Agent skill

Verify Login Logout

by reticlehq in reticlehq/reticle

Prove sign-in lands the user where they should be, sign-out really ends the session so a protected page sends them back to sign in, and an expired session asks to sign in again instead of breaking.

Apache-2.0Auto-check passed

Install Verify Login Logout

skills CLI
$ npx skills add reticlehq/reticle --skill verify-login-logout -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install reticlehq/reticle verify-login-logout --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/reticlehq/reticle.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/verify-login-logout .claude/skills/verify-login-logout && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-login-logout
GitHub stars
1.2k
Token cost
~1.4k tokens
SKILL.md length
621 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Prove sign-in lands the user where they should be, sign-out really ends the session so a protected page sends them back to sign in, and an expired session asks to sign in again instead of breaking.

  • Works in 3 steps: Sign in, and name where it must land → Sign out, then try to go back → Expire the session, and prove the app…
  • A logout button
  • SKILL.md covers Before you start, 1. Sign in, and name where it…, 2. Sign out, then try to go back and 3. Expire the session, and…, plus 1 more section
  • Calls curl and npx; reaches docs.reticle.sh

What it does

Verify Login Logout is an agent skill from reticlehq/reticle. Prove sign-in lands the user where they should be, sign-out really ends the session so a protected page sends them back to sign in, and an expired session asks to sign in again instead of breaking. Use when auth, a login form, a logout button, route guards or token refresh were added or changed, or when a user reports being logged out, or not logged out, unexpectedly.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: AI agents can generate code, but still struggle to understand what they build. Reticle brings Jev-style machine-native runtime perception to web & desktop applications. The licence is Apache-2.0.

When your agent uses it

  • A logout button
  • Token refresh were added
  • A user reports being logged out

Example prompts

  • “/verify-login-logout”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Sign in, and name where it must land
  2. Sign out, then try to go back
  3. Expire the session, and prove the app asks again

What it can do on your machine

Read from SKILL.md and the folder at commit 178e5c0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • docs.reticle.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Login Logout loads about 1.4k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 621 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from reticlehq/reticle at commit 178e5c0, republished under its Apache-2.0 licence (© reticlehq). 621 words, ~1,435 tokens.

Download SKILL.mdSave it as .claude/skills/verify-login-logout/SKILL.md (or your agent's skills folder).
name
verify-login-logout
description
Prove sign-in lands the user where they should be, sign-out really ends the session so a protected page sends them back to sign in, and an expired session asks to sign in again instead of breaking. Use when auth, a login form, a logout button, route guards or token refresh were added or changed, or when a user reports being logged out, or not logged out, unexpectedly.
license
Apache-2.0
metadata.version
3.7.0
metadata.homepage
https://www.reticle.sh
metadata.repository
https://github.com/reticlehq/reticle

Signed in on screen is not signed in

A login form that shows the dashboard after submit proves the page changed. It does not prove the server accepted the credentials, that signing out ends anything, or that a user whose session ran out gets a sign-in page instead of a blank screen and a loop of 401s.

Reticle can check all three in the running app. Not installed? RETICLE_INSTALL_SOURCE=npx_skill npx @reticlehq/server@latest init, then the install-and-verify skill.

Before you start

  • Use the project's test account. Take credentials from its seed data, fixtures or .env.example, or ask the user. Never type a real person's password.
  • Confirm the session can observe: reticle_session({ action: "list" }). A hidden or throttled tab can accept a click and render nothing. If it is not healthy, report the run as blocked, not passed.
  • Step 3 needs a browser Reticle owns. Forcing an expired session uses reticle_network_mock, which works in a leased tab (reticle_run({ tool: "reticle_lease", args: { action: "acquire", url } })) or a driven one, and not through the always-on SDK. Without one, do steps 1 and 2 and report step 3 as unknown.

1. Sign in, and name where it must land

Get the form's refs with reticle_look({ action: "page", sessionId, mode: "interactive" }), fill the fields with reticle_act, then submit and state the consequence before you click:

reticle_act_and_wait({ sessionId, ref: "<sign-in button>", action: "click", until: { kind: "allOf", predicates: [
  { kind: "net", urlContains: "/api/login", ok: true },
  { kind: "route", pathname: "/dashboard" },
  { kind: "element", query: { role: "button", name: "Account" } },
]}})

All three, because each alone can lie: a route change can happen on the client before the server answers, and a user menu can render from a stale cache. Use the app's real origin, endpoints, landing route and signed-in marker throughout: the ones here are examples.

reticle_run({ tool: "reticle_storage", sessionId, args: {} }) shows what the app stored. Sensitive keys come back redacted and httpOnly cookies are invisible to the page by design, so this is evidence about where the session lives, not a verdict.

