Agent skill

Neo4j Security Skill

by neo4j-contrib in neo4j-contrib/neo4j-skills

Programmatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER), role lifecycle (CREATE/GRANT ROLE/DROP ROLE), privilege grants and denies (GRANT/DENY/REVOKE on graph…

MITAuto-check: notesBackend & APIs

Install Neo4j Security Skill

skills CLI
$ npx skills add neo4j-contrib/neo4j-skills --skill neo4j-security-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install neo4j-contrib/neo4j-skills neo4j-security-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/neo4j-contrib/neo4j-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/neo4j-security-skill .claude/skills/neo4j-security-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
neo4j-security-skill
GitHub stars
114
Token cost
~4k tokens
SKILL.md length
897 words
Files
3 (incl. references)
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Programmatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER), role lifecycle (CREATE/GRANT ROLE/DROP ROLE), privilege grants and denies (GRANT/DENY/REVOKE on graph…

  • Works in 9 steps: User Management → Role Management → Privilege Decision Table → …
  • An agent needs to manage users
  • SKILL.md covers When to Use, When NOT to Use, MCP Write Gate — MANDATORY and Execution Context, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Neo4j Security Skill is an agent skill from neo4j-contrib/neo4j-skills. Programmatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER), role lifecycle (CREATE/GRANT ROLE/DROP ROLE), privilege grants and denies (GRANT/DENY/REVOKE on graph, database, DBMS), property-level access control, sub-graph access control, SHOW PRIVILEGES inspection, and auth provider config reference (LDAP, OIDC/SSO). Use when an agent needs to manage users, roles, or privileges programmatically via Cypher on the system database. Does NOT handle Cypher query writing — use…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `README.md` and `references/privilege-reference.md`).

It sits in Backend & APIs, covering Authorization and RBAC. It works with Neo4j. The repository describes itself as: Neo4j Skills for Coding and other Agents including Cypher. The licence is MIT.

When your agent uses it

  • An agent needs to manage users
  • Privileges programmatically via Cypher on the system database

Example prompts

  • “/neo4j-security-skill”

Requirements

  • Pre-approved tools (allowed-tools): Bash, WebFetch

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. User Management
  2. Role Management
  3. Privilege Decision Table
  4. Common Role Patterns
  5. Property-Level Access Control (Enterprise)
  6. ABAC — Attribute-Based Access Control (Enterprise)
  7. SHOW PRIVILEGES Patterns
  8. Built-in Roles (do not drop)
  9. Auth Provider Config Reference (operational — not Cypher)

What it can do on your machine

Read from SKILL.md and the folder at commit bb30e1f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • WebFetch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are cypher).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Neo4j Security Skill loads about 4k tokens when it runs, and up to ~6.4k if it reads all its reference files. Until then it costs about 170 tokens; SKILL.md has 897 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~170
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, WebFetch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from neo4j-contrib/neo4j-skills at commit bb30e1f, republished under its MIT licence (© neo4j-contrib). 897 words, ~4,011 tokens.

Download SKILL.mdSave it as .claude/skills/neo4j-security-skill/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
neo4j-security-skill
description
Programmatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER), role lifecycle (CREATE/GRANT ROLE/DROP ROLE), privilege grants and denies (GRANT/DENY/REVOKE on graph, database, DBMS), property-level access control, sub-graph access control, SHOW PRIVILEGES inspection, and auth provider config reference (LDAP, OIDC/SSO). Use when an agent needs to manage users, roles, or privileges programmatically via Cypher on the system database. Does NOT handle Cypher query writing — use neo4j-cypher-skill. Does NOT handle cluster ops or backups — use neo4j-cli-tools-skill. Property-level security and ABAC require Enterprise Edition.
allowed-tools
Bash, WebFetch
version
1.0.11

When to Use

  • Creating, altering, suspending, or dropping users
  • Creating roles, granting/revoking role membership
  • Granting/denying/revoking graph, database, or DBMS privileges
  • Inspecting current privileges (SHOW PRIVILEGES)
  • Implementing property-level access control (read/write per property)
  • Setting up ABAC rules against OIDC claims or native user tags
  • Referencing LDAP/SSO auth provider configuration

When NOT to Use

  • Writing Cypher queries against application data → neo4j-cypher-skill
  • Cluster ops, backups, server config → neo4j-cli-tools-skill
  • Driver connection setup → neo4j-driver-*-skill

MCP Write Gate — MANDATORY

Before executing ANY of the following, show the planned command and wait for explicit confirmation:

  • CREATE USER / ALTER USER / DROP USER
  • CREATE ROLE / DROP ROLE
  • GRANT / DENY / REVOKE (any privilege)
  • CREATE AUTH RULE / DROP AUTH RULE

Never auto-execute privilege changes. Show exact Cypher, annotate impact, get "yes".


