Agent skill

Project Map

by gjovanovicst in gjovanovicst/golang-auth-api

Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.

MITAuto-check passedBackend & APIs

Install Project Map

skills CLI
$ npx skills add gjovanovicst/golang-auth-api --skill project-map -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gjovanovicst/golang-auth-api project-map --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gjovanovicst/golang-auth-api.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/project-map .claude/skills/project-map && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
project-map
GitHub stars
129
Token cost
~2.6k tokens
SKILL.md length
860 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.

  • Tasks that involve Authentication
  • SKILL.md covers What This Project Is, Architecture, Entry Point and Domain Modules (internal/), plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Authorization and RBAC

What it does

Project Map is an agent skill from gjovanovicst/golang-auth-api. Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview. Load this first in any new session.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication, Authorization and RBAC and REST APIs. It works with PostgreSQL and Redis. The repository describes itself as: A modern, production-ready Go REST API for authentication and authorization, featuring social login, email verification, JWT, and Redis integration. The licence is MIT.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve Authorization and RBAC
  • Tasks that involve REST APIs

Example prompts

  • “/project-map”

What it can do on your machine

Read from SKILL.md and the folder at commit 795d18d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Project Map loads about 2.6k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 860 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gjovanovicst/golang-auth-api at commit 795d18d, republished under its MIT licence (© gjovanovicst). 860 words, ~2,598 tokens.

Download SKILL.mdSave it as .claude/skills/project-map/SKILL.md (or your agent's skills folder).
name
project-map
description
Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview. Load this first in any new session.
license
MIT

What This Project Is

A multi-tenant authentication and authorization REST API in Go 1.23+, using Gin, PostgreSQL (GORM), and Redis. It provides user registration, login, OAuth2 social login, TOTP/email/SMS/backup-email 2FA, WebAuthn/passkeys, magic links, RBAC, session management, OIDC provider, webhooks, brute-force protection, GeoIP IP rules, health/metrics, and a full admin interface (JSON API + HTMX GUI).

Architecture

Pattern: Repository -> Service -> Handler (Clean Architecture)

Key design decisions:

  • Concrete struct dependency injection (no interface-based DI containers)
  • Function-type callbacks between modules to avoid import cycles (e.g., RoleLookupFunc, AssignDefaultRoleFunc)
  • Multi-tenancy: Tenant -> Application -> User hierarchy
  • Every user is scoped to an AppID (UUID), with default app 00000000-0000-0000-0000-000000000001

Entry Point

  • cmd/api/main.go -- Dependency injection, route setup, server startup

Domain Modules (internal/)

internal/admin/ (11 files)

Tenant/app CRUD, OAuth provider configuration, email management, API key management, admin account authentication, 2FA for admin accounts, system settings (env -> DB -> default resolution), dashboard stats, HTMX GUI handler.

FilePurpose
gui_handler.goHTMX admin GUI (4976 lines, largest file)
handler.goAdmin JSON REST API (1146 lines)
repository.goData access for tenants, apps, OAuth, users, API keys, logs (952 lines)
account_service.goAdmin auth, sessions, 2FA, CSRF, password ops
account_repository.goAdminAccount GORM queries
dashboard_service.goDashboard stats aggregation (PostgreSQL + Redis)
settings_service.goSystem settings with 3-tier resolution (env > DB > default)
settings_repository.goSystemSetting GORM queries with upsert
apikey_util.goAPI key generation (SHA-256 hash, prefix/suffix)
apikey_util_test.goTests for API key utilities
account_service_test.goTests for admin account service
internal/user/ (5 files)

Registration, login (with self-healing role assignment), password reset, magic link auth, email change with verification, profile management.

FilePurpose
handler.goUser HTTP handlers
service.goUser business logic
repository.goUser GORM queries
handler_test.goHandler tests
service_test.goService tests
internal/social/ (4 files)

Google, Facebook, GitHub OAuth2 flows. Supports account linking and direct social login/registration.

FilePurpose
handler.goOAuth2 HTTP handlers (login, callback, link)
service.goOAuth2 business logic
repository.goSocialAccount GORM queries
oauth_state.goOAuth state parameter encoding (appID, provider, action, HMAC)
internal/twofa/ (3 files)

TOTP (authenticator apps), email-based 2FA codes, SMS 2FA (Twilio), backup email 2FA, recovery codes, trusted devices.

FilePurpose
handler.go2FA HTTP handlers (TOTP, email, SMS, backup email, trusted devices, phone management)
service.go2FA business logic (TOTP + email + SMS + backup email codes, trusted device validation)
trusted_device_repository.goTrustedDevice GORM queries
internal/webauthn/ (5 files)

Full WebAuthn support for users and admin accounts.

FilePurpose
handler.goPasskey HTTP handlers
service.goWebAuthn ceremony logic
repository.goWebAuthnCredential GORM queries
config.goRelying party configuration
user_adapter.goAdapts User/AdminAccount to WebAuthn user interface
internal/session/ (2 files)

Redis-backed sessions with refresh token rotation, multi-device tracking.

