Security Review
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.
$ npx skills add romshark/datapages --skill datapages-sessions -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install romshark/datapages datapages-sessions --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/romshark/datapages.git skills-src && mkdir -p .claude/skills && cp -r skills-src/internal/generator/agentdocs/data/skills/datapages-sessions .claude/skills/datapages-sessions && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "datapages-sessions" agent skill from https://github.com/romshark/datapages/tree/main/internal/generator/agentdocs/data/skills/datapages-sessions into .claude/skills/datapages-sessions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "datapages-sessions", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/romshark/datapages/tree/main/internal/generator/agentdocs/data/skills/datapages-sessionsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add romshark/datapages --skill datapages-sessions -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install romshark/datapages datapages-sessions --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/romshark/datapages.git skills-src && mkdir -p .agents/skills && cp -r skills-src/internal/generator/agentdocs/data/skills/datapages-sessions .agents/skills/datapages-sessions && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "datapages-sessions" agent skill from https://github.com/romshark/datapages/tree/main/internal/generator/agentdocs/data/skills/datapages-sessions into .agents/skills/datapages-sessions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "datapages-sessions", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add romshark/datapages --skill datapages-sessions -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install romshark/datapages datapages-sessions --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/romshark/datapages.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/internal/generator/agentdocs/data/skills/datapages-sessions .cursor/skills/datapages-sessions && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "datapages-sessions" agent skill from https://github.com/romshark/datapages/tree/main/internal/generator/agentdocs/data/skills/datapages-sessions into .cursor/skills/datapages-sessions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "datapages-sessions", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/romshark/datapages.git --path internal/generator/agentdocs/data/skills/datapages-sessions--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add romshark/datapages --skill datapages-sessions -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install romshark/datapages datapages-sessions --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/romshark/datapages.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/internal/generator/agentdocs/data/skills/datapages-sessions .gemini/skills/datapages-sessions && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "datapages-sessions" agent skill from https://github.com/romshark/datapages/tree/main/internal/generator/agentdocs/data/skills/datapages-sessions into .gemini/skills/datapages-sessions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "datapages-sessions", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install romshark/datapages datapages-sessionsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add romshark/datapages --skill datapages-sessions -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/romshark/datapages.git skills-src && mkdir -p .github/skills && cp -r skills-src/internal/generator/agentdocs/data/skills/datapages-sessions .github/skills/datapages-sessions && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "datapages-sessions" agent skill from https://github.com/romshark/datapages/tree/main/internal/generator/agentdocs/data/skills/datapages-sessions into .github/skills/datapages-sessions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "datapages-sessions", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add romshark/datapages --skill datapages-sessions -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install romshark/datapages datapages-sessions --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/romshark/datapages.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/internal/generator/agentdocs/data/skills/datapages-sessions .opencode/skills/datapages-sessions && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "datapages-sessions" agent skill from https://github.com/romshark/datapages/tree/main/internal/generator/agentdocs/data/skills/datapages-sessions into .opencode/skills/datapages-sessions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "datapages-sessions", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
datapages-sessionsAdd Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.
Datapages Sessions is an agent skill from romshark/datapages. Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager. Use when adding sign-in, sign-out or authenticated handlers to a Datapages app.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Web application vulnerabilities and Authentication. The repository describes itself as: A Datastar Go web frontend framework. The licence is MIT.
Read from SKILL.md and the folder at commit 87d5a44. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are go).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Datapages Sessions loads about 1.1k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 490 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from romshark/datapages at commit 87d5a44, republished under its MIT licence (© romshark). 490 words, ~1,056 tokens.
.claude/skills/datapages-sessions/SKILL.md (or your agent's skills folder).Read datapages first for the build loop, hard rules and naming conventions.
Declare the session data and alias once in the app package. Do not declare them when the app has no authentication.
type SessionData struct{ Name string }
type Session = datapages.Session[SessionData]Use struct{} when the session has no application data. Every handler must use the same data type. Use the shared alias in every handler.
Pages, actions, event handlers and stream hooks may take session Session. It is read-only and provides UserID(), IsGuest(), Token(), IssuedAt(), ExpiresAt() and Data(). Datapages treats an expired session as unauthenticated and deletes its cookie. A stream opened with the session ends when the session closes or reaches ExpiresAt(), and its page reloads after 1s.
Add session Session to every action that must reject a closed or expired session. Without this parameter, Datapages does not read the session store. It checks the CSRF token against the session cookie if the request has one, and accepts a request without a cookie: guests can call the action. Take session Session and check IsGuest() when only signed-in users may call it.
Return values, from a GET or an action:
// POSTSignIn is /sign-in
func (*App) POSTSignIn(
r *http.Request,
signals datapages.Signals[struct {
Name string `json:"name"`
}],
) (
newSession datapages.NewSession[SessionData],
redirect datapages.Redirect,
err error,
) {
name := signals.Values.Name
if err := datapages.ValidateUserID(name); err != nil {
return datapages.NewSession[SessionData]{},
datapages.Redirect{}, datapages.ErrBadRequest
}
return datapages.NewSession[SessionData]{
UserID: name,
Data: SessionData{Name: name},
}, datapages.Redirect{URL: href.PageIndex()}, nil
}NewSession contains UserID, Data and an optional ExpiresAt. Datapages creates the token and sets the issue time. A zero UserID creates no session. To sign out, return closeSession datapages.CloseSession set to true.