Execution Context

All security Cypher runs against the system database:

cypher
// Neo4j auto-routes CREATE/ALTER/SHOW USER|ROLE|PRIVILEGE to system
// If using cypher-shell: cypher-shell -d system
// If using driver: use database="system"

1. User Management

Create user
cypher
CREATE USER alice SET PASSWORD 'secret' CHANGE NOT REQUIRED;
// CHANGE REQUIRED (default): forces password change on first login
// CHANGE NOT REQUIRED: password valid immediately
// SET STATUS ACTIVE (default) | SUSPENDED
Parameterised password (preferred in scripts)
cypher
CREATE USER $username SET PASSWORD $password CHANGE NOT REQUIRED;
Alter user
cypher
ALTER USER alice SET PASSWORD $newPw CHANGE NOT REQUIRED;
ALTER USER alice SET STATUS SUSPENDED;          // lock account
ALTER USER alice SET STATUS ACTIVE;             // unlock
ALTER USER alice SET HOME DATABASE mydb;        // default db on connect
ALTER USER alice IF EXISTS SET PASSWORD $pw;    // safe if missing
User tags [2026.06+, Enterprise]

Tags are arbitrary strings on the native user object, readable in ABAC rules via abac.native.user_tags().

cypher
CREATE USER jake SET PASSWORD $pw SET TAGS 'finance', 'auditor';
ALTER USER jake REMOVE TAG 'auditor' ADD TAG 'on-call';   // REMOVE before ADD before SET
ALTER USER jake SET TAGS 'finance', 'auditor';            // replaces all existing tags
ALTER USER jake REMOVE ALL TAGS;
ALTER USERS jake, alice ADD TAGS 'pii-access';            // bulk tag edit

SET/ADD/REMOVE TAG[S] requires SET USER METADATA; reading tag values requires SHOW USER METADATA:

cypher
GRANT SET USER METADATA ON DBMS TO userAdmin;
GRANT SHOW USER METADATA ON DBMS TO auditor;
GRANT USER METADATA MANAGEMENT ON DBMS TO userManager;   // both of the above
Show users
cypher
SHOW USERS YIELD user, roles, passwordChangeRequired, suspended, home
WHERE suspended = false
RETURN user, roles ORDER BY user;

// tags column returns null without SHOW USER METADATA [2026.06+]
SHOW USERS YIELD user, roles, tags;

// runnable CREATE USER commands for the whole DBMS [2026.09]
// requires SHOW USER + SHOW USER CREDENTIALS; tags omitted without SHOW USER METADATA
SHOW USERS AS COMMANDS;
SHOW USERS WITH AUTH AS COMMANDS;   // includes auth provider config + credentials

SHOW USERS WITH AUTH AS COMMANDS exposes credentials. Use only for secured backup/restore handling. Prefer SHOW USERS AS COMMANDS when auth material is not required. Never paste auth-export output into plaintext docs, logs, tickets, or source control.

Drop user
cypher
DROP USER alice IF EXISTS;

2. Role Management

Create / drop role
cypher
CREATE ROLE analyst;
CREATE ROLE analyst IF NOT EXISTS;
DROP ROLE analyst IF EXISTS;
Assign / remove roles
cypher
GRANT ROLE analyst TO alice;
GRANT ROLE analyst, writer TO alice, bob;   // bulk
REVOKE ROLE analyst FROM alice;
Inspect roles
cypher
SHOW ROLES YIELD role, member ORDER BY role;
SHOW ROLE analyst PRIVILEGES AS COMMANDS;   // returns runnable GRANT commands
SHOW POPULATED ROLES YIELD role;            // only roles with members

// runnable CREATE ROLE commands for the whole DBMS [2026.09]
SHOW ROLES AS COMMANDS;
SHOW ROLES WITH USERS AS COMMANDS;          // adds GRANT ROLE ... TO user
SHOW ROLES WITH AUTH RULES AS COMMANDS;     // adds GRANT ROLE ... TO AUTH RULE

