Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
PowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计). An agent skill from ArtisanCloud/PowerX.
$ npx skills add ArtisanCloud/PowerX --skill sts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ArtisanCloud/PowerX sts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/sts .claude/skills/sts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sts" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/sts into .claude/skills/sts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/stsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ArtisanCloud/PowerX --skill sts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ArtisanCloud/PowerX sts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/sts .agents/skills/sts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sts" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/sts into .agents/skills/sts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArtisanCloud/PowerX --skill sts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ArtisanCloud/PowerX sts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/sts .cursor/skills/sts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sts" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/sts into .cursor/skills/sts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ArtisanCloud/PowerX.git --path .codex/skills/sts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ArtisanCloud/PowerX --skill sts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ArtisanCloud/PowerX sts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/sts .gemini/skills/sts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sts" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/sts into .gemini/skills/sts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ArtisanCloud/PowerX stsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ArtisanCloud/PowerX --skill sts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/sts .github/skills/sts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sts" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/sts into .github/skills/sts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArtisanCloud/PowerX --skill sts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ArtisanCloud/PowerX sts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArtisanCloud/PowerX.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/sts .opencode/skills/sts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sts" agent skill from https://github.com/ArtisanCloud/PowerX/tree/release%2Fv1.0.0/.codex/skills/sts into .opencode/skills/sts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
stsPowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计). An agent skill from ArtisanCloud/PowerX.
Sts is an agent skill from ArtisanCloud/PowerX. PowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计)。
Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `dev_sts_guides.md`).
It sits in Backend & APIs. The repository describes itself as: PowerX是一款以企业微信为基础的微信私域运营开放平台,帮助企业实现引流获客、精细运营。 The licence is Apache-2.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3f7619d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sts loads about 774 tokens when it runs. Until then it costs about 12 tokens; SKILL.md has 17 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ArtisanCloud/PowerX at commit 3f7619d, republished under its Apache-2.0 licence (© ArtisanCloud). 17 words, ~774 tokens.
.claude/skills/sts/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.本文件内嵌规则。# PowerX STS & 插件对接规范
> 目标:定义插件以**租户维度**访问 PowerX 的鉴权方式(STS 令牌交换)、凭证生成/轮换、令牌使用与安全要求。
> 传输层可为 gRPC/HTTP,拦截器/中间件与 Crypto KeyRing 统一。
## 1. 范围与术语
- STS(Security Token Service):`Exchange(client_id, client_secret, aud, scope, ttl)` → 短期 JWT。
- 客户端:插件进程(per-tenant)。
- KeyRing:HS256 密钥集合(带 `kid`),STS 与 gRPC 拦截器共用。
## 2. 架构与目录
- STS 服务:`internal/transport/grpc/auth/sts_handler.go`(`Exchange`)
- KeyRing:`internal/transport/grpc/auth/key_ring.go`
- gRPC 拦截器:`internal/transport/grpc/auth/middleware/auth_interceptor.go`
- Proto:`api/grpc/contracts/powerx/auth/sts/v1/sts.proto`(Buf 生成到 `api/grpc/gen/go/...`)
- 插件-宿主关系与访问形态:详见《powerx_agent_plugin.md》。
## 3. 凭证模型(租户维度)
- 启用插件生成:`plugin_instance_configs(tenant_id, plugin_id, key="auth.credentials")`
- 字段:`client_id`(`<pluginID>.<tenantID>`)、`client_secret_hash`(仅存 hash)。
- 明文 `client_secret` 仅创建/轮换时展示一次,插件自行安全保存。
- 轮换:旧 secret 立即失效,插件更新后继续 Exchange。
## 4. 令牌交换(STS Exchange)
- 请求:`client_id`、`client_secret`、`audience=powerx:api`、`scope=access`、`ttl=300(秒)`。
- 返回:`access_token`(HS256,header.kid 写入)、`expires_in`、`aud`、`scope`、`iss`、`sub=client:<client_id>`。
- 验证:STS 验签与 gRPC 拦截器使用**同一 KeyRing**(kid 选择密钥)。
## 5. 令牌使用(插件 → PowerX)
- gRPC:在 metadata 设置 `authorization: Bearer <token>`;拦截器校验通过后带入 `tenant_id/actor` 上下文。
