Agent skill

Configuration Users

by greenpau in greenpau/caddy-security

Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.

Apache-2.0Auto-check passedBackend & APIs

Install Configuration Users

skills CLI
$ npx skills add greenpau/caddy-security --skill configuration-users -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install greenpau/caddy-security configuration-users --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/greenpau/caddy-security.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/configuration-users .claude/skills/configuration-users && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
configuration-users
GitHub stars
2.3k
Token cost
~2k tokens
SKILL.md length
817 words
Files
3 (incl. references)
Skills in repo
29
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.

  • Caddyfile-owned users
  • SKILL.md covers Purpose, Shape, Fields and Stored authentication rules, plus 3 more sections
  • Needs ALICE_PASSWORD and USERS_ADMIN_SECRET
  • Online administration belongs to scripts-and-automation

What it does

Configuration Users is an agent skill from greenpau/caddy-security. Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules. Use for Caddyfile-owned users; online administration belongs to scripts-and-automation.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `agents/openai.yaml` and `references/password-hashing.md`).

It sits in Backend & APIs, covering Authentication. The repository describes itself as: 🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google…. The licence is Apache-2.0.

When your agent uses it

  • Caddyfile-owned users
  • Online administration belongs to scripts-and-automation

Example prompts

  • “/configuration-users”

Requirements

  • A credential in USERS_ADMIN_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit a48553d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are caddyfile).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ALICE_PASSWORD
    • USERS_ADMIN_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Configuration Users loads about 2k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 817 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from greenpau/caddy-security at commit a48553d, republished under its Apache-2.0 licence (© greenpau). 817 words, ~1,955 tokens.

Download SKILL.mdSave it as .claude/skills/configuration-users/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
configuration-users
description
Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules. Use for Caddyfile-owned users; online administration belongs to scripts-and-automation.

Configuration Users

Purpose

Use this skill for user <username> entries inside local identity store blocks. The Caddyfile syntax is authoritative in caddyfile_identity_store.go; the provisioning behavior is authoritative in the selected go-authcrunch module, especially pkg/ids/local/user.go, pkg/ids/local/authenticator.go, and pkg/identity/database.go.

The surrounding store belongs to configuration-identity-stores; account changes do not require reloading that router unless store settings change.

Shape

caddyfile
local identity store localdb {
	realm local
	path assets/config/users.json

	user alice {
		name "Alice Example"
		email alice@example.com
		password {env.ALICE_PASSWORD} overwrite
		roles authp/user authp/admin
		api key kid123456789012345678901 {env.ALICE_API_KEY_BCRYPT}
	}
}

kid123456789012345678901 is intentionally 24 characters. For static user API keys, authcrunch treats the Caddyfile key id as the API key prefix and currently requires exactly 24 characters.

Fields

The current Caddyfile parser supports only these subdirectives:

  • name <full name> with one or more words; multi-word names are joined with spaces.
  • email <address>.
  • password <plaintext_or_imported_hash> [overwrite].
  • roles <role> [<role>...].
  • api key <key_id> <bcrypt_value_or_secret_reference>.
  • auth challenges <rule body>; repeat to append ordered rules.

Use overwrite when the configured password should replace the existing stored password during provisioning. With selected go-authcrunch v1.3.6, passwords may be plaintext, bcrypt:<cost>:<hash>, or argon2:<PHC> imports. The unchanged plaintext path creates bcrypt hashes. Static API-key payloads remain bcrypt; password-import support does not change their format. Read password imports and generation for the exact Argon2 format, generation commands, resource limits, trusted-input boundary, and Caddy qualification.

Duplicate password updates can reuse the active hash while still advancing the account's credential version. Legacy records without credential_version remain supported. See local identity compatibility for update versus reset behavior, invalidation, and Caddy tests.

Static user blocks are not a full sync mechanism. During local store configuration, authcrunch creates the user when it does not exist. When the user already exists, password ... overwrite replaces its password; configured API keys are passed to the upstream key operation, and explicit challenge rules replace its stored rules. Name, email and roles are not synchronized. Keep the configured email consistent with the existing identity.

For api key, use a stable 24-character key id and a bcrypt-formatted payload or a placeholder/secret that resolves to one. Do not generate plaintext static API key payload examples.

Stored authentication rules

For example, inside user alice, repeat rule bodies in preference order:

caddyfile
auth challenges u2f
auth challenges password totp if u2f not available
auth challenges password if u2f and totp not available

The shared challenge parser validates the complete list. Methods are password, totp, u2f, and mfa; adjacent methods require all, or selects the first available choice, and if ... [and ...] not available tests registered credentials. Email challenges/conditions, duplicates, empty and malformed rules fail adaptation. Keywords must be literal. See the conditional transform grammar for selection, precedence and verified AMR. A matching transform policy can replace the stored selection.

Explicit static rules are applied both when creating and when provisioning an existing user. Omitting them preserves the stored policy; removing lines does not reset it. Caddyfile rules do not enroll factors. Ensure users have the credentials required by a rule or provide a deliberate fallback.

Use profile flow management for user-owned changes or an explicit reset with an empty challenges array. security local update user replaces rules through the server API, which requires a nonempty list. The static API-key directive still has no overwrite suffix; do not invent one from the upstream struct field.

Show full SKILL.md (322 more words)Show less

Secrets

Prefer environment placeholders or secret lookups for passwords and API keys:

caddyfile
password "{env.USERS_ADMIN_SECRET}" overwrite
password "secrets:users/alice:password" overwrite
api key kid123456789012345678901 "secrets:users/alice:api_key"

Make sure API key placeholders and secret lookups resolve to a value in the bcrypt:<cost>:<hash> form.

Secret-backed values follow the manager contract and runtime field contract.

