Agent skill

Better Auth Security Best Practices

by EpicenterHQ in EpicenterHQ/epicenter

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

Custom licenceAuto-check passedBackend & APIs

Install Better Auth Security Best Practices

skills CLI
$ npx skills add EpicenterHQ/epicenter --skill better-auth-security-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EpicenterHQ/epicenter better-auth-security-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EpicenterHQ/epicenter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/better-auth-security-best-practices .claude/skills/better-auth-security-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
better-auth-security-best-practices
GitHub stars
4.8k
Token cost
~896 tokens
SKILL.md length
360 words
Files
2 (incl. references)
Skills in repo
65
Repo updated
First seen
Licence
Custom licence

At a glance

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

  • Reviewing auth security
  • SKILL.md covers Reference Repositories, Upstream Grounding, Do Not Trust Localhost In… and Account Linking and Provider…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Brute-force protection

What it does

Better Auth Security Best Practices is an agent skill from EpicenterHQ/epicenter. Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. Use when reviewing auth security, brute-force protection, token handling, or deployment safety.

Its SKILL.md is about 900 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/configuration.md`).

It sits in Backend & APIs, covering Security review, Web application vulnerabilities and Rate limiting. It works with Better Auth and GitHub. The repository describes itself as: Open-source, local-first apps.

When your agent uses it

  • Reviewing auth security
  • Brute-force protection
  • Deployment safety

Example prompts

  • “/better-auth-security-best-practices”

What it can do on your machine

Read from SKILL.md and the folder at commit 5b4bb69. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Better Auth Security Best Practices loads about 896 tokens when it runs, and up to ~3.5k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 360 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~896
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 360 words (~896 tokens).

“When Better Auth rate limiting, CSRF and origin checks, cookie settings, secret handling, token encryption, audit behavior, or deployment security defaults affect correctness, ask DeepWiki a narrow question against better-auth/better-auth before relying on memory. Use it to orient, then verify…”

— opening of SKILL.md by EpicenterHQ, Custom licence
name
better-auth-security-best-practices
metadata.author
epicenter
metadata.version
1.0

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file (references) in .agents/skills/better-auth-security-best-practices of EpicenterHQ/epicenter.

  • SKILL.md
  • references/configuration.md

Open the folder on GitHubat commit 5b4bb69

Compare with similar skills

Better Auth Security Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Better Auth Security Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Better Auth Security Best Practices this skillEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence
Better Auth Security Best Practicesagutinbaigo28/financial-agent-api128—~2.7kAutomated safety check: PassNone
Implementing API Threat Protection With Apigeemukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
API Security Best Practicesdavila7/claude-code-templates33k8 repos~5.8kAutomated safety check: PassMIT
API Security ReviewOWASP/secure-agent-playbook188—~744Automated safety check: PassCC-BY-4.0
Security PatternsCloudAI-X/claude-workflow-v21.4k—~3.6kAutomated safety check: NotesMIT

Similar skills

  • Better Auth Security Best Practices

    agutinbaigo28/financial-agent-api

    Configure rate limiting, manage auth secrets, set up CSRF protection, define trusted origins, secure sessions and cookies, encrypt OAuth tokens, track IP addresses, and implement audit logging for…

    128 GitHub stars~2.7k tokensUpdated 26 days ago
    Backend & APIsAuto-check passed
  • Implementing API Threat Protection With Apigee

    mukul975/Anthropic-Cybersecurity-Skills

    Implements API threat protection using Google Apigee reverse-proxy policies, including JSON/XML threat protection, OAuth 2.0 enforcement, SpikeArrest rate limiting, regex-based threat detection, and…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • API Security Best Practices

    davila7/claude-code-templates

    Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

    33k GitHub starsUsed in 8 repos~5.8k tokens
    Backend & APIsAuto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    188 GitHub stars~744 tokensUpdated 15 days ago
    SecurityAuto-check passed
  • Security Patterns

    CloudAI-X/claude-workflow-v2

    Implements authentication, authorization, encryption, secrets management, and security hardening patterns.

    1.4k GitHub stars~3.6k tokensUpdated 4 days ago
    Backend & APIsAuto-check: notes
  • Security Review

    affaan-m/ECC

    Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

    276k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: notes

More from EpicenterHQ/epicenter

All 65 skills in this repo
  • Agent Instructions

    EpicenterHQ/epicenter

    Write and maintain repository guidance across AGENTS.md, CLAUDE.md, and .agents/skills.

    4.8k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Consult Claude

    EpicenterHQ/epicenter

    Assign Claude Code a read-only investigation, recommendation, or finished text draft.

    4.8k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Cohesion Over Testability

    EpicenterHQ/epicenter

    Collapse test-shaped production boundaries while preserving behavior and coverage.

    4.8k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Collapse Pass

    EpicenterHQ/epicenter

    Remove indirection that does not earn its boundary across a diff or package.

    4.8k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Error Handling

    EpicenterHQ/epicenter

    Apply Wellcrafted Result patterns to fallible operations and preserve failures at boundaries.

    4.8k GitHub stars~1.4k tokensUpdated 2 days ago
    Auto-check passed
  • Factory Function Composition

    EpicenterHQ/epicenter

    Factory function patterns to compose clients and services. An agent skill from EpicenterHQ/epicenter.

    4.8k GitHub stars~3k tokensUpdated 2 days ago
    Auto-check passed

Questions about Better Auth Security Best Practices

What does Better Auth Security Best Practices do?

Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging. Better Auth Security Best Practices is an agent skill from EpicenterHQ/epicenter. Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

When should I use Better Auth Security Best Practices?

Better Auth Security Best Practices fits situations like: reviewing auth security; brute-force protection; deployment safety.

How do I install Better Auth Security Best Practices in Claude Code?

Run `npx skills add EpicenterHQ/epicenter --skill better-auth-security-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/better-auth-security-best-practices in EpicenterHQ/epicenter) into .claude/skills/better-auth-security-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Better Auth Security Best Practices in Codex?

Run `npx skills add EpicenterHQ/epicenter --skill better-auth-security-best-practices -a codex`. Or copy the skill folder (.agents/skills/better-auth-security-best-practices in EpicenterHQ/epicenter) into .agents/skills/better-auth-security-best-practices in your project. Codex loads it when a task matches its description.

Can I use Better Auth Security Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EpicenterHQ/epicenter --skill better-auth-security-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/better-auth-security-best-practices, .gemini/skills/better-auth-security-best-practices, .github/skills/better-auth-security-best-practices and .opencode/skills/better-auth-security-best-practices in your project.

What does Better Auth Security Best Practices need to run?

SKILL.md names no scripts, command-line tools or credentials: Better Auth Security Best Practices is instructions for the agent only.

Does Better Auth Security Best Practices access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Better Auth Security Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Better Auth Security Best Practices use?

Better Auth Security Best Practices has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Better Auth Security Best Practices use?

About 896 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Better Auth Security Best Practices?

Skills that share tags, products or a category with Better Auth Security Best Practices: Better Auth Security Best Practices (agutinbaigo28/financial-agent-api, 128 stars), Implementing API Threat Protection With Apigee (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), API Security Best Practices (davila7/claude-code-templates, 33k stars) and API Security Review (OWASP/secure-agent-playbook, 188 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Better Auth Security Best Practices?

EpicenterHQ (a GitHub organization) maintains it in EpicenterHQ/epicenter, which has 4,822 GitHub stars. The repository holds 65 skills in this directory. The repository was last updated on October 8, 2026.

Source: EpicenterHQ/epicenter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.