Agent skill

Guidewire Install Auth

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Authenticate production Guidewire Cloud API integrations and survive the auth-side failures — token expiry storms, scope drift, private-CA PKIX errors, secret rotation.

MITAuto-check: notesBackend & APIs

Install Guidewire Install Auth

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill guidewire-install-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace guidewire-install-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/guidewire-install-auth .claude/skills/guidewire-install-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guidewire-install-auth
GitHub stars
2.8k
Token cost
~3.4k tokens
SKILL.md length
1,299 words
Files
3 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Authenticate production Guidewire Cloud API integrations and survive the auth-side failures — token expiry storms, scope drift, private-CA PKIX errors, secret rotation.

  • Works in 4 steps: Token expiry storms — every request… → Scope drift — a GCC admin removes a… → PKIX path building failed — JVM cannot… → …
  • Hardening OAuth2 token caching
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 4 more sections
  • Calls git and openssl; needs GW_CLIENT_SECRET

What it does

Guidewire Install Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Authenticate production Guidewire Cloud API integrations and survive the auth-side failures — token expiry storms, scope drift, private-CA PKIX errors, secret rotation. Use when hardening OAuth2 token caching, configuring JVM trust stores, or rotating client secrets without downtime. Trigger with "guidewire auth", "guidewire OAuth2", "guidewire token cache", "guidewire PKIX", "guidewire secret rotation".

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/API_REFERENCE.md` and `references/implementation-guide.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Secrets management, OAuth and OpenID Connect and Third-party API integration. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Hardening OAuth2 token caching
  • Configuring JVM trust stores
  • Rotating client secrets without downtime
  • With guidewire auth

Example prompts

  • “guidewire auth”
  • “guidewire OAuth2”
  • “guidewire token cache”
  • “/guidewire-install-auth”

Requirements

  • A credential in GW_CLIENT_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(java:*), Bash(keytool:*), Bash(openssl:*), Grep

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Token expiry storms — every request races to refresh, the Hub rate-limits the auth endpoint, the integration cascades to red.
  2. Scope drift — a GCC admin removes a scope, every cached token starts returning 403, retrying does not help.
  3. PKIX path building failed — JVM cannot validate the tenant's TLS chain because the private CA is not in the trust store; common when…
  4. Secret rotation downtime — the active client secret is rotated and the old secret stops working before the new one is loaded; in-flight…

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(curl:*)
    • Bash(jq:*)
    • Bash(java:*)
    • Bash(keytool:*)
    • Bash(openssl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.guidewire.com
    • developer.guidewire.com
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GW_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Guidewire Install Auth loads about 3.4k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 1,299 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:91
    t lives somewhere reviewable (committed `.env`, container image layer, unencrypted Kubernetes `Secret`). Three patterns
  • NoteMentions a .env fileSKILL.md:96
    # idempotent; writes .sops.yaml + .env.sops + scripts/sops-env
  • NoteMentions a .env fileSKILL.md:142
    / Vault Agent / dual-secret env), not a `.env` file or container image.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,299 words, ~3,429 tokens.

Download SKILL.mdSave it as .claude/skills/guidewire-install-auth/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
guidewire-install-auth
description
Authenticate production Guidewire Cloud API integrations and survive the auth-side failures — token expiry storms, scope drift, private-CA PKIX errors, secret rotation. Use when hardening OAuth2 token caching, configuring JVM trust stores, or rotating client secrets without downtime. Trigger with "guidewire auth", "guidewire OAuth2", "guidewire token cache", "guidewire PKIX", "guidewire secret rotation".
allowed-tools
Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(java:*), Bash(keytool:*), Bash(openssl:*), Grep
compatibility
Designed for Claude Code
version
1.26.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
guidewire, oauth2, authentication, token-management, secret-rotation, pkix

Guidewire Install & Auth

Overview

Authenticate a backend service to a Guidewire Cloud tenant using OAuth2 client credentials and operate the auth layer in production. This is not a hello-world walkthrough; it is the auth code your service runs at 3am when a token expires mid-batch, when a tenant admin rotates a scope, when a private CA renews a cert, and when on-call needs to swap a leaked secret without dropping in-flight requests.

The four production failures this skill prevents:

  1. Token expiry storms — every request races to refresh, the Hub rate-limits the auth endpoint, the integration cascades to red.
  2. Scope drift — a GCC admin removes a scope, every cached token starts returning 403, retrying does not help.
  3. PKIX path building failed — JVM cannot validate the tenant's TLS chain because the private CA is not in the trust store; common when carriers front Cloud API with their own DLP appliance.
  4. Secret rotation downtime — the active client secret is rotated and the old secret stops working before the new one is loaded; in-flight token refreshes fail until restart.

