authorization skills

72 tagged authorization, measured the same way as everything else here.

Browse within: access-control 24authentication 23AI Safety 18ai-governance 18api-security 12convex 10jwt 9appsec 8owasp 8business-logic 7rate-limiting 6CrewAI 5audit 5audit-trail 5

xalgorix/xalgorix

Skill Claude CodeCodex

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The tester identifies admin and privileged endpoints, then attempts to access them with regular user credentials by manipulating…

942 2d ago A 108 tokens original Apache-2.0

emiliaprotocol/emilia-protocol

Skill Claude CodeCodex

Verify the authenticity of AI-agent authorization receipts and human-device signoffs. Use this whenever a user shares a "trust receipt", an "authorization receipt", a "signoff", or WebAuthn/passkey approval evidence and asks whether it is valid, genuine, or tampered with. Pairs with the public EMILIA Protocol MCP…

653 yesterday A 94 tokens original Apache-2.0

console

03

thunder-id/thunderid

Skill Claude CodeCodex

Navigate and interact with the ThunderID Console UI. Use when exploring the ThunderID admin console, testing UI changes, creating users/applications/roles, or debugging the frontend.

565 4d ago A 37 tokens original Apache-2.0

db

04

thunder-id/thunderid

Skill Claude CodeCodex

Database schema and query conventions for ThunderID. Use when changing schema scripts, defining SQL queries, updating store constants, or reviewing deployment-scoped persistence rules.

565 4d ago A 33 tokens original Apache-2.0

docs

05

thunder-id/thunderid

Skill Claude CodeCodex

Handles every ThunderID documentation task in one skill: scaffolding a new page, writing content into an existing page, checking structural standards, reviewing writing quality/tone/AI-vocabulary, verifying technical accuracy, reviewing API documentation (OpenAPI specs and SDK reference pages) for consistency and…

565 4d ago A 183 tokens original Apache-2.0

waynesutton/convexskills

Skill Claude CodeCodex

Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations.

405 6mo ago A 28 tokens original Apache-2.0

chaitin/OctoBus

Skill Claude CodeCodex

Use when creating, reviewing, or fixing OctoBus JavaScript service packages from API docs, request examples, existing implementations, or proto/service manifests. Helps generate npm-compatible service packages with service.json, package.json bin, proto contracts, SDK handlers, config/secret schemas, and tests.

193 4d ago A 63 tokens GPL-3.0

agentfront/frontmcp

Skill Claude CodeCodex

Use when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what. Covers the RBAC, ABAC, and ReBAC models and when to choose each; JWT claims mapping per identity provider (Auth0, Keycloak, Okta, Cognito, Frontegg); reusable named authority…

147 25d ago A 165 tokens original Apache-2.0

adversarial-review

09

Firma-AI/openfirma

Skill Claude CodeCodex

Selects an independent reviewer for OpenFirma design plans and implemented changes without duplicating review work. Use before implementation, before opening or modifying a PR, or when the user requests adversarial review.

114 3d ago A 44 tokens GPL-3.0

planning-changes

10

Firma-AI/openfirma

Skill Claude CodeCodex

Plans substantial OpenFirma changes through proportional repository research, program design, proof obligations, vertical slices, and independent review. Use before implementing behavior, architecture, stable contracts, migrations, trust boundaries, or invariant-owner changes.

114 3d ago A 47 tokens GPL-3.0

reviewing-plans

11

Firma-AI/openfirma

Skill Claude CodeCodex

Independently reviews an OpenFirma design plan before implementation by inspecting the repository, reconstructing high-risk traces, challenging proof obligations, and reporting preserved findings. Use for Full and Compact planning review.

