Better Auth Security Best Practices
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
Configure external OAuth/OIDC login providers, credentials, scopes, issuer/audience trust, JWKS, PKCE, and portal enablement.
$ npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security configuration-oauth-providers --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-oauth-providers .claude/skills/configuration-oauth-providers && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuration-oauth-providers" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-oauth-providers into .claude/skills/configuration-oauth-providers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-oauth-providers", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-oauth-providersType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security configuration-oauth-providers --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/configuration-oauth-providers .agents/skills/configuration-oauth-providers && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuration-oauth-providers" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-oauth-providers into .agents/skills/configuration-oauth-providers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-oauth-providers", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security configuration-oauth-providers --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/configuration-oauth-providers .cursor/skills/configuration-oauth-providers && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuration-oauth-providers" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-oauth-providers into .cursor/skills/configuration-oauth-providers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-oauth-providers", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/configuration-oauth-providers--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security configuration-oauth-providers --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/configuration-oauth-providers .gemini/skills/configuration-oauth-providers && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuration-oauth-providers" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-oauth-providers into .gemini/skills/configuration-oauth-providers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-oauth-providers", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security configuration-oauth-providersInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/configuration-oauth-providers .github/skills/configuration-oauth-providers && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuration-oauth-providers" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-oauth-providers into .github/skills/configuration-oauth-providers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-oauth-providers", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security configuration-oauth-providers --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/configuration-oauth-providers .opencode/skills/configuration-oauth-providers && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuration-oauth-providers" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-oauth-providers into .opencode/skills/configuration-oauth-providers/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-oauth-providers", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuration-oauth-providersConfigure external OAuth/OIDC login providers, credentials, scopes, issuer/audience trust, JWKS, PKCE, and portal enablement.
Configuration OAuth Providers is an agent skill from greenpau/caddy-security. Configure external OAuth/OIDC login providers, credentials, scopes, issuer/audience trust, JWKS, PKCE, and portal enablement. Named relying-party registrations and portal OPs belong to OAuth applications.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/shared-parser.md`).
It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with GitHub. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
goFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AZURE_ID_TOKENAUTHP_ID_TOKENGITHUB_APP_CLIENT_SECRETAZURE_APP_CLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Configuration OAuth Providers loads about 3.2k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 59 tokens; SKILL.md has 1,286 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 1,286 words, ~3,155 tokens.
.claude/skills/configuration-oauth-providers/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Use this skill to configure oauth identity provider <name> blocks. The
Caddyfile syntax is authoritative in caddyfile_identity.go and
caddyfile_identity_provider_oauth.go; it delegates to the shared upstream
OAuth parser. The provisioning behavior is authoritative in
the module selected by go.mod and any active replacement, especially
pkg/idp/oauth/config.go. A sibling checkout is read-only context and may differ
from that selection; inspect go list -m -json github.com/greenpau/go-authcrunch.
Do not use this skill for sso provider <name> blocks. Those configure the SSO
app/SAML role-assumption feature and belong in configuration-sso-app. Also do
not route saml identity provider <name> blocks here; their headers share the dispatcher
but SAML uses the local go-authcrunch/pkg/idp/saml implementation.
Read shared parsing, grammar compatibility, and trust when changing OAuth directives, issuer/audience, keys, or parser validation.
The qualified operator examples include an actual TLS journey using explicit issuer/access-token audience and static Ed25519 keys. Upstream login does not create downstream OP or local portal-refresh authority.
Use assets/config/home.Caddyfile as the nearest repository example for Azure,
GitHub, and LinkedIn OAuth providers.
{
security {
oauth identity provider azure {
realm azure
driver azure
tenant_id {env.AZURE_APP_TENANT_ID}
client_id {env.AZURE_APP_CLIENT_ID}
client_secret {env.AZURE_APP_CLIENT_SECRET}
scopes openid email profile
enable id token cookie id_token AZURE_ID_TOKEN
}
oauth identity provider github {
realm github
driver github
client_id {env.GITHUB_APP_CLIENT_ID}
client_secret {env.GITHUB_APP_CLIENT_SECRET}
icon github priority 100
disable pkce
}
authentication portal myportal {
enable identity provider azure github
}
}
}The identity provider name must match the portal's
enable identity provider <name> value. The realm is what user transforms
usually match:
transform user {
match realm github
action add role authp/user
}go-authcrunch currently supports these OAuth drivers:
azure, cognito, discord, facebook, generic, github, gitlab, google, linkedin,
nextcloud, oktaEvery OAuth provider needs realm, driver, client_id, and
client_secret; the Caddyfile provider name becomes authcrunch's config
Name. Use Caddy placeholders or secrets for client secrets. For runtime
references, retain the app's oauth_provider_directives snapshot in adapted
JSON: it recalculates driver defaults after resolving the original arguments.
See runtime references.
