Agent skill

Securing Authentication

by ancoleman in ancoleman/ai-design-components

Authentication, authorization, and API security implementation.

MITAuto-check passedBackend & APIs

Install Securing Authentication

skills CLI
$ npx skills add ancoleman/ai-design-components --skill securing-authentication -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ancoleman/ai-design-components securing-authentication --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/securing-authentication .claude/skills/securing-authentication && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
securing-authentication
GitHub stars
526
Token cost
~3.4k tokens
SKILL.md length
869 words
Files
13 (incl. scripts, references)
Skills in repo
75
Repo updated
First seen
Licence
MIT

At a glance

Authentication, authorization, and API security implementation.

  • Works in 4 steps: OAuth 2.1 Integration → JWT Implementation → Passkeys Setup → …
  • Building user systems
  • SKILL.md covers When to Use This Skill, OAuth 2.1 Mandatory…, JWT Best Practices and Password Hashing with Argon2id, plus 8 more sections
  • Runs Python scripts from its folder; calls python

What it does

Securing Authentication is an agent skill from ancoleman/ai-design-components. Authentication, authorization, and API security implementation. Use when building user systems, protecting APIs, or implementing access control. Covers OAuth 2.1/OIDC, JWT patterns, sessions, Passkeys/WebAuthn, RBAC/ABAC/ReBAC, policy engines (OPA, Casbin, SpiceDB), managed auth (Clerk, Auth0), self-hosted (Keycloak, Ory), and API security best practices.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 16 other files, including scripts and reference files (for example `examples/authjs-nextjs/README.md`, `outputs.yaml` and `references/api-security.md`).

It sits in Backend & APIs, covering Authorization and RBAC, Authentication and OAuth and OpenID Connect. It works with Auth0. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.

When your agent uses it

  • Building user systems
  • Protecting APIs
  • Implementing access control

Example prompts

  • “/securing-authentication”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. OAuth 2.1 Integration
  2. JWT Implementation
  3. Passkeys Setup
  4. Authorization Engine Setup

What it can do on your machine

Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Securing Authentication loads about 3.4k tokens when it runs, and up to ~39k if it reads all its reference files. Until then it costs about 95 tokens; SKILL.md has 869 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~95
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~39k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 869 words, ~3,426 tokens.

Download SKILL.mdSave it as .claude/skills/securing-authentication/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
securing-authentication
description
Authentication, authorization, and API security implementation. Use when building user systems, protecting APIs, or implementing access control. Covers OAuth 2.1/OIDC, JWT patterns, sessions, Passkeys/WebAuthn, RBAC/ABAC/ReBAC, policy engines (OPA, Casbin, SpiceDB), managed auth (Clerk, Auth0), self-hosted (Keycloak, Ory), and API security best practices.

Authentication & Security

Implement modern authentication, authorization, and API security across Python, Rust, Go, and TypeScript.

When to Use This Skill

Use this skill when:

  • Building user authentication systems (login, signup, SSO)
  • Implementing authorization (roles, permissions, access control)
  • Securing APIs (JWT validation, rate limiting)
  • Adding passwordless auth (Passkeys/WebAuthn)
  • Migrating from password-based to modern auth
  • Integrating enterprise SSO (SAML, OIDC)
  • Implementing fine-grained permissions (RBAC, ABAC, ReBAC)

OAuth 2.1 Mandatory Requirements (2025 Standard)

┌─────────────────────────────────────────────────────────────┐
│           OAuth 2.1 MANDATORY REQUIREMENTS                  │
│                   (RFC 9798 - 2025)                         │
├─────────────────────────────────────────────────────────────┤
│                                                             │
│  ✅ REQUIRED (Breaking Changes from OAuth 2.0)             │
│  ├─ PKCE (Proof Key for Code Exchange) MANDATORY           │
│  │   └─ S256 method (SHA-256), minimum entropy 43 chars   │
│  ├─ Exact redirect URI matching                            │
│  │   └─ No wildcard matching, no substring matching       │
│  ├─ Authorization code flow ONLY for public clients       │
│  │   └─ All other flows require confidential client       │
│  └─ TLS 1.2+ required for all endpoints                   │
│                                                             │
│  ❌ REMOVED (No Longer Supported)                          │
│  ├─ Implicit grant (security vulnerabilities)             │
│  ├─ Resource Owner Password Credentials grant              │
│  │   └─ Use OAuth 2.0 Device Flow (RFC 8628) instead      │
│  └─ Bearer token in query parameters                       │
│      └─ Must use Authorization header or POST body        │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Critical: PKCE is now mandatory for ALL OAuth flows, not just public clients.