3. Privilege Decision Table

GoalCommand
Allow db connectionGRANT ACCESS ON DATABASE mydb TO analyst
Read all graph dataGRANT MATCH {*} ON GRAPH mydb ELEMENTS * TO analyst
Read specific labelGRANT MATCH {*} ON GRAPH mydb NODES Person TO analyst
Read specific rel typeGRANT MATCH {*} ON GRAPH mydb RELATIONSHIPS KNOWS TO analyst
Read one propertyGRANT READ {email} ON GRAPH mydb NODES Person TO analyst
Traverse but hide propertiesGRANT TRAVERSE ON GRAPH mydb NODES Person TO analyst
Write (create/set)GRANT WRITE ON GRAPH mydb TO writer
Create nodes onlyGRANT CREATE ON GRAPH mydb NODES Person TO writer
Delete nodes onlyGRANT DELETE ON GRAPH mydb NODES Person TO writer
Execute procedureGRANT EXECUTE PROCEDURE apoc.* TO analyst
Execute functionGRANT EXECUTE USER DEFINED FUNCTION apoc.* TO analyst
All on one dbGRANT ALL ON DATABASE mydb TO dba
Full DBMS adminGRANT ALL ON DBMS TO dba
Manage usersGRANT USER MANAGEMENT ON DBMS TO secadmin
Manage user tags [2026.06]GRANT USER METADATA MANAGEMENT ON DBMS TO secadmin
Manage rolesGRANT ROLE MANAGEMENT ON DBMS TO secadmin
Schema changesGRANT CREATE ELEMENT TYPES ON DATABASE mydb TO schemaadmin
DENY overrides GRANT
cypher
// Analyst can read Person but NOT the ssn property
GRANT MATCH {*} ON GRAPH mydb NODES Person TO analyst;
DENY  READ {ssn} ON GRAPH mydb NODES Person TO analyst;
REVOKE removes a specific grant or deny
cypher
REVOKE GRANT READ {email} ON GRAPH mydb NODES Person FROM analyst;
REVOKE DENY  READ {ssn}   ON GRAPH mydb NODES Person FROM analyst;
REVOKE MATCH {*} ON GRAPH mydb NODES Person FROM analyst;  // removes both grant+deny

4. Common Role Patterns

Read-only analyst
cypher
CREATE ROLE analyst IF NOT EXISTS;
GRANT ACCESS            ON DATABASE mydb TO analyst;
GRANT MATCH {*}         ON GRAPH mydb ELEMENTS * TO analyst;
GRANT EXECUTE PROCEDURE apoc.* TO analyst;
Write role (no admin)
cypher
CREATE ROLE writer IF NOT EXISTS;
GRANT ACCESS  ON DATABASE mydb TO writer;
GRANT MATCH {*} ON GRAPH mydb ELEMENTS * TO writer;
GRANT WRITE   ON GRAPH mydb TO writer;
Read-only on specific labels only
cypher
CREATE ROLE limited_reader IF NOT EXISTS;
GRANT ACCESS    ON DATABASE mydb TO limited_reader;
GRANT TRAVERSE  ON GRAPH mydb ELEMENTS * TO limited_reader;      // can traverse
GRANT MATCH {*} ON GRAPH mydb NODES Person TO limited_reader;    // Person props visible
GRANT MATCH {*} ON GRAPH mydb NODES Company TO limited_reader;   // Company props visible
// Other labels: traversable but properties invisible
DBA role (full admin)
cypher
CREATE ROLE dba IF NOT EXISTS;
GRANT ALL ON DBMS     TO dba;
GRANT ALL ON DATABASE * TO dba;

5. Property-Level Access Control (Enterprise)

Restrict read access to individual properties:

cypher
// Grant read on all Person props, then deny sensitive ones
GRANT MATCH {*}   ON GRAPH mydb NODES Person TO analyst;
DENY  READ {ssn, dateOfBirth} ON GRAPH mydb NODES Person TO analyst;

Property-based pattern matching (sub-graph access):

cypher
// Only see Person nodes where classification = 'public'
GRANT MATCH {*} ON GRAPH mydb
  FOR (n:Person) WHERE n.classification = 'public'
  TO analyst;