FilePurpose
service.goSession lifecycle (create, refresh, revoke, list)
handler.goSession API endpoints
internal/rbac/ (3 files)

Roles per-application, permissions as resource:action, Redis-cached authorization.

FilePurpose
service.goRBAC logic with Redis caching
repository.goRole/Permission/UserRole GORM queries
handler.goRBAC API endpoints
internal/email/ (8 files)

Multi-layered email system: Service -> VariableResolver + Renderer + Sender.

FilePurpose
service.goOrchestrator (send pipeline, template/SMTP resolution)
resolver.goVariable resolution pipeline (4 layers)
renderer.goThree template engines (go_template, placeholder, raw_html)
sender.goSMTP sending via gopkg.in/mail.v2
types.goConstants, structs, variable registry
defaults.go7 hardcoded default email templates
repository.goEmail types, templates, server configs GORM queries
email_integration_test.goIntegration tests
Show full SKILL.md (359 more words)Show less
internal/log/ (6 files)

Async channel-based logging with anomaly detection.

FilePurpose
service.goAsync log service (buffered channel, background worker)
anomaly.goAnomaly detection (new IP, new UA, unusual time)
cleanup.goScheduled log retention/cleanup
query_service.goFiltered, paginated log querying
handler.goLog API endpoints
repository.goActivityLog GORM queries
internal/middleware/ (13 files)
FilePurpose
auth.goJWT auth + token blacklist checking
admin_auth.goAdmin API Key auth (static env + DB-backed)
app_api_key.goPer-app API Key auth
gui_auth.goAdmin GUI cookie session auth
csrf.goCSRF protection for GUI
app_id.goX-App-ID header extraction
app_route_guard.goCross-app URL parameter validation
rate_limit.goRedis + in-memory fallback rate limiting
cors.goCORS configuration
security_headers.goCSP, HSTS, X-Frame-Options
auth_test.goAuth middleware tests
rate_limit_test.goRate limit tests
security_headers_test.goSecurity header tests
Other internal packages
PackageFilePurpose
internal/oidc/7 filesFull OIDC provider: discovery, authorize, token, userinfo, introspect, revoke, end_session, JWKS, RS256 id_token signing
internal/webhook/3 filesWebhook endpoint registry, async delivery dispatcher, retry queue, HMAC-SHA256 signing
internal/bruteforce/2 filesAccount lockout, progressive login delays, CAPTCHA trigger threshold
internal/geoip/3 filesMaxMind GeoLite2 service, IP rule repository, IP rule evaluator (CIDR/country per app)
internal/health/1 fileGET /health liveness, GET /metrics Prometheus, PrometheusMiddleware, MetricsSummary
internal/sms/3 filesSMS sender interface, Twilio implementation, config loader
internal/database/db.goPostgreSQL connection + GORM auto-migration
internal/redis/redis.goRedis connection + token blacklisting + session helpers
internal/config/logging.goLogging configuration
internal/util/client_info.go, frontend_url.goClient info extraction, frontend URL resolution

Shared Packages (pkg/)

PackageFilesPurpose
pkg/models/17+ model filesGORM models: User, Tenant, Application, Role, Permission, UserRole, AdminAccount, SocialAccount, WebAuthnCredential, ActivityLog, ApiKey, ApiKeyUsage, EmailType, EmailTemplate, EmailServerConfig, OAuthProviderConfig, SystemSetting, SchemaMigration, OIDCClient, OIDCAuthCode, WebhookEndpoint, WebhookDelivery, IPRule, TrustedDevice
pkg/dto/7+ filesRequest/response DTOs: auth, admin, session, RBAC, WebAuthn, email, activity_log, oidc, webhook, geoip
pkg/errors/errors.go, errors_test.goAppError type with 6 HTTP status code mappings
pkg/jwt/jwt.go, jwt_test.goJWT Claims (UserID, AppID, SessionID, TokenType, Roles), generate/parse

Web Package (web/)

FilePurpose
renderer.goHTML template renderer (embedded templates, funcMap)
context_keys.goShared context keys, SessionValidator/ApiKeyValidator interfaces, cookie helpers
static/embed.goEmbedded static files (CSS/JS)

