Clerk Auth
davila7/claude-code-templates
Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user authentication, sign in, sign up.
A skill your agent uses when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.
$ npx skills add different-ai-studio/teamclu --skill app-auth -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install different-ai-studio/teamclu app-auth --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/different-ai-studio/teamclu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/app/src/lib/skills/app-auth .claude/skills/app-auth && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "app-auth" agent skill from https://github.com/different-ai-studio/teamclu/tree/main/packages/app/src/lib/skills/app-auth into .claude/skills/app-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "app-auth", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/different-ai-studio/teamclu/tree/main/packages/app/src/lib/skills/app-authType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add different-ai-studio/teamclu --skill app-auth -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install different-ai-studio/teamclu app-auth --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/different-ai-studio/teamclu.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/app/src/lib/skills/app-auth .agents/skills/app-auth && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "app-auth" agent skill from https://github.com/different-ai-studio/teamclu/tree/main/packages/app/src/lib/skills/app-auth into .agents/skills/app-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "app-auth", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add different-ai-studio/teamclu --skill app-auth -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install different-ai-studio/teamclu app-auth --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/different-ai-studio/teamclu.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/app/src/lib/skills/app-auth .cursor/skills/app-auth && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "app-auth" agent skill from https://github.com/different-ai-studio/teamclu/tree/main/packages/app/src/lib/skills/app-auth into .cursor/skills/app-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "app-auth", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/different-ai-studio/teamclu.git --path packages/app/src/lib/skills/app-auth--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add different-ai-studio/teamclu --skill app-auth -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install different-ai-studio/teamclu app-auth --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/different-ai-studio/teamclu.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/app/src/lib/skills/app-auth .gemini/skills/app-auth && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "app-auth" agent skill from https://github.com/different-ai-studio/teamclu/tree/main/packages/app/src/lib/skills/app-auth into .gemini/skills/app-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "app-auth", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install different-ai-studio/teamclu app-authInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add different-ai-studio/teamclu --skill app-auth -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/different-ai-studio/teamclu.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/app/src/lib/skills/app-auth .github/skills/app-auth && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "app-auth" agent skill from https://github.com/different-ai-studio/teamclu/tree/main/packages/app/src/lib/skills/app-auth into .github/skills/app-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "app-auth", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add different-ai-studio/teamclu --skill app-auth -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install different-ai-studio/teamclu app-auth --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/different-ai-studio/teamclu.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/app/src/lib/skills/app-auth .opencode/skills/app-auth && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "app-auth" agent skill from https://github.com/different-ai-studio/teamclu/tree/main/packages/app/src/lib/skills/app-auth into .opencode/skills/app-auth/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "app-auth", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
app-authA skill your agent uses when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.
App Auth is an agent skill from different-ai-studio/teamclu. Use when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: TeamClu, AI Agent Desktop Workspace. The licence is MIT.
Read from SKILL.md and the folder at commit e4ff421. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
App Auth loads about 1.5k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 729 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from different-ai-studio/teamclu at commit e4ff421, republished under its MIT licence (© different-ai-studio). 729 words, ~1,531 tokens.
.claude/skills/app-auth/SKILL.md (or your agent's skills folder).Platform login and application-owned login are separate. Keep an applicant's mock SMS session if requested; do not replace it with platform login. Platform login runs at the gateway, not in a new employee password system.
Before changing login permissions, call manage_app auth_info for the selected app. Use its organization, organization-scoped active role codes, raw rules, and effective policies. If discovery fails or the organization is unconfigured, report that and stop role configuration; an unavailable catalog is not an empty catalog.
Choose the intended required audience explicitly: roles: [] admits any signed-in user; audience: "org" with no roles admits any current or future active organization role; a nonempty roles array admits one of those selected codes. Explicit roles wins over rule audience, then the app default. Preserve untouched raw rules, including inherited defaults, when replacing the full list. Do not add a fixed User ID allowlist for organization-role permissions. The gateway checks current active organization roles on each matching request; do not rebuild that decision with an app-side member list. App code consumes the trusted platform identity on gateway-protected requests. App creators and collaborators do not automatically pass the site's role check; manage_app_access manages collaborators, not visitors.
Check page URLs and the actual data endpoints separately. Longest matching path prefix wins; a protected page does not protect an unmatched data request. Public and employee flows may share Server Functions: inspect their actual routes and checks, and preserve public access rather than locking the shared prefix wholesale. No particular employee endpoint path is required.
Use the existing permission update tool and native approval, then call auth_info again to compare persisted raw rules and effective audiences with the intent. Verify public and restricted requests, including a visitor without a matching role. A rejected update leaves the previous policy in place; do not report success from a proposed patch or bypass approval. These access checks do not authorize publishing or changing role assignments.
X-Teamclu-User-Id is the authenticated platform user ID, not an actor ID. created_by_actor_id names the app creator's actor; never compare it with that header or embed it as an employee ID. Email, browser IDs and client-provided role claims do not authorize staff. A gateway identity proves who made this request; it only proves employee admission when this exact endpoint has the required employee policy.
“Creator has employee access” is a business requirement, not an automatic organization-role grant. owner is an organization role, not necessarily the app creator. Use supported control-plane policies and verified facts to express the intended audience. If creator-only access cannot be represented or its role eligibility cannot be established with available tools, explain the limitation and clarify the policy; do not substitute all signed-in users, guess an identity mapping, or add a static creator/member allowlist. Never change organization role assignments implicitly.
Protect /staff and /api/staff with the same intended role codes, discovered through auth_info, before publishing. /api/staff is a path prefix; protect all employee reads and mutations below it. Public applicant endpoints stay separate. Do not lock the shared /_serverFn prefix when it also serves applicants, and do not leave employee Server Functions exposed there. Inspect the actual request URLs.