// Block access to classified nodes
DENY MATCH {*} ON GRAPH mydb
  FOR (n) WHERE n.classification <> 'UNCLASSIFIED'
  TO regularUsers;

// List-valued property contains a value [2026.08, Cypher 25]
GRANT MATCH {*} ON GRAPH mydb
  FOR (n) WHERE 'gold' IN n.clearanceLevels
  TO goldTier;
GRANT READ {*} ON GRAPH mydb FOR (n) WHERE 'EU' IN n.regions TO regularUsers;
GRANT MATCH {*} ON GRAPH mydb FOR (n) WHERE NOT 'EU' IN n.regions TO regularUsers;

// Property on the right-hand side of a comparison [2026.08, Cypher 25]
GRANT MATCH {*} ON GRAPH mydb
  FOR (n) WHERE 1 > n.level
  TO analyst;
GRANT READ {*} ON GRAPH mydb FOR (n) WHERE 3 < n.securityLevel TO regularUsers;
  • value IN n.listProp — list property contains value
  • Missing or scalar property — no match
  • Left value — non-null, not NaN
  • n.prop IN [v1, v2] — scalar-against-list
  • Pre-Cypher-25 — keep property on left side of comparison

PBAC edge cases and export patterns → references/privilege-reference.md

Constraints:

  • FOR pattern applies to read privileges only — not write
  • Each property-based privilege restricted by a single property
  • Pre-2026.08: list membership and property-on-RHS predicates are rejected — invert to n.prop <op> <literal> or maintain a scalar flag property
  • Performance overhead scales with number of rules; TRAVERSE rules cost more than READ
  • Ensure the property used for rules cannot be modified by the restricted role

Show full SKILL.md (334 more words)Show less

6. ABAC — Attribute-Based Access Control (Enterprise)

ABAC grants roles dynamically from OIDC/JWT claims or native user tags rather than explicit GRANT ROLE ... TO user.

Prerequisites
# neo4j.conf — providers must also appear in dbms.security.authorization_providers
dbms.security.abac.authorization_providers=<oidc-provider-alias>,native   # native [2026.06+]

Unlisted provider → its accessor function (abac.oidc.user_attribute(), abac.native.user_tags()) unavailable and rules referencing it fail (no silent default).

Create auth rule
cypher
CREATE AUTH RULE salesRule
  SET CONDITION abac.oidc.user_attribute('department') = 'sales';

GRANT ROLE analyst TO AUTH RULE salesRule;
Compound conditions
cypher
CREATE OR REPLACE AUTH RULE seniorRule
  SET CONDITION abac.oidc.user_attribute('department') = 'engineering'
    AND abac.oidc.user_attribute('level') >= 5;

GRANT ROLE senior_engineer TO AUTH RULE seniorRule;
Manage auth rules
cypher
SHOW AUTH RULES YIELD ruleName, condition, roles;
ALTER AUTH RULE salesRule SET ENABLED false;     // disable without dropping
RENAME AUTH RULE salesRule TO salesDeptRule;
DROP AUTH RULE salesDeptRule;
REVOKE ROLE analyst FROM AUTH RULE salesRule;

Native users [2026.06+]: tag native DB users (see User tags) and match tags in rules via abac.native.user_tags() — no OIDC required:

cypher
CREATE AUTH RULE nativeSalesRule
  SET CONDITION 'sales' IN abac.native.user_tags();
GRANT ROLE analyst TO AUTH RULE nativeSalesRule;

// require several tags at once
CREATE AUTH RULE financeAuditRule
  SET CONDITION all(tag IN ['finance', 'auditor'] WHERE tag IN abac.native.user_tags());

// combine tags with OIDC claims and temporal conditions
CREATE AUTH RULE onCallRule
  SET CONDITION 'on-call' IN abac.native.user_tags()
    AND abac.oidc.user_attribute('department') = 'engineering'
    AND time.transaction('UTC').hour >= 9;

❌ Never condition on tag absence: NOT ('restricted' IN abac.native.user_tags()) — any user created without tags satisfies it, escalating privileges. ✅ Require presence of a tag: 'unrestricted' IN abac.native.user_tags().