JWT Best Practices

Signing Algorithms (Priority Order)
  1. EdDSA with Ed25519 (Recommended)

    • Fastest performance
    • Smallest signature size
    • Modern cryptography
  2. ES256 (ECDSA with P-256)

    • Good performance
    • Industry standard
    • Wide compatibility
  3. RS256 (RSA)

    • Legacy compatibility
    • Larger signatures
    • Slower performance

NEVER allow alg: none or algorithm switching attacks.

Token Lifetimes (Concrete Values)
  • Access token: 5-15 minutes
  • Refresh token: 1-7 days with rotation
  • ID token: Same as access token (5-15 minutes)

Refresh token rotation: Each refresh generates new access AND refresh tokens, invalidating the old refresh token.

Token Storage
  • Access token: Memory only (never localStorage)
  • Refresh token: HTTP-only cookie + SameSite=Strict
  • CSRF token: Separate non-HTTP-only cookie
  • Never log tokens: Redact in application logs
JWT Claims (Required)
json
{
  "iss": "https://auth.example.com",
  "sub": "user-id-123",
  "aud": "api.example.com",
  "exp": 1234567890,
  "iat": 1234567890,
  "jti": "unique-token-id",
  "scope": "read:profile write:data"
}

Password Hashing with Argon2id

OWASP 2025 Parameters
Algorithm: Argon2id
Memory cost (m): 64 MB (65536 KiB)
Time cost (t): 3 iterations
Parallelism (p): 4 threads
Salt length: 16 bytes (128 bits)
Target hash time: 150-250ms
Implementation

For concrete implementations, see references/password-hashing.md.

Key Points:

  • Argon2id is hybrid: data-independent timing + memory-hard
  • Tune memory cost to achieve 150-250ms on YOUR hardware
  • Use timing-safe comparison for verification
  • Migrate from bcrypt gradually (verify with old, rehash with new)

Passkeys / WebAuthn

Passkeys provide phishing-resistant, passwordless authentication using FIDO2/WebAuthn.

When to Use Passkeys
  • User-facing applications prioritizing security
  • Reducing password-related support burden
  • Mobile-first applications (biometric auth)
  • Applications requiring MFA without SMS
Cross-Device Passkey Sync
  • iCloud Keychain: Apple ecosystem (iOS 16+, macOS 13+)
  • Google Password Manager: Android, Chrome
  • 1Password, Bitwarden: Third-party password managers

For implementation guide, see references/passkeys-webauthn.md.

Authorization Models

┌─────────────────────────────────────────────────────────────┐
│                Authorization Model Selection                │
├─────────────────────────────────────────────────────────────┤
│                                                             │
│  Simple Roles (<20 roles)                                  │
│  └─ RBAC with Casbin (embedded, any language)              │
│      Example: Admin, User, Guest                           │
│                                                             │
│  Complex Attribute Rules                                    │
│  └─ ABAC with OPA or Cerbos                                │
│      Example: "Allow if user.clearance >= doc.level        │
│                AND user.dept == doc.dept"                   │
│                                                             │
│  Relationship-Based (Multi-Tenant, Collaborative)          │
│  └─ ReBAC with SpiceDB (Zanzibar model)                    │
│      Example: "Can edit if member of doc's workspace       │
│                AND workspace.plan includes feature"         │
│      Use cases: Notion-like, GitHub-like permissions       │
│                                                             │
│  Kubernetes / Infrastructure Policies                       │
│  └─ OPA (Gatekeeper for admission control)                 │
│      Example: Enforce pod security policies                │
│                                                             │
└─────────────────────────────────────────────────────────────┘

For detailed comparison, see references/authorization-patterns.md.

