Agent skill

Ron Auth

by bionic-gpt in bionic-gpt/bionic-gpt

Implement identity and authorization boundaries in Rust on Nails applications.

Apache-2.0Auto-check passedBackend & APIs

Install Ron Auth

skills CLI
$ npx skills add bionic-gpt/bionic-gpt --skill ron-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bionic-gpt/bionic-gpt ron-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bionic-gpt/bionic-gpt.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ron-auth .claude/skills/ron-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ron-auth
GitHub stars
2.4k
Token cost
~667 tokens
SKILL.md length
325 words
Files
2
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

Implement identity and authorization boundaries in Rust on Nails applications.

  • Verified identity
  • SKILL.md covers Identity boundary, Authorization, Local contract example and Verification
  • Runs Rust scripts from its folder
  • Team membership

What it does

Ron Auth is an agent skill from bionic-gpt/bionic-gpt. Implement identity and authorization boundaries in Rust on Nails applications. Use for verified identity, team membership, permissions, ownership, and authenticated transaction context.

Its SKILL.md is about 670 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files.

It sits in Backend & APIs, covering Authorization and RBAC. It works with Rust. The repository describes itself as: Bionic is sovereign Agentic AI for the enterprise — Runs on-premise and can securely work with your sensitive data and systems. The licence is Apache-2.0.

When your agent uses it

  • Verified identity
  • Team membership
  • Authenticated transaction context

Example prompts

  • “/ron-auth”

What it can do on your machine

Read from SKILL.md and the folder at commit c155c00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Rust), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ron Auth loads about 667 tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 325 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~667

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from bionic-gpt/bionic-gpt at commit c155c00, republished under its Apache-2.0 licence (© bionic-gpt). 325 words, ~667 tokens.

Download SKILL.mdSave it as .claude/skills/ron-auth/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
ron-auth
description
Implement identity and authorization boundaries in Rust on Nails applications. Use for verified identity, team membership, permissions, ownership, and authenticated transaction context.

Rust on Nails Authentication and Authorization

Inspect the destination project's identity provider, middleware, request extractor, permissions, and database policies. Do not assume header names or helper functions.

Identity boundary

Use an identity already verified by trusted authentication middleware. Decoding a JWT payload does not verify its signature, issuer, audience, or expiry. Forwarded identity headers are trustworthy only when an authenticated upstream controls them and clients cannot bypass it or inject identity headers. Never add a development identity override as a production authentication mechanism.

Authorization

  • Resolve user identity from authentication, not form or tool input.
  • Authorize the selected team before loading protected data. Team IDs from routes remain untrusted selectors until checked against membership.
  • Check operation permissions and record scope. Being able to read a shared record does not imply permission to edit it; membership in two teams does not permit substituting either team's record under the other's route.
  • Enforce ownership/permissions in the handler and persistence layer. UI checks only hide controls. Keep record authorization and writes atomic.
  • For PostgreSQL RLS, set context transaction-locally before protected queries on the same connection. Never leave per-user state on a pooled connection after a request. Inspect table-owner/BYPASSRLS behavior and the application's actual database role.
  • Treat background privileged access as a separate workflow, not a user-facing bypass.

Local contract example

authorization.rs defines verified identity, item scope, and explicit team/owner checks using only the Rust standard library. It is a policy example: all team members may read; only owners may mutate. Populate identity from verified middleware and obtain item scope from trusted storage. Apply equivalent predicates in the same database statement/transaction as mutations.

No framework extractor or identity-provider setup is assumed. Adapt the policy to real roles without treating the example's owner-only rule as a universal requirement.

Verification

Test absent/invalid identity at middleware, nonmember teams, wrong owner, swapped team IDs even for a multi-team member, and allowed read/write paths. Test RLS context isolation across pooled requests. Optional companion: ron-database, if installed.

© bionic-gpt, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/ron-auth of bionic-gpt/bionic-gpt.

  • SKILL.md
  • examples/authorization.rs

Open the folder on GitHubat commit c155c00

Compare with similar skills

Ron Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ron Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ron Auth this skillbionic-gpt/bionic-gpt2.4k—~667Automated safety check: PassApache-2.0
Auth Architecturemajiayu000/litellm-rs117—~1.9kAutomated safety check: PassMIT
Cloud Storage Hexagonal Architecturemacro-inc/macro4.6k—~3kAutomated safety check: PassAGPL-3.0
Tenuo Denial Triagetenuo-ai/tenuo102—~2.3kAutomated safety check: PassApache-2.0
Trust Hmi ContractsjohannesPettersson80/trust-platform221—~611Automated safety check: PassApache-2.0
Smart Contract Auditelophanto/EloPhanto106—~2.7kAutomated safety check: PassCustom licence

Similar skills

  • Auth Architecture

    majiayu000/litellm-rs

    LiteLLM-RS Authentication Architecture. An agent skill from majiayu000/litellm-rs.