Notes:

  • Missing claims evaluate to NULL → rule condition false → role not granted
  • Rules apply immediately to existing sessions when claims are already loaded
  • OIDC claims via abac.oidc.user_attribute(); native user tags via abac.native.user_tags() [2026.06+]. LDAP has no accessor function — tag the LDAP user's native user object instead
  • User-defined functions rejected in PBAC property-rule predicates [2026.06+]
  • Infinigraph (sharded property databases) supports PBAC READ only, granted on the virtual database [2026.07+, not on Aura] — see references/privilege-reference.md

7. SHOW PRIVILEGES Patterns

cypher
// All privileges in the system
SHOW PRIVILEGES YIELD *;

// Privileges for a specific user (as runnable commands)
SHOW USER alice PRIVILEGES AS COMMANDS;

// Privileges for a specific role
SHOW ROLE analyst PRIVILEGES YIELD privilege, action, resource, graph, segment;

// Privileges of roles granted to an auth rule [2026.09]
SHOW AUTH RULES salesRule PRIVILEGES AS COMMANDS;

// Find who has access to a database
SHOW PRIVILEGES YIELD *
WHERE graph = 'mydb'
RETURN role, action, resource, segment ORDER BY role;

// Find all DENY rules
SHOW PRIVILEGES YIELD *
WHERE access = 'DENIED'
RETURN role, action, resource, segment;

8. Built-in Roles (do not drop)

RoleScope
adminFull DBMS + all databases
architectSchema changes + write on all databases
publisherWrite on all databases
editorWrite excluding schema changes
readerRead-only on all databases
publicAll users implicitly; default home database access

Assign built-in roles: GRANT ROLE reader TO alice;


9. Auth Provider Config Reference (operational — not Cypher)

Native (default)
dbms.security.auth_enabled=true
dbms.security.auth_max_failed_attempts=3    # lockout threshold
LDAP
dbms.security.auth_provider=ldap
dbms.security.ldap.host=ldap://ldap.example.com
dbms.security.ldap.authentication.mechanism=simple
dbms.security.ldap.authentication.user_dn_template=uid={0},ou=users,dc=example,dc=com
dbms.security.ldap.authorization.group_membership_attributes=memberOf
dbms.security.ldap.authorization.group_to_role_mapping=\
  "cn=analysts,ou=groups,dc=example,dc=com" = analyst;\
  "cn=admins,ou=groups,dc=example,dc=com"   = admin
OIDC / SSO (Okta, Auth0, Entra ID)
dbms.security.oidc.<alias>.display_name=Okta
dbms.security.oidc.<alias>.auth_flow=pkce      # `implicit` deprecated 2026.06, removal planned — keep pkce
dbms.security.oidc.<alias>.well_known_discovery_uri=https://example.okta.com/.well-known/openid-configuration
dbms.security.oidc.<alias>.audience=neo4j
dbms.security.oidc.<alias>.claims.username=email
dbms.security.oidc.<alias>.claims.groups=groups
dbms.security.oidc.<alias>.authorization.group_to_role_mapping=\
  "neo4j-analysts" = analyst;\
  "neo4j-admins"   = admin

Config changes require server restart. Roles referenced in mappings must exist in Neo4j (native or created via Cypher).


Checklist — New Role Setup

  • Determine required operations: read / write / admin
  • Identify target database(s) and graph scope (all labels vs specific)
  • Identify any properties that must be hidden (→ DENY READ)
  • Create role: CREATE ROLE ... IF NOT EXISTS
  • Grant ACCESS on database
  • Grant MATCH / TRAVERSE / WRITE as needed
  • Apply DENY for restricted properties
  • Run SHOW ROLE ... PRIVILEGES AS COMMANDS to verify
  • Assign to users: GRANT ROLE ... TO ...
  • Test with SHOW USER ... PRIVILEGES AS COMMANDS

Full privilege syntax → references/privilege-reference.md

© neo4j-contrib, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in neo4j-security-skill of neo4j-contrib/neo4j-skills.

  • SKILL.md
  • README.md
  • references/privilege-reference.md

Open the folder on GitHubat commit bb30e1f

Compare with similar skills

Neo4j Security Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Neo4j Security Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Neo4j Security Skill this skillneo4j-contrib/neo4j-skills114—~4kAutomated safety check: NotesMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
Convex Setup Authspokvulcan/poker-planning1158 repos~1.8kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    spokvulcan/poker-planning

    Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.