Prerequisites

  • JDK 17 (Guidewire Cloud release 202503 and later)
  • A registered Service Application in Guidewire Cloud Console (GCC) with Cloud API roles assigned per least privilege
  • Network egress from your runtime to *.guidewire.net (runtime APIs) and gcc.guidewire.com (console only)
  • A secret store the runtime can read at startup and on rotation signal (AWS Secrets Manager, GCP Secret Manager, HashiCorp Vault, or Kubernetes Secret with CSI driver)
  • For private-CA tenants: the carrier's CA chain in PEM form

Instructions

Build the auth layer in this order. Each section solves one production failure mode; do not skip steps because the failure shows up in production, not in dev.

  1. Implement the token-cache pattern below — proactive refresh, single-flight gate, JWT-based expiry.
  2. Wire secret rotation to your secret store; do not commit secrets or bake them into images.
  3. For private-CA tenants, install the trust store at the JVM/init-container layer.
  4. Validate scope hardening on every refresh so drift fails fast, not on the next business call.
Token-cache pattern (production)

Tokens are short-lived, typically one hour. Reactive refresh on 401 is wrong: it doubles latency on the failing request and creates a thundering herd when many requests notice expiry simultaneously. Cache the token in-process and refresh proactively at 80% of TTL, behind a single-flight gate so concurrent refreshers serialize.

typescript
import jwt from "jsonwebtoken";

type Cached = { value: string; expiresAt: number };
let cached: Cached | null = null;
let inflight: Promise<string> | null = null;

export async function getToken(): Promise<string> {
  if (cached && Date.now() < cached.expiresAt - 60_000) return cached.value;
  if (inflight) return inflight;

  inflight = (async () => {
    const res = await fetch(process.env.GW_AUTH_URL!, {
      method: "POST",
      headers: { "Content-Type": "application/x-www-form-urlencoded" },
      body: new URLSearchParams({
        grant_type: "client_credentials",
        client_id: process.env.GW_CLIENT_ID!,
        client_secret: process.env.GW_CLIENT_SECRET!,
        scope: process.env.GW_SCOPES!,
      }),
    });
    if (!res.ok) throw new Error(`auth ${res.status}: ${await res.text()}`);
    const { access_token } = await res.json();
    const { exp } = jwt.decode(access_token) as { exp: number };
    // exp is seconds since epoch; multiply by 1000 for JS ms. Refresh at 80% of remaining TTL.
    const expMs = exp * 1000;
    cached = { value: access_token, expiresAt: expMs - 0.2 * (expMs - Date.now()) };
    return access_token;
  })().finally(() => { inflight = null; });

  return inflight;
}

The exp - 20% early-refresh window absorbs clock skew and prevents the cliff at TTL boundary. The inflight single-flight gate makes a high-rps service issue one refresh per cache-miss, not one per concurrent request — without it, a 1000-rps service produces 1000 simultaneous Hub calls and trips 429 rate-limiting on the auth endpoint.

Secret rotation without downtime

Rotation breaks if the runtime reads the secret only at startup, or if the plaintext lives somewhere reviewable (committed .env, container image layer, unencrypted Kubernetes Secret). Three patterns work, in order of operational simplicity:

SOPS + age (recommended for VM/container deployments). Encrypt secrets.prod.sops.yaml with one or more age public keys, commit the encrypted file to git, decrypt in-process at startup and on SIGHUP. The repo holds an auditable history of who rotated what and when; only holders of the age private key can read plaintext. Bootstrap a repo with the same conventions used across this organization:

text
sops-init                                    # idempotent; writes .sops.yaml + .env.sops + scripts/sops-env
sops secrets.prod.sops.yaml   # interactive edit; ciphertext re-written on save
eval "$(sops -d secrets.prod.sops.yaml | sed -nE 's/^([A-Za-z_][A-Za-z0-9_]*)=(.*)$/export \1=\2/p')"

The anchored sed regex is non-negotiable: a naive sed 's/^/export /' turns blank lines and comments into bare export calls, and bare export dumps every exported variable to stdout — every secret leaks if anything captures that stdout (cron mail, an SSH session running this).

Cloud-native projection (managed Kubernetes / cloud VMs). Mount the secret as a file from the secret store via Vault Agent, the Secrets Store CSI driver, or AWS Secrets and Configuration Provider. The orchestrator handles restart-on-rotation and the runtime re-reads the file on each token refresh.

Dual-secret env-var window (manual rotation, last resort). Configure the runtime with both GW_CLIENT_SECRET_PRIMARY and GW_CLIENT_SECRET_SECONDARY. On invalid_client from the primary, fall back to the secondary; on success, schedule the swap. Close the window when monitoring confirms 24h of zero primary failures.

Private-CA trust store setup (PKIX)

When a carrier fronts Cloud API with a DLP appliance or proxy that re-signs TLS with a private CA, the JVM rejects the chain. Symptom: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException.

