Security Review
doorkeeper-gem/doorkeeper
Verify that code changes do not introduce OAuth security vulnerabilities.
Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard.
$ npx skills add diegosouzapw/OmniRoute --skill omni-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install diegosouzapw/OmniRoute omni-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/diegosouzapw/OmniRoute.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/omni-auth .claude/skills/omni-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "omni-auth" agent skill from https://github.com/diegosouzapw/OmniRoute/tree/release%2Fv3.8.52/skills/omni-auth into .claude/skills/omni-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "omni-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/diegosouzapw/OmniRoute/tree/release%2Fv3.8.52/skills/omni-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add diegosouzapw/OmniRoute --skill omni-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install diegosouzapw/OmniRoute omni-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diegosouzapw/OmniRoute.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/omni-auth .agents/skills/omni-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "omni-auth" agent skill from https://github.com/diegosouzapw/OmniRoute/tree/release%2Fv3.8.52/skills/omni-auth into .agents/skills/omni-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "omni-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add diegosouzapw/OmniRoute --skill omni-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install diegosouzapw/OmniRoute omni-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diegosouzapw/OmniRoute.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/omni-auth .cursor/skills/omni-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "omni-auth" agent skill from https://github.com/diegosouzapw/OmniRoute/tree/release%2Fv3.8.52/skills/omni-auth into .cursor/skills/omni-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "omni-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/diegosouzapw/OmniRoute.git --path skills/omni-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add diegosouzapw/OmniRoute --skill omni-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install diegosouzapw/OmniRoute omni-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diegosouzapw/OmniRoute.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/omni-auth .gemini/skills/omni-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "omni-auth" agent skill from https://github.com/diegosouzapw/OmniRoute/tree/release%2Fv3.8.52/skills/omni-auth into .gemini/skills/omni-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "omni-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install diegosouzapw/OmniRoute omni-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add diegosouzapw/OmniRoute --skill omni-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/diegosouzapw/OmniRoute.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/omni-auth .github/skills/omni-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "omni-auth" agent skill from https://github.com/diegosouzapw/OmniRoute/tree/release%2Fv3.8.52/skills/omni-auth into .github/skills/omni-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "omni-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add diegosouzapw/OmniRoute --skill omni-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install diegosouzapw/OmniRoute omni-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/diegosouzapw/OmniRoute.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/omni-auth .opencode/skills/omni-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "omni-auth" agent skill from https://github.com/diegosouzapw/OmniRoute/tree/release%2Fv3.8.52/skills/omni-auth into .opencode/skills/omni-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "omni-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
omni-authDocuments how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard.
Remote API requests carry a Bearer credential, while dashboard login is separate: POST /api/auth/login takes a management password and returns an auth_token session cookie. Logout needs a CSRF token fetched from /api/auth/csrf, and /api/auth/status reports the current state. The skill is positioned as the place to start for authenticating against OmniRoute, an OpenAI-compatible gateway reached through an OMNIROUTE_URL setting.
OIDC login for the dashboard admin gate works in two steps. The login route builds an authorization URL from the configured issuer and client, sets a short-lived oidc_state cookie and redirects. The callback validates that cookie, exchanges the code for tokens, verifies the ID token against the issuer's JWKS, optionally checks the subject or email against an allowlist, then issues the same 30-day session token as password login and redirects to the dashboard. Password login stays available as a fallback.
Read from SKILL.md and the folder at commit 8ad6b1c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OMNIROUTE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
OmniRoute Authentication loads about 1.8k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 409 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from diegosouzapw/OmniRoute at commit 8ad6b1c, republished under its MIT licence (© diegosouzapw). 409 words, ~1,845 tokens.
.claude/skills/omni-auth/SKILL.md (or your agent's skills folder).<!-- generated by src/lib/agentSkills/generator.ts; manual edits will be overwritten -->
Manage API key authentication and session tokens. Start here to authenticate requests via Bearer token, obtain session cookies, and configure login requirements for the OmniRoute API.
Remote API requests use a Bearer credential. Dashboard login is different: POST /api/auth/login accepts a management password and returns an auth_token session cookie.
Authenticate user
curl -X POST https://localhost:20128/api/auth/login \
-H "Content-Type: application/json" \
-c cookie.jar \
-d '{"password":"<management-password>"}'Log out
CSRF_TOKEN=$(curl -s https://localhost:20128/api/auth/csrf -b cookie.jar | jq -r .token)
curl -X POST https://localhost:20128/api/auth/logout \
-b cookie.jar \
-H "x-omniroute-csrf: $CSRF_TOKEN" \
-H "Content-Type: application/json" \
-d '{}'Start OIDC login for the dashboard admin gate
Builds an authorization URL from the configured OIDC issuer/client (discovered
via {issuer}/.well-known/openid-configuration, falling back to {issuer}/authorize),
sets a short-lived oidc_state cookie, and redirects the browser. Password login
remains available as a fallback while OIDC is enabled.
curl https://localhost:20128/api/auth/oidc/login \
-b cookie.jarComplete OIDC login for the dashboard admin gate
Validates the state cookie, exchanges the authorization code for tokens,
verifies the ID token against the issuer's JWKS (audience = client id), and —
if oidcAllowedSubjects is configured — checks the token's sub/email against
that allowlist. On success it mints the same 30-day auth_token dashboard-session
JWT used by password login and redirects to /dashboard.
curl https://localhost:20128/api/auth/oidc/callback \
-b cookie.jarGET auth › csrf
curl https://localhost:20128/api/auth/csrf \
-b cookie.jarGET auth › status
curl https://localhost:20128/api/auth/status \
-b cookie.jarSee the full OpenAPI specification at GET /api/openapi/spec or docs/openapi.yaml for detailed request/response schemas.
