Backend Code Review
langgenius/dify
Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.
A skill your agent uses when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party…
$ npx skills add awebai/aweb --skill team-cert-verification -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install awebai/aweb team-cert-verification --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .claude/skills && cp -r skills-src/naapp/folio/skills/team-cert-verification .claude/skills/team-cert-verification && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "team-cert-verification" agent skill from https://github.com/awebai/aweb/tree/main/naapp/folio/skills/team-cert-verification into .claude/skills/team-cert-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "team-cert-verification", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/awebai/aweb/tree/main/naapp/folio/skills/team-cert-verificationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add awebai/aweb --skill team-cert-verification -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install awebai/aweb team-cert-verification --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .agents/skills && cp -r skills-src/naapp/folio/skills/team-cert-verification .agents/skills/team-cert-verification && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "team-cert-verification" agent skill from https://github.com/awebai/aweb/tree/main/naapp/folio/skills/team-cert-verification into .agents/skills/team-cert-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "team-cert-verification", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awebai/aweb --skill team-cert-verification -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install awebai/aweb team-cert-verification --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/naapp/folio/skills/team-cert-verification .cursor/skills/team-cert-verification && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "team-cert-verification" agent skill from https://github.com/awebai/aweb/tree/main/naapp/folio/skills/team-cert-verification into .cursor/skills/team-cert-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "team-cert-verification", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/awebai/aweb.git --path naapp/folio/skills/team-cert-verification--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add awebai/aweb --skill team-cert-verification -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install awebai/aweb team-cert-verification --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/naapp/folio/skills/team-cert-verification .gemini/skills/team-cert-verification && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "team-cert-verification" agent skill from https://github.com/awebai/aweb/tree/main/naapp/folio/skills/team-cert-verification into .gemini/skills/team-cert-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "team-cert-verification", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install awebai/aweb team-cert-verificationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add awebai/aweb --skill team-cert-verification -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .github/skills && cp -r skills-src/naapp/folio/skills/team-cert-verification .github/skills/team-cert-verification && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "team-cert-verification" agent skill from https://github.com/awebai/aweb/tree/main/naapp/folio/skills/team-cert-verification into .github/skills/team-cert-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "team-cert-verification", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add awebai/aweb --skill team-cert-verification -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install awebai/aweb team-cert-verification --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/awebai/aweb.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/naapp/folio/skills/team-cert-verification .opencode/skills/team-cert-verification && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "team-cert-verification" agent skill from https://github.com/awebai/aweb/tree/main/naapp/folio/skills/team-cert-verification into .opencode/skills/team-cert-verification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "team-cert-verification", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
team-cert-verificationA skill your agent uses when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party…
Team Cert Verification is an agent skill from awebai/aweb. Use when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party, wiring aw id request --team-auth, or debugging X-AWEB-Signed-Payload and team certificate failures in a new service.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. The repository describes itself as: Communication for AI agents: stable identity, durable mail and chat, and wake-up events across sessions, runtimes, machines, and organizations. MIT, self-hostable. The licence is MIT.
10 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit a6ca92a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are http and json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Team Cert Verification loads about 1.8k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 832 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from awebai/aweb at commit a6ca92a, republished under its MIT licence (© awebai). 832 words, ~1,831 tokens.
.claude/skills/team-cert-verification/SKILL.md (or your agent's skills folder).Use this when your service is a BYOT relying party: agents present a DIDKey
signature plus an AWID team certificate on every team-scoped request. The code
ground truth is src/folio/auth.py; the test ground truth is
tests/test_auth_v2_envelope.py. Port both and keep the tests green.
