Memstack Security API Audit
cwinvestments/memstack
A skill your agent uses when the user says 'audit API', 'check API security', 'API routes security', 'endpoint audit', 'check my routes', or needs to verify API route protection.
Provides authentication implementation patterns for Next.js 15+ App Router using Auth.js 5 (NextAuth.js).
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit nextjs-authentication --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/nextjs-authentication .claude/skills/nextjs-authentication && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nextjs-authentication" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/nextjs-authentication into .claude/skills/nextjs-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nextjs-authentication", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/nextjs-authenticationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit nextjs-authentication --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/nextjs-authentication .agents/skills/nextjs-authentication && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nextjs-authentication" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/nextjs-authentication into .agents/skills/nextjs-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nextjs-authentication", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit nextjs-authentication --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/nextjs-authentication .cursor/skills/nextjs-authentication && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nextjs-authentication" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/nextjs-authentication into .cursor/skills/nextjs-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nextjs-authentication", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/giuseppe-trisciuoglio/developer-kit.git --path plugins/developer-kit-typescript/skills/nextjs-authentication--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit nextjs-authentication --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/nextjs-authentication .gemini/skills/nextjs-authentication && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nextjs-authentication" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/nextjs-authentication into .gemini/skills/nextjs-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nextjs-authentication", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install giuseppe-trisciuoglio/developer-kit nextjs-authenticationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/nextjs-authentication .github/skills/nextjs-authentication && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nextjs-authentication" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/nextjs-authentication into .github/skills/nextjs-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nextjs-authentication", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit nextjs-authentication --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/nextjs-authentication .opencode/skills/nextjs-authentication && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nextjs-authentication" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/nextjs-authentication into .opencode/skills/nextjs-authentication/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nextjs-authentication", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nextjs-authenticationProvides authentication implementation patterns for Next.js 15+ App Router using Auth.js 5 (NextAuth.js).
Nextjs Authentication is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides authentication implementation patterns for Next.js 15+ App Router using Auth.js 5 (NextAuth.js). Use when setting up authentication flows, implementing protected routes, managing sessions in Server Components and Server Actions, configuring OAuth providers, implementing role-based access control, or handling sign-in/sign-out flows in Next.js applications.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/authjs-setup.md`, `references/best-practices.md` and `references/database-adapter.md`).
It sits in Backend & APIs, covering Authorization and RBAC and Authentication. It works with Next.js. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBashFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmopensslFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AUTH_SECRETGITHUB_SECRETGOOGLE_CLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nextjs Authentication loads about 2.8k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 505 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Create `.env.local` with required variables:allowed-tools: Read, Write, Edit, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 505 words, ~2,811 tokens.
.claude/skills/nextjs-authentication/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Provides authentication implementation patterns for Next.js 15+ App Router using Auth.js 5 (NextAuth.js), covering the complete authentication lifecycle from initial setup to production-ready role-based access control implementations.
Install Auth.js v5 (beta) for Next.js App Router:
npm install next-auth@betaCreate .env.local with required variables:
# Required for Auth.js
AUTH_SECRET="your-secret-key-here"