2. Sign out, then try to go back

reticle_act_and_wait({ sessionId, ref: "<sign-out control>", action: "click", until: { kind: "allOf", predicates: [
  { kind: "route", contains: "/login" },
  { kind: "element", query: { role: "button", name: "Account" }, absent: true },
]}})

Landing on the sign-in page proves the UI moved. It does not prove the session ended. Navigate straight to a protected page, on the app's real origin and route, and prove it refuses you:

reticle_navigate({ sessionId, url: "<the app's origin>/dashboard" })
reticle_assert({ sessionId, predicate: { kind: "allOf", predicates: [
  { kind: "route", contains: "/login" },
  { kind: "text", contains: "Sign in" },
  { kind: "net", urlContains: "/api/me", status: 401 },
]}})

The net clause is what proves the server ended the session. A client-side guard can redirect to /login off a cleared flag while the server still honours the old session, and the route and text would pass. The request the page makes to learn who is signed in must now be refused. If the page makes no such request, say so and report the server half as unknown.

A protected page that still renders after sign-out is the most important finding this skill can produce. Report it even if everything else passed.

Show full SKILL.md (186 more words)Show less

3. Expire the session, and prove the app asks again

Sign in again (step 1). Then make the server treat the session as expired by failing the call the app uses to check it:

reticle_run({ tool: "reticle_network_mock", sessionId, args: {
  mocks: [{ urlContains: "/api/me", status: 401 }],
}})

Reload a protected page and name what must happen:

reticle_navigate({ sessionId, url: "<the app's origin>/dashboard" })
reticle_assert({ sessionId, timeout_ms: 5000, predicate: { kind: "allOf", predicates: [
  { kind: "net", urlContains: "/api/me", status: 401 },
  { kind: "route", contains: "/login" },
  { kind: "console", level: "error", absent: true },
]}})

The net clause proves the mocked 401 was the thing the app reacted to. If the app never called the mocked endpoint, a redirect that happens anyway is a coincidence, not expiry handling, so the verdict is unknown until you mock the call it really makes. The console clause matters: an app that "handles" expiry by throwing an uncaught error and showing a blank page has not handled it. Clear the mock with { clear: true } when you are done.

Honesty

Only verified: "yes" is a pass. Step 3 is a stand-in: Reticle cannot delete an httpOnly cookie or edit storage, so a mocked 401 is how the expiry is forced. Say which endpoint you mocked. Clear every mock and sign out before handing back, and never report a password, token or cookie value you saw.


Capability reference: curl https://docs.reticle.sh/capabilities.md. Everything else: curl https://docs.reticle.sh/llms.txt.

© reticlehq, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/verify-login-logout of reticlehq/reticle.

Open the folder on GitHubat commit 178e5c0

Compare with similar skills

Verify Login Logout next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Login Logout compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Login Logout this skillreticlehq/reticle1.2k—~1.4kAutomated safety check: PassApache-2.0
Landingalirezarezvani/claude-skills28k—~3.8kAutomated safety check: PassMIT
Document Signingasgeirtj/system_prompts_leaks69k—~1.5kAutomated safety check: PassCC0-1.0
Login Flownexu-io/open-design100k—~334Automated safety check: PassApache-2.0
Landing Page Conversion Auditgithub/awesome-copilot40k1 repos~1.8kAutomated safety check: PassMIT
SEO Aeo Landing Page Writersickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Landing

    alirezarezvani/claude-skills

    Generates a premium single-page HTML landing page with 3D CSS animations, GSAP scroll effects, and mouse-parallax depth.

    28k GitHub stars~3.8k tokensUpdated 1 mo ago
    Frontend & DesignAuto-check passed
  • Document Signing

    asgeirtj/system_prompts_leaks

    Review documents for signature or prepare a signing packet; verify fields and recipients while keeping sending and signing under explicit user authorization.

    69k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Login Flow

    nexu-io/open-design

    Mobile login and authentication flow screens. An agent skill from nexu-io/open-design.