ExpiresAt also sets the cookie's Max-Age and Expires attributes. A nonzero value can keep the client signed in after a browser restart. A zero value creates a cookie that the browser deletes when it closes. The session record remains in the store until the application deletes it.
Opening or closing a session cannot be combined with a datapages.SSE parameter. The SSE response headers are sent before the handler runs, so the handler cannot change the cookie. Sign in or out without sse, then return a redirect.
With an offline page cache, sign-in and sign-out actions also take pageCache
and call ClearAll(). A snapshot cached for a guest still shows signed-out
navigation after login. See datapages-offline.
CSRF protection is enabled for every app with a session type. Datapages derives the token from the session. Do not set a CSRF header in a template. A normal browser form submission does not include the token. Submit forms through a Datastar action as shown in datapages-templates. Use datapages.WithCSRFProtection(datapages.CSRFConfig{...}) only to replace the token source or disable protection. A QUERYXXX action skips the check. Never change state in it.
The store is a server option, see datapages-server:
opts = append(opts, datapages.WithSessionManager[app.SessionData](mgr))Specify the data type in this call. Go cannot infer it here. The type argument also makes the compiler check that the manager matches the app's session type.
Use modules/sessions/natskv. Use modules/sessions/inmem only for development. It stores sessions in memory and loses them on restart.
Datapages does not scan the store for expired records. It deletes an expired record only when a client sends that session. Call mgr.DeleteExpired(ctx) on a ticker to delete all other expired records.
© romshark, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in internal/generator/agentdocs/data/skills/datapages-sessions of romshark/datapages.
Open the folder on GitHubat commit 87d5a44
Datapages Sessions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Datapages Sessions this skillromshark/datapages | 113 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Kuri Agentjustrach/kuri | 365 | — | ~1.3k | Automated safety check: Notes | Custom licence | |
| API Security Checklistrevfactory/harness-100 | 1.3k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Secure Code GuardianJeffallan/claude-skills | 12k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Security ConvexIgorWarzocha/Opencode-Workflows | 122 | — | ~3.1k | Automated safety check: Pass | None |
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
justrach/kuri
Use kuri-agent to automate Chrome — navigate pages, interact with elements via a11y refs, capture screenshots, run security audits, enumerate cookies/JWTs, probe for IDOR vulnerabilities, and make…
revfactory/harness-100
Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.
Jeffallan/claude-skills
Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.
IgorWarzocha/Opencode-Workflows
Review Convex security audit patterns for authentication and authorization.
telagod/code-abyss
Application security defense knowledge for builders. An agent skill from telagod/code-abyss.
romshark/datapages
Apply the Datapages framework rules, build loop and naming conventions, and select the relevant task skill.
romshark/datapages
Datapages real-time events: event types and subjects, dispatchers, On handlers, per-user and signal-bound subject fields, and the StreamOpen and StreamClose hooks.
romshark/datapages
Add per-tab Datapages State[T], initialize and use it in handlers, dispatch state-scoped events, and configure the live instance limit.
romshark/datapages
Classify Datapages findings by reach and severity and write review-.md reports.
romshark/datapages
Write Datapages commit messages, including the breaking-change marker and the BREAKING block.
romshark/datapages
Write Datapages action handlers (POST, PUT, PATCH, DELETE, QUERY): parameters, return values, Datastar signals, SSE patching, HTTP error status codes and the RecoverError hook.
Categories
Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager. Datapages Sessions is an agent skill from romshark/datapages. Add Datapages authentication: define and read the Session type, open and close sessions, configure CSRF protection and choose a session manager.
Datapages Sessions fits situations like: authenticated handlers to a Datapages app; tasks that involve Web application vulnerabilities; tasks that involve Authentication.
Run `npx skills add romshark/datapages --skill datapages-sessions -a claude-code`. Or copy the skill folder (internal/generator/agentdocs/data/skills/datapages-sessions in romshark/datapages) into .claude/skills/datapages-sessions in your project. Claude Code loads it when a task matches its description.
Run `npx skills add romshark/datapages --skill datapages-sessions -a codex`. Or copy the skill folder (internal/generator/agentdocs/data/skills/datapages-sessions in romshark/datapages) into .agents/skills/datapages-sessions in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add romshark/datapages --skill datapages-sessions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/datapages-sessions, .gemini/skills/datapages-sessions, .github/skills/datapages-sessions and .opencode/skills/datapages-sessions in your project.
SKILL.md names no scripts, command-line tools or credentials: Datapages Sessions is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Datapages Sessions is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Datapages Sessions: Security Review (jewbetcha/opentrace, 116 stars), Kuri Agent (justrach/kuri, 365 stars), API Security Checklist (revfactory/harness-100, 1.3k stars) and Secure Code Guardian (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
romshark (a GitHub user) maintains it in romshark/datapages, which has 113 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.
Source: romshark/datapages on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.