Library Selection by Language

TypeScript
Use CaseLibraryContext7 IDTrustNotes
Auth FrameworkAuth.js v5/websites/authjs_dev87.4Multi-framework (Next, Svelte, Solid)
JWTjose 5.x--EdDSA, ES256, RS256 support
Passkeys@simplewebauthn/server 11.x--FIDO2 server
ValidationZod 3.x/colinhacks/zod90.4Schema validation
Policy EngineCasbin.js 1.x--RBAC/ABAC embedded
Python
Use CaseLibraryNotes
Auth FrameworkAuthlib 1.3+OAuth/OIDC client + server
JWTjoserfc 1.xModern, maintained
Passkeyspy_webauthn 2.xWebAuthn server
Password Hashingargon2-cffi 24.xOWASP parameters
ValidationPydantic 2.xFastAPI integration
Policy EnginePyCasbin 1.xRBAC/ABAC embedded
Rust
Use CaseLibraryNotes
JWTjsonwebtoken 10.xEdDSA, ES256, RS256
OAuth Clientoauth2 5.xOAuth 2.1 flows
Passkeyswebauthn-rs 0.5.xWebAuthn + attestation
Password Hashingargon2 0.5.xNative Argon2id
Policy EngineCasbin-RS 2.xRBAC/ABAC embedded
Go
Use CaseLibraryNotes
JWTgolang-jwt v5Community-maintained
OAuth Clientgo-oidc v3OIDC client only
Passkeysgo-webauthn 0.11.xDuo-maintained
Password Hashinggolang.org/x/crypto/argon2Standard library
Policy EngineCasbin v2Original implementation

Managed Auth Services

ServiceBest ForKey Features
ClerkRapid development, startupsPrebuilt UI, Next.js SDK
Auth0Enterprise, established25+ social providers, SSO
WorkOS AuthKitB2B SaaS, enterprise SSOSAML/SCIM, admin portal
Supabase AuthPostgres usersBuilt on Postgres, RLS

For detailed comparison, see references/managed-auth-comparison.md.

Self-Hosted Solutions

SolutionLanguageUse Case
KeycloakJavaEnterprise, on-prem
OryGoCloud-native, microservices
AuthentikPythonModern, developer-friendly

For setup guides, see references/self-hosted-auth.md.

Show full SKILL.md (345 more words)Show less

API Security Best Practices

Rate Limiting
typescript
// Tiered rate limiting (per IP + per user)
const rateLimits = {
  anonymous: '10 requests/minute',
  authenticated: '100 requests/minute',
  premium: '1000 requests/minute',
}

Use sliding window algorithm (not fixed window) with Redis.

CORS Configuration
typescript
// Restrictive CORS (production)
const corsOptions = {
  origin: ['https://app.example.com'],
  credentials: true,
  maxAge: 86400, // 24 hours
  allowedHeaders: ['Content-Type', 'Authorization'],
  methods: ['GET', 'POST', 'PUT', 'DELETE', 'PATCH'],
}

// NEVER use origin: '*' with credentials: true
Security Headers
typescript
const securityHeaders = {
  'Strict-Transport-Security': 'max-age=63072000; includeSubDomains; preload',
  'X-Frame-Options': 'DENY',
  'X-Content-Type-Options': 'nosniff',
  'Referrer-Policy': 'strict-origin-when-cross-origin',
  'Permissions-Policy': 'geolocation=(), microphone=(), camera=()',
  'Content-Security-Policy': "default-src 'self'; script-src 'self'",
}

For complete API security guide, see references/api-security.md.