    100k GitHub stars~334 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Landing Page Conversion Audit

    github/awesome-copilot

    Official

    Audit a landing page, sales page or checkout page for conversion leaks and return a fix list ordered by expected revenue impact.

    40k GitHub starsUsed in 1 repo~1.8k tokens
    Frontend & DesignAuto-check passed
  • SEO Aeo Landing Page Writer

    sickn33/agentic-awesome-skills

    Writes or improves conversion-focused landing pages for products, services, and offers with practical SEO and AEO structure.

    47k GitHub starsUsed in 1 repo~1.5k tokens
    Frontend & DesignAuto-check passed
  • Ads Landing

    AgriciDaniel/claude-ads

    Audit paid-ad landing pages for message match, mobile experience, performance, accessibility, trust, forms, consent, tracking, security, and conversion friction.

    9.9k GitHub stars~612 tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed

More from reticlehq/reticle

All 19 skills in this repo
  • Agentic TDD

    reticlehq/reticle

    Applies red-green TDD to behavior unit tests cannot reach, by stating the expected outcome against the running app with Reticle before writing the feature.

    1.2k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed
  • Whole-App Health Sweep

    reticlehq/reticle

    Sweeps a running web app by clicking every reachable control, then reports dead buttons, console errors, failed requests and mismatches between API data and the screen.

    1.2k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Broken UI Debugger

    reticlehq/reticle

    Finds why a running web app misbehaves when the console is empty and the code looks fine, by reading the click, request, store and console together.

    1.2k GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Drives and verifies Electron or Tauri desktop apps through Reticle, which sees the renderer and the IPC calls that a browser-based testing tool cannot observe.

    1.2k GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Finds out why a passing test suite sits on top of a broken app by comparing what the running app does with what the tests claim, using Reticle.

    1.2k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Fix What I Pointed At

    reticlehq/reticle

    Picks up bugs a person flagged by pointing at elements in the running app, each mark carrying the element, their note and the source file and line, then fixes and verifies them.

    1.2k GitHub stars~878 tokensUpdated 2 days ago
    Auto-check passed

Questions about Verify Login Logout

What does Verify Login Logout do?

Prove sign-in lands the user where they should be, sign-out really ends the session so a protected page sends them back to sign in, and an expired session asks to sign in again instead of breaking. Verify Login Logout is an agent skill from reticlehq/reticle. Prove sign-in lands the user where they should be, sign-out really ends the session so a protected page sends them back to sign in, and an expired session asks to sign in again instead of breaking.

When should I use Verify Login Logout?

Verify Login Logout fits situations like: A logout button; token refresh were added; A user reports being logged out.

How do I install Verify Login Logout in Claude Code?

Run `npx skills add reticlehq/reticle --skill verify-login-logout -a claude-code`. Or copy the skill folder (skills/verify-login-logout in reticlehq/reticle) into .claude/skills/verify-login-logout in your project. Claude Code loads it when a task matches its description.

How do I install Verify Login Logout in Codex?

Run `npx skills add reticlehq/reticle --skill verify-login-logout -a codex`. Or copy the skill folder (skills/verify-login-logout in reticlehq/reticle) into .agents/skills/verify-login-logout in your project. Codex loads it when a task matches its description.

Can I use Verify Login Logout in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add reticlehq/reticle --skill verify-login-logout -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-login-logout, .gemini/skills/verify-login-logout, .github/skills/verify-login-logout and .opencode/skills/verify-login-logout in your project.

What does Verify Login Logout need to run?

Going by SKILL.md and its folder, Verify Login Logout needs the command-line tools its instructions call (curl and npx). Our summary lists: Node.js.

Does Verify Login Logout access the network?

SKILL.md names 1 domain. In commands or code: docs.reticle.sh; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Verify Login Logout safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Login Logout use?

Verify Login Logout is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Login Logout use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Login Logout?

Skills that share tags, products or a category with Verify Login Logout: Landing (alirezarezvani/claude-skills, 28k stars), Document Signing (asgeirtj/system_prompts_leaks, 69k stars), Login Flow (nexu-io/open-design, 100k stars) and Landing Page Conversion Audit (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Login Logout?

reticlehq (a GitHub organization) maintains it in reticlehq/reticle, which has 1,199 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: reticlehq/reticle on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.