AUTH_URL="http://localhost:3000"
# OAuth Providers (add as needed)
GITHUB_ID="your-github-client-id"
GITHUB_SECRET="your-github-client-secret"
GOOGLE_CLIENT_ID="your-google-client-id"
GOOGLE_CLIENT_SECRET="your-google-client-secret"Generate AUTH_SECRET with:
openssl rand -base64 32Create auth.ts in the project root with providers and callbacks:
import NextAuth from "next-auth";
import GitHub from "next-auth/providers/github";
import Google from "next-auth/providers/google";
export const {
handlers: { GET, POST },
auth,
signIn,
signOut,
} = NextAuth({
providers: [
GitHub({
clientId: process.env.GITHUB_ID!,
clientSecret: process.env.GITHUB_SECRET!,
}),
Google({
clientId: process.env.GOOGLE_CLIENT_ID!,
clientSecret: process.env.GOOGLE_CLIENT_SECRET!,
}),
],
callbacks: {
async jwt({ token, user }) {
if (user) {
token.id = user.id;
}
return token;
},
async session({ session, token }) {
if (token) {
session.user.id = token.id as string;
}
return session;
},
},
pages: {
signIn: "/login",
error: "/error",
},
});Create app/api/auth/[...nextauth]/route.ts:
export { GET, POST } from "@/auth";Create middleware.ts in the project root:
import { auth } from "@/auth";
import { NextResponse } from "next/server";
export default auth((req) => {
const { nextUrl } = req;
const isLoggedIn = !!req.auth;
const isApiAuthRoute = nextUrl.pathname.startsWith("/api/auth");
const isPublicRoute = ["/", "/login", "/register"].includes(nextUrl.pathname);
const isProtectedRoute = nextUrl.pathname.startsWith("/dashboard");
if (isApiAuthRoute) return NextResponse.next();
if (!isLoggedIn && isProtectedRoute) {
return NextResponse.redirect(new URL("/login", nextUrl));
}
if (isLoggedIn && nextUrl.pathname === "/login") {
return NextResponse.redirect(new URL("/dashboard", nextUrl));
}
return NextResponse.next();
});
export const config = {
matcher: ["/((?!_next/static|_next/image|favicon.ico|.*\\.png$).*)"],
};Use the auth() function to access session in Server Components:
import { auth } from "@/auth";
import { redirect } from "next/navigation";
export default async function DashboardPage() {
const session = await auth();
if (!session) {
redirect("/login");
}
return (
<div>
<h1>Welcome, {session.user.name}</h1>
</div>
);
}Always verify authentication in Server Actions before mutations:
"use server";
import { auth } from "@/auth";
export async function createTodo(formData: FormData) {
const session = await auth();
if (!session?.user) {
throw new Error("Unauthorized");
}
// Proceed with protected action
const title = formData.get("title") as string;
await db.todo.create({
data: { title, userId: session.user.id },
});
}Create a login page with server action:
// app/login/page.tsx
import { signIn } from "@/auth";
import { redirect } from "next/navigation";
export default function LoginPage() {
async function handleLogin(formData: FormData) {
"use server";
const result = await signIn("credentials", {
email: formData.get("email"),
password: formData.get("password"),
redirect: false,
});
if (result?.error) {
return { error: "Invalid credentials" };
}
redirect("/dashboard");
}
return (
<form action={handleLogin}>
<input name="email" type="email" placeholder="Email" required />
<input name="password" type="password" placeholder="Password" required />
<button type="submit">Sign In</button>
</form>
);
}For client-side sign-out:
"use client";
import { signOut } from "next-auth/react";
export function SignOutButton() {
return <button onClick={() => signOut()}>Sign Out</button>;
}Check roles in Server Components:
import { auth } from "@/auth";
import { unauthorized } from "next/navigation";
export default async function AdminPage() {
const session = await auth();
if (session?.user?.role !== "admin") {
unauthorized();
}
return <AdminDashboard />;
}Create types/next-auth.d.ts for type-safe sessions:
import { DefaultSession } from "next-auth";
declare module "next-auth" {
interface Session {
user: {
id: string;
role: "user" | "admin";
} & DefaultSession["user"];
}
interface User {
role?: "user" | "admin";
}
}
declare module "next-auth/jwt" {
interface JWT {
id?: string;
role?: "user" | "admin";
}
}Input: User needs a dashboard accessible only to authenticated users
Implementation:
// app/dashboard/page.tsx
import { auth } from "@/auth";
import { redirect } from "next/navigation";
import { getUserTodos } from "@/app/lib/data";
export default async function DashboardPage() {
const session = await auth();
if (!session?.user?.id) {
redirect("/login");
}
const todos = await getUserTodos(session.user.id);
return (
<main>
<h1>Welcome, {session.user.name}</h1>
<p>Email: {session.user.email}</p>
<TodoList todos={todos} />
</main>
);
}Output: Dashboard renders only for authenticated users, with their specific data.
Input: Admin panel should be accessible only to users with "admin" role
Implementation:
// app/admin/page.tsx
import { auth } from "@/auth";
import { unauthorized } from "next/navigation";
export default async function AdminPage() {
const session = await auth();
if (session?.user?.role !== "admin") {
unauthorized();
}
return (
<main>
<h1>Admin Panel</h1>
<p>Welcome, administrator {session.user.name}</p>
</main>
);
}Output: Only admin users see the panel; others get 401 error.
