Agent skill

Configuration

by greenpau in greenpau/caddy-security

Build or review caddy-security Caddyfiles and select focused configuration skills.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration .claude/skills/configuration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration
GitHub stars
2.3k
Token cost
~2.6k tokens
SKILL.md length
972 words
Files
5 (incl. references)
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Build or review caddy-security Caddyfiles and select focused configuration skills.

  • Works in 5 steps: Identify the requested auth flow: local… → Follow only the matching Domain Map… → Start from the smallest valid security… → …
  • Security app declarations and authenticate/authorize route wiring
  • SKILL.md covers Purpose, Syntax Currency, Workflow and Common Shape, plus 3 more sections
  • Needs JWT_SHARED_KEY

What it does

Configuration is an agent skill from greenpau/caddy-security. Build or review caddy-security Caddyfiles and select focused configuration skills. Use for security app declarations and authenticate/authorize route wiring.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `agents/openai.yaml`, `references/authcrunch-compatibility.md` and `references/operator-examples.md`).

It sits in Backend & APIs. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Security app declarations and authenticate/authorize route wiring

Example prompts

  • “/configuration”

Requirements

  • A credential in JWT_SHARED_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify the requested auth flow: local login, LDAP, OAuth/OIDC, SAML, API
  2. Follow only the matching Domain Map routes before drafting the Caddyfile.
  3. Start from the smallest valid security app block, then add route handlers
  4. Prefer environment placeholders or secret lookups for passwords, API keys,
  5. Check generated syntax against the local wrappers, selected upstream grammar

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are caddyfile).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SHARED_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration loads about 2.6k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 43 tokens; SKILL.md has 972 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 972 words, ~2,627 tokens.

Download SKILL.mdSave it as .claude/skills/configuration/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
configuration
description
Build or review caddy-security Caddyfiles and select focused configuration skills. Use for security app declarations and authenticate/authorize route wiring.

Configuration

Purpose

Use this skill as the entry point for generating caddy-security Caddyfile configuration. Keep the parent skill as a router: load only the domain skills needed for the requested configuration.

The repository scope applies to every configuration domain. Upstream paths in these skills are read-only implementation references. Keep Caddyfiles, fixtures, custom assets, and local validation changes here; missing upstream behavior is separate work, not a reason to edit or run tests in ../go-authcrunch.

The parser entry point is caddyfile.go. Put security { ... } inside Caddy's outer global options block, { ... }. Route-level HTTP integrations reference configured objects with authenticate with <portal> and authorize with <policy>. Define the global security option once; duplicate blocks fail instead of silently replacing the previous app. Collect declarations inside that one block.

Do not generate global Caddy directive-order overrides for caddy-security by default. authenticate and authorize register their own order in plugin_authn.go and plugin_authz.go. Only add global order directives when debugging a proven directive-order conflict with another third-party plugin, and explain why.

Syntax Currency

Use Syntax maintenance when auditing syntax, changing directives, or consuming a Caddy/go-authcrunch dependency update. The AuthCrunch compatibility map tracks changed upstream surfaces, Caddy ownership and validation. The Caddy wrappers and the selected upstream parsers jointly define the syntax. Maintain Go syntax comments, standalone Caddyfiles, fixtures, and domain skills together, including grammar delegated to upstream libraries or external modules.

Keep recognized-but-restricted forms visible with their validation status. For example, document logout_url <logout_url> and the shared OAuth validator's rejection; do not erase it or silently filter it from input. Upstream typed fields alone do not establish Caddyfile support.

Examples containing only inner blocks or individual directives are fragments for the enclosing scope described by the domain skill. Complete configurations need the outer global block and site routes. <value> denotes a required value, <a|b> a required choice, [value] an optional argument, and ... repetition; syntax catalogues with these placeholders are not runnable examples.

