Agent skill

Horse Security Auth

by HashLoad in HashLoad/horse

Guide for securing routes, configuring JWT and Basic-Auth middlewares, and handling route authentication groups.

MITAuto-check passedBackend & APIs

Install Horse Security Auth

skills CLI
$ npx skills add HashLoad/horse --skill horse-security-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HashLoad/horse horse-security-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HashLoad/horse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/doc/skills/horse-security-auth .claude/skills/horse-security-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
horse-security-auth
GitHub stars
1.4k
Token cost
~701 tokens
SKILL.md length
160 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Guide for securing routes, configuring JWT and Basic-Auth middlewares, and handling route authentication groups.

  • Works in 4 steps: Organizing Public and Protected Routes → Setting Up JWT (JSON Web Token)… → Setting Up Basic Authentication → …
  • Tasks that involve Authentication
  • SKILL.md covers 1. Organizing Public and…, 2. Setting Up JWT (JSON Web…, 3. Setting Up Basic… and 4. Security Best Practices
  • Needs JWT_SECRET_KEY

What it does

Horse Security Auth is an agent skill from HashLoad/horse. Guide for securing routes, configuring JWT and Basic-Auth middlewares, and handling route authentication groups.

Its SKILL.md is about 700 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. The repository describes itself as: Fast, opinionated, minimalist web framework for Delphi. The licence is MIT.

When your agent uses it

  • Tasks that involve Authentication

Example prompts

  • “/horse-security-auth”

Requirements

  • A credential in JWT_SECRET_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Organizing Public and Protected Routes
  2. Setting Up JWT (JSON Web Token) Authentication
  3. Setting Up Basic Authentication
  4. Security Best Practices

What it can do on your machine

Read from SKILL.md and the folder at commit d4351a5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are pascal).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Horse Security Auth loads about 701 tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 160 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~33
When it runs · the whole SKILL.md, loaded when a task matches
~701

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HashLoad/horse at commit d4351a5, republished under its MIT licence (© HashLoad). 160 words, ~701 tokens.

Download SKILL.mdSave it as .claude/skills/horse-security-auth/SKILL.md (or your agent's skills folder).
name
horse-security-auth
description
Guide for securing routes, configuring JWT and Basic-Auth middlewares, and handling route authentication groups.

Horse Security & Authentication

1. Organizing Public and Protected Routes

Always separate public endpoints (e.g., authentication, login, system health) from protected ones. Use THorse.Group to configure middleware layers specifically for protected routes without affecting public endpoints:

pascal
begin
  // Global Middlewares (CORS, Johnson, etc.)
  THorse.Use(CORS).Use(Jhonson);

  // 1. Public Routes
  THorse.Post('/login', DoLoginHandler);
  THorse.Get('/health', GetHealthHandler);

  // 2. Protected Routes (Using a Group with JWT Middleware)
  THorse.Group.Prefix('/api/v1')
    .Use(HorseJWT('my_secret_key')) // Authenticates all routes within this group
    .Get('/customers', GetCustomersHandler)
    .Get('/orders', GetOrdersHandler);

  THorse.Listen(9000);
end;

2. Setting Up JWT (JSON Web Token) Authentication

The official JWT middleware is horse-jwt.

Acquiring Token Payload in Handlers

Once HorseJWT authenticates the request, it decodes the payload and stores it in the Session property of THorseRequest. You can retrieve claims using the Session dictionary:

pascal
procedure GetProfileHandler(Req: THorseRequest; Res: THorseResponse; Next: TProc);
var
  LClaims: TJWTClaims; // Or TJSONObject depending on the horse-jwt version used
  LUserId: string;
begin
  // Example of pulling JWT claims
  LUserId := Req.Session<TJSONObject>.GetValue<string>('sub');
  
  Res.Send(Format('Hello, User %s!', [LUserId]));
end;

3. Setting Up Basic Authentication

For quick, credential-based authentication, use the official horse-basic-auth middleware:

pascal
uses Horse.BasicAuth;

begin
  // Protect all API routes with Basic-Auth
  THorse.Group.Prefix('/api')
    .Use(HorseBasicAuth(
      function(AUsername, APassword: string): Boolean
      begin
        // Replace with secure database/credential lookup
        Result := (AUsername = 'admin') and (APassword = 'secret123');
      end
    ))
    .Get('/secrets', GetSecretsHandler);
end;

4. Security Best Practices

  1. Secret Management: Never hardcode encryption keys directly in the source code. Always pull them from Environment Variables or external configurations (e.g., GetEnvironmentVariable('JWT_SECRET_KEY')).
  2. JWT Lifetime: Set short expiration times (exp claim) on issued JWTs and implement a refresh token pattern for long-running client sessions.
  3. Transport Security: Never transmit JWTs or credentials over HTTP. Always enforce HTTPS (SSL/TLS) in production environments.