Input: Form submission should only work for authenticated users
Implementation:
// app/components/create-todo-form.tsx
"use server";
import { auth } from "@/auth";
import { revalidatePath } from "next/cache";
export async function createTodo(formData: FormData) {
const session = await auth();
if (!session?.user?.id) {
throw new Error("Unauthorized");
}
const title = formData.get("title") as string;
await db.todo.create({
data: {
title,
userId: session.user.id,
},
});
revalidatePath("/dashboard");
}
// Usage in component
export function CreateTodoForm() {
return (
<form action={createTodo}>
<input name="title" placeholder="New todo..." required />
<button type="submit">Add Todo</button>
</form>
);
}Output: Todo created only for authenticated user; unauthorized requests throw error.
useSession() for reactive session updatescache() for repeated lookups in the same renderauth() function in unit tests// ❌ WRONG: Setting cookies in Server Component
export default async function Page() {
cookies().set("key", "value"); // Won't work
}
// ✅ CORRECT: Use Server Action
async function setCookieAction() {
"use server";
cookies().set("key", "value");
}// ❌ WRONG: Database queries in Middleware
export default auth(async (req) => {
const user = await db.user.findUnique(); // Won't work in Edge
});
// ✅ CORRECT: Use only Edge-compatible APIs
export default auth(async (req) => {
const session = req.auth; // This works
});unauthorized() for unauthenticated access, redirect() for other caseshttpOnly cookiessameSite attributes© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in plugins/developer-kit-typescript/skills/nextjs-authentication of giuseppe-trisciuoglio/developer-kit.
Open the folder on GitHubat commit fe73fb3
Nextjs Authentication next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nextjs Authentication this skillgiuseppe-trisciuoglio/developer-kit | 357 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Memstack Security API Auditcwinvestments/memstack | 423 | — | ~3.9k | Automated safety check: Pass | Proprietary | |
| Authaiskillstore/marketplace | 433 | — | ~1.6k | Automated safety check: Pass | None | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Payloadpayloadcms/payload | 45k | 5 repos | ~6.2k | Automated safety check: Pass | MIT | |
| Supabasecurvenote/curvenote | 170 | 5 repos | ~2.2k | Automated safety check: Pass | Custom licence |
cwinvestments/memstack
A skill your agent uses when the user says 'audit API', 'check API security', 'API routes security', 'endpoint audit', 'check my routes', or needs to verify API route protection.
aiskillstore/marketplace
Authentication and access control skill for Next.js 15 + Supabase applications.
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
payloadcms/payload
A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
giuseppe-trisciuoglio/developer-kit
Generates complete CRUD modules for NestJS applications with Drizzle ORM.
giuseppe-trisciuoglio/developer-kit
Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.
giuseppe-trisciuoglio/developer-kit
Provides and generates complete CRUD workflows for Spring Boot 3 services.
giuseppe-trisciuoglio/developer-kit
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…
giuseppe-trisciuoglio/developer-kit
Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.
giuseppe-trisciuoglio/developer-kit
Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.
Works with
Categories
Provides authentication implementation patterns for Next.js 15+ App Router using Auth.js 5 (NextAuth.js). Nextjs Authentication is an agent skill from giuseppe-trisciuoglio/developer-kit.js).
Nextjs Authentication fits situations like: setting up authentication flows; implementing protected routes; managing sessions in Server Components and Server Actions; configuring OAuth providers.
Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a claude-code`. Or copy the skill folder (plugins/developer-kit-typescript/skills/nextjs-authentication in giuseppe-trisciuoglio/developer-kit) into .claude/skills/nextjs-authentication in your project. Claude Code loads it when a task matches its description.
Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a codex`. Or copy the skill folder (plugins/developer-kit-typescript/skills/nextjs-authentication in giuseppe-trisciuoglio/developer-kit) into .agents/skills/nextjs-authentication in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill nextjs-authentication -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nextjs-authentication, .gemini/skills/nextjs-authentication, .github/skills/nextjs-authentication and .opencode/skills/nextjs-authentication in your project.
Going by SKILL.md and its folder, Nextjs Authentication needs the command-line tools its instructions call (npm and openssl) and credentials named AUTH_SECRET, GITHUB_SECRET and GOOGLE_CLIENT_SECRET. Our summary lists: Node.js; A credential in AUTH_SECRET; A credential in GITHUB_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Nextjs Authentication is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Nextjs Authentication: Memstack Security API Audit (cwinvestments/memstack, 423 stars), Auth (aiskillstore/marketplace, 433 stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars) and Payload (payloadcms/payload, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.
Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.