For the TanStack Start data template, an employee read route can use this shape in src/routes/api.staff.applications.ts:
import { createFileRoute } from '@tanstack/react-router'
import { visitorFrom } from '../lib/platform-auth'
import { sql } from '../db'
export const Route = createFileRoute('/api/staff/applications')({
server: {
handlers: {
GET: async ({ request }) => {
// PRECONDITION: this exact endpoint has the employee role policy.
// Platform ingress strips spoofed identity headers; direct origins
// must reject requests that bypass it. This check alone is not RBAC.
const visitor = visitorFrom(request.headers)
if (!visitor) return Response.json({ error: 'platform_login_required' }, { status: 401 })
const records = await sql`select id, phone, status from applications order by created_at desc`
return Response.json({ records })
},
},
},
})Adapt the table and returned columns to the app schema. The front end fetches this endpoint instead of a shared Server Function. Review and coupon mutations use the same protected prefix, validate input and same-origin/CSRF requirements, and record visitor.id for audit; it is not an authorization allowlist. Applicant reads and images still enforce application-owned record ownership.
Use local tests for missing identity, input/ownership checks, and applicant isolation; test mocks do not prove production role admission. Read auth_info after policy changes to verify saved rules and effective policy for page and employee endpoint paths. An anonymous live request to employee data must not return data; test spoofed identity headers through the gateway without real credentials. Check available origin-security status, and report unknown bypass protection rather than assuming it.
Real-account sign-in requires an available account and authorized interactive access. If the agent cannot sign in, mark real sign-in, role admission and rejection, logout, and request checks after role changes as "pending acceptance" and provide manual test steps. Do not report mock tests or policy readback as successful real-account sign-in acceptance.
© different-ai-studio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in packages/app/src/lib/skills/app-auth of different-ai-studio/teamclu.
Open the folder on GitHubat commit e4ff421
App Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| App Auth this skilldifferent-ai-studio/teamclu | 167 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Clerk Authdavila7/claude-code-templates | 32k | 5 repos | ~376 | Automated safety check: Pass | MIT | |
| AuthEpicenterHQ/epicenter | 4.8k | — | ~7k | Automated safety check: Pass | Custom licence | |
| Authmicrosoft/apm | 4k | — | ~756 | Automated safety check: Pass | MIT | |
| Document Signingasgeirtj/system_prompts_leaks | 69k | — | ~1.5k | Automated safety check: Pass | CC0-1.0 | |
| Aria Rolesthedaviddias/Front-End-Checklist | 74k | — | ~515 | Automated safety check: Pass | MIT |
davila7/claude-code-templates
Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user authentication, sign in, sign up.
EpicenterHQ/epicenter
Epicenter auth packages: @epicenter/auth and the Svelte adapter at @epicenter/auth/svelte, OAuth sessions, identity state, auth-owned fetch/WebSocket, and the reload gate that makes a page lifetime…
microsoft/apm
Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…
asgeirtj/system_prompts_leaks
Review documents for signature or prepare a signing packet; verify fields and recipients while keeping sending and signing under explicit user authorization.
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Use valid ARIA role values.
sickn33/agentic-awesome-skills
Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync
different-ai-studio/teamclu
Create a workspace role that follows the ROLE.md specification.
different-ai-studio/teamclu
生成图片:配图、插图、海报、头像、示意图、Logo 草稿、封面、banner。触发词:画一张、画个、生成图片、生成一张图、做张图、做个图、配图、出图、生图、AI 绘图、image、draw、illustration、poster。仅从零生成,不做已有图片的编辑或修改。
different-ai-studio/teamclu
Control macOS desktop applications: open/operate apps, click buttons, type text, scroll, keyboard shortcuts, window management, toggle options, dropdown selections, etc.
different-ai-studio/teamclu
A skill your agent uses when the user wants to fix a Sentry issue, auto-repair a bug from Sentry, or create a fix PR for a Sentry error.
different-ai-studio/teamclu
A skill your agent uses when the user wants to check Sentry issues, run a Sentry daily report, or monitor error trends.
different-ai-studio/teamclu
Control Windows desktop applications: open/operate apps, click controls, type text, scroll, keyboard shortcuts, window management, toggle options, lists and combos, etc.
A skill your agent uses when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions. App Auth is an agent skill from different-ai-studio/teamclu. Use when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.
App Auth fits situations like: implementing TeamClu platform sign-in; organization-role access; protected data endpoints in an app; changing its login permissions.
Run `npx skills add different-ai-studio/teamclu --skill app-auth -a claude-code`. Or copy the skill folder (packages/app/src/lib/skills/app-auth in different-ai-studio/teamclu) into .claude/skills/app-auth in your project. Claude Code loads it when a task matches its description.
Run `npx skills add different-ai-studio/teamclu --skill app-auth -a codex`. Or copy the skill folder (packages/app/src/lib/skills/app-auth in different-ai-studio/teamclu) into .agents/skills/app-auth in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add different-ai-studio/teamclu --skill app-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/app-auth, .gemini/skills/app-auth, .github/skills/app-auth and .opencode/skills/app-auth in your project.
SKILL.md names no scripts, command-line tools or credentials: App Auth is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
App Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with App Auth: Clerk Auth (davila7/claude-code-templates, 32k stars), Auth (EpicenterHQ/epicenter, 4.8k stars), Auth (microsoft/apm, 4k stars) and Document Signing (asgeirtj/system_prompts_leaks, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
different-ai-studio (a GitHub organization) maintains it in different-ai-studio/teamclu, which has 167 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 7, 2026.
Source: different-ai-studio/teamclu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.