A skill your agent uses when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.

MITAuto-check passed

Install App Auth

skills CLI
$ npx skills add different-ai-studio/teamclu --skill app-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install different-ai-studio/teamclu app-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/different-ai-studio/teamclu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/app/src/lib/skills/app-auth .claude/skills/app-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
app-auth
GitHub stars
167
Token cost
~1.5k tokens
SKILL.md length
729 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.

  • Implementing TeamClu platform sign-in
  • SKILL.md covers Identity is not authorization, Employee endpoint example and Verification and limits
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Organization-role access

What it does

App Auth is an agent skill from different-ai-studio/teamclu. Use when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: TeamClu, AI Agent Desktop Workspace. The licence is MIT.

When your agent uses it

  • Implementing TeamClu platform sign-in
  • Organization-role access
  • Protected data endpoints in an app
  • Changing its login permissions

Example prompts

  • “/app-auth”

What it can do on your machine

Read from SKILL.md and the folder at commit e4ff421. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

App Auth loads about 1.5k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 729 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from different-ai-studio/teamclu at commit e4ff421, republished under its MIT licence (© different-ai-studio). 729 words, ~1,531 tokens.

Download SKILL.mdSave it as .claude/skills/app-auth/SKILL.md (or your agent's skills folder).
name
app-auth
description
Use when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.

TeamClu app identity and access

Platform login and application-owned login are separate. Keep an applicant's mock SMS session if requested; do not replace it with platform login. Platform login runs at the gateway, not in a new employee password system.

Before changing login permissions, call manage_app auth_info for the selected app. Use its organization, organization-scoped active role codes, raw rules, and effective policies. If discovery fails or the organization is unconfigured, report that and stop role configuration; an unavailable catalog is not an empty catalog.

Choose the intended required audience explicitly: roles: [] admits any signed-in user; audience: "org" with no roles admits any current or future active organization role; a nonempty roles array admits one of those selected codes. Explicit roles wins over rule audience, then the app default. Preserve untouched raw rules, including inherited defaults, when replacing the full list. Do not add a fixed User ID allowlist for organization-role permissions. The gateway checks current active organization roles on each matching request; do not rebuild that decision with an app-side member list. App code consumes the trusted platform identity on gateway-protected requests. App creators and collaborators do not automatically pass the site's role check; manage_app_access manages collaborators, not visitors.

Check page URLs and the actual data endpoints separately. Longest matching path prefix wins; a protected page does not protect an unmatched data request. Public and employee flows may share Server Functions: inspect their actual routes and checks, and preserve public access rather than locking the shared prefix wholesale. No particular employee endpoint path is required.

Use the existing permission update tool and native approval, then call auth_info again to compare persisted raw rules and effective audiences with the intent. Verify public and restricted requests, including a visitor without a matching role. A rejected update leaves the previous policy in place; do not report success from a proposed patch or bypass approval. These access checks do not authorize publishing or changing role assignments.

Identity is not authorization

X-Teamclu-User-Id is the authenticated platform user ID, not an actor ID. created_by_actor_id names the app creator's actor; never compare it with that header or embed it as an employee ID. Email, browser IDs and client-provided role claims do not authorize staff. A gateway identity proves who made this request; it only proves employee admission when this exact endpoint has the required employee policy.

“Creator has employee access” is a business requirement, not an automatic organization-role grant. owner is an organization role, not necessarily the app creator. Use supported control-plane policies and verified facts to express the intended audience. If creator-only access cannot be represented or its role eligibility cannot be established with available tools, explain the limitation and clarify the policy; do not substitute all signed-in users, guess an identity mapping, or add a static creator/member allowlist. Never change organization role assignments implicitly.

Show full SKILL.md (259 more words)Show less

Employee endpoint example

Protect /staff and /api/staff with the same intended role codes, discovered through auth_info, before publishing. /api/staff is a path prefix; protect all employee reads and mutations below it. Public applicant endpoints stay separate. Do not lock the shared /_serverFn prefix when it also serves applicants, and do not leave employee Server Functions exposed there. Inspect the actual request URLs.

For the TanStack Start data template, an employee read route can use this shape in src/routes/api.staff.applications.ts:

ts
import { createFileRoute } from '@tanstack/react-router'
import { visitorFrom } from '../lib/platform-auth'
import { sql } from '../db'

export const Route = createFileRoute('/api/staff/applications')({
  server: {
    handlers: {
      GET: async ({ request }) => {
        // PRECONDITION: this exact endpoint has the employee role policy.
        // Platform ingress strips spoofed identity headers; direct origins
        // must reject requests that bypass it. This check alone is not RBAC.
        const visitor = visitorFrom(request.headers)
        if (!visitor) return Response.json({ error: 'platform_login_required' }, { status: 401 })
        const records = await sql`select id, phone, status from applications order by created_at desc`
        return Response.json({ records })
      },
    },
  },
})

Adapt the table and returned columns to the app schema. The front end fetches this endpoint instead of a shared Server Function. Review and coupon mutations use the same protected prefix, validate input and same-origin/CSRF requirements, and record visitor.id for audit; it is not an authorization allowlist. Applicant reads and images still enforce application-owned record ownership.

Verification and limits

Use local tests for missing identity, input/ownership checks, and applicant isolation; test mocks do not prove production role admission. Read auth_info after policy changes to verify saved rules and effective policy for page and employee endpoint paths. An anonymous live request to employee data must not return data; test spoofed identity headers through the gateway without real credentials. Check available origin-security status, and report unknown bypass protection rather than assuming it.