Frontend Integration Patterns

Protected Routes (Next.js)
typescript
// middleware.ts
import { withAuth } from 'next-auth/middleware'

export default withAuth({
  callbacks: {
    authorized: ({ token, req }) => {
      if (req.nextUrl.pathname.startsWith('/dashboard')) {
        return !!token
      }
      if (req.nextUrl.pathname.startsWith('/admin')) {
        return token?.role === 'admin'
      }
      return true
    },
  },
})

export const config = {
  matcher: ['/dashboard/:path*', '/admin/:path*'],
}
Role-Based UI Rendering
typescript
import { useSession } from 'next-auth/react'

export function AdminPanel() {
  const { data: session } = useSession()

  if (session?.user?.role !== 'admin') {
    return null
  }

  return <div>Admin Controls</div>
}

Common Workflows

1. OAuth 2.1 Integration
  1. Generate PKCE challenge
  2. Redirect to authorization endpoint
  3. Handle callback with authorization code
  4. Exchange code for tokens (with code_verifier)
  5. Store tokens securely
  6. Implement refresh token rotation

See references/oauth21-guide.md for complete implementation.

2. JWT Implementation
  1. Generate signing keys using scripts/generate_jwt_keys.py
  2. Configure token lifetimes (5-15 min access, 1-7 day refresh)
  3. Implement token validation middleware
  4. Set up refresh token rotation
  5. Configure token storage (memory for access, HTTP-only cookie for refresh)

See references/jwt-best-practices.md for detailed patterns.

3. Passkeys Setup
  1. Register credential during signup/settings
  2. Generate challenge for registration
  3. Verify attestation
  4. Store credential ID and public key
  5. Implement authentication flow with assertion

See examples/passkeys-demo/ for runnable implementation.

4. Authorization Engine Setup
  1. Choose engine (Casbin for simple RBAC, SpiceDB for ReBAC)
  2. Define schema/policies
  3. Implement check functions
  4. Integrate with route handlers
  5. Add audit logging

See references/authorization-patterns.md for detailed comparison.

Integration with Other Skills

Forms Skill
  • Login/register forms with validation
  • Error states for auth failures
  • Password strength indicators
  • Email validation
API Patterns Skill
  • JWT middleware integration
  • Error response formats (401, 403)
  • OpenAPI security schemas
  • CORS configuration
Dashboards Skill
  • Role-based widget visibility
  • User profile display
  • Permission-based data filtering
  • Audit trail visualization
Observability Skill
  • Auth event logging (login, logout, permission denied)
  • Failed login tracking
  • Token refresh monitoring
  • Security incident alerting

Scripts

Generate JWT Keys
bash
python scripts/generate_jwt_keys.py --algorithm EdDSA

Generates EdDSA or ES256 key pairs for JWT signing.

Validate OAuth 2.1 Configuration
bash
python scripts/validate_oauth_config.py --config oauth.json

Validates OAuth 2.1 compliance (PKCE enabled, exact redirect URIs, etc.).

Examples

Auth.js + Next.js

Complete implementation with OAuth providers, credentials, and session management.

Location: examples/authjs-nextjs/

Keycloak + FastAPI

Self-hosted Keycloak with FastAPI integration via OIDC.

Location: examples/keycloak-fastapi/

Passkeys Demo

Runnable passkeys implementation with @simplewebauthn.

Location: examples/passkeys-demo/

Reference Documentation

  • references/oauth21-guide.md - OAuth 2.1 implementation guide
  • references/jwt-best-practices.md - JWT generation, validation, storage
  • references/passkeys-webauthn.md - Passkeys/WebAuthn implementation
  • references/authorization-patterns.md - RBAC, ABAC, ReBAC comparison
  • references/password-hashing.md - Argon2id parameters, migration

© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts, references) in skills/securing-authentication of ancoleman/ai-design-components.