Every team-scoped request carries four headers:
Authorization: DIDKey <did:key:z6Mk...> <base64url-no-padding-ed25519-signature>
X-AWEB-Timestamp: <RFC3339 UTC timestamp>
X-AWID-Team-Certificate: <base64-standard-json-team-certificate>
X-AWEB-Signed-Payload: <base64url-no-padding canonical-JSON of the signed payload>X-AWEB-Signed-Payload decodes to canonical JSON with these fields:
{"aud":"https://<service-origin>","body_sha256":"<sha256 hex of request body>","method":"<UPPER>","path":"<raw path?query>","team_id":"<team>:<namespace>","timestamp":"<RFC3339 UTC timestamp>","v":2}Rules:
= is rejected in
folio; see src/folio/auth.py:137-146).canonical_json(parsed) == decoded bytes (src/folio/auth.py:188-193).src/folio/auth.py:217-220).Follow this implementation order when porting src/folio/auth.py. The cert is
parsed early to obtain team_id for request binding and to compare
member_did_key; it is still untrusted data until the AWID-resolved team key
verifies its signature and revocation passes.
team_id/certificate_id/member_did_key/
alias, or certificate.member_did_key != request did:key. Why: the signed
payload's team_id must bind to the presented cert's team, and the cert must
name the same member key as the request signer.body_sha256 differs. Why: bodyless and bodyful
methods use the same rule; tampered bodies fail.X-AWEB-Signed-Payload — 401 on missing, malformed,
padded, non-canonical, or non-object payload. Why: the presented canonical
bytes are the signed object; accepting alternatives creates ambiguity.v == 2 — 401 on absent or other versions. Why: v1/compact
payloads do not bind method/path/audience.certificate_id is revoked or the cert signature fails; 503 if the
AWID-resolved team public key is invalid. Why: membership can be removed
outside your app, and cert signatures must verify against AWID-resolved
authority.team_id.raw_path plus raw
query_string, preserving percent-encoding and query order; include
root_path for mounted apps. See src/folio/auth.py:149-173 and
tests/test_auth_v2_envelope.py:258-272.aweb.team_auth_envelope / awid.log.canonical_server_origin: scheme and
host lowercased, default ports removed, no path/query/fragment. See
src/folio/auth.py:209-215 and the interop check in
tests/test_auth_v2_envelope.py:312-343.X-AWEB-Signed-Payload, verify those bytes, then compare parsed claims to the
actual request. Do not sign or verify a server-reconstructed dictionary.src/folio/auth.py:43-100).src/folio/auth.py:58-87).src/folio/auth.py:67-87).src/folio/auth.py:287-288).public_origin should make every v2 request fail closed. That
is a feature: it prevents accepting signatures for the wrong host and exposes
deploy misconfiguration immediately.| Anti-pattern | Failure it creates |
|---|---|
Verify the cert against its own team_did_key field. | Lets a forged cert bring its own authority. Resolve the team key from AWID. |
| Accept absent version, v1, or compact payloads. | Drops method/path/audience binding and enables cross-endpoint replay. |
Skip body_sha256 for GET or empty bodies. | Creates a second contract and lets body mutation bugs hide. Hash exact bytes always. |
| Trust the presented cert when AWID is down. | Converts an availability incident into an auth bypass. Use unexpired cache or fail closed. |
| Set clock skew very wide. | Expands replay window. Keep the default small (folio default: 300 seconds). |
| Add API keys, trusted headers, sessions, or OAuth “just for testing.” | Creates a second auth path reviewers and users must reason about. Test the real verifier. |
| Use router-normalized paths. | Breaks percent-encoding/query-order binding and disagrees with aw id request --team-auth. |
| Verify a reconstructed payload. | Lets the verifier sign what it wishes it saw, not what the agent actually signed. |
src/folio/auth.py — copyable FastAPI verifier implementation.tests/test_auth_v2_envelope.py — spec by example; port it with the code and
keep it green.docs/sot.md Authentication envelope section — product/source-of-truth
contract (docs/sot.md:61-126 on main when this skill was written).aweb/docs/vectors/team-auth-envelope-v2.json and aweb/test-vectors/ —
byte-for-byte interop fixtures used by the tests.© awebai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in naapp/folio/skills/team-cert-verification of awebai/aweb.