Real-account sign-in requires an available account and authorized interactive access. If the agent cannot sign in, mark real sign-in, role admission and rejection, logout, and request checks after role changes as "pending acceptance" and provide manual test steps. Do not report mock tests or policy readback as successful real-account sign-in acceptance.

© different-ai-studio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/app/src/lib/skills/app-auth of different-ai-studio/teamclu.

Open the folder on GitHubat commit e4ff421

Compare with similar skills

App Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

App Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
App Auth this skilldifferent-ai-studio/teamclu167—~1.5kAutomated safety check: PassMIT
Clerk Authdavila7/claude-code-templates32k5 repos~376Automated safety check: PassMIT
AuthEpicenterHQ/epicenter4.8k—~7kAutomated safety check: PassCustom licence
Authmicrosoft/apm4k—~756Automated safety check: PassMIT
Document Signingasgeirtj/system_prompts_leaks69k—~1.5kAutomated safety check: PassCC0-1.0
Aria Rolesthedaviddias/Front-End-Checklist74k—~515Automated safety check: PassMIT

Similar skills

  • Clerk Auth

    davila7/claude-code-templates

    Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user authentication, sign in, sign up.

    32k GitHub starsUsed in 5 repos~376 tokens
    Backend & APIsAuto-check passed
  • Auth

    EpicenterHQ/epicenter

    Epicenter auth packages: @epicenter/auth and the Svelte adapter at @epicenter/auth/svelte, OAuth sessions, identity state, auth-owned fetch/WebSocket, and the reload gate that makes a page lifetime…

    4.8k GitHub stars~7k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Auth

    microsoft/apm

    Official

    Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…

    4k GitHub stars~756 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Document Signing

    asgeirtj/system_prompts_leaks

    Review documents for signature or prepare a signing packet; verify fields and recipients while keeping sending and signing under explicit user authorization.

    69k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Aria Roles

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Use valid ARIA role values.

    74k GitHub stars~515 tokensUpdated 2 days ago
    Frontend & DesignAuto-check passed
  • Clerk Auth

    sickn33/agentic-awesome-skills

    Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync

    47k GitHub starsUsed in 2 repos~355 tokens
    Backend & APIsAuto-check passed

More from different-ai-studio/teamclu

All 8 skills in this repo
  • Create Role

    different-ai-studio/teamclu

    Create a workspace role that follows the ROLE.md specification.

    167 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Image Gen

    different-ai-studio/teamclu

    生成图片:配图、插图、海报、头像、示意图、Logo 草稿、封面、banner。触发词:画一张、画个、生成图片、生成一张图、做张图、做个图、配图、出图、生图、AI 绘图、image、draw、illustration、poster。仅从零生成,不做已有图片的编辑或修改。

    167 GitHub stars~430 tokensUpdated yesterday
    Auto-check passed
  • macOS Control

    different-ai-studio/teamclu

    Control macOS desktop applications: open/operate apps, click buttons, type text, scroll, keyboard shortcuts, window management, toggle options, dropdown selections, etc.

    167 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Sentry Fix

    different-ai-studio/teamclu

    A skill your agent uses when the user wants to fix a Sentry issue, auto-repair a bug from Sentry, or create a fix PR for a Sentry error.

    167 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Sentry Monitor

    different-ai-studio/teamclu

    A skill your agent uses when the user wants to check Sentry issues, run a Sentry daily report, or monitor error trends.

    167 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Windows Control

    different-ai-studio/teamclu

    Control Windows desktop applications: open/operate apps, click controls, type text, scroll, keyboard shortcuts, window management, toggle options, lists and combos, etc.

    167 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Questions about App Auth

What does App Auth do?

A skill your agent uses when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions. App Auth is an agent skill from different-ai-studio/teamclu. Use when implementing TeamClu platform sign-in, organization-role access, employee pages or protected data endpoints in an app, or changing its login permissions.

When should I use App Auth?

App Auth fits situations like: implementing TeamClu platform sign-in; organization-role access; protected data endpoints in an app; changing its login permissions.

How do I install App Auth in Claude Code?

Run `npx skills add different-ai-studio/teamclu --skill app-auth -a claude-code`. Or copy the skill folder (packages/app/src/lib/skills/app-auth in different-ai-studio/teamclu) into .claude/skills/app-auth in your project. Claude Code loads it when a task matches its description.

How do I install App Auth in Codex?

Run `npx skills add different-ai-studio/teamclu --skill app-auth -a codex`. Or copy the skill folder (packages/app/src/lib/skills/app-auth in different-ai-studio/teamclu) into .agents/skills/app-auth in your project. Codex loads it when a task matches its description.

Can I use App Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add different-ai-studio/teamclu --skill app-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/app-auth, .gemini/skills/app-auth, .github/skills/app-auth and .opencode/skills/app-auth in your project.

What does App Auth need to run?

SKILL.md names no scripts, command-line tools or credentials: App Auth is instructions for the agent only.

Does App Auth access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is App Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does App Auth use?

App Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does App Auth use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to App Auth?

Skills that share tags, products or a category with App Auth: Clerk Auth (davila7/claude-code-templates, 32k stars), Auth (EpicenterHQ/epicenter, 4.8k stars), Auth (microsoft/apm, 4k stars) and Document Signing (asgeirtj/system_prompts_leaks, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains App Auth?

different-ai-studio (a GitHub organization) maintains it in different-ai-studio/teamclu, which has 167 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 7, 2026.

Source: different-ai-studio/teamclu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.