The shortcut form is supported only for github, google, and facebook:
oauth identity provider github {env.GITHUB_APP_CLIENT_ID} {env.GITHUB_APP_CLIENT_SECRET}Prefer full blocks when adding icons, scopes, cookie behavior, or provider toggles.
When scopes is omitted, authcrunch defaults by driver:
github: read:user.facebook: email.discord: identify.nextcloud: email.google, cognito, linkedin, and the fallback for azure, gitlab,
okta, and generic: openid email profile.tenant_id when targeting a tenant. If omitted, authcrunch
defaults to common and computes Azure base and metadata URLs from it.client_id has no
dot, authcrunch appends .apps.googleusercontent.com.access_token in the token response.domain_name to gitlab.com and computes base
and metadata URLs from it.assets/config/home.Caddyfile
enables an id token cookie for this provider.domain_name and server_id even when overriding URLs. If
base_auth_url is omitted, authcrunch computes base and metadata URLs from
those fields; if base_auth_url is supplied manually, also supply
metadata_url unless using the explicit static-key path below.region and user_pool_id; authcrunch computes base and
metadata URLs from them.base_auth_url; authcrunch derives the authorization and
token URLs from it.base_auth_url. Then either set
metadata_url for discovery, or set authorization_url, token_url, and
jwks key <kid> <pem_path> together. Static and combined key sources retain
TLS, nonce, PKCE, and signature verification. Explicit static IDs override colliding discovery keys.With go-authcrunch v1.3.8, authenticated GitHub /user IDs also appear as the
lossless string claim github_id. Numeric metadata.id and login-based
sub remain unchanged. A rename therefore does not change ID matching; missing
IDs cannot match, and malformed supplied IDs reject login.
For organization claims, add user_org_filters .* (or narrower login-name
regexes) inside the GitHub provider. Only returned organizations passing those
filters populate github_orgs; existing github.com/<org>/members groups remain.
No filter means no organization lookup. The existing endpoint exposes a single
page of public memberships; this feature adds no pagination or private
membership discovery, and adding read:org alone does not change the endpoint.
Use configuration-authentication-user-transforms
to assign roles with match github id <exact|regex> <value> and
match github org <exact|regex> <value>. The actual backend driver establishes
trust; naming another driver's realm github does not grant these claims.
Transforms cannot mutate either claim, including through nested actions.
TestCaddyGithubTransformsE2E qualifies these contracts through Caddy and a
local TLS OAuth fixture, including lookup denial and provider impersonation.
Some OAuth failures require changes in the upstream provider console, not the Caddyfile parser:
identify scope yields the Discord user identity. Add
email for email claims, guilds for guild membership, and
guilds.members.read for guild role checks. When user_group_filters
matches a guild, authcrunch can emit roles such as
discord.com/<guild_id>/members, discord.com/<guild_id>/admins, and
discord.com/<guild_id>/role/<role_id> for transform matching./whoami or transforms need email claims. Without this provider
permission and user consent, email may be absent even when the Caddyfile is
valid.custom:roles and custom:timezone may not appear
in the issued portal token without additional provider/userinfo extraction
behavior.The parser accepts single-value OAuth fields such as realm, driver,
tenant_id, domain_name, client_id, client_secret, server_id,
base_auth_url, metadata_url, authorization_url, token_url,
issuer, access_token_audience, region, user_pool_id,
identity_token_field_name, identity_token_cookie_name, and
user_info_roles_field_name. Shared keys also accept separate words.
Recognized syntax with a shared-validation restriction:
logout_url <logout_url>
logout url <logout_url>These are aliases for one scalar in upstream pkg/idp/oauth/parser/fields.go.
The selected v1.3.4 shared validator in pkg/idp/config.go excludes that field,
so Caddy adaptation rejects it. Keep both forms documented with that status;
exclude them from runnable examples until shared validation supports them.
enable logout / logout enabled remains a separate supported switch.
It accepts numeric retry and delayed-start fields:
delay_start 10
retry_attempts 5
retry_interval 5With delay_start but no retry settings, authcrunch defaults to two attempts
and uses delay_start as the retry interval. With retry_attempts but no
interval, authcrunch defaults the interval to 5 seconds.
It accepts repeatable/list fields:
scopes openid email profile
user_group_filters "^github.com/example/"
user_org_filters "^example-org$"
response_type code
required_token_fields access_token id_token
jwks key main testdata/oauth/87329db33bf_pub.pemFor generic OpenID providers with a discovered userinfo_endpoint, choose
one extraction line below; optionally set the roles field:
extract email profile roles from userinfo
extract all from userinfo
user_info_roles_field_name rolesAccepted toggles include:
disable metadata discovery
disable key verification
disable pass grant type
disable response type
disable scope
disable nonce
disable tls verification
disable email claim check
disable pkce
enable accept header
enable js callback
enable logout
enable id token cookie id_token AZURE_ID_TOKENdisable metadata discovery is parsed into
metadata_discovery_disabled, but current authcrunch OAuth provider setup does
not use that flag by itself to skip discovery. To avoid metadata fetching,
configure explicit URLs as required by the driver and account for JWKS behavior.