114 3d ago A 44 tokens GPL-3.0

integrate-grantex

12

mishrasanjeev/grantex

Skill Claude CodeCodex

Add Grantex delegated authorization to an agent, CLI tool, API, MCP server, or framework integration. Use when implementing or reviewing agent identity, scoped grants, consent, JWT verification, tool manifests, service-boundary enforcement, audit logging, delegation, or revocation, and when choosing among the Grantex…

31 yesterday A 89 tokens

mishrasanjeev/grantex

Skill Claude CodeCodex

Enterprise implementation guardrails for Grantex Commerce V1 across grantex.dev and agenticorg.ai. Use when reviewing, planning, implementing, testing, or signing off Grantex Commerce, agentic commerce, merchant AI-native onboarding, MCP/UCP/ACP publishing, merchant catalog/inventory/pricing, Commerce Passports…

31 yesterday A 117 tokens

ship-verification

14

mishrasanjeev/grantex

Skill Claude CodeCodex

Post-merge verification pass for Grantex. After any PR merges to main or ships to prod, run this pass without being asked — verify README, Mintlify docs, landing page, SDK READMEs (TS, Python, Go), integration docs, and SEO surfaces are consistent with what just shipped. Use this skill whenever a PR merges, a release…

31 yesterday A 84 tokens

igor9silva/meseeks

Skill Claude CodeCodex

Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations.

20 1mo ago A 28 tokens AGPL-3.0

integration-tests

16

HexamindOrganisation/hexgate

Skill Claude CodeCodex

Run the opt-in integration test suites (pytest -m integration) for the SDK and/or the platform API — the ones that hit a live ClickHouse (and, for the SDK, a live platform-api server). Use when asked to run, verify, or debug integration tests, as opposed to the default unit test suite.

18 3d ago A 68 tokens original MIT

auth0-docs

17

pledgeandgrow/pledge-skills

Skill Claude CodeCodex

Auth0 — identity platform: auth flows, Universal Login, SSO, identity providers, MFA, RBAC, Actions, tokens.

10 1mo ago A 32 tokens original MIT

acartag7/mcp-sso

Skill Claude CodeCodex

Exact-head local PR review for mcp-sso that refuses PASS until a defective behavior is closed across every sibling cell, not just the named instance. Use when reviewing a pull request locally, after a Codex finding, before requesting another hosted review round, or when leftover claims, unswept adapters/stores…

8 yesterday A 84 tokens original MIT

sparda-mcp

19

zyx77550/sparda

Skill Claude CodeCodex

Drive a SPARDA compiled Behavior Runtime to its full potential. Use this whenever you are connected to a backend running the SPARDA Runtime (compiled into a Unified Behavior Graph - UBG) — recognizable by the tools spardagetcontext, spardainfo, spardaconfirm, or composite tools. It teaches the graph-context-first…

8 6d ago A 109 tokens

sparda-mcp

20

zyx77550/sparda

Skill Claude CodeCodex

Drive a SPARDA compiled Behavior Runtime to its full potential. Use this whenever you are connected to a backend running the SPARDA Runtime (compiled into a Unified Behavior Graph - UBG) — recognizable by the tools spardagetcontext, spardainfo, spardaconfirm, or composite tools. It teaches the graph-context-first…

8 6d ago A 109 tokens

k8s-rbac-quota

21

kudig-io/kudig-database

Skill Claude CodeCodex

A troubleshooting guide for Kubernetes access permissions and resource limits. Kubernetes is software for running and managing containers, while RBAC controls who can do what and ResourceQuota limits resource usage.

5 2d ago A 22 tokens

auth-review

22

MuhammedZohaib/patchman

Skill Claude CodeCodex

Perform a defensive review of authentication and authorization flows in an authorized codebase. Use for login, session, MFA, OAuth, password reset, cookie security, JWT validation, impersonation, privilege checks, and object-level access control.

3 4mo ago A 49 tokens original MIT

MuhammedZohaib/patchman

Skill Claude CodeCodex

Review an authorized application for business-logic vulnerabilities, workflow abuse, approval bypasses, replay conditions, quota circumvention, plan enforcement bugs, and state-transition errors. Use for billing, invites, approvals, refunds, admin actions, and multi-step workflows.

3 4mo ago A 56 tokens original MIT

security-audit

24

MuhammedZohaib/patchman

Skill Claude CodeCodex

Conduct authorized defensive security audits of codebases and web applications. Use for broad appsec review across OWASP, authz, business logic, SSRF, XSS, CSRF, injection, file upload, secrets, logging, and tenant isolation. Produces structured findings with severity, confidence, evidence, and safe remediation…

3 4mo ago A 70 tokens original MIT