© HashLoad, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in doc/skills/horse-security-auth of HashLoad/horse.

Open the folder on GitHubat commit d4351a5

Compare with similar skills

Horse Security Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Horse Security Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Horse Security Auth this skillHashLoad/horse1.4k—~701Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Supabasecurvenote/curvenote1695 repos~2.2kAutomated safety check: PassCustom licence
Gitnexus Exploringaws-samples/sample-kolya-br-proxy10611 repos~749Automated safety check: PassMIT-0

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    169 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Gitnexus Exploring

    aws-samples/sample-kolya-br-proxy

    Official

    A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.

    106 GitHub starsUsed in 11 repos~749 tokens
    Backend & APIsAuto-check passed
  • Agentic Wallet

    coinbase/agentic-wallet-skills

    Crypto wallet operations via the awal CLI — sign in, check balances, send USDC/ETH/POL/SOL, trade tokens, fund the wallet, and use the x402 payment protocol to discover paid services, pay for API…

    127 GitHub starsUsed in 3 repos~1k tokens
    Backend & APIsAuto-check passed

More from HashLoad/horse

All 23 skills in this repo
  • Horse App Structure

    HashLoad/horse

    Guide for setting up Horse applications, bootstrap program (.dpr), basic console initialization, and registering modules.

    1.4k GitHub stars~716 tokensUpdated yesterday
    Auto-check passed
  • Guide for setting up thread-safe database connection pooling (FireDAC / UniDAC) in multithreaded Horse applications.

    1.4k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Guide for managing request-scoped contextual services and IoC (dependency injection) in Delphi and Lazarus.

    1.4k GitHub stars~985 tokensUpdated yesterday
    Auto-check passed
  • Horse Files Streams

    HashLoad/horse

    Guide to handling file uploads (multipart), downloads, and stream lifetime management in the Horse framework.

    1.4k GitHub stars~601 tokensUpdated yesterday
    Auto-check passed
  • Horse Grpc

    HashLoad/horse

    Guidelines and workflows for developing and maintaining gRPC services, HTTP/2 h2c transport, and Protobuf serialization within the Horse framework.

    1.4k GitHub stars~776 tokensUpdated yesterday
    Auto-check passed
  • Guide for writing automated integration tests for Horse endpoints using DUnit/DUnitX and THTTPClient.

    1.4k GitHub stars~964 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Horse Security Auth

What does Horse Security Auth do?

Guide for securing routes, configuring JWT and Basic-Auth middlewares, and handling route authentication groups. Horse Security Auth is an agent skill from HashLoad/horse. Guide for securing routes, configuring JWT and Basic-Auth middlewares, and handling route authentication groups.

When should I use Horse Security Auth?

Horse Security Auth fits situations like: tasks that involve Authentication.

How do I install Horse Security Auth in Claude Code?

Run `npx skills add HashLoad/horse --skill horse-security-auth -a claude-code`. Or copy the skill folder (doc/skills/horse-security-auth in HashLoad/horse) into .claude/skills/horse-security-auth in your project. Claude Code loads it when a task matches its description.

How do I install Horse Security Auth in Codex?

Run `npx skills add HashLoad/horse --skill horse-security-auth -a codex`. Or copy the skill folder (doc/skills/horse-security-auth in HashLoad/horse) into .agents/skills/horse-security-auth in your project. Codex loads it when a task matches its description.

Can I use Horse Security Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HashLoad/horse --skill horse-security-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/horse-security-auth, .gemini/skills/horse-security-auth, .github/skills/horse-security-auth and .opencode/skills/horse-security-auth in your project.

What does Horse Security Auth need to run?

Going by SKILL.md and its folder, Horse Security Auth needs credentials named JWT_SECRET_KEY. Our summary lists: A credential in JWT_SECRET_KEY.

Does Horse Security Auth access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Horse Security Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Horse Security Auth use?

Horse Security Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Horse Security Auth use?

About 701 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Horse Security Auth?

Skills that share tags, products or a category with Horse Security Auth: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Supabase (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Horse Security Auth?

HashLoad (a GitHub organization) maintains it in HashLoad/horse, which has 1,377 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 7, 2026.

Source: HashLoad/horse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.