Workflow

  1. Identify the requested auth flow: local login, LDAP, OAuth/OIDC, SAML, API keys, basic auth, registration, SSO app, or policy-only authorization.
  2. Follow only the matching Domain Map routes before drafting the Caddyfile. HTTP handler placement includes the HTTP integration route; external SAML login follows the SAML provider route, separately from portal SSO apps. Authentication's narrower routes cover portal sub-blocks. HTTP client/API contracts belong to authentication-portal-api.
  3. Start from the smallest valid security app block, then add route handlers that reference the configured portal or policy by name.
  4. Prefer environment placeholders or secret lookups for passwords, API keys, client secrets, signing keys, and private material.
  5. Check generated syntax against the local wrappers, selected upstream grammar and validators, and the fixtures under testdata/caddyfile_adapt/. Test and fixture changes follow the testing contract.

Common Shape

caddyfile
{
	security {
		local identity store localdb {
			realm local
			path assets/config/users.json
		}

		authentication portal myportal {
			crypto key sign-verify {env.JWT_SHARED_KEY}
			enable identity store localdb
		}

		authorization policy app_policy {
			crypto key verify {env.JWT_SHARED_KEY}
			set auth url /auth
			allow roles authp/admin authp/user
		}
	}
}

example.com {
	@portal path /auth /auth/*
	route @portal {
		authenticate with myportal
	}

	route /app* {
		authorize with app_policy
		reverse_proxy 127.0.0.1:8080
	}
}

Use the optional matcher forms only when needed:

caddyfile
@portal path /auth /auth/*
authenticate @portal with myportal
authorize /api/* with api_policy
Show full SKILL.md (514 more words)Show less

Domain Map

  • Use configuration-logging to configure diagnostic skip rules, parsed by caddyfile_logging.go. AuthCrunch component filtering is supported; Caddy's independent authentication middleware logger needs an upstream hook.
  • Use configuration-state to configure persistent runtime state, parsed by caddyfile_state.go. Stop/start persistence also supports policy-only OAuth.
  • Use configuration-http-integrations to place authenticate and authorize HTTP routes, parsed by plugin_authn.go and plugin_authz.go.
  • Use configuration-authentication to configure authentication portals, parsed by caddyfile_authn.go and caddyfile_authn_*.go. Its routes own cookies, UI, transforms, cross-device login, and Portal APIs.
  • Use configuration-authorization to configure authorization policies, parsed by caddyfile_authz.go and caddyfile_authz_*.go.
  • Use configuration-crypto to configure crypto directives and token or System API keys, parsed by caddyfile_authn_crypto.go and caddyfile_authz_crypto.go, implemented by go-authcrunch/pkg/kms, and resolved by caddyfile_resolve.go.
  • Use configuration-credentials to configure reusable generic credentials, parsed by caddyfile_credentials.go.
  • Use configuration-identity-stores to configure local and LDAP stores, parsed by caddyfile_identity.go and caddyfile_identity_store.go.
  • Use configuration-messaging to configure messaging providers, parsed by caddyfile_messaging.go.
  • Use configuration-oauth-providers to configure external OAuth/OIDC identity providers, parsed by caddyfile_identity.go, caddyfile_identity_provider.go, and caddyfile_identity_provider_oauth.go, delegated to go-authcrunch/pkg/idp/parser and pkg/idp/oauth/parser.
  • Use configuration-oauth-applications to register named OAuth clients, configure private registration storage and portal oidc provider blocks, or provision credentials through the CLI. caddyfile_oauth_application.go delegates client parsing to go-authcrunch/pkg/oidc/parser and Config.AddOAuthApplication. Clients have explicit or persisted credentials. caddyfile_oauth_registration_store.go parses oauth registration store; app JSON uses oauth_registration_store. This holds application credentials and provider keys independently of user registration and sessions.
  • Use configuration-saml-providers to configure SAML login identity providers, parsed by caddyfile_identity.go and caddyfile_identity_provider.go, implemented by go-authcrunch/pkg/idp/saml.
  • Use configuration-registrations to configure user registrations, parsed by caddyfile_user.go and caddyfile_user_registration.go.
  • Use configuration-runtime-resolution to configure runtime placeholder and secret resolution, applied by caddyfile_resolve.go.
  • Use configuration-secrets to configure secrets managers and secret lookups, parsed by caddyfile_secrets.go and resolved by caddyfile_resolve.go.
  • Use configuration-sso-app to configure SSO app providers, parsed by caddyfile_sso_provider.go.

