Fortify Development
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
Configure portal UI templates, static assets, themes, languages, links, and custom CSS/JS/HTML.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-ui --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-authentication-ui .claude/skills/configuration-authentication-ui && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuration-authentication-ui" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-ui into .claude/skills/configuration-authentication-ui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-ui", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-uiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-ui --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/configuration-authentication-ui .agents/skills/configuration-authentication-ui && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuration-authentication-ui" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-ui into .agents/skills/configuration-authentication-ui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-ui", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-ui --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/configuration-authentication-ui .cursor/skills/configuration-authentication-ui && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuration-authentication-ui" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-ui into .cursor/skills/configuration-authentication-ui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-ui", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/configuration-authentication-ui--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-ui --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/configuration-authentication-ui .gemini/skills/configuration-authentication-ui && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuration-authentication-ui" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-ui into .gemini/skills/configuration-authentication-ui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-ui", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security configuration-authentication-uiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/configuration-authentication-ui .github/skills/configuration-authentication-ui && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuration-authentication-ui" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-ui into .github/skills/configuration-authentication-ui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-ui", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security configuration-authentication-ui --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/configuration-authentication-ui .opencode/skills/configuration-authentication-ui && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuration-authentication-ui" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-authentication-ui into .opencode/skills/configuration-authentication-ui/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-authentication-ui", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuration-authentication-uiConfigure portal UI templates, static assets, themes, languages, links, and custom CSS/JS/HTML.
Configuration Authentication UI is an agent skill from greenpau/caddy-security. Configure portal UI templates, static assets, themes, languages, links, and custom CSS/JS/HTML. Use for branding and refresh-aware templates; transform-generated links belong to user transforms.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Backend & APIs, covering Authentication. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are caddyfile and gotemplate).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Configuration Authentication UI loads about 2k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 728 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 728 words, ~1,958 tokens.
.claude/skills/configuration-authentication-ui/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.The v1.3.3 embedded portal and OIDC pages supply their themed layouts and
browser color preference behavior automatically. theme basic remains the
only registered Caddy theme; do not invent theme dark or theme light.
Profile assets include profile/images/banner.svg, favicon.svg and
logo.svg. Custom static PNG assets remain supported. Avoid pinning internal
hashed assets when customizing templates; inspect the selected embedded UI.
Conditional flow selection and profile policy editing need no extra UI setting;
see authentication flows.
Use this skill for ui blocks inside authentication portal <name> blocks.
Read these files when details matter:
caddyfile_authn_ui.go for accepted Caddyfile UI syntax.../go-authcrunch/pkg/authn/ui/params.go for
authcrunch UI parameters.../go-authcrunch/pkg/authn/portal.go for UI
defaults, template loading, static assets, theme and language validation.../go-authcrunch/pkg/authn/ui/static.go for
static asset loading and content-type handling.The surrounding portal belongs to
configuration-authentication.
Transform-generated ui link entries belong to
configuration-authentication-user-transforms;
they are separate from static links in this UI block.
The Caddyfile ui parser supports templates, metadata, private links, static
assets, themes, languages, logos, auto_redirect_url, and custom CSS,
JavaScript, or HTML-header injection. Use parser-supported forms:
authentication portal myportal {
ui {
theme basic
language en
meta title "Example Authentication Portal"
meta author "Example"
meta description "Example sign-in portal"
template login ui/login.template
static_asset "assets/images/logo.png" "image/png" ui/logo.png
logo url "/auth/assets/images/logo.png"
logo description "Example"
auto_redirect_url /auth/portal
links {
"My Identity" "/auth/whoami" icon "las la-user"
"Docs" "https://docs.example.com/" target_blank
}
}
}links entries use a title as the subdirective token and require a target URL.
Optional keys are target_blank, icon <class>, and disabled.
static_asset URIs must start with assets/; the content type is passed
through as provided, and authcrunch loads the file from the filesystem path:
static_asset "assets/images/banner.jpg" "image/jpeg" ui/banner.jpgCustom CSS and JavaScript are registered at fixed asset paths:
custom css path ui/custom.css
custom js path ui/custom.jsThese become assets/css/custom.css and assets/js/custom.js. custom html header path <path> injects file content into the built-in templates immediately
in the parser path. That injection mutates process-global template data; custom
CSS/JS and static assets also use a global asset registry. Do not promise
independent branding for portals registering the same asset paths or repeatable
header injection across adaptations. Qualify coexistence and reload behavior
before relying on that isolation; adaptation success alone does not prove it.
Do not invent UI directives from authcrunch struct fields unless
caddyfile_authn_ui.go parses them. The Caddyfile parser does not currently
support a top-level ui title or allow settings for role subdirective.