Review Checklist

Check generated local user entries against these code-backed constraints:

  • The entry is inside local identity store <name> { ... }, not an LDAP store.
  • The username is present and compatible with the local database policy; the default policy requires length 3-50.
  • New users have a password compatible with the local database policy; the default policy requires length 8-128. The default bcrypt creation path also rejects plaintext longer than 72 bytes; the policy's upper bound does not override that algorithm limit. Trusted imported hashes use their own format validation because the underlying plaintext length is unavailable.
  • email is a single valid address. Although its presence is not checked by the Caddyfile parser, new-user provisioning requires it; an existing user's configured username and email must identify the same stored account.
  • roles has at least one role when used.
  • Repeated auth challenges rules form one validated, ordered policy.
  • password overwrite has only the literal overwrite as its second argument.
  • api key has exactly key, a 24-character key id, and one payload value.
  • Static API key payloads are bcrypt-formatted or resolve to bcrypt-formatted values.

Fixtures

Use these examples:

  • caddyfile_identity_store.go for accepted Caddyfile subdirectives.
  • caddyfile_identity_store_test.go for local store parser coverage.
  • testcase_authenticate_with_argon2 for quoted imports, adapt-time environment expansion, runtime placeholders, bcrypt and plaintext compatibility.
  • TestPasswordImportAdaptAndResolve, TestPasswordImportProvisioningRejectsMalformed and TestCaddyPasswordArgon2E2E for preservation, redacted rejection and actual executable TLS login, restart, overwrite and public self-service boundaries.
  • testcase_authenticate_with_challenges for adaptation and resolution.
  • TestCaddyAuthenticationChallengesE2E for stored policy creation, replacement, omission, native login and profile policy management through Caddy.
  • testdata/caddyfile_adapt/testcase_security_authentication_portal.Caddyfile.

testcase_security_with_secrets contains the static API-key lookup form. TestIdentityStoreSecretsFixture checks its local-user block independently of the optional external module, and the challenge E2E provisions a bcrypt API key through the Caddyfile and exercises native login and policy rejection.

© greenpau, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .codex/skills/configuration-users of greenpau/caddy-security.

  • SKILL.md
  • agents/openai.yaml
  • references/password-hashing.md

Open the folder on GitHubat commit a48553d

Compare with similar skills

Configuration Users next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Configuration Users compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Configuration Users this skillgreenpau/caddy-security2.3k—~2kAutomated safety check: PassApache-2.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Supabasecurvenote/curvenote1695 repos~2.2kAutomated safety check: PassCustom licence
Gitnexus Exploringaws-samples/sample-kolya-br-proxy10611 repos~749Automated safety check: PassMIT-0

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    169 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Gitnexus Exploring

    aws-samples/sample-kolya-br-proxy

    Official

    A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.

    106 GitHub starsUsed in 11 repos~749 tokens
    Backend & APIsAuto-check passed
  • Agentic Wallet

    coinbase/agentic-wallet-skills

    Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API…

    127 GitHub starsUsed in 3 repos~1k tokens
    Backend & APIsAuto-check passed

More from greenpau/caddy-security

All 29 skills in this repo
  • Authentication Portal API

    greenpau/caddy-security

    Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS.

    2.3k GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Coding Directives

    greenpau/caddy-security

    Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation.

    2.3k GitHub stars~4.1k tokensUpdated 2 days ago
    Auto-check passed
  • Configuration

    greenpau/caddy-security

    Build or review caddy-security Caddyfiles and select focused configuration skills.

    2.3k GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • Configuration Crypto

    greenpau/caddy-security

    Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys.

    2.3k GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed
  • Configuration HTTP Integrations

    greenpau/caddy-security

    Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata.

    2.3k GitHub stars~3.2k tokensUpdated 2 days ago
    Auto-check passed
  • Configuration State

    greenpau/caddy-security

    Configure durable AuthCrunch runtime state, exclusive storage ownership, stop/start persistence, reload rejection, and recovery.

    2.3k GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Configuration Users

What does Configuration Users do?

Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules. Configuration Users is an agent skill from greenpau/caddy-security. Configure static local accounts, required identity fields, trusted password imports, bcrypt API keys, roles, and stored challenge rules.

When should I use Configuration Users?

Configuration Users fits situations like: caddyfile-owned users; online administration belongs to scripts-and-automation.

How do I install Configuration Users in Claude Code?

Run `npx skills add greenpau/caddy-security --skill configuration-users -a claude-code`. Or copy the skill folder (.codex/skills/configuration-users in greenpau/caddy-security) into .claude/skills/configuration-users in your project. Claude Code loads it when a task matches its description.

How do I install Configuration Users in Codex?

Run `npx skills add greenpau/caddy-security --skill configuration-users -a codex`. Or copy the skill folder (.codex/skills/configuration-users in greenpau/caddy-security) into .agents/skills/configuration-users in your project. Codex loads it when a task matches its description.

Can I use Configuration Users in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add greenpau/caddy-security --skill configuration-users -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/configuration-users, .gemini/skills/configuration-users, .github/skills/configuration-users and .opencode/skills/configuration-users in your project.

What does Configuration Users need to run?

Going by SKILL.md and its folder, Configuration Users needs credentials named ALICE_PASSWORD and USERS_ADMIN_SECRET. Our summary lists: A credential in USERS_ADMIN_SECRET.

Does Configuration Users access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Configuration Users safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Configuration Users use?

Configuration Users is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Configuration Users use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.

What are the alternatives to Configuration Users?

Skills that share tags, products or a category with Configuration Users: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Supabase (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Configuration Users?

greenpau (a GitHub user) maintains it in greenpau/caddy-security, which has 2,251 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 5, 2026.

Source: greenpau/caddy-security on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.