Ron Auth
bionic-gpt/bionic-gpt
Implement identity and authorization boundaries in Rust on Nails applications.
Enforce hexagonal architecture in the Rust backend. An agent skill from macro-inc/macro.
$ npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install macro-inc/macro cloud-storage-hexagonal-architecture --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/macro-inc/macro.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cloud-storage-hexagonal-architecture .claude/skills/cloud-storage-hexagonal-architecture && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cloud-storage-hexagonal-architecture" agent skill from https://github.com/macro-inc/macro/tree/main/.agents/skills/cloud-storage-hexagonal-architecture into .claude/skills/cloud-storage-hexagonal-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-storage-hexagonal-architecture", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/macro-inc/macro/tree/main/.agents/skills/cloud-storage-hexagonal-architectureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install macro-inc/macro cloud-storage-hexagonal-architecture --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macro-inc/macro.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/cloud-storage-hexagonal-architecture .agents/skills/cloud-storage-hexagonal-architecture && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cloud-storage-hexagonal-architecture" agent skill from https://github.com/macro-inc/macro/tree/main/.agents/skills/cloud-storage-hexagonal-architecture into .agents/skills/cloud-storage-hexagonal-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-storage-hexagonal-architecture", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install macro-inc/macro cloud-storage-hexagonal-architecture --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macro-inc/macro.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/cloud-storage-hexagonal-architecture .cursor/skills/cloud-storage-hexagonal-architecture && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cloud-storage-hexagonal-architecture" agent skill from https://github.com/macro-inc/macro/tree/main/.agents/skills/cloud-storage-hexagonal-architecture into .cursor/skills/cloud-storage-hexagonal-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-storage-hexagonal-architecture", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/macro-inc/macro.git --path .agents/skills/cloud-storage-hexagonal-architecture--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install macro-inc/macro cloud-storage-hexagonal-architecture --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macro-inc/macro.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/cloud-storage-hexagonal-architecture .gemini/skills/cloud-storage-hexagonal-architecture && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cloud-storage-hexagonal-architecture" agent skill from https://github.com/macro-inc/macro/tree/main/.agents/skills/cloud-storage-hexagonal-architecture into .gemini/skills/cloud-storage-hexagonal-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-storage-hexagonal-architecture", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install macro-inc/macro cloud-storage-hexagonal-architectureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/macro-inc/macro.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/cloud-storage-hexagonal-architecture .github/skills/cloud-storage-hexagonal-architecture && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cloud-storage-hexagonal-architecture" agent skill from https://github.com/macro-inc/macro/tree/main/.agents/skills/cloud-storage-hexagonal-architecture into .github/skills/cloud-storage-hexagonal-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-storage-hexagonal-architecture", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install macro-inc/macro cloud-storage-hexagonal-architecture --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/macro-inc/macro.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/cloud-storage-hexagonal-architecture .opencode/skills/cloud-storage-hexagonal-architecture && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cloud-storage-hexagonal-architecture" agent skill from https://github.com/macro-inc/macro/tree/main/.agents/skills/cloud-storage-hexagonal-architecture into .opencode/skills/cloud-storage-hexagonal-architecture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-storage-hexagonal-architecture", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cloud-storage-hexagonal-architectureEnforce hexagonal architecture in the Rust backend. An agent skill from macro-inc/macro.
Cloud Storage Hexagonal Architecture is an agent skill from macro-inc/macro. Enforce hexagonal architecture in the Rust backend. Use before modifying crates or Rust services, especially inbound axum/tool/listener adapters, domain services/ports, outbound adapters, authorization, permissions, database access, or external clients.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authorization and RBAC. It works with Rust. The repository describes itself as: Macro is a unified workspace for teams: email, chat, docs, tasks, agents, calls, and CRM — @-linked together with shared AI memory. The licence is AGPL-3.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 49418e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cloud Storage Hexagonal Architecture loads about 3k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 1,043 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from macro-inc/macro at commit 49418e7, republished under its AGPL-3.0 licence (© macro-inc). 1,043 words, ~3,032 tokens.
.claude/skills/cloud-storage-hexagonal-architecture/SKILL.md (or your agent's skills folder).Use this skill whenever you add, change, or review Rust code under crates/** or services/** that touches a crate with src/domain, src/inbound, or src/outbound.
This repository follows the ports-and-adapters / hexagonal style described in Master Hexagonal Architecture in Rust and the howtocodeit/hexarch 3-simple-service branch: domain models + ports + services are the center; inbound and outbound adapters are replaceable shells around that center.