  • SKILL.md
  • examples/authjs-nextjs/README.md
  • outputs.yaml
  • references/api-security.md
  • references/authorization-patterns.md
  • references/jwt-best-practices.md
  • references/managed-auth-comparison.md
  • references/oauth21-guide.md
  • references/passkeys-webauthn.md
  • references/password-hashing.md
  • references/self-hosted-auth.md
  • scripts/generate_jwt_keys.py
  • scripts/validate_oauth_config.py

Open the folder on GitHubat commit 76551b7

Compare with similar skills

Securing Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Securing Authentication compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Securing Authentication this skillancoleman/ai-design-components526—~3.4kAutomated safety check: PassMIT
Iam Auditbriiirussell/cybersecurity-skills412—~3.1kAutomated safety check: NotesMIT
Cometchat Securitycometchat/cometchat-skills1291 repos~1.9kAutomated safety check: PassMIT
Convex AuthIgorWarzocha/Opencode-Workflows122—~744Automated safety check: PassNone
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS6179 repos~4.4kAutomated safety check: PassNone

Similar skills

  • Iam Audit

    briiirussell/cybersecurity-skills

    Audit, design, and migrate Identity and Access Management — cloud provider IAM (AWS, GCP, Azure), identity providers (Okta, Entra ID / Azure AD, Auth0, Google Workspace), application authorization…

    412 GitHub stars~3.1k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Cometchat Security

    cometchat/cometchat-skills

    Enterprise auth & access control for CometChat — SSO/OIDC/SAML via your own IdP, server-minted auth tokens, token revocation & session control, and role-based access (RBAC app-wide roles + group…

    129 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Convex Auth

    IgorWarzocha/Opencode-Workflows

    Implement Convex authentication and authorization patterns with OIDC providers or Convex Auth.

    122 GitHub stars~744 tokensUpdated 8 mo ago
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 9 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    676 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from ancoleman/ai-design-components

All 75 skills in this repo
  • Building AI Chat

    ancoleman/ai-design-components

    Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.

    526 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check passed
  • Building Forms

    ancoleman/ai-design-components

    Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.

    526 GitHub stars~3.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Building Tables

    ancoleman/ai-design-components

    Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.

    526 GitHub stars~1.8k tokensUpdated 10 mo ago
    Auto-check passed
  • Creating Dashboards

    ancoleman/ai-design-components

    Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.

    526 GitHub stars~3.5k tokensUpdated 10 mo ago
    Auto-check passed
  • Designing Layouts

    ancoleman/ai-design-components

    Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.

    526 GitHub stars~1.7k tokensUpdated 10 mo ago
    Auto-check passed
  • Displaying Timelines

    ancoleman/ai-design-components

    Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.

    526 GitHub stars~2.7k tokensUpdated 10 mo ago
    Auto-check passed

Works with

Categories

Questions about Securing Authentication

What does Securing Authentication do?

Authentication, authorization, and API security implementation. Securing Authentication is an agent skill from ancoleman/ai-design-components. Authentication, authorization, and API security implementation.

When should I use Securing Authentication?

Securing Authentication fits situations like: building user systems; protecting APIs; implementing access control.

How do I install Securing Authentication in Claude Code?

Run `npx skills add ancoleman/ai-design-components --skill securing-authentication -a claude-code`. Or copy the skill folder (skills/securing-authentication in ancoleman/ai-design-components) into .claude/skills/securing-authentication in your project. Claude Code loads it when a task matches its description.

How do I install Securing Authentication in Codex?

Run `npx skills add ancoleman/ai-design-components --skill securing-authentication -a codex`. Or copy the skill folder (skills/securing-authentication in ancoleman/ai-design-components) into .agents/skills/securing-authentication in your project. Codex loads it when a task matches its description.

Can I use Securing Authentication in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill securing-authentication -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securing-authentication, .gemini/skills/securing-authentication, .github/skills/securing-authentication and .opencode/skills/securing-authentication in your project.

What does Securing Authentication need to run?

Going by SKILL.md and its folder, Securing Authentication needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Securing Authentication access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Securing Authentication safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Securing Authentication use?

Securing Authentication is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Securing Authentication use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 36k tokens, read only when the agent opens those files.

What are the alternatives to Securing Authentication?

Skills that share tags, products or a category with Securing Authentication: Iam Audit (briiirussell/cybersecurity-skills, 412 stars), Cometchat Security (cometchat/cometchat-skills, 129 stars), Convex Auth (IgorWarzocha/Opencode-Workflows, 122 stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Securing Authentication?

ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.

Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.