Portal JSON/admin API contracts belong to authentication-portal-api, routed from configuration-authentication. The upstream go-authcrunch/pkg/authn/handle_* handlers implement them; authentication portal options enable them in Caddyfile.

Keep this map and its intermediate authentication routes synchronized with every directory matching .codex/skills/configuration-*.

SAML identity-provider blocks are distinct from SSO app providers: the SAML provider route configures external login, while the SSO app route configures portal-provided SAML app endpoints.

Fixtures

Use qualified operator examples for complete outer Caddyfiles and their generated, tested native JSON: legacy access, local token refresh, Ed25519 upstream OAuth, named applications, two OPs with refresh, and explicit administrative private export. It covers private setup, exact provisioning commands, realm/token/cookie boundaries and replacement limits.

Use these examples for orientation:

  • testdata/caddyfile_adapt/testcase_security_authentication_portal.Caddyfile for local users, portal crypto, cookies, UI links, and transforms.
  • testdata/caddyfile_adapt/testcase_authenticate_with_oauth.Caddyfile for OAuth plus authorization policy wiring.
  • testdata/caddyfile_adapt/testcase_authenticate_with_registration.Caddyfile for registration, messaging, local users, and portal wiring.
  • testdata/caddyfile_adapt/testcase_security_with_secrets.Caddyfile for secrets manager values consumed by users and crypto keys.

Acceptance criteria

  • A requested login/provider combination has one owning route; external SAML login, SAML SSO apps, external OAuth login, and portal OIDC clients remain distinct.
  • Complete examples include global security declarations, matching portal/policy names, and exact portal mounts. Fragments state the enclosing scope and missing wiring; successful adaptation alone is not reported as successful login.
  • Runtime values are checked against the fields that actually resolve. Missing plugins or unsupported upstream behavior remain explicit qualification limits.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in .codex/skills/configuration of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml
  • references/authcrunch-compatibility.md
  • references/operator-examples.md
  • references/syntax-maintenance.md

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration this skillgreenpau/caddy-security2.3k—~2.6kAutomated safety check: PassApache-2.0
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api43k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    43k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • Configuration Users

    greenpau/caddy-security

    Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.

    2.3k GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Configuration

What does Configuration do?

Build or review caddy-security Caddyfiles and select focused configuration skills. Configuration is an agent skill from greenpau/caddy-security. Build or review caddy-security Caddyfiles and select focused configuration skills.

When should I use Configuration?

Configuration fits situations like: security app declarations and authenticate/authorize route wiring.

How do I install Configuration in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration -a claude-code`. Or copy the skill folder (.codex/skills/configuration in greenpau/caddy-security) into .claude/skills/configuration in your project. Claude Code loads it when a task matches its description.

How do I install Configuration in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration -a codex`. Or copy the skill folder (.codex/skills/configuration in greenpau/caddy-security) into .agents/skills/configuration in your project. Codex loads it when a task matches its description.

Can I use Configuration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration, .gemini/skills/configuration, .github/skills/configuration and .opencode/skills/configuration in your project.

What does Configuration need to run?

Going by SKILL.md and its folder, Configuration needs credentials named JWT_SHARED_KEY. Our summary lists: A credential in JWT_SHARED_KEY.

Does Configuration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration use?

Configuration is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration use?

About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Configuration?

Skills that share tags, products or a category with Configuration: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 43k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.