2.1 KB runs code
- assets/middleware/firebase/nextjs-middleware.ts 3.0 KB runs code
- assets/middleware/hono-middleware.ts 4.7 KB runs code
- assets/middleware/nextjs-middleware.ts 9.0 KB runs code
- assets/schemas/drizzle-auth-schema.ts 5.0 KB runs code
- assets/schemas/prisma-auth-schema.prisma 4.3 KB
- assets/schemas/supabase-migration.sql 4.0 KB
- assets/templates/providers/better-auth/README.md.tmpl 12 KB
- assets/templates/providers/firebase/README.md.tmpl 10 KB
- assets/themes/ocean.css 1.9 KB
- assets/themes/README.md 1.5 KB
- assets/themes/sunrise.css 1.8 KB
- evals/evals.json 8.8 KB
- references/01-choosing-provider.md 3.3 KB
- references/02-better-auth-guide.md 12 KB
- references/03-clerk-guide.md 4.4 KB
- references/04-authjs-guide.md 3.8 KB
- references/05-firebase-auth-guide.md 15 KB
- references/06-supabase-auth-guide.md 5.2 KB
- references/07-oauth-social-login.md 4.8 KB
- references/08-database-auth-schema.md 5.1 KB
- references/09-common-pitfalls.md 26 KB
- references/10-existing-project-integration.md 8.0 KB
- scripts/auth-init.ts 6.5 KB runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 499 lines · 53 tokens per session scan C 9229eb193cd7
auth-setup is a skill published in the GitHub repository ShipWithAI/shipwithai-plugins (10 stars, last pushed 21d ago), licensed MIT. It adds 53 tokens to every session and 8,126 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it C with 1 finding (recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
rulesync
Generates and syncs AI rule configuration files (.cursorrules, CLAUDE.md, copilot-instructions.md) across 20+ coding tools from a single source. Use when syncing AI rules, running rulesync commands, importing or generating rule files, or managing shared AI coding configurations.
agent-workspace-linux
Use when a task needs an isolated hidden Linux desktop or workspace-owned browser: GUI app QA, web/browser/shopping automation, sandboxed app observation, or stale workspace cleanup. Routes agent-workspace-linux MCP tools on demand. Does NOT apply to host desktop/Chrome control, generic MCP setup, or pure code/file…
ss-component
Generate a new UI component following the StyleSeed design conventions.
loongsuite-pilot-insight
基于 LoongSuite Pilot / AI Coding Agent 日志生成事件洞察、组织洞察、数据质量、研发效能和 AI Native 使用类 SLS 报表时使用;包含 AI Coding 事件表语义,以及团队报表可选的部门维表、deptuser 组织关系、指标口径和公共 CTE,通常与 sls-dashboard-builder 一起使用。.
map-review
Interactive 4-section code review using monitor, predictor, and evaluator agents plus the user and maintainer role reviewers on current changes. Use when reviewing a diff, PR, or staged work before merge. Do NOT use to plan or implement; use map-plan or map-efficient.
map-fast
Minimal workflow for small, low-risk changes — no planning, no learning.