Fortify Development
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.
$ npx skills add greenpau/caddy-security --skill configuration-users -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install greenpau/caddy-security configuration-users --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-users .claude/skills/configuration-users && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "configuration-users" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-users into .claude/skills/configuration-users/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-users", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-usersType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add greenpau/caddy-security --skill configuration-users -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install greenpau/caddy-security configuration-users --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.codex/skills/configuration-users .agents/skills/configuration-users && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "configuration-users" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-users into .agents/skills/configuration-users/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-users", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-users -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install greenpau/caddy-security configuration-users --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.codex/skills/configuration-users .cursor/skills/configuration-users && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "configuration-users" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-users into .cursor/skills/configuration-users/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-users", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/greenpau/caddy-security.git --path .codex/skills/configuration-users--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add greenpau/caddy-security --skill configuration-users -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install greenpau/caddy-security configuration-users --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.codex/skills/configuration-users .gemini/skills/configuration-users && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "configuration-users" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-users into .gemini/skills/configuration-users/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-users", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install greenpau/caddy-security configuration-usersInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add greenpau/caddy-security --skill configuration-users -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .github/skills && cp -r skills-src/.codex/skills/configuration-users .github/skills/configuration-users && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "configuration-users" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-users into .github/skills/configuration-users/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-users", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add greenpau/caddy-security --skill configuration-users -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install greenpau/caddy-security configuration-users --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.codex/skills/configuration-users .opencode/skills/configuration-users && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "configuration-users" agent skill from https://github.com/greenpau/caddy-security/tree/main/.codex/skills/configuration-users into .opencode/skills/configuration-users/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "configuration-users", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
configuration-usersConfigure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.
Configuration Users is an agent skill from greenpau/caddy-security. Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules. Use for Caddyfile-owned users; online administration belongs to scripts-and-automation.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/password-hashing.md`).
It sits in Backend & APIs, covering Authentication. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are caddyfile).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ALICE_PASSWORDUSERS_ADMIN_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Configuration Users loads about 2k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 817 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 817 words, ~1,955 tokens.
.claude/skills/configuration-users/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Use this skill for user <username> entries inside local identity store
blocks. The Caddyfile syntax is authoritative in caddyfile_identity_store.go;
the provisioning behavior is authoritative in the selected go-authcrunch module,
especially pkg/ids/local/user.go, pkg/ids/local/authenticator.go, and
pkg/identity/database.go.
The surrounding store belongs to configuration-identity-stores; account changes do not require reloading that router unless store settings change.
local identity store localdb {
realm local
path assets/config/users.json
user alice {
name "Alice Example"
email alice@example.com
password {env.ALICE_PASSWORD} overwrite
roles authp/user authp/admin
api key kid123456789012345678901 {env.ALICE_API_KEY_BCRYPT}
}
}kid123456789012345678901 is intentionally 24 characters. For static user API
keys, authcrunch treats the Caddyfile key id as the API key prefix and currently
requires exactly 24 characters.
The current Caddyfile parser supports only these subdirectives:
name <full name> with one or more words; multi-word names are joined with
spaces.email <address>.password <plaintext_or_imported_hash> [overwrite].roles <role> [<role>...].api key <key_id> <bcrypt_value_or_secret_reference>.auth challenges <rule body>; repeat to append ordered rules.Use overwrite when the configured password should replace the existing stored
password during provisioning. With selected go-authcrunch v1.3.6, passwords may
be plaintext, bcrypt:<cost>:<hash>, or argon2:<PHC> imports. The unchanged
plaintext path creates bcrypt hashes. Static API-key payloads remain bcrypt;
password-import support does not change their format. Read
password imports and generation for the exact
Argon2 format, generation commands, resource limits, trusted-input boundary,
and Caddy qualification.
Duplicate password updates can reuse the active hash while still advancing the
account's credential version. Legacy records without credential_version
remain supported. See local identity compatibility
for update versus reset behavior, invalidation, and Caddy tests.
Static user blocks are not a full sync mechanism. During local store
configuration, authcrunch creates the user when it does not exist. When the user
already exists, password ... overwrite replaces its password; configured API
keys are passed to the upstream key operation, and explicit challenge rules
replace its stored rules. Name, email and roles are not synchronized. Keep the
configured email consistent with the existing identity.
For api key, use a stable 24-character key id and a bcrypt-formatted payload
or a placeholder/secret that resolves to one. Do not generate plaintext static
API key payload examples.