- HTTP(如需):中间件与 STS 对齐验签策略(issuer/secret/kid)。
- 客户端缓存:仅内存缓存;若剩余寿命 <60s 先刷新;401/403 触发强制刷新再重试一次。
### 5.1 HTTP direct route 边界
- 插件调用底座能力的推荐主路径是 `/api/v1/tenant/invocations`。
- 插件 STS token 直接访问 Core HTTP 时,允许集合由 capability governance 管理:
`static plugin runtime contracts + formal platform_capabilities REST endpoints - STS blocklist`。
- 普通开放 REST 能力必须先进入正式 `backend/config/platform_capabilities/*.yaml` 的 REST protocol;不得通过手工改 STS validator 代替能力登记。
- `/api/v1/admin/*` 是后台用户态 API 命名空间。插件 Admin 页面、PowerX Admin 页面、以及任何携带用户 JWT 的后台请求,仍然由用户鉴权、租户成员、RBAC 和业务权限判定,不受服务态 STS direct blocklist 影响。
- 普通 STS token 是插件服务态身份,不携带 `uid/mid`,不能代表登录用户调用 `/api/v1/admin/*` 绕过用户 RBAC。插件后端如果要代表当前用户调用底座后台 API,必须引入 delegated/on-behalf-of 机制。
- 对服务态 STS direct call,`/admin/*`、`/internal/*`、`/public/*`、`/auth/*`、`/setup/*`、debug、migration、root、drain、bootstrap、mock、health、根级动态路径默认不允许。确认为插件服务运行时合同的少量入口必须进入 static allow 并补测试。
## 6. 安全与审计
- TTL 建议 2–10 分钟;`client_secret` 安全存储;校验 `aud/scope` 最小权限;
- 审计:记录 Exchange/业务调用的 `tenant/plugin/subject/trace_id`;异常 401/403 计数告警。
- 禁止在 `tenant_id=0` 上下文下生成租户凭证。
## 7. 与 Agent/插件关系(何时走 MCP)
- 插件直调 PowerX(gRPC/HTTP)或对外自暴露服务;
- 需要纳入统一“工具目录/市场”时,将插件能力包装为 MCP 工具(详见《powerx_agent_plugin.md》)。
## 8. 验收要点(Checklist)
- [ ] 存在 STS `Exchange` 实现与注册,Proto 契约落在 `powerx/auth/sts/v1`;
- [ ] KeyRing(HS256+`kid`)与拦截器复用,STS 签发的 token 可直接通过业务 RPC 鉴权;
- [ ] 插件凭证落在 `plugin_instance_configs`(仅存 hash),支持“轮换”;
- [ ] 客户端仅内存缓存 token,支持预刷新与 401/403 强制刷新;
- [ ] 审计与安全策略(TTL/aud/scope/告警)到位;
- [ ] 与 HTTP/gRPC 的错误语义一致(Unauthenticated/PermissionDenied)。© ArtisanCloud, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/sts of ArtisanCloud/PowerX.
Open the folder on GitHubat commit 3f7619d
Sts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sts this skillArtisanCloud/PowerX | 379 | — | ~774 | Automated safety check: Pass | Apache-2.0 | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Nestjs Best Practicesrolling-scopes/rsschool-app | 10k | 6 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Sub2API AdminWei-Shaw/sub2api | 43k | 1 repos | ~717 | Automated safety check: Pass | LGPL-3.0 | |
| Firecrawl Build Onboardingfirecrawl/firecrawl | 190k | 1 repos | ~1.4k | Automated safety check: Notes | ISC | |
| Obsidian BasesAtmosphere/atmosphere | 3.8k | 22 repos | ~3.2k | Automated safety check: Pass | Apache-2.0 |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
rolling-scopes/rsschool-app
NestJS best practices and architecture patterns for building production-ready applications.
Wei-Shaw/sub2api
Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.
firecrawl/firecrawl
Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.
Atmosphere/atmosphere
Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
ArtisanCloud/PowerX
PowerX API 命名与访问规范(/api/v1、/admin、/internal 边界). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX 底座 Capability 治理与发布准入规则。用于审计 REST/OpenAPI/gRPC/Gin 生成的能力候选、正式 platformcapabilities 目录、Capability Registry 登记、agentusable/permissioncode/risklevel 元数据、ignore…
ArtisanCloud/PowerX
PowerX CRUD 依赖注入规则(Deps 单入口、构造注入、跨传输复用). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX CRUD gRPC 开发规范(proto、server、拦截器、错误映射). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX HTTP Handler 规则(绑定校验、统一回包、无 DB IO). An agent skill from ArtisanCloud/PowerX.
ArtisanCloud/PowerX
PowerX CRUD HTTP 开发规范(管理端路由、绑定、错误桥接、多租户). An agent skill from ArtisanCloud/PowerX.
Categories
PowerX STS 与插件鉴权规范(Exchange、KeyRing、拦截器、审计). An agent skill from ArtisanCloud/PowerX. Sts is an agent skill from ArtisanCloud/PowerX.
Sts fits situations like: backend & APIs work in your project.
Run `npx skills add ArtisanCloud/PowerX --skill sts -a claude-code`. Or copy the skill folder (.codex/skills/sts in ArtisanCloud/PowerX) into .claude/skills/sts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ArtisanCloud/PowerX --skill sts -a codex`. Or copy the skill folder (.codex/skills/sts in ArtisanCloud/PowerX) into .agents/skills/sts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArtisanCloud/PowerX --skill sts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sts, .gemini/skills/sts, .github/skills/sts and .opencode/skills/sts in your project.
SKILL.md names no scripts, command-line tools or credentials: Sts is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sts is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 774 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sts: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 43k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ArtisanCloud (a GitHub organization) maintains it in ArtisanCloud/PowerX, which has 379 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 8, 2026.
Source: ArtisanCloud/PowerX on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.