External logout is separate from local portal logout. enable logout enables
provider-specific logout handling when the driver implements it. It does not
make typed-only logout_url available through Caddy's shared dispatcher.
For id token cookies, these are alternative spaced Caddyfile forms:
enable id token cookie
enable id token cookie id_token
enable id token cookie id_token AZURE_ID_TOKENThe first optional value is the token response field to copy and must be
id_token or access_token; the second optional value is the cookie name.
When the cookie name is omitted, authcrunch uses AUTHP_ID_TOKEN for the provider
identity-token cookie.
Check generated OAuth provider entries against these code-backed constraints:
oauth identity provider <name>, not sso provider <name>.realm, driver, client_id, and client_secret.go-authcrunch.base_auth_url plus either metadata_url or
explicit authorization_url, token_url, and static jwks key entries.enable identity provider <name> in the authentication portal.match realm <realm> in transforms when assigning roles after OAuth
login.enable id token cookie ...; avoid inventing
enable id_token cookie.disable metadata discovery as a parsed flag, not as sufficient
runtime behavior by itself.Use these examples:
assets/config/home.Caddyfile for Azure, GitHub, and LinkedIn.testdata/caddyfile_adapt/testcase_authenticate_with_oauth.Caddyfile for
OAuth plus portal and authorization wiring.caddyfile_identity_provider_oauth.go for Caddy translations into the shared
parser, with grammar inventory and validation in the linked reference.go-authcrunch/pkg/idp/oauth/config.go for driver defaults and validation.© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .codex/skills/configuration-oauth-providers of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Configuration OAuth Providers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuration OAuth Providers this skillgreenpau/caddy-security | 2.3k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Better Auth Security Best PracticesEpicenterHQ/epicenter | 4.8k | — | ~896 | Automated safety check: Pass | Custom licence | |
| GitHub OAuth Nango IntegrationAgentWorkforce/relay | 872 | 1 repos | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| EmulateUsefulSoftwareCo/executor | 4.1k | — | ~2.2k | Automated safety check: Notes | MIT | |
| Nuget Trusted Publishingrodri-oliveira-dev/Dapper-FluentMap | 454 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Auth Setupbutterbase-ai/butterbase-skills | 534 | — | ~2.2k | Automated safety check: Pass | MIT |
EpicenterHQ/epicenter
Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.
AgentWorkforce/relay
A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling
UsefulSoftwareCo/executor
Use the @executor-js/emulate service emulators (GitHub, Google, Stripe, Resend, WorkOS, …) to test integrations for real — full OpenAPI specs, working OAuth flows, mintable credentials, and a…
rodri-oliveira-dev/Dapper-FluentMap
Review, maintain, or set up NuGet trusted publishing (OIDC) for GitHub Actions.
butterbase-ai/butterbase-skills
A skill your agent uses when configuring OAuth providers (Google/GitHub/Apple/X/etc.), setting up post-login auth hooks, tuning JWT lifetimes, or generating service API keys
rome-os/rome
Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…
greenpau/caddy-security
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
Works with
Categories
Configure external OAuth/OIDC login providers, credentials, scopes, issuer/audience trust, JWKS, PKCE, and portal enablement. Configuration OAuth Providers is an agent skill from greenpau/caddy-security. Configure external OAuth/OIDC login providers, credentials, scopes, issuer/audience trust, JWKS, PKCE, and portal enablement.
Configuration OAuth Providers fits situations like: tasks that involve OAuth and OpenID Connect.
Run `npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a claude-code`. Or copy the skill folder (.codex/skills/configuration-oauth-providers in greenpau/caddy-security) into .claude/skills/configuration-oauth-providers in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a codex`. Or copy the skill folder (.codex/skills/configuration-oauth-providers in greenpau/caddy-security) into .agents/skills/configuration-oauth-providers in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-oauth-providers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-oauth-providers, .gemini/skills/configuration-oauth-providers, .github/skills/configuration-oauth-providers and .opencode/skills/configuration-oauth-providers in your project.
Going by SKILL.md and its folder, Configuration OAuth Providers needs the command-line tools its instructions call (go) and credentials named AZURE_ID_TOKEN, AUTHP_ID_TOKEN, GITHUB_APP_CLIENT_SECRET and AZURE_APP_CLIENT_SECRET. Our summary lists: A credential in AZURE_APP_CLIENT_SECRET; A credential in AZURE_ID_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Configuration OAuth Providers is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Configuration OAuth Providers: Better Auth Security Best Practices (EpicenterHQ/epicenter, 4.8k stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 872 stars), Emulate (UsefulSoftwareCo/executor, 4.1k stars) and Nuget Trusted Publishing (rodri-oliveira-dev/Dapper-FluentMap, 454 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.