<!-- skill:custom-start -->
<!-- Migrated from skills/omniroute/SKILL.md (preserved curated content) -->
Local/remote AI gateway exposing OpenAI-compatible REST. One key, 327 providers, auto-fallback, RTK token saver, MCP server, A2A agents.
export OMNIROUTE_URL="http://localhost:20128" # or VPS / tunnel URL
export OMNIROUTE_KEY="sk-..." # from Dashboard → API KeysAll requests: ${OMNIROUTE_URL}/v1/... with Authorization: Bearer ${OMNIROUTE_KEY}.
Verify: curl $OMNIROUTE_URL/api/health → {"ok":true}
curl $OMNIROUTE_URL/v1/models # chat/LLM (default)
curl $OMNIROUTE_URL/v1/models/image # image-gen
curl $OMNIROUTE_URL/v1/models/tts # text-to-speech
curl $OMNIROUTE_URL/v1/models/embedding # embeddings
curl $OMNIROUTE_URL/v1/models/web # web search + fetch
curl $OMNIROUTE_URL/v1/models/stt # speech-to-textUse data[].id as model field in requests. Combos appear with owned_by:"combo".
401 → set/refresh OMNIROUTE_KEY (Dashboard → API Keys)400 Invalid model format → check model exists in /v1/models/<kind>503 Provider circuit open → upstream provider down; retry after Retry-After seconds429 → rate limited; honor Retry-After<!-- skill:custom-end -->
© diegosouzapw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/omni-auth of diegosouzapw/OmniRoute.
Open the folder on GitHubat commit 8ad6b1c
OmniRoute Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| OmniRoute Authentication this skilldiegosouzapw/OmniRoute | 74k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Security Reviewdoorkeeper-gem/doorkeeper | 5.5k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Open Redirect TestingNeoTheCapt/RedteamAgent | 140 | — | ~608 | Automated safety check: Pass | None | |
| Web Ssrfs0ld13rr/pentestcode | 817 | — | ~660 | Automated safety check: Warn | MIT | |
| Secure Authjamditis/claude-skills-journalism | 416 | — | ~14k | Automated safety check: Pass | MIT | |
| API Security EngineerFerroxLabs/wayland | 608 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 |
doorkeeper-gem/doorkeeper
Verify that code changes do not introduce OAuth security vulnerabilities.
NeoTheCapt/RedteamAgent
Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains
s0ld13rr/pentestcode
Server-Side Request Forgery detection→internal-access→proof for web apps.
jamditis/claude-skills-journalism
Secure authentication patterns (OWASP, NIST). An agent skill from jamditis/claude-skills-journalism.
FerroxLabs/wayland
API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
diegosouzapw/OmniRoute
Backup and restore OmniRoute data from the CLI. Trigger incremental snapshots, sync to cloud storage, manage backup schedules, and restore from archive files.
diegosouzapw/OmniRoute
Read and update global application settings: system prompts, thinking budget, IP filters, payload rules, combo defaults, and require-login configuration.
diegosouzapw/OmniRoute
Runs a scoped, read-only quality scan on a repository candidate and reports exact evidence, failures and frozen debt, without treating a static scan as release acceptance.
diegosouzapw/OmniRoute
Trigger system backups, restore from backup files, and manage the SQLite database lifecycle. Supports export, import, and incremental snapshot strategies.
diegosouzapw/OmniRoute
Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.
diegosouzapw/OmniRoute
Documents OmniRoute's cache endpoints for reading cache statistics and clearing entries, statistics or the reasoning cache, with notes on TTL and similarity settings.
Categories
Documents how OmniRoute authenticates requests: Bearer credentials for the API, management-password login with session cookies, CSRF tokens and optional OIDC for the dashboard. Remote API requests carry a Bearer credential, while dashboard login is separate: POST /api/auth/login takes a management password and returns an auth_token session cookie. Logout needs a CSRF token fetched from /api/auth/csrf, and /api/auth/status reports the current state.
OmniRoute Authentication fits situations like: authenticating requests to the OmniRoute API with a Bearer token; logging in to the dashboard and keeping a session cookie in a script; setting up OIDC login for the dashboard admin gate; checking login status or fetching a CSRF token before logging out.
Run `npx skills add diegosouzapw/OmniRoute --skill omni-auth -a claude-code`. Or copy the skill folder (skills/omni-auth in diegosouzapw/OmniRoute) into .claude/skills/omni-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add diegosouzapw/OmniRoute --skill omni-auth -a codex`. Or copy the skill folder (skills/omni-auth in diegosouzapw/OmniRoute) into .agents/skills/omni-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add diegosouzapw/OmniRoute --skill omni-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/omni-auth, .gemini/skills/omni-auth, .github/skills/omni-auth and .opencode/skills/omni-auth in your project.
Going by SKILL.md and its folder, OmniRoute Authentication needs the command-line tools its instructions call (curl and jq) and credentials named OMNIROUTE_KEY. Our summary lists: A running OmniRoute server, with a management password or Bearer key.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
OmniRoute Authentication is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with OmniRoute Authentication: Security Review (doorkeeper-gem/doorkeeper, 5.5k stars), Open Redirect Testing (NeoTheCapt/RedteamAgent, 140 stars), Web Ssrf (s0ld13rr/pentestcode, 817 stars) and Secure Auth (jamditis/claude-skills-journalism, 416 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
diegosouzapw (a GitHub user) maintains it in diegosouzapw/OmniRoute, which has 73,701 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 6, 2026.
Source: diegosouzapw/OmniRoute on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.