Fix at the JVM level, not the application level:

bash
keytool -importcert \
  -alias guidewire-tenant-ca \
  -file ./tenant-ca.pem \
  -keystore "$JAVA_HOME/lib/security/cacerts" \
  -storepass changeit -noprompt

For Kubernetes deployments, bake the CA into a sidecar that runs keytool against a shared cacerts volume, or use JAVA_OPTS=-Djavax.net.ssl.trustStore=/etc/ssl/cacerts.jks. Do not disable validation with -Dcom.sun.net.ssl.checkRevocation=false or trust-all SSL contexts; the OWASP A02 audit will find that too.

Show full SKILL.md (545 more words)Show less
Scope hardening

Assign roles per least privilege under GCC > Identity & Access > Applications > [your-app] > Permissions. A read-only reporting integration should not hold pc.account.write; a webhook consumer should not hold pc.policy.bind. Scope strings are tenant-configured and vary across environments, so do not hard-code them — read from GW_SCOPES and validate at startup that the issued token contains the expected scopes:

typescript
const decoded = jwt.decode(token) as { scope: string };
const required = (process.env.GW_REQUIRED_SCOPES || "").split(" ");
const granted = decoded.scope.split(" ");
const missing = required.filter(s => !granted.includes(s));
if (missing.length) throw new Error(`scope drift: missing ${missing.join(", ")}`);

Run this check on every token refresh. It catches scope drift the moment a tenant admin removes a permission, instead of letting it surface as 403 on the next business call.

Output

A production-grade auth layer ships with all of the following:

  • A token cache with proactive refresh (80% TTL), single-flight gate, and JWT-based expiry calculation rather than fixed 3600s assumption.
  • Secret loading from a runtime-readable secret store (CSI / Vault Agent / dual-secret env), not a .env file or container image.
  • JVM trust store containing the tenant's CA chain when applicable, configured at the JVM or sidecar layer rather than at application startup.
  • Scope-drift detection on every refresh, failing fast on missing required scopes.
  • Structured logs distinguishing invalid_client, invalid_scope, expired token, and PKIX failures — recognizable in the observability dashboard before they cascade.

Examples

Example 1 — Production token-cache module (TypeScript)

The getToken() snippet above is the canonical implementation. Drop it into the integration's auth module and call it from every Cloud API request wrapper. Validates against scope drift on each refresh; absorbs Hub-side 5xx with retry-once.

Example 2 — SOPS + age rotation (Bash)
bash
# Edit the encrypted file in-place; sops handles re-encryption transparently
sops secrets.prod.sops.yaml         # change GW_CLIENT_SECRET_SECONDARY to the newly issued value
git add secrets.prod.sops.yaml && git commit -m "rotate(gw): issue secondary client secret"

# In the runtime startup or SIGHUP handler — anchored regex prevents bare-export leak
eval "$(sops -d secrets.prod.sops.yaml | sed -nE 's/^([A-Za-z_][A-Za-z0-9_]*)=(.*)$/export \1=\2/p')"
# Monitor: zero invalid_client failures from primary for 24h, then promote secondary → primary
Example 3 — PKIX recovery for private-CA tenant
bash
# Pull the tenant's chain straight from the endpoint
echo | openssl s_client -connect "[TENANT].guidewire.net:443" -servername "[TENANT].guidewire.net" -showcerts 2>/dev/null \
  | sed -ne '/BEGIN CERTIFICATE/,/END CERTIFICATE/p' > tenant-chain.pem

# Import into JVM trust store (do this in the Dockerfile or init container, not at runtime)
keytool -importcert -alias gw-tenant-ca -file tenant-chain.pem \
  -keystore "$JAVA_HOME/lib/security/cacerts" -storepass changeit -noprompt

Error Handling

ErrorCauseSolution
invalid_client (400 from /oauth/token)wrong client_id/client_secret, or app disabled in GCCverify in GCC > Identity & Access > Applications; if mid-rotation, fall back to secondary secret per dual-secret pattern
invalid_scope (400 from /oauth/token)requested scope not granted to this app, or tenant admin removed itscope-drift check on every refresh catches this immediately; alert and re-issue from GCC
401 Unauthorized (from Cloud API)token expired before next refresh windowindicates clock skew or aggressive proxy caching; tighten the early-refresh window from 20% to 30%
403 Forbidden (from Cloud API)token valid but app lacks the role for that resourceleast-privilege violation surfaced — assign the role in GCC, do not retry
409 Conflict (from PATCH/POST)stale checksum on the resourcenot an auth error — covered in guidewire-sdk-patterns
PKIX path building failedprivate-CA cert chain missing from JVM trust storeimport per the trust-store section above; fix at JVM/init-container layer, not in code
ENOTFOUND [TENANT].guidewire.netDNS or firewall blocking egress to runtime API domainconfirm *.guidewire.net egress; runtime APIs are NOT on *.guidewire.com (that is the console)
429 Too Many Requests from Hub /oauth/tokenthundering herd refresh from token cache without single-flightthe inflight gate in the token-cache pattern prevents this; verify it's active

For deeper coverage (M2M vs delegated flows, mTLS-fronted tenants, multi-region failover, GCC scope auditing), see implementation guide and API reference.