Dependencies point inward:
inbound adapters ──► domain ports/models/services ◄── outbound adapters
composition root ──► inbound + domain service + outbound implementationsdomain/ must not depend on inbound/, outbound/, axum, HTTP response types, SQLx pools/queries, AWS SDKs, Redis, reqwest, environment variables, or transport DTOs.inbound/ may depend on domain ports/models/services. It must not own business decisions or persistence/external-service implementation details.outbound/ implements domain ports for databases, S3, HTTP clients, queues, metrics, etc. It must not own use-case policy.src/domain/**)Put the following here:
src/inbound/**)Axum handlers, AI tools, Kafka/listener handlers, lambda handlers, and CLI entrypoints are adapters. Keep them thin:
MacroAuthorizationExtractor, OptionalMacroAuthorizationExtractor, JWT, signed internal header, request context).Inbound adapters must not:
entity_access, roles_and_permissions, repositories, SQLx, S3, Redis, SQS, reqwest, or other outbound implementations to make a use-case decision.AccessLevel, role, owner/admin/member, tenant/team membership, project membership, subscription tier, feature entitlement, entity state, or ownership for business policy.src/outbound/**)Put implementation details here:
Outbound adapters must not:
crate::inbound::*, axum extractors/responses, or transport DTOs.EntityAccessReceipt ruleAuthentication can happen at the edge. Entity access checks should cross the boundary as a typed capability: EntityAccessReceipt<T>.
EntityAccessReceipt<T> means the entity access layer has verified the caller has at least permission T for the entity. Inbound adapters may obtain this receipt through the standard access extractors or by calling the entity access service specifically to mint a receipt. After that, ordinary handlers/tools/listeners must pass the receipt inward instead of re-checking or branching on authorization.
Allowed in inbound:
401 / unauthenticated).actor, request_context, user_id, service identity, internal principal, or a typed EntityAccessReceipt<T>.generate_entity_access_receipt::<RequiredLevel>(...) to mint a receipt.Forbidden in ordinary inbound handlers/tools/listeners:
if user_id != owner_id { ... }if access_level < Edit { ... }entity_access_service.get_access_level(...) or can_edit(...) followed by allow/deny branching.receipt.entity_permission() to decide use-case business policy.Correct pattern:
ViewAccessLevel, EditAccessLevel, or OwnerAccessLevel.EntityAccessReceipt<RequiredLevel> using the existing entity access boundary.Unauthorized, Forbidden, or a typed policy error.Bad: the handler branches on permissions and performs the protected action itself.
pub async fn edit_document_handler(
State(state): State<DocumentRouterState>,
Json(args): Json<EditDocumentServiceArgs>,
) -> Result<Json<EditDocumentResponse>, DocumentError> {
let access_level = state
.entity_access
.get_access_level(current_user(), &args.document_id, EntityType::Document)
.await?
.ok_or(DocumentError::Unauthorized)?;
if access_level < AccessLevel::Edit {
return Err(DocumentError::Unauthorized);
}
if args.share_permission.is_some() && access_level != AccessLevel::Owner {
return Err(DocumentError::Unauthorized);
}
state.document_repo.update_document(args).await?;
Ok(Json(EditDocumentResponse::success()))
}Good: inbound obtains a typed receipt and forwards it; the domain service owns policy and orchestration.
pub async fn edit_document_handler<T: DocumentService, Svc: EntityAccessService>(
access: DocumentAccessExtractor<EditAccessLevel, Svc>,
State(state): State<DocumentRouterState<T, Svc>>,
document_context: LoadedDocumentBasic,
project: ProjectBodyAccessLevelExtractor<EditAccessLevel, EditDocumentServiceArgs, Svc>,
) -> Result<Json<EditDocumentResponse>, DocumentError> {
state
.service
.edit_document(
access.entity_access_receipt,
document_context.into_inner(),
project.into_inner(),
)
.await?;
Ok(Json(EditDocumentResponse::success()))
}async fn edit_document(
&self,
receipt: EntityAccessReceipt<EditAccessLevel>,
document_context: DocumentBasic,
args: EditDocumentServiceArgs,
) -> Result<(), DocumentError> {
if let EntityPermission::AccessLevel { access_level } = receipt.entity_permission() {
if args.project_id.is_some() && *access_level != AccessLevel::Owner {
return Err(DocumentError::Unauthorized);
}
if args.share_permission.is_some() && *access_level != AccessLevel::Owner {
return Err(DocumentError::Unauthorized);
}
}
let document_id = receipt.entity().entity_id.clone();
self.repo
.edit_document_metadata(document_id, document_context, args)
.await
}Before editing code, classify each touched file:
domain, inbound, outbound, or composition/wiring?If a step has no answer, stop and design that boundary before writing code.
For every diff under crates/** or services/**, reject or refactor if any of these are true:
src/domain/** imports axum, http::StatusCode, IntoResponse, Json, Router, Request, HeaderMap, SQLx pools/queries, AWS SDK clients, Redis clients, reqwest clients, crate::inbound, or crate::outbound.src/inbound/** contains SQLx queries, transaction handling, repository calls, AWS/Redis/OpenSearch/reqwest calls, or direct calls to outbound implementations.src/inbound/** handlers/tools/listeners contain authorization decisions (AccessLevel, role checks, owner checks, team/project membership checks, can_*, authorize_*, ensure_*permission*) instead of forwarding a typed EntityAccessReceipt<T> or identity to a service. Dedicated access extractors whose job is to mint receipts are the exception.Set CRATE to the crate you are touching, for example CRATE=crates/documents.
