Agent skill

Configuration Registrations

by greenpau in greenpau/caddy-security

Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration Registrations

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-registrations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-registrations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-registrations .claude/skills/configuration-registrations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-registrations
GitHub stars
2.3k
Token cost
~1.6k tokens
SKILL.md length
745 words
Files
2
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging.

  • Registration versus account activation
  • SKILL.md covers Purpose, Shape, Required and Defaulted Fields and Supported Lines, plus 2 more sections
  • Calls kind
  • OAuth client registration is separate

What it does

Configuration Registrations is an agent skill from greenpau/caddy-security. Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging. Use for registration versus account activation; OAuth client registration is separate.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Dropbox. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Registration versus account activation
  • OAuth client registration is separate

Example prompts

  • “/configuration-registrations”

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kind

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Registrations loads about 1.6k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 745 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 745 words, ~1,644 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-registrations/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
configuration-registrations
description
Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging. Use for registration versus account activation; OAuth client registration is separate.

Configuration Registrations

Purpose

Use this skill to configure user registration <name> blocks. Dispatch starts in caddyfile_user.go; registration instructions are collected by caddyfile_user_registration.go. The Caddyfile parser injects name <block-name> and kind local, then forwards the block instructions to authcrunch for validation.

Registration flows attach to the target identity store declared by identity store <name> [<realm>]. During authcrunch validation, portals using that identity store get registration enabled for that store and the registry is attached at runtime. The current portal parser does not accept enable user registration <name>; use enable identity store <name> on the portal instead.

Shape

caddyfile
{
	security {
		user registration signup {
			title "User Registration"
			code {env.REGISTER_CODE}
			dropbox assets/config/registrations_local.json
			require accept terms
			require domain mx
			email provider smtp
			admin email admin@example.com
			identity store localdb
			link terms https://example.com/terms
			link privacy https://example.com/privacy
			allow domain example.com
		}

		local identity store localdb {
			realm local
			path assets/config/users.json
		}

		authentication portal myportal {
			enable identity store localdb
		}
	}
}

Required and Defaulted Fields

Authcrunch requires the effective registry config to have name, kind, dropbox, email provider, at least one admin email address, and identity store. In Caddyfile configuration, name comes from the block name and kind local is injected by caddy-security.

title is optional and defaults to Sign Up. code is optional; when present, the registration form requires the exact configured value. require accept terms and require domain mx are optional boolean flags.

The authcrunch parser accepts exactly one admin email address per instruction: admin email <address> or admin emails <address>. Multiple addresses on one line are invalid, and repeated admin-email lines overwrite rather than append.

Supported Lines

The parser forwards registration lines to authcrunch. Supported patterns in authcrunch include:

  • title <name>
  • code <value>
  • dropbox <path>
  • require accept terms
  • require domain mx
  • email provider <name>
  • admin email <address>
  • admin emails <address>
  • identity store <name> [<realm>]
  • link terms <url>
  • link privacy <url>
  • allow domain <string>
  • deny domain <string>
  • allow <exact|partial|prefix|suffix|regex> domain <string>
  • deny <exact|partial|prefix|suffix|regex> domain <string>

Domain restrictions are validated by authcrunch. Matching stops at the first rule that matches the email domain; if no rule matches, the default action is the opposite of the last configured rule. For a simple allow list, use only allow rules. For a simple deny list, use only deny rules.

Coordinate the email provider value with configuration-messaging; despite the directive name, authcrunch can notify through a matching email or file messaging provider. Coordinate identity store names with configuration-identity-stores.

Show full SKILL.md (405 more words)Show less

Workflow Notes

Registration is not the same as immediate account activation. The user reaches the form from the portal's register link, submits username, password, email, name, optional registration code, and required terms acceptance, then receives an email confirmation link and short passcode. The confirmation passcode is time-limited in authcrunch; when it expires, the user must register again.

After email confirmation, the handler consumes the pending registration, adds the user to the dropbox database and attempts an administrator notification. That database is separate from the target login store. Approval and transfer into the login store remain a separate management operation; no full approval UI is implemented here. Do not edit a serving identity database as a routine approval step. Use a supported management path or arrange an offline import and explicit reload. A notification failure after the dropbox commit is logged and does not undo the committed registration.

