Agent skill

Sts

by ArtisanCloud in ArtisanCloud/PowerX

PowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计). An agent skill from ArtisanCloud/PowerX.

Apache-2.0Auto-check passedBackend & APIs

Install Sts

skills CLI
$ npx skills add ArtisanCloud/PowerX --skill sts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArtisanCloud/PowerX sts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/sts .claude/skills/sts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sts
GitHub stars
379
Token cost
~774 tokens
SKILL.md length
17 words
Files
2
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

PowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计). An agent skill from ArtisanCloud/PowerX.

  • Works in 3 steps: 打开 本文件内嵌规则。 → 按规则执行实现/校对。 → 完成后按核对清单验收。
  • Backend & APIs work in your project
  • SKILL.md covers 步骤, 核对点 and 规则(内嵌)
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Sts is an agent skill from ArtisanCloud/PowerX. PowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计)。

Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `dev_sts_guides.md`).

It sits in Backend & APIs. The repository describes itself as: PowerX是一款以企业微信为基础的微信私域运营开放平台,帮助企业实现引流获客、精细运营。 The licence is Apache-2.0.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/sts”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 打开 本文件内嵌规则。
  2. 按规则执行实现/校对。
  3. 完成后按核对清单验收。

What it can do on your machine

Read from SKILL.md and the folder at commit 3f7619d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sts loads about 774 tokens when it runs. Until then it costs about 12 tokens; SKILL.md has 17 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~12
When it runs · the whole SKILL.md, loaded when a task matches
~774

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArtisanCloud/PowerX at commit 3f7619d, republished under its Apache-2.0 licence (© ArtisanCloud). 17 words, ~774 tokens.

Download SKILL.mdSave it as .claude/skills/sts/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
sts
description
PowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计)。

PowerX STS

步骤

  1. 打开 本文件内嵌规则。
  2. 按规则执行实现/校对。
  3. 完成后按核对清单验收。

核对点

  • 与 PowerX 当前代码结构、路径与命名一致。
  • 仅在传输层/契约层做职责内改动,不跨层越界。

规则(内嵌)

dev_sts_guides.md
markdown
# PowerX STS & 插件对接规范

> 目标:定义插件以**租户维度**访问 PowerX 的鉴权方式(STS 令牌交换)、凭证生成/轮换、令牌使用与安全要求。  
> 传输层可为 gRPC/HTTP,拦截器/中间件与 Crypto KeyRing 统一。

## 1. 范围与术语
- STS(Security Token Service):`Exchange(client_id, client_secret, aud, scope, ttl)` → 短期 JWT。
- 客户端:插件进程(per-tenant)。
- KeyRing:HS256 密钥集合(带 `kid`),STS 与 gRPC 拦截器共用。

## 2. 架构与目录
- STS 服务:`internal/transport/grpc/auth/sts_handler.go`(`Exchange`)
- KeyRing:`internal/transport/grpc/auth/key_ring.go`
- gRPC 拦截器:`internal/transport/grpc/auth/middleware/auth_interceptor.go`
- Proto:`api/grpc/contracts/powerx/auth/sts/v1/sts.proto`(Buf 生成到 `api/grpc/gen/go/...`)
- 插件-宿主关系与访问形态:详见《powerx_agent_plugin.md》。

## 3. 凭证模型(租户维度)
- 启用插件生成:`plugin_instance_configs(tenant_id, plugin_id, key="auth.credentials")`
    - 字段:`client_id`(`<pluginID>.<tenantID>`)、`client_secret_hash`(仅存 hash)。
    - 明文 `client_secret` 仅创建/轮换时展示一次,插件自行安全保存。
- 轮换:旧 secret 立即失效,插件更新后继续 Exchange。

## 4. 令牌交换(STS Exchange)
- 请求:`client_id`、`client_secret`、`audience=powerx:api`、`scope=access`、`ttl=300(秒)`。
- 返回:`access_token`(HS256,header.kid 写入)、`expires_in`、`aud`、`scope`、`iss`、`sub=client:<client_id>`。
- 验证:STS 验签与 gRPC 拦截器使用**同一 KeyRing**(kid 选择密钥)。

## 5. 令牌使用(插件 → PowerX)
- gRPC:在 metadata 设置 `authorization: Bearer <token>`;拦截器校验通过后带入 `tenant_id/actor` 上下文。
- HTTP(如需):中间件与 STS 对齐验签策略(issuer/secret/kid)。
- 客户端缓存:仅内存缓存;若剩余寿命 <60s 先刷新;401/403 触发强制刷新再重试一次。

