Agent skill

Sidecar Auth Context

by extra-org in extra-org/extra

Working on resolver plugins, the fixed access plugin contract, mapping resolver outputs into ExecutionContext, or protected-node filtering.

MITAuto-check passedBackend & APIs

Install Sidecar Auth Context

skills CLI
$ npx skills add extra-org/extra --skill sidecar-auth-context -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install extra-org/extra sidecar-auth-context --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/extra-org/extra.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sidecar-auth-context .claude/skills/sidecar-auth-context && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sidecar-auth-context
GitHub stars
113
Token cost
~547 tokens
SKILL.md length
202 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Working on resolver plugins, the fixed access plugin contract, mapping resolver outputs into ExecutionContext, or protected-node filtering.

  • Tasks that involve GraphQL
  • SKILL.md covers When to use this skill, Files to read first, Architecture rules and Implementation rules, plus 2 more sections
  • Calls make

What it does

Sidecar Auth Context is an agent skill from extra-org/extra. Working on resolver plugins, the fixed access plugin contract, mapping resolver outputs into ExecutionContext, or protected-node filtering. Primary task is tasks/0006-sidecar-auth-context.md.

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering GraphQL. The repository describes itself as: Turn your product into an AI-powered assistant. The licence is MIT.

When your agent uses it

  • Tasks that involve GraphQL

Example prompts

  • “/sidecar-auth-context”

What it can do on your machine

Read from SKILL.md and the folder at commit 023b0a0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sidecar Auth Context loads about 547 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 202 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~547

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from extra-org/extra at commit 023b0a0, republished under its MIT licence (© extra-org). 202 words, ~547 tokens.

Download SKILL.mdSave it as .claude/skills/sidecar-auth-context/SKILL.md (or your agent's skills folder).
name
sidecar-auth-context
description
Working on resolver plugins, the fixed access plugin contract, mapping resolver outputs into ExecutionContext, or protected-node filtering. Primary task is tasks/0006-sidecar-auth-context.md.
generated
true
source
.ai/skills/sidecar-auth-context.md
<!--
This file is generated by tools/skills.
Do not edit this file directly.
Edit .ai/skills/sidecar-auth-context.md and run `make generate-ai`.
-->

Skill: Plugin Context & Access

When to use this skill

Use this when working on resolver plugins, the fixed access plugin contract, mapping resolver outputs into ExecutionContext, or protected-node filtering. Primary task: tasks/0006-sidecar-auth-context.md.

Files to read first

  • AGENTS.md
  • docs/SIDECAR_CONTEXT_AUTH.md
  • docs/ARCHITECTURE.md
  • docs/PROMPT_RENDERING.md

Architecture rules

  • The runtime contains no customer-specific auth/business logic.
  • Resolver plugins fill prompt variables before a node runs.
  • Tool plugins are separate and run during LLM execution.
  • Protected nodes are hidden from routers unless the access plugin allows them.
  • Access failures fail closed.
  • Secrets are redacted in traces.

Implementation rules

  • Implement plugin integration in src/agentplatform/context.
  • Build ctx from request headers and request data.
  • Call resolver plugin methods declared in top-level resolvers.
  • If any node has protected: true, require plugins/access.py with AccessResolver.can_access(ctx, node_id) -> bool.
  • Keep plugin instances shared where appropriate; keep request data on ExecutionContext.

Validation checklist

  • No customer-specific logic in the runtime.
  • Resolver outputs are request-scoped.
  • Protected nodes are filtered before routing.
  • Deny/error cases fail closed and are traced.
  • Secrets redacted in traces.
  • Tests use fake plugins covering allow/deny/error.
  • make check passes.

Common mistakes to avoid

  • Implementing auth/tenant/business rules inside the engine.
  • Failing open when access plugin raises.
  • Exposing resolver plugins to the LLM as tools.
  • Logging raw tokens/secrets in the trace.

© extra-org, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/sidecar-auth-context of extra-org/extra.