The selected embedded login template shows the cross-device action only when the portal enables it. Keep that action outside the ordinary provider-link visibility condition: a single local realm can hide ordinary links while still offering cross-device login. Preserve the dedicated request/confirmation pages and their embedded script instead of copying runtime assets into Caddy. Use configuration-authentication-cross-device to check explicit approval, matching-code/account display, navigation, cancellation and embedded-browser compatibility when customizing those pages.
The built-in portal and session templates already load the matching embedded client. Custom portal templates must retain its conditional inclusion:
{{ if .Data.refresh_enabled }}
<script src="{{ pathjoin .ActionEndpoint "/assets/js/refresh.js" }}"
data-base="{{ .ActionEndpoint }}"
data-session="{{ .Data.refresh_session }}"
data-expires="{{ .Data.refresh_expires }}"></script>
{{ end }}Custom session continuation/confirmation templates use the action metadata:
<p id="session-message">{{ .Message }}</p>
{{ if eq .Data.session_action "logout" }}
<button id="session-logout" type="button">Sign out</button>
{{ end }}
<a href="{{ pathjoin .ActionEndpoint "/login" }}?fresh=1">Sign in</a>
<script src="{{ pathjoin .ActionEndpoint "/assets/js/refresh.js" }}"
data-base="{{ .ActionEndpoint }}"
data-action="{{ .Data.session_action }}"
data-next="{{ .Data.session_next }}"></script>These are fragments inside the corresponding HTML template, not Caddyfile
syntax. Keep the served refresh.js name stable and use the library's
AuthCrunchSession.refresh()/.logout() for custom controls. Do not substitute
an independent client, inline credentials or mark untrusted return URLs safe.
Session/expiry attributes are hints; the coordinator verifies signed access
state before using them. Preserve the continuation page's CSP and no-store
headers and offer fresh login when browser coordination is unavailable.
See browser refresh
for Web Locks, pending-state recovery, top-level navigation and Caddy TLS tests.
Use language <id> inside the ui block for portal localization:
ui {
language fr
}The supported language set and message keys come from the selected module
translation data, especially pkg/translate/data/messages.json. Check that
file when validating whether a language or message is available; do not infer
support from screenshots alone.
Custom JavaScript can implement post-login behavior that auto_redirect_url
cannot express, such as calling /whoami, checking the referrer from a
/sandbox/ path, inspecting roles, and redirecting users to a role-specific
dashboard. Treat such scripts as application code: review same-origin
assumptions, JSON Accept headers, role checks, and failure behavior.
Use this fixture as the main example:
testdata/caddyfile_adapt/testcase_authenticate_with_ui.CaddyfileThe UI fixture proves parser/adapted JSON behavior. It does not qualify custom CSS/JS/HTML execution, missing-file failures, or simultaneous portal branding; this repository has no dedicated Caddy E2E coverage for those customizations. When changing them, verify served paths/content types, intended page inclusion, missing-input failure, and behavior across two portals and reload. Keep global asset/template effects visible rather than asserting per-portal isolation.
For custom refresh templates, preserve the embedded client's conditional script and metadata plus fresh-login recovery. Existing browser-refresh journeys cover the built-in templates; a custom template needs its own actual browser evidence.
© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .codex/skills/configuration-authentication-ui of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Configuration Authentication UI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuration Authentication UI this skillgreenpau/caddy-security | 2.3k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Supabasecurvenote/curvenote | 169 | 5 repos | ~2.2k | Automated safety check: Pass | Custom licence | |
| Gitnexus Exploringaws-samples/sample-kolya-br-proxy | 106 | 11 repos | ~749 | Automated safety check: Pass | MIT-0 |
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
aws-samples/sample-kolya-br-proxy
A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.
coinbase/agentic-wallet-skills
Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API…
greenpau/caddy-security
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
Categories
Configure portal UI templates, static assets, themes, languages, links, and custom CSS/JS/HTML. Configuration Authentication UI is an agent skill from greenpau/caddy-security. Configure portal UI templates, static assets, themes, languages, links, and custom CSS/JS/HTML.
Configuration Authentication UI fits situations like: branding and refresh-aware templates; transform-generated links belong to user transforms.
Run `npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a claude-code`. Or copy the skill folder (.codex/skills/configuration-authentication-ui in greenpau/caddy-security) into .claude/skills/configuration-authentication-ui in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a codex`. Or copy the skill folder (.codex/skills/configuration-authentication-ui in greenpau/caddy-security) into .agents/skills/configuration-authentication-ui in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-authentication-ui -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-authentication-ui, .gemini/skills/configuration-authentication-ui, .github/skills/configuration-authentication-ui and .opencode/skills/configuration-authentication-ui in your project.
SKILL.md names no scripts, command-line tools or credentials: Configuration Authentication UI is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Configuration Authentication UI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Configuration Authentication UI: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Supabase (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.