Open the folder on GitHubat commit a6ca92a
Team Cert Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Team Cert Verification this skillawebai/aweb | 115 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Backend Code Reviewlanggenius/dify | 158k | — | ~676 | Automated safety check: Pass | Custom licence | |
| Native Data FetchingCherryHQ/cherry-studio-app | 4k | 6 repos | ~2.9k | Automated safety check: Notes | MIT | |
| Twenty App Entity Developmenttwentyhq/twenty | 58k | — | ~1.8k | Automated safety check: Pass | Custom licence | |
| Go Pedantrychromedp/chromedp | 13k | — | ~3.7k | Automated safety check: Pass | MIT | |
| Gumroad Prod Consoleantiwork/gumroad | 9.8k | — | ~2.9k | Automated safety check: Notes | MIT |
langgenius/dify
Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.
CherryHQ/cherry-studio-app
A skill your agent uses when implementing or debugging ANY network request, API call, or data fetching.
twentyhq/twenty
Guides changes to an existing Twenty app: adding or editing objects, layouts, logic functions and front components, with a plan stated before multi-entity edits.
chromedp/chromedp
This skill should be used when the user is writing Go code and needs guidance on Go-specific pedantry: error wrapping with fmt.Errorf and %w, interface design (accept interfaces return structs)…
antiwork/gumroad
Execute read-only Ruby/Rails commands against Gumroad's production database for debugging and investigation.
langbot-app/LangBot
Guides building, debugging and testing LangBot plugins: components, SDK calls, README and locale rules, SDK pitfalls and WebSocket-based testing.
awebai/aweb
Recognizes old aweb bootstrap-era `agents/` directories and migrates them to current team and identity primitives, since the old command family is retired.
awebai/aweb
Guides decisions for agents working in an aweb team: when to check shared state, claim tasks, take locks, read team roles and instructions, and open separate worktrees.
awebai/aweb
Guides how an agent reads and responds to aweb mail and chat events, choosing between asynchronous mail and synchronous chat and respecting sender verification and encryption boundaries.
awebai/aweb
This skill should be used when joining or being added to an aweb team, picking the correct invite/add-member path for the team's authority model (hosted vs BYOT), accepting invites, fetching team…
awebai/aweb
Creates or appends a folio document from the built-in pitch, memo or metrics templates by sending schema-checked slots that folio renders to Markdown.
awebai/aweb
A skill your agent uses when an agent needs to show a human an folio document: mint a document-bound capability link with POST /v1/present, open the returned URL for the human, print it as fallback…
Categories
A skill your agent uses when implementing or reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope, porting folio auth.py, building a BYOT relying party…. Team Cert Verification is an agent skill from awebai/aweb.py, building a BYOT relying party, wiring aw id request --team-auth, or debugging X-AWEB-Signed-Payload and team certificate failures in a new service.
Team Cert Verification fits situations like: reviewing AWID team-certificate authentication — verifying the request-bound v2 team-auth envelope; porting folio auth.py; building a BYOT relying party; wiring aw id request --team-auth.
Run `npx skills add awebai/aweb --skill team-cert-verification -a claude-code`. Or copy the skill folder (naapp/folio/skills/team-cert-verification in awebai/aweb) into .claude/skills/team-cert-verification in your project. Claude Code loads it when a task matches its description.
Run `npx skills add awebai/aweb --skill team-cert-verification -a codex`. Or copy the skill folder (naapp/folio/skills/team-cert-verification in awebai/aweb) into .agents/skills/team-cert-verification in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add awebai/aweb --skill team-cert-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/team-cert-verification, .gemini/skills/team-cert-verification, .github/skills/team-cert-verification and .opencode/skills/team-cert-verification in your project.
SKILL.md names no scripts, command-line tools or credentials: Team Cert Verification is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Team Cert Verification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Team Cert Verification: Backend Code Review (langgenius/dify, 158k stars), Native Data Fetching (CherryHQ/cherry-studio-app, 4k stars), Twenty App Entity Development (twentyhq/twenty, 58k stars) and Go Pedantry (chromedp/chromedp, 13k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
awebai (a GitHub organization) maintains it in awebai/aweb, which has 115 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 9, 2026.
Source: awebai/aweb on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.