# Domain must not know transport or concrete infrastructure.
rg -n "use (axum|http::StatusCode)|IntoResponse|Json<|Router|HeaderMap|Request<|sqlx::|PgPool|aws_sdk|redis::|reqwest|crate::inbound|crate::outbound" "$CRATE/src/domain" --glob '*.rs'
# Inbound authz/policy hits require inspection. Receipt-minting extractors are allowed;
# ordinary handlers should forward EntityAccessReceipt<T> instead of branching.
rg -n "entity_access|EntityAccessReceipt|roles_and_permissions|AccessLevel|RoleId|owner|admin|member|tenant|team|project|permission|authorize|authz|can_|ensure_.*permission|Forbidden|Unauthorized" "$CRATE/src/inbound" --glob '*.rs'
# Inbound should not do persistence or infrastructure work.
rg -n "sqlx::|query!|query_as!|PgPool|Transaction|aws_sdk|redis::|opensearch|reqwest|S3|Sqs|Dynamo" "$CRATE/src/inbound" --glob '*.rs'
# Outbound must not depend on inbound transport.
rg -n "crate::inbound|axum|IntoResponse|Json<|Router|StatusCode" "$CRATE/src/outbound" --glob '*.rs'rg hits are not automatically failures, but every hit must be explained by layer responsibilities. When in doubt, move policy inward.
When you use this skill, explicitly state that the hexagonal boundary was checked and summarize where authz/business policy lives after your change.
© macro-inc, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/cloud-storage-hexagonal-architecture of macro-inc/macro.
Open the folder on GitHubat commit 49418e7
Cloud Storage Hexagonal Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cloud Storage Hexagonal Architecture this skillmacro-inc/macro | 4.6k | — | ~3k | Automated safety check: Pass | AGPL-3.0 | |
| Ron Authbionic-gpt/bionic-gpt | 2.4k | — | ~667 | Automated safety check: Pass | Apache-2.0 | |
| Auth Architecturemajiayu000/litellm-rs | 117 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Tenuo Denial Triagetenuo-ai/tenuo | 102 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Trust Hmi ContractsjohannesPettersson80/trust-platform | 221 | — | ~611 | Automated safety check: Pass | Apache-2.0 | |
| Smart Contract Auditelophanto/EloPhanto | 106 | — | ~2.7k | Automated safety check: Pass | Custom licence |
bionic-gpt/bionic-gpt
Implement identity and authorization boundaries in Rust on Nails applications.
majiayu000/litellm-rs
LiteLLM-RS Authentication Architecture. An agent skill from majiayu000/litellm-rs.
tenuo-ai/tenuo
Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority.
johannesPettersson80/trust-platform
Implement and review trust-platform HMI schema/value/write contracts with safety guardrails.
elophanto/EloPhanto
A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.
bionic-gpt/bionic-gpt
Manage PostgreSQL migrations, typed SQL queries, generated Rust bindings, and database authorization in Rust on Nails applications.
macro-inc/macro
Interact with the Mintlify REST API to manage deployments, trigger builds, and query documentation site metadata programmatically.
macro-inc/macro
Add or change an in-app feature tour (a view's guided flyover) in the web app.
macro-inc/macro
Define a frontend feature flag with defineFlag and wire its readers.
macro-inc/macro
Run the Macro app on Cursor Cloud and pick up edits. An agent skill from macro-inc/macro.
macro-inc/macro
Wrap a new backend endpoint in the TypeScript SDK (packages/sdk), or record it as skipped.
macro-inc/macro
A skill your agent uses when adding collaborative markdown, notes, or descriptions to a feature with collab surfaces.
Works with
Categories
Enforce hexagonal architecture in the Rust backend. An agent skill from macro-inc/macro. Cloud Storage Hexagonal Architecture is an agent skill from macro-inc/macro. Enforce hexagonal architecture in the Rust backend.
Cloud Storage Hexagonal Architecture fits situations like: tasks that involve Authorization and RBAC.
Run `npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a claude-code`. Or copy the skill folder (.agents/skills/cloud-storage-hexagonal-architecture in macro-inc/macro) into .claude/skills/cloud-storage-hexagonal-architecture in your project. Claude Code loads it when a task matches its description.
Run `npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a codex`. Or copy the skill folder (.agents/skills/cloud-storage-hexagonal-architecture in macro-inc/macro) into .agents/skills/cloud-storage-hexagonal-architecture in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add macro-inc/macro --skill cloud-storage-hexagonal-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-storage-hexagonal-architecture, .gemini/skills/cloud-storage-hexagonal-architecture, .github/skills/cloud-storage-hexagonal-architecture and .opencode/skills/cloud-storage-hexagonal-architecture in your project.
Going by SKILL.md and its folder, Cloud Storage Hexagonal Architecture needs the command-line tools its instructions call (rg).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cloud Storage Hexagonal Architecture is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cloud Storage Hexagonal Architecture: Ron Auth (bionic-gpt/bionic-gpt, 2.4k stars), Auth Architecture (majiayu000/litellm-rs, 117 stars), Tenuo Denial Triage (tenuo-ai/tenuo, 102 stars) and Trust Hmi Contracts (johannesPettersson80/trust-platform, 221 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
macro-inc (a GitHub organization) maintains it in macro-inc/macro, which has 4,590 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.
Source: macro-inc/macro on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.