Agent skill

Datapages Sessions

by romshark in romshark/datapages

Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.

MITAuto-check passedSecurity

Install Datapages Sessions

skills CLI
$ npx skills add romshark/datapages --skill datapages-sessions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install romshark/datapages datapages-sessions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/romshark/datapages.git skills-src && mkdir -p .claude/skills && cp -r skills-src/internal/generator/agentdocs/data/skills/datapages-sessions .claude/skills/datapages-sessions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
datapages-sessions
GitHub stars
113
Token cost
~1.1k tokens
SKILL.md length
490 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.

  • Authenticated handlers to a Datapages app
  • SKILL.md covers Read, Open and close, CSRF and Manager
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Web application vulnerabilities

What it does

Datapages Sessions is an agent skill from romshark/datapages. Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager. Use when adding sign-in, sign-out or authenticated handlers to a Datapages app.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities and Authentication. The repository describes itself as: A Datastar Go web frontend framework. The licence is MIT.

When your agent uses it

  • Authenticated handlers to a Datapages app
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve Authentication

Example prompts

  • “/datapages-sessions”

What it can do on your machine

Read from SKILL.md and the folder at commit 87d5a44. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are go).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Datapages Sessions loads about 1.1k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 490 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from romshark/datapages at commit 87d5a44, republished under its MIT licence (© romshark). 490 words, ~1,056 tokens.

Download SKILL.mdSave it as .claude/skills/datapages-sessions/SKILL.md (or your agent's skills folder).
name
datapages-sessions
description
Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager. Use when adding sign-in, sign-out or authenticated handlers to a Datapages app.

Sessions

Read datapages first for the build loop, hard rules and naming conventions.

Declare the session data and alias once in the app package. Do not declare them when the app has no authentication.

go
type SessionData struct{ Name string }

type Session = datapages.Session[SessionData]

Use struct{} when the session has no application data. Every handler must use the same data type. Use the shared alias in every handler.

Read

Pages, actions, event handlers and stream hooks may take session Session. It is read-only and provides UserID(), IsGuest(), Token(), IssuedAt(), ExpiresAt() and Data(). Datapages treats an expired session as unauthenticated and deletes its cookie. A stream opened with the session ends when the session closes or reaches ExpiresAt(), and its page reloads after 1s.

Add session Session to every action that must reject a closed or expired session. Without this parameter, Datapages does not read the session store. It checks the CSRF token against the session cookie if the request has one, and accepts a request without a cookie: guests can call the action. Take session Session and check IsGuest() when only signed-in users may call it.

Open and close

Return values, from a GET or an action:

go
// POSTSignIn is /sign-in
func (*App) POSTSignIn(
	r *http.Request,
	signals datapages.Signals[struct {
		Name string `json:"name"`
	}],
) (
	newSession datapages.NewSession[SessionData],
	redirect datapages.Redirect,
	err error,
) {
	name := signals.Values.Name
	if err := datapages.ValidateUserID(name); err != nil {
		return datapages.NewSession[SessionData]{},
			datapages.Redirect{}, datapages.ErrBadRequest
	}
	return datapages.NewSession[SessionData]{
		UserID: name,
		Data:   SessionData{Name: name},
	}, datapages.Redirect{URL: href.PageIndex()}, nil
}

NewSession contains UserID, Data and an optional ExpiresAt. Datapages creates the token and sets the issue time. A zero UserID creates no session. To sign out, return closeSession datapages.CloseSession set to true.

ExpiresAt also sets the cookie's Max-Age and Expires attributes. A nonzero value can keep the client signed in after a browser restart. A zero value creates a cookie that the browser deletes when it closes. The session record remains in the store until the application deletes it.

Opening or closing a session cannot be combined with a datapages.SSE parameter. The SSE response headers are sent before the handler runs, so the handler cannot change the cookie. Sign in or out without sse, then return a redirect.

With an offline page cache, sign-in and sign-out actions also take pageCache and call ClearAll(). A snapshot cached for a guest still shows signed-out navigation after login. See datapages-offline.

Show full SKILL.md (156 more words)Show less

CSRF

CSRF protection is enabled for every app with a session type. Datapages derives the token from the session. Do not set a CSRF header in a template. A normal browser form submission does not include the token. Submit forms through a Datastar action as shown in datapages-templates. Use datapages.WithCSRFProtection(datapages.CSRFConfig{...}) only to replace the token source or disable protection. A QUERYXXX action skips the check. Never change state in it.

Manager

The store is a server option, see datapages-server:

go
opts = append(opts, datapages.WithSessionManager[app.SessionData](mgr))

Specify the data type in this call. Go cannot infer it here. The type argument also makes the compiler check that the manager matches the app's session type.