### 5.1 HTTP direct route 边界
- 插件调用底座能力的推荐主路径是 `/api/v1/tenant/invocations`。
- 插件 STS token 直接访问 Core HTTP 时,允许集合由 capability governance 管理:
  `static plugin runtime contracts + formal platform_capabilities REST endpoints - STS blocklist`。
- 普通开放 REST 能力必须先进入正式 `backend/config/platform_capabilities/*.yaml` 的 REST protocol;不得通过手工改 STS validator 代替能力登记。
- `/api/v1/admin/*` 是后台用户态 API 命名空间。插件 Admin 页面、PowerX Admin 页面、以及任何携带用户 JWT 的后台请求,仍然由用户鉴权、租户成员、RBAC 和业务权限判定,不受服务态 STS direct blocklist 影响。
- 普通 STS token 是插件服务态身份,不携带 `uid/mid`,不能代表登录用户调用 `/api/v1/admin/*` 绕过用户 RBAC。插件后端如果要代表当前用户调用底座后台 API,必须引入 delegated/on-behalf-of 机制。
- 对服务态 STS direct call,`/admin/*`、`/internal/*`、`/public/*`、`/auth/*`、`/setup/*`、debug、migration、root、drain、bootstrap、mock、health、根级动态路径默认不允许。确认为插件服务运行时合同的少量入口必须进入 static allow 并补测试。

## 6. 安全与审计
- TTL 建议 2–10 分钟;`client_secret` 安全存储;校验 `aud/scope` 最小权限;
- 审计:记录 Exchange/业务调用的 `tenant/plugin/subject/trace_id`;异常 401/403 计数告警。
- 禁止在 `tenant_id=0` 上下文下生成租户凭证。

## 7. 与 Agent/插件关系(何时走 MCP)
- 插件直调 PowerX(gRPC/HTTP)或对外自暴露服务;
- 需要纳入统一“工具目录/市场”时,将插件能力包装为 MCP 工具(详见《powerx_agent_plugin.md》)。

## 8. 验收要点(Checklist)
- [ ] 存在 STS `Exchange` 实现与注册,Proto 契约落在 `powerx/auth/sts/v1`;
- [ ] KeyRing(HS256+`kid`)与拦截器复用,STS 签发的 token 可直接通过业务 RPC 鉴权;
- [ ] 插件凭证落在 `plugin_instance_configs`(仅存 hash),支持“轮换”;
- [ ] 客户端仅内存缓存 token,支持预刷新与 401/403 强制刷新;
- [ ] 审计与安全策略(TTL/aud/scope/告警)到位;
- [ ] 与 HTTP/gRPC 的错误语义一致(Unauthenticated/PermissionDenied)。

© ArtisanCloud, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/sts of ArtisanCloud/PowerX.

  • SKILL.md
  • dev_sts_guides.md

Open the folder on GitHubat commit 3f7619d

Compare with similar skills

Sts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sts this skillArtisanCloud/PowerX379—~774Automated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api43k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    43k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from ArtisanCloud/PowerX

All 21 skills in this repo
  • API Naming

    ArtisanCloud/PowerX

    PowerX API 命名与访问规范(/api/v1、/admin、/internal 边界). An agent skill from ArtisanCloud/PowerX.

    379 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Capability Governance

    ArtisanCloud/PowerX

    PowerX 底座 Capability 治理与发布准入规则。用于审计 REST/OpenAPI/gRPC/Gin 生成的能力候选、正式 platformcapabilities 目录、Capability Registry 登记、agentusable/permissioncode/risklevel 元数据、ignore…

    379 GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Crud Di

    ArtisanCloud/PowerX

    PowerX CRUD 依赖注入规则(Deps 单入口、构造注入、跨传输复用). An agent skill from ArtisanCloud/PowerX.

    379 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Crud Grpc

    ArtisanCloud/PowerX

    PowerX CRUD gRPC 开发规范(proto、server、拦截器、错误映射). An agent skill from ArtisanCloud/PowerX.

    379 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Crud Handler HTTP

    ArtisanCloud/PowerX

    PowerX HTTP Handler 规则(绑定校验、统一回包、无 DB IO). An agent skill from ArtisanCloud/PowerX.

    379 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Crud HTTP

    ArtisanCloud/PowerX

    PowerX CRUD HTTP 开发规范(管理端路由、绑定、错误桥接、多租户). An agent skill from ArtisanCloud/PowerX.

    379 GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Categories

Questions about Sts

What does Sts do?

PowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计). An agent skill from ArtisanCloud/PowerX. Sts is an agent skill from ArtisanCloud/PowerX.

When should I use Sts?

Sts fits situations like: backend & APIs work in your project.

How do I install Sts in Claude Code?

Run `npx skills add ArtisanCloud/PowerX --skill sts -a claude-code`. Or copy the skill folder (.codex/skills/sts in ArtisanCloud/PowerX) into .claude/skills/sts in your project. Claude Code loads it when a task matches its description.

How do I install Sts in Codex?

Run `npx skills add ArtisanCloud/PowerX --skill sts -a codex`. Or copy the skill folder (.codex/skills/sts in ArtisanCloud/PowerX) into .agents/skills/sts in your project. Codex loads it when a task matches its description.

Can I use Sts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArtisanCloud/PowerX --skill sts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sts, .gemini/skills/sts, .github/skills/sts and .opencode/skills/sts in your project.

What does Sts need to run?

SKILL.md names no scripts, command-line tools or credentials: Sts is instructions for the agent only.

Does Sts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sts use?

Sts is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sts use?

About 774 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sts?

Skills that share tags, products or a category with Sts: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 43k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sts?

ArtisanCloud (a GitHub organization) maintains it in ArtisanCloud/PowerX, which has 379 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.

Source: ArtisanCloud/PowerX on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.