For example, inside user alice, repeat rule bodies in preference order:
auth challenges u2f
auth challenges password totp if u2f not available
auth challenges password if u2f and totp not availableThe shared challenge parser validates the complete list. Methods are password,
totp, u2f, and mfa; adjacent methods require all, or selects the first
available choice, and if ... [and ...] not available tests registered
credentials. Email challenges/conditions, duplicates, empty and malformed rules
fail adaptation. Keywords must be literal. See the
conditional transform grammar
for selection, precedence and verified AMR. A matching transform policy can
replace the stored selection.
Explicit static rules are applied both when creating and when provisioning an existing user. Omitting them preserves the stored policy; removing lines does not reset it. Caddyfile rules do not enroll factors. Ensure users have the credentials required by a rule or provide a deliberate fallback.
Use profile flow management
for user-owned changes or an explicit reset with an empty challenges array.
security local update user
replaces rules through the server API, which requires a nonempty list. The static API-key directive still has no overwrite suffix;
do not invent one from the upstream struct field.
Prefer environment placeholders or secret lookups for passwords and API keys:
password "{env.USERS_ADMIN_SECRET}" overwrite
password "secrets:users/alice:password" overwrite
api key kid123456789012345678901 "secrets:users/alice:api_key"Make sure API key placeholders and secret lookups resolve to a value in the
bcrypt:<cost>:<hash> form.
Secret-backed values follow the manager contract and runtime field contract.
Check generated local user entries against these code-backed constraints:
local identity store <name> { ... }, not an LDAP store.email is a single valid address. Although its presence is not checked by
the Caddyfile parser, new-user provisioning requires it; an existing user's
configured username and email must identify the same stored account.roles has at least one role when used.auth challenges rules form one validated, ordered policy.password overwrite has only the literal overwrite as its second argument.api key has exactly key, a 24-character key id, and one payload value.Use these examples:
caddyfile_identity_store.go for accepted Caddyfile subdirectives.caddyfile_identity_store_test.go for local store parser coverage.testcase_authenticate_with_argon2 for quoted imports, adapt-time environment
expansion, runtime placeholders, bcrypt and plaintext compatibility.TestPasswordImportAdaptAndResolve, TestPasswordImportProvisioningRejectsMalformed
and TestCaddyPasswordArgon2E2E for preservation, redacted rejection and actual
executable TLS login, restart, overwrite and public self-service boundaries.testcase_authenticate_with_challenges for adaptation and resolution.TestCaddyAuthenticationChallengesE2E for stored policy creation, replacement,
omission, native login and profile policy management through Caddy.testdata/caddyfile_adapt/testcase_security_authentication_portal.Caddyfile.testcase_security_with_secrets contains the static API-key lookup form.
TestIdentityStoreSecretsFixture checks its local-user block independently of
the optional external module, and the challenge E2E provisions a bcrypt API
key through the Caddyfile and exercises native login and policy rejection.
© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references) in .codex/skills/configuration-users of greenpau/caddy-security.
Open the folder on GitHubat commit a48553d
Configuration Users next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Configuration Users this skillgreenpau/caddy-security | 2.3k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Supabasecurvenote/curvenote | 169 | 5 repos | ~2.2k | Automated safety check: Pass | Custom licence | |
| Gitnexus Exploringaws-samples/sample-kolya-br-proxy | 106 | 11 repos | ~749 | Automated safety check: Pass | MIT-0 |
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
aws-samples/sample-kolya-br-proxy
A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.
coinbase/agentic-wallet-skills
Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API…
greenpau/caddy-security
Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.
greenpau/caddy-security
Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.
greenpau/caddy-security
Build or review caddy-security Caddyfiles and select focused configuration skills.
greenpau/caddy-security
Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.
greenpau/caddy-security
Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.
greenpau/caddy-security
Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.
Categories
Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules. Configuration Users is an agent skill from greenpau/caddy-security. Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.
Configuration Users fits situations like: caddyfile-owned users; online administration belongs to scripts-and-automation.
Run `npx skills add greenpau/caddy-security --skill configuration-users -a claude-code`. Or copy the skill folder (.codex/skills/configuration-users in greenpau/caddy-security) into .claude/skills/configuration-users in your project. Claude Code loads it when a task matches its description.
Run `npx skills add greenpau/caddy-security --skill configuration-users -a codex`. Or copy the skill folder (.codex/skills/configuration-users in greenpau/caddy-security) into .agents/skills/configuration-users in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-users -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-users, .gemini/skills/configuration-users, .github/skills/configuration-users and .opencode/skills/configuration-users in your project.
Going by SKILL.md and its folder, Configuration Users needs credentials named ALICE_PASSWORD and USERS_ADMIN_SECRET. Our summary lists: A credential in USERS_ADMIN_SECRET.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Configuration Users is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Configuration Users: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Supabase (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.
Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.