Pending registrations are held in the registry's in-memory cache. Reload or restart discards them; the durable dropbox only contains confirmed entries. An expired or lost pending registration must be started again. A supplied password must be plaintext: the selected AuthCrunch rejects reserved password-hash import prefixes on the public registration path, while trusted static-user imports are separate.

When multiple registrations target different identity stores or realms, use separate dropbox paths. The portal exposes realm-specific registration URLs, for example:

text
/auth/register/local
/auth/register/userpool1.localdomain

For local validation without SMTP, point email provider at a file messaging provider whose root_dir is a disposable path under this checkout's tmp/. Inspect the confirmation link and passcode in its .eml output using synthetic identities and separate temporary dropbox/login databases. This does not check SMTP authentication, TLS, sender headers or BCC delivery; the messaging skill documents those limits.

Fixtures

Use these examples:

  • testdata/caddyfile_adapt/testcase_authenticate_with_registration.Caddyfile.
  • assets/config/registrations_local.json.

The adaptation/resolution fixture verifies configuration shape and defaults, not a registration journey. TestCaddyPasswordArgon2E2E/public-registration uses the actual executable and a disposable file sender to reject valid, malformed and whitespace-padded bcrypt/Argon2 imports without a message or persisted user; ordinary plaintext reaches confirmation-message delivery. This does not qualify confirmation, approval, transfer or SMTP. The lifecycle tests exercise registry ownership and replacement, but this checkout has no complete user-signup E2E. Do not confuse TestCaddyRegistrationE2E, which covers persisted OAuth client registrations, with user signup. A future user-signup acceptance case should reject wrong codes and disallowed domains, confirm one emitted link/passcode, verify only the dropbox receives the account, reject replay or lost pending state, and observe the administrator notification and separate activation.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .codex/skills/configuration-registrations of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Registrations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Registrations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Registrations this skillgreenpau/caddy-security2.3k—~1.6kAutomated safety check: PassApache-2.0
Dropboxyc-software/qm15k—~1.8kAutomated safety check: PassMIT
DropboxLeoYeAI/openclaw-master-skills2.2k—~4.3kAutomated safety check: PassMIT
Dropbox BusinessLeoYeAI/openclaw-master-skills2.2k—~6.9kAutomated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
OmniRoute Provider Managementdiegosouzapw/OmniRoute75k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Dropbox

    yc-software/qm

    Browse, search, read, upload, and share the user's Dropbox — including team/shared folders — through per-user OAuth.

    15k GitHub stars~1.8k tokensUpdated today
    Backend & APIsAuto-check passed
  • Dropbox

    LeoYeAI/openclaw-master-skills

    Dropbox API integration with managed OAuth. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.3k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Dropbox Business

    LeoYeAI/openclaw-master-skills

    Dropbox Business API integration with managed OAuth. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~6.9k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    75k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 5 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 5 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about Configuration Registrations

What does Configuration Registrations do?

Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging. Configuration Registrations is an agent skill from greenpau/caddy-security. Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging.

When should I use Configuration Registrations?

Configuration Registrations fits situations like: registration versus account activation; OAuth client registration is separate.

How do I install Configuration Registrations in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-registrations -a claude-code`. Or copy the skill folder (.codex/skills/configuration-registrations in greenpau/caddy-security) into .claude/skills/configuration-registrations in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Registrations in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-registrations -a codex`. Or copy the skill folder (.codex/skills/configuration-registrations in greenpau/caddy-security) into .agents/skills/configuration-registrations in your project. Codex loads it when a task matches its description.

Can I use Configuration Registrations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-registrations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-registrations, .gemini/skills/configuration-registrations, .github/skills/configuration-registrations and .opencode/skills/configuration-registrations in your project.

What does Configuration Registrations need to run?

Going by SKILL.md and its folder, Configuration Registrations needs the command-line tools its instructions call (kind).

Does Configuration Registrations access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration Registrations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Registrations use?

Configuration Registrations is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Registrations use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Configuration Registrations?

Skills that share tags, products or a category with Configuration Registrations: Dropbox (yc-software/qm, 15k stars), Dropbox (LeoYeAI/openclaw-master-skills, 2.2k stars), Dropbox Business (LeoYeAI/openclaw-master-skills, 2.2k stars) and Fortify Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Registrations?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,252 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.