Use modules/sessions/natskv. Use modules/sessions/inmem only for development. It stores sessions in memory and loses them on restart.

Datapages does not scan the store for expired records. It deletes an expired record only when a client sends that session. Call mgr.DeleteExpired(ctx) on a ticker to delete all other expired records.

© romshark, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in internal/generator/agentdocs/data/skills/datapages-sessions of romshark/datapages.

Open the folder on GitHubat commit 87d5a44

Compare with similar skills

Datapages Sessions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Datapages Sessions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Datapages Sessions this skillromshark/datapages113—~1.1kAutomated safety check: PassMIT
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Kuri Agentjustrach/kuri365—~1.3kAutomated safety check: NotesCustom licence
API Security Checklistrevfactory/harness-1001.3k—~1.7kAutomated safety check: PassApache-2.0
Secure Code GuardianJeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT
Security ConvexIgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNone

Similar skills

  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Kuri Agent

    justrach/kuri

    Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make…

    365 GitHub stars~1.3k tokensUpdated 2 mo ago
    SecurityAuto-check: notes
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Secure Code Guardian

    Jeffallan/claude-skills

    Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.

    12k GitHub stars~1.8k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Security Convex

    IgorWarzocha/Opencode-Workflows

    Review Convex security audit patterns for authentication and authorization.

    122 GitHub stars~3.1k tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Defending Applications

    telagod/code-abyss

    Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

    243 GitHub stars~777 tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from romshark/datapages

All 15 skills in this repo
  • Datapages

    romshark/datapages

    Apply the Datapages framework rules, build loop and naming conventions, and select the relevant task skill.

    113 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Datapages Events

    romshark/datapages

    Datapages real-time events: event types and subjects, dispatchers, On handlers, per-user and signal-bound subject fields, and the StreamOpen and StreamClose hooks.

    113 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Datapages State

    romshark/datapages

    Add per-tab Datapages State[T], initialize and use it in handlers, dispatch state-scoped events, and configure the live instance limit.

    113 GitHub stars~806 tokensUpdated yesterday
    Auto-check passed
  • Review Criteria

    romshark/datapages

    Classify Datapages findings by reach and severity and write review-.md reports.

    113 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Git Commits

    romshark/datapages

    Write Datapages commit messages, including the breaking-change marker and the BREAKING block.

    113 GitHub stars~960 tokensUpdated yesterday
    Auto-check passed
  • Datapages Actions

    romshark/datapages

    Write Datapages action handlers (POST, PUT, PATCH, DELETE, QUERY): parameters, return values, Datastar signals, SSE patching, HTTP error status codes and the RecoverError hook.

    113 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Questions about Datapages Sessions

What does Datapages Sessions do?

Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager. Datapages Sessions is an agent skill from romshark/datapages. Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.

When should I use Datapages Sessions?

Datapages Sessions fits situations like: authenticated handlers to a Datapages app; tasks that involve Web application vulnerabilities; tasks that involve Authentication.

How do I install Datapages Sessions in Claude Code?

Run `npx skills add romshark/datapages --skill datapages-sessions -a claude-code`. Or copy the skill folder (internal/generator/agentdocs/data/skills/datapages-sessions in romshark/datapages) into .claude/skills/datapages-sessions in your project. Claude Code loads it when a task matches its description.

How do I install Datapages Sessions in Codex?

Run `npx skills add romshark/datapages --skill datapages-sessions -a codex`. Or copy the skill folder (internal/generator/agentdocs/data/skills/datapages-sessions in romshark/datapages) into .agents/skills/datapages-sessions in your project. Codex loads it when a task matches its description.

Can I use Datapages Sessions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add romshark/datapages --skill datapages-sessions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/datapages-sessions, .gemini/skills/datapages-sessions, .github/skills/datapages-sessions and .opencode/skills/datapages-sessions in your project.

What does Datapages Sessions need to run?

SKILL.md names no scripts, command-line tools or credentials: Datapages Sessions is instructions for the agent only.

Does Datapages Sessions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Datapages Sessions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Datapages Sessions use?

Datapages Sessions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Datapages Sessions use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Datapages Sessions?

Skills that share tags, products or a category with Datapages Sessions: Security Review (jewbetcha/opentrace, 116 stars), Kuri Agent (justrach/kuri, 365 stars), API Security Checklist (revfactory/harness-100, 1.3k stars) and Secure Code Guardian (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Datapages Sessions?

romshark (a GitHub user) maintains it in romshark/datapages, which has 113 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: romshark/datapages on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.