    115 GitHub starsUsed in 8 repos~1.8k tokens
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from neo4j-contrib/neo4j-skills

All 28 skills in this repo
  • Neo4j Aura Agent Skill

    neo4j-contrib/neo4j-skills

    Manages Neo4j Aura Agents via the v2beta1 REST API — create, list, get, update, delete, and invoke Aura agents backed by an AuraDB instance.

    114 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check: notes
  • Neo4j Cypher Skill

    neo4j-contrib/neo4j-skills

    Generates, optimizes, and validates Cypher 25 queries for Neo4j 2025.x and 2026.x.

    114 GitHub starsUsed in 1 repo~6.1k tokens
    Auto-check passed
  • Neo4j Aura Graph Analytics Skill

    neo4j-contrib/neo4j-skills

    Serverless Aura Graph Analytics (AGA) GDS Sessions — covers GdsSessions, AuraGraphDataScience, AuraAPICredentials, DbmsConnectionInfo, SessionMemory, getorcreate, remote graph projection with…

    114 GitHub stars~4.6k tokensUpdated yesterday
    Auto-check: notes
  • Neo4j Getting Started Skill

    neo4j-contrib/neo4j-skills

    Orchestrates zero-to-running-app in 8 stages — prerequisites → context → provision → model → load → explore → query → build.

    114 GitHub stars~4.3k tokensUpdated yesterday
    Auto-check: warnings
  • Neo4j Aura Provisioning Skill

    neo4j-contrib/neo4j-skills

    Provisions and manages Neo4j Aura instances via CLI (aura-cli v1.7+) or REST API.

    114 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Neo4j Driver Dotnet Skill

    neo4j-contrib/neo4j-skills

    Neo4j .NET Driver v6 — IDriver lifecycle, DI registration (singleton), ExecutableQuery fluent API, ExecuteReadAsync/ExecuteWriteAsync managed transactions, IResultCursor (FetchAsync/ ToListAsync)…

    114 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check: notes

Works with

Categories

Questions about Neo4j Security Skill

What does Neo4j Security Skill do?

Programmatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER), role lifecycle (CREATE/GRANT ROLE/DROP ROLE), privilege grants and denies (GRANT/DENY/REVOKE on graph…. Neo4j Security Skill is an agent skill from neo4j-contrib/neo4j-skills. Programmatic security management in Neo4j — RBAC/ABAC, user lifecycle (CREATE/ALTER/DROP USER), role lifecycle (CREATE/GRANT ROLE/DROP ROLE), privilege grants and denies (GRANT/DENY/REVOKE on graph, database, DBMS), property-level access control, sub-graph access control, SHOW PRIVILEGES inspection, and auth provider config reference (LDAP, OIDC/SSO).

When should I use Neo4j Security Skill?

Neo4j Security Skill fits situations like: an agent needs to manage users; privileges programmatically via Cypher on the system database.

How do I install Neo4j Security Skill in Claude Code?

Run `npx skills add neo4j-contrib/neo4j-skills --skill neo4j-security-skill -a claude-code`. Or copy the skill folder (neo4j-security-skill in neo4j-contrib/neo4j-skills) into .claude/skills/neo4j-security-skill in your project. Claude Code loads it when a task matches its description.

How do I install Neo4j Security Skill in Codex?

Run `npx skills add neo4j-contrib/neo4j-skills --skill neo4j-security-skill -a codex`. Or copy the skill folder (neo4j-security-skill in neo4j-contrib/neo4j-skills) into .agents/skills/neo4j-security-skill in your project. Codex loads it when a task matches its description.

Can I use Neo4j Security Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add neo4j-contrib/neo4j-skills --skill neo4j-security-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/neo4j-security-skill, .gemini/skills/neo4j-security-skill, .github/skills/neo4j-security-skill and .opencode/skills/neo4j-security-skill in your project.

What does Neo4j Security Skill need to run?

SKILL.md names no scripts, command-line tools or credentials: Neo4j Security Skill is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, WebFetch.

Does Neo4j Security Skill access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Neo4j Security Skill safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Neo4j Security Skill use?

Neo4j Security Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Neo4j Security Skill use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Neo4j Security Skill?

Skills that share tags, products or a category with Neo4j Security Skill: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Neo4j Security Skill?

neo4j-contrib (a GitHub organization) maintains it in neo4j-contrib/neo4j-skills, which has 114 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 9, 2026.

Source: neo4j-contrib/neo4j-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.