Agent skill

Robel Auth

by waynesutton in waynesutton/markdown-site

Integrate and maintain Robelest Convex Auth in apps by always checking upstream before implementation.

MITAuto-check passedBackend & APIs

Install Robel Auth

skills CLI
$ npx skills add waynesutton/markdown-site --skill robel-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install waynesutton/markdown-site robel-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/waynesutton/markdown-site.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/robel-auth .claude/skills/robel-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
robel-auth
GitHub stars
628
Token cost
~4.4k tokens
SKILL.md length
1,403 words
Files
2 (incl. scripts)
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Integrate and maintain Robelest Convex Auth in apps by always checking upstream before implementation.

  • Works in 3 steps: Register the component → Configure auth → Wire up HTTP routes
  • Adding auth setup
  • SKILL.md covers Non negotiable upstream check…, Important assumptions for this…, Published package reality… and Clarifying questions to ask…, plus 12 more sections
  • Runs Shell scripts from its folder; calls npm and bash; reaches auth.estifanos.com and github.com; needs AUTH_GITHUB_SECRET and AUTH_GOOGLE_SECRET

What it does

Robel Auth is an agent skill from waynesutton/markdown-site. Integrate and maintain Robelest Convex Auth in apps by always checking upstream before implementation. Use when adding auth setup, updating auth wiring, migrating between upstream patterns, or troubleshooting @robelest/convex-auth behavior across projects.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/check-upstream.sh`).

It sits in Backend & APIs. It works with npm and GitHub. The repository describes itself as: An open-source publishing framework built for AI agents and developers to ship websites, docs, or blogs. Write markdown, sync from the terminal. Your content is instantly… The licence is MIT.

When your agent uses it

  • Adding auth setup
  • Updating auth wiring
  • Migrating between upstream patterns
  • Troubleshooting @robelest/convex-auth behavior across projects

Example prompts

  • “/robel-auth”

Requirements

  • Node.js
  • A Bash shell
  • A credential in AUTH_GITHUB_SECRET
  • A credential in AUTH_GOOGLE_SECRET

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Register the component
  2. Configure auth
  3. Wire up HTTP routes

What it can do on your machine

Read from SKILL.md and the folder at commit 3872c59. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • auth.estifanos.com
    • github.com
    • raw.githubusercontent.com
    • discord.com
    • agentskills.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AUTH_GITHUB_SECRET
    • AUTH_GOOGLE_SECRET
    • AUTH_APPLE_KEY_ID
    • AUTH_APPLE_PRIVATE_KEY
    • AUTH_DISCORD_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Robel Auth loads about 4.4k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 1,403 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from waynesutton/markdown-site at commit 3872c59, republished under its MIT licence (© waynesutton). 1,403 words, ~4,439 tokens.

Download SKILL.mdSave it as .claude/skills/robel-auth/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
robel-auth
description
Integrate and maintain Robelest Convex Auth in apps by always checking upstream before implementation. Use when adding auth setup, updating auth wiring, migrating between upstream patterns, or troubleshooting @robelest/convex-auth behavior across projects.

Robel auth skill

Use this skill when a user asks to implement, update, or debug auth based on robelest/convex-auth.

This skill is designed to be copied into other repos.

Non negotiable upstream check before any auth change

Run this every time before proposing code or commands.

Preferred command:

bash
bash .cursor/skills/robel-auth/scripts/check-upstream.sh

Manual checklist if script is unavailable:

  1. Read official docs: https://auth.estifanos.com/getting-started/installation/
  2. Read latest main README: https://raw.githubusercontent.com/robelest/convex-auth/main/README.md
  3. Read latest release README: https://raw.githubusercontent.com/robelest/convex-auth/release/README.md
  4. Check branch level differences: https://github.com/robelest/convex-auth/compare/release...main
  5. Read current self hosting docs if portal or static hosting is involved:
    • https://raw.githubusercontent.com/get-convex/self-hosting/main/INTEGRATION.md
    • https://github.com/get-convex/self-hosting

If main and release conflict, prefer the branch requested by the user. If unspecified, use release for stability and explain that choice.

Important assumptions for this skill

  • Treat the official docs site (auth.estifanos.com) and GitHub as sources of truth every time.
  • Do not assume npm package availability.
  • Validate package availability at execution time.
  • If npm is unavailable, use a GitHub source install pinned to a branch or commit.
  • Keep all Convex code type safe and validator complete.

Published package reality check (critical)

The docs site (auth.estifanos.com) and main branch sometimes describe APIs ahead of the latest preview release on npm. Before writing imports, always inspect what