Dependencies Between Modules

main.go wires everything:
  user.Service depends on: user.Repository, email.Service, rbac.Service (via callbacks), session.Service, webhook.Service, sms.Sender
  social.Service depends on: user.Repository, social.Repository, rbac.Service (via callbacks), session.Service, webhook.Service
  twofa.Service depends on: user.Repository, email.Service, sms.Sender, trusted_device.Repository
  twofa.Handler depends on: rbac.Service (via callbacks), session.Service, trusted_device.Repository
  webauthn.Service depends on: webauthn.Repository, user.Repository
  webauthn.Handler depends on: rbac.Service (via callbacks), session.Service, webhook.Service
  oidc.Service depends on: oidc.Repository, rbac.Service (GetUserRoleNames)
  webhook.Service depends on: webhook.Repository
  bruteforce.Service depends on: database.DB (Redis-less, PostgreSQL counters)
  geoip.IPRuleEvaluator depends on: geoip.IPRuleRepository, geoip.Service
  health.Handler depends on: database.DB, redis.Rdb, SMTP address
  rbac.Service depends on: rbac.Repository
  session.Service depends on: Redis
  email.Service depends on: email.Repository, VariableResolver, Renderer, Sender
  log.Service depends on: log.Repository, AnomalyDetector
  admin.Handler depends on: admin.Repository, email.Service, trusted_device.Repository
  admin.GUIHandler depends on: AccountService, DashboardService, admin.Repository, SettingsService, email.Service, rbac.Service, webauthn.Service, webhook.Service, oidc.Service, health.Handler, trusted_device.Repository

When To Use This Skill

Load this skill at the start of any session to understand the project structure. For domain-specific deep dives, also load the relevant skill: route-map, data-model, auth-flows, email-system, or admin-gui.

© gjovanovicst, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .opencode/skills/project-map of gjovanovicst/golang-auth-api.

Open the folder on GitHubat commit 795d18d

Compare with similar skills

Project Map next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Project Map compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Project Map this skillgjovanovicst/golang-auth-api129—~2.6kAutomated safety check: PassMIT
Discover APIrand/cc-polymath1811 repos~1.5kAutomated safety check: PassMIT
Spring Security ConfigurationAmplicode/spring-skills126—~4.3kAutomated safety check: PassNone
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Auth Implementation Patternsynulihao/AgentSkillOS6179 repos~4.4kAutomated safety check: PassNone
Nodejs Express Serverever-works/ever-works158—~965Automated safety check: PassAGPL-3.0

Similar skills

  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • Spring Security Configuration

    Amplicode/spring-skills

    Creates a Spring Security configuration class with authentication, authorization, and HTTP protection setup.

    126 GitHub stars~4.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    617 GitHub starsUsed in 9 repos~4.4k tokens
    Backend & APIsAuto-check passed
  • Nodejs Express Server

    ever-works/ever-works

    Build production-ready Express.js servers with middleware, authentication, routing, and database integration.

    158 GitHub stars~965 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    676 GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from gjovanovicst/golang-auth-api

  • Admin Gui

    gjovanovicst/golang-auth-api

    Documentation of the HTMX admin GUI including template rendering, session management, CRUD patterns, and the GUIHandler structure.

    129 GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Auth Flows

    gjovanovicst/golang-auth-api

    Detailed documentation of the 4 authentication systems, token lifecycle, middleware pipeline, session management, and RBAC authorization.

    129 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Data Model

    gjovanovicst/golang-auth-api

    All 17 GORM database models with fields, relationships, indexes, and the entity relationship diagram for the Auth API.

    129 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Email System

    gjovanovicst/golang-auth-api

    Complete documentation of the email subsystem including template resolution, variable pipeline, rendering engines, SMTP config, and default templates.

    129 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Route Map

    gjovanovicst/golang-auth-api

    Complete HTTP route structure with auth layers, middleware chains, rate limiting, and handler mappings for all API and GUI endpoints.

    129 GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Project Map

What does Project Map do?

Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview. Project Map is an agent skill from gjovanovicst/golang-auth-api. Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.

When should I use Project Map?

Project Map fits situations like: tasks that involve Authentication; tasks that involve Authorization and RBAC; tasks that involve REST APIs.

How do I install Project Map in Claude Code?

Run `npx skills add gjovanovicst/golang-auth-api --skill project-map -a claude-code`. Or copy the skill folder (.opencode/skills/project-map in gjovanovicst/golang-auth-api) into .claude/skills/project-map in your project. Claude Code loads it when a task matches its description.

How do I install Project Map in Codex?

Run `npx skills add gjovanovicst/golang-auth-api --skill project-map -a codex`. Or copy the skill folder (.opencode/skills/project-map in gjovanovicst/golang-auth-api) into .agents/skills/project-map in your project. Codex loads it when a task matches its description.

Can I use Project Map in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gjovanovicst/golang-auth-api --skill project-map -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/project-map, .gemini/skills/project-map, .github/skills/project-map and .opencode/skills/project-map in your project.

What does Project Map need to run?

SKILL.md names no scripts, command-line tools or credentials: Project Map is instructions for the agent only.

Does Project Map access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Project Map safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Project Map use?

Project Map is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Project Map use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Project Map?

Skills that share tags, products or a category with Project Map: Discover API (rand/cc-polymath, 181 stars), Spring Security Configuration (Amplicode/spring-skills, 126 stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars) and Auth Implementation Patterns (ynulihao/AgentSkillOS, 617 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Project Map?

gjovanovicst (a GitHub user) maintains it in gjovanovicst/golang-auth-api, which has 129 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on July 30, 2026.

Source: gjovanovicst/golang-auth-api on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.