Open the folder on GitHubat commit 023b0a0

Compare with similar skills

Sidecar Auth Context next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sidecar Auth Context compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sidecar Auth Context this skillextra-org/extra113—~547Automated safety check: PassMIT
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works15817 repos~4kAutomated safety check: PassAGPL-3.0
GraphQL Operations with CodegenChrisWiles/claude-code-showcase6.1k3 repos~1.5kAutomated safety check: PassNone
Supabasecurvenote/curvenote1695 repos~2.2kAutomated safety check: PassCustom licence
API And Interface Designdzhalaevd/Donatello1359 repos~2.6kAutomated safety check: PassApache-2.0

Similar skills

  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 17 repos~4k tokens
    Backend & APIsAuto-check passed
  • GraphQL Operations with Codegen

    ChrisWiles/claude-code-showcase

    Sets the rules for writing GraphQL queries and mutations in .gql files, running codegen, and using generated Apollo hooks with proper error and loading handling.

    6.1k GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    169 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • API And Interface Design

    dzhalaevd/Donatello

    Guides stable API and interface design. An agent skill from dzhalaevd/Donatello.

    135 GitHub starsUsed in 9 repos~2.6k tokens
    Backend & APIsAuto-check passed
  • API Design Principles

    jh941213/my-cc-harness

    REST 및 GraphQL API 설계 원칙 가이드. An agent skill from jh941213/my-cc-harness.

    126 GitHub starsUsed in 19 repos~3.4k tokens
    Backend & APIsAuto-check passed

More from extra-org/extra

All 14 skills in this repo
  • Testing

    extra-org/extra

    How to write and run fast, deterministic, behavior-focused pytest tests that never touch real external systems.

    113 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Architecture Review

    extra-org/extra

    Guard the project's architecture invariants. An agent skill from extra-org/extra.

    113 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Documentation

    extra-org/extra

    Keep the repository's documentation accurate, honest, and synchronized with the code.

    113 GitHub stars~848 tokensUpdated 1 mo ago
    Auto-check passed
  • The standard for writing Python here — small, typed, explicit, testable modules with side effects pushed to the edges.

    113 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Skill Authoring

    extra-org/extra

    How to create or restructure a skill so the .ai/skills/ system stays consistent, operational, and trustworthy.

    113 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check passed
  • Code Review

    extra-org/extra

    Senior-level code review for the agent platform — architecture and boundaries first, then correctness, security, testability, and simplicity.

    113 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Sidecar Auth Context

What does Sidecar Auth Context do?

Working on resolver plugins, the fixed access plugin contract, mapping resolver outputs into ExecutionContext, or protected-node filtering. Sidecar Auth Context is an agent skill from extra-org/extra. Working on resolver plugins, the fixed access plugin contract, mapping resolver outputs into ExecutionContext, or protected-node filtering.

When should I use Sidecar Auth Context?

Sidecar Auth Context fits situations like: tasks that involve GraphQL.

How do I install Sidecar Auth Context in Claude Code?

Run `npx skills add extra-org/extra --skill sidecar-auth-context -a claude-code`. Or copy the skill folder (.claude/skills/sidecar-auth-context in extra-org/extra) into .claude/skills/sidecar-auth-context in your project. Claude Code loads it when a task matches its description.

How do I install Sidecar Auth Context in Codex?

Run `npx skills add extra-org/extra --skill sidecar-auth-context -a codex`. Or copy the skill folder (.claude/skills/sidecar-auth-context in extra-org/extra) into .agents/skills/sidecar-auth-context in your project. Codex loads it when a task matches its description.

Can I use Sidecar Auth Context in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add extra-org/extra --skill sidecar-auth-context -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sidecar-auth-context, .gemini/skills/sidecar-auth-context, .github/skills/sidecar-auth-context and .opencode/skills/sidecar-auth-context in your project.

What does Sidecar Auth Context need to run?

Going by SKILL.md and its folder, Sidecar Auth Context needs the command-line tools its instructions call (make).

Does Sidecar Auth Context access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sidecar Auth Context safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sidecar Auth Context use?

Sidecar Auth Context is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sidecar Auth Context use?

About 547 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sidecar Auth Context?

Skills that share tags, products or a category with Sidecar Auth Context: API Designer (Jeffallan/claude-skills, 12k stars), Nodejs Backend Patterns (ever-works/ever-works, 158 stars), GraphQL Operations with Codegen (ChrisWiles/claude-code-showcase, 6.1k stars) and Supabase (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sidecar Auth Context?

extra-org (a GitHub organization) maintains it in extra-org/extra, which has 113 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 7, 2026.

Source: extra-org/extra on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.