Agent skill

Better Auth Security Best Practices

by agutinbaigo28 in agutinbaigo28/financial-agent-api

Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…

No licenceAuto-check passedBackend & APIs

Install Better Auth Security Best Practices

skills CLI
$ npx skills add agutinbaigo28/financial-agent-api --skill better-auth-security-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agutinbaigo28/financial-agent-api better-auth-security-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agutinbaigo28/financial-agent-api.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/better-auth-security-best-practices .claude/skills/better-auth-security-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
better-auth-security-best-practices
GitHub stars
128
Token cost
~2.7k tokens
SKILL.md length
453 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
None found

At a glance

Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…

  • Works in 3 steps: options.secret in your config → BETTER_AUTH_SECRET environment variable → AUTH_SECRET environment variable
  • Users need to secure their auth setup
  • SKILL.md covers Secret Management, Rate Limiting, CSRF Protection and Trusted Origins, plus 9 more sections
  • Calls openssl; needs BETTER_AUTH_SECRET and AUTH_SECRET

What it does

Better Auth Security Best Practices is an agent skill from agutinbaigo28/financial-agent-api. Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth. Use when users need to secure their auth setup, prevent brute force attacks, or harden a Better Auth deployment.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Rate limiting, Web application vulnerabilities and OAuth and OpenID Connect. It works with Better Auth. The repository describes itself as: financial agent api with multi-agent framework for scalable AI systems focusing on financial intelligence, RAG pipelines, observability, and secure governance. ACP Openclaw….

When your agent uses it

  • Users need to secure their auth setup
  • Prevent brute force attacks
  • Harden a Better Auth deployment

Example prompts

  • “/better-auth-security-best-practices”

Requirements

  • A credential in BETTER_AUTH_SECRET
  • A credential in AUTH_SECRET

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. options.secret in your config
  2. BETTER_AUTH_SECRET environment variable
  3. AUTH_SECRET environment variable

What it can do on your machine

Read from SKILL.md and the folder at commit 9c163cf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • BETTER_AUTH_SECRET
    • AUTH_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Better Auth Security Best Practices loads about 2.7k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 453 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 453 words (~2,651 tokens).

“Better Auth looks for secrets in this order:”

— opening of SKILL.md by agutinbaigo28
name
better-auth-security-best-practices

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .github/skills/better-auth-security-best-practices of agutinbaigo28/financial-agent-api.

Open the folder on GitHubat commit 9c163cf

Compare with similar skills

Better Auth Security Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Better Auth Security Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Better Auth Security Best Practices this skillagutinbaigo28/financial-agent-api128—~2.7kAutomated safety check: PassNone
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
Implementing API Threat Protection With Apigeemukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Better Auth Security Best Practicesviclafouch/meme-studio110—~4.2kAutomated safety check: PassNone
Frappe Errors APIImpertio-Studio/Frappe_Claude_Skill_Package189—~4kAutomated safety check: PassMIT
Discord Php Bot Securitydiscord-php/DiscordPHP1.1k—~1.2kAutomated safety check: NotesMIT

Similar skills

  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Implementing API Threat Protection With Apigee

    mukul975/Anthropic-Cybersecurity-Skills

    Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • This skill provides guidance for implementing security features that span across Better Auth, including rate limiting, CSRF protection, session security, trusted origins, secret management, OAuth…

    110 GitHub stars~4.2k tokensUpdated 6 mo ago
    Backend & APIsAuto-check passed
  • Frappe Errors API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.

    189 GitHub stars~4k tokensUpdated 24 days ago
    Backend & APIsAuto-check passed
  • Discord Php Bot Security

    discord-php/DiscordPHP

    Audit checklist for DiscordPHP bots and API libraries — stop the bot token leaking to third-party APIs or logs, keep secrets out of customids and exception messages, use constant-time comparison and…

    1.1k GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Rails Security Multitenancy

    marckohlbrugge/37signals-skills

    Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates.

    724 GitHub stars~1.7k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed

More from agutinbaigo28/financial-agent-api

  • Gemini

    agutinbaigo28/financial-agent-api

    Execute Gemini CLI for AI-powered code analysis and generation.

    128 GitHub starsUsed in 2 repos~790 tokens
    Auto-check passed
  • Browser

    agutinbaigo28/financial-agent-api

    This skill should be used for browser automation tasks using Chrome DevTools Protocol (CDP).

    128 GitHub starsUsed in 1 repo~480 tokens
    Auto-check passed
  • Test Cases

    agutinbaigo28/financial-agent-api

    This skill should be used when generating comprehensive test cases from PRD documents or user requirements.

    128 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed

Works with

Categories

Questions about Better Auth Security Best Practices

What does Better Auth Security Best Practices do?

Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…. Better Auth Security Best Practices is an agent skill from agutinbaigo28/financial-agent-api. Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for Better Auth.

When should I use Better Auth Security Best Practices?

Better Auth Security Best Practices fits situations like: users need to secure their auth setup; prevent brute force attacks; harden a Better Auth deployment.

How do I install Better Auth Security Best Practices in Claude Code?

Run `npx skills add agutinbaigo28/financial-agent-api --skill better-auth-security-best-practices -a claude-code`. Or copy the skill folder (.github/skills/better-auth-security-best-practices in agutinbaigo28/financial-agent-api) into .claude/skills/better-auth-security-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Better Auth Security Best Practices in Codex?

Run `npx skills add agutinbaigo28/financial-agent-api --skill better-auth-security-best-practices -a codex`. Or copy the skill folder (.github/skills/better-auth-security-best-practices in agutinbaigo28/financial-agent-api) into .agents/skills/better-auth-security-best-practices in your project. Codex loads it when a task matches its description.

Can I use Better Auth Security Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agutinbaigo28/financial-agent-api --skill better-auth-security-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/better-auth-security-best-practices, .gemini/skills/better-auth-security-best-practices, .github/skills/better-auth-security-best-practices and .opencode/skills/better-auth-security-best-practices in your project.

What does Better Auth Security Best Practices need to run?

Going by SKILL.md and its folder, Better Auth Security Best Practices needs the command-line tools its instructions call (openssl) and credentials named BETTER_AUTH_SECRET and AUTH_SECRET. Our summary lists: A credential in BETTER_AUTH_SECRET; A credential in AUTH_SECRET.

Does Better Auth Security Best Practices access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Better Auth Security Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Better Auth Security Best Practices use?

No licence was found for Better Auth Security Best Practices or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Better Auth Security Best Practices use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Better Auth Security Best Practices?

Skills that share tags, products or a category with Better Auth Security Best Practices: Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), Implementing API Threat Protection With Apigee (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Better Auth Security Best Practices (viclafouch/meme-studio, 110 stars) and Frappe Errors API (Impertio-Studio/Frappe_Claude_Skill_Package, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Better Auth Security Best Practices?

agutinbaigo28 (a GitHub user) maintains it in agutinbaigo28/financial-agent-api, which has 128 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 14, 2026.

Source: agutinbaigo28/financial-agent-api on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.