See Also

  • guidewire-sdk-patterns — wraps this auth into a retrying, rate-limit-aware Cloud API client; handles checksum-based optimistic locking
  • guidewire-security-and-rbac — secret storage architecture, least-privilege role design, audit capture, PII redaction in logs
  • guidewire-observability-and-incident-response — triage trees and recovery playbooks for 401 spikes, scope drift, and PKIX cascades in production
  • guidewire-ci-cd-pipeline — credential rotation across promoted environments without breaking running deployments

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/.curated/guidewire-install-auth of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/API_REFERENCE.md
  • references/implementation-guide.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Guidewire Install Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guidewire Install Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guidewire Install Auth this skilljeremylongshore/tons-of-skills-marketplace2.8k—~3.4kAutomated safety check: NotesMIT
OneCLI Gatewaynanocoai/nanoclaw31k—~856Automated safety check: PassMIT
Dial Docsepam/ai-dial-chat504—~1.6kAutomated safety check: PassApache-2.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
OmniRoute Provider Managementdiegosouzapw/OmniRoute75k—~2.4kAutomated safety check: PassMIT
Notion Worker Third-Party Auth Guidemakenotion/workers-template4391 repos~3.5kAutomated safety check: NotesMIT

Similar skills

  • OneCLI Gateway

    nanocoai/nanoclaw

    Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

    31k GitHub stars~856 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Dial Docs

    epam/ai-dial-chat

    On-demand index of the AI DIAL Chat design docs in docs/. An agent skill from epam/ai-dial-chat.

    504 GitHub stars~1.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • OmniRoute Provider Management

    diegosouzapw/OmniRoute

    Manages AI provider connections, API keys, OAuth flows and connection tests through OmniRoute's REST API across its 327-provider catalog.

    75k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Notion Worker Third-Party Auth Guide

    makenotion/workers-template

    Official

    Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

    439 GitHub starsUsed in 1 repo~3.5k tokens
    Backend & APIsAuto-check: notes
  • A skill your agent uses when adding or editing Nango integration documentation - creates and maintains integration pages, setup guides, connect guides, navigation, and provider metadata following…

    13k GitHub stars~2.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Guidewire Install Auth

What does Guidewire Install Auth do?

Authenticate production Guidewire Cloud API integrations and survive the auth-side failures — token expiry storms, scope drift, private-CA PKIX errors, secret rotation. Guidewire Install Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Authenticate production Guidewire Cloud API integrations and survive the auth-side failures — token expiry storms, scope drift, private-CA PKIX errors, secret rotation.

When should I use Guidewire Install Auth?

Guidewire Install Auth fits situations like: hardening OAuth2 token caching; configuring JVM trust stores; rotating client secrets without downtime; with guidewire auth.

How do I install Guidewire Install Auth in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill guidewire-install-auth -a claude-code`. Or copy the skill folder (skills/.curated/guidewire-install-auth in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/guidewire-install-auth in your project. Claude Code loads it when a task matches its description.

How do I install Guidewire Install Auth in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill guidewire-install-auth -a codex`. Or copy the skill folder (skills/.curated/guidewire-install-auth in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/guidewire-install-auth in your project. Codex loads it when a task matches its description.

Can I use Guidewire Install Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill guidewire-install-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guidewire-install-auth, .gemini/skills/guidewire-install-auth, .github/skills/guidewire-install-auth and .opencode/skills/guidewire-install-auth in your project.

What does Guidewire Install Auth need to run?

Going by SKILL.md and its folder, Guidewire Install Auth needs the command-line tools its instructions call (git and openssl) and credentials named GW_CLIENT_SECRET. Our summary lists: A credential in GW_CLIENT_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(curl:*), Bash(jq:*), Bash(java:*), Bash(keytool:*), Bash(openssl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Guidewire Install Auth access the network?

SKILL.md names 3 domains. As links in the text: docs.guidewire.com, developer.guidewire.com and owasp.org. This is read from the text; nothing was executed.

Is Guidewire Install Auth safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Guidewire Install Auth use?

Guidewire Install Auth is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guidewire Install Auth use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Guidewire Install Auth?

Skills that share tags, products or a category with Guidewire Install Auth: OneCLI Gateway (nanocoai/nanoclaw, 31k stars), Dial Docs (epam/ai-dial-chat, 504 stars), Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars) and OmniRoute Provider Management (diegosouzapw/OmniRoute, 75k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guidewire Install Auth?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.