    117 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Enforce hexagonal architecture in the Rust backend. An agent skill from macro-inc/macro.

    4.6k GitHub stars~3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Tenuo Denial Triage

    tenuo-ai/tenuo

    Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority.

    102 GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed
  • Trust Hmi Contracts

    johannesPettersson80/trust-platform

    Implement and review trust-platform HMI schema/value/write contracts with safety guardrails.

    221 GitHub stars~611 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Smart Contract Audit

    elophanto/EloPhanto

    A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

    106 GitHub stars~2.7k tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes

More from bionic-gpt/bionic-gpt

All 21 skills in this repo
  • Static Sites

    bionic-gpt/bionic-gpt

    Create or modify Bionic's generated marketing site, documentation, blog, course pages, and static assets.

    2.4k GitHub stars~920 tokensUpdated yesterday
    Auto-check passed
  • Automationbench Eval

    bionic-gpt/bionic-gpt

    Load the repository's AutomationBench OpenAPI catalogue and run evaluations against the local simulator.

    2.4k GitHub stars~619 tokensUpdated yesterday
    Auto-check passed
  • Ron Web Pages

    bionic-gpt/bionic-gpt

    Build server-rendered Dioxus pages using opinionated Rust on Nails patterns.

    2.4k GitHub stars~616 tokensUpdated yesterday
    Auto-check passed
  • Document Generation

    bionic-gpt/bionic-gpt

    Create polished printable documents and PDFs, including forms, checklists, reports, briefs, comparisons, worksheets, task lists, and other operational documents.

    2.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Local Deployment

    bionic-gpt/bionic-gpt

    Deploy one or more locally built Bionic services into the user's k3d cluster.

    2.4k GitHub stars~540 tokensUpdated yesterday
    Auto-check: notes
  • Office Tools

    bionic-gpt/bionic-gpt

    Regenerate the built-in Office OpenAPI specs from a selected Archipelago ref.

    2.4k GitHub stars~352 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Ron Auth

What does Ron Auth do?

Implement identity and authorization boundaries in Rust on Nails applications. Ron Auth is an agent skill from bionic-gpt/bionic-gpt. Implement identity and authorization boundaries in Rust on Nails applications.

When should I use Ron Auth?

Ron Auth fits situations like: verified identity; team membership; authenticated transaction context.

How do I install Ron Auth in Claude Code?

Run `npx skills add bionic-gpt/bionic-gpt --skill ron-auth -a claude-code`. Or copy the skill folder (.agents/skills/ron-auth in bionic-gpt/bionic-gpt) into .claude/skills/ron-auth in your project. Claude Code loads it when a task matches its description.

How do I install Ron Auth in Codex?

Run `npx skills add bionic-gpt/bionic-gpt --skill ron-auth -a codex`. Or copy the skill folder (.agents/skills/ron-auth in bionic-gpt/bionic-gpt) into .agents/skills/ron-auth in your project. Codex loads it when a task matches its description.

Can I use Ron Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bionic-gpt/bionic-gpt --skill ron-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ron-auth, .gemini/skills/ron-auth, .github/skills/ron-auth and .opencode/skills/ron-auth in your project.

What does Ron Auth need to run?

Going by SKILL.md and its folder, Ron Auth needs Rust for the scripts in its folder.

Does Ron Auth access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ron Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ron Auth use?

Ron Auth is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ron Auth use?

About 667 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ron Auth?

Skills that share tags, products or a category with Ron Auth: Auth Architecture (majiayu000/litellm-rs, 117 stars), Cloud Storage Hexagonal Architecture (macro-inc/macro, 4.6k stars), Tenuo Denial Triage (tenuo-ai/tenuo, 102 stars) and Trust Hmi Contracts (johannesPettersson80/trust-platform, 221 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ron Auth?

bionic-gpt (a GitHub organization) maintains it in bionic-gpt/bionic-gpt, which has 2,383 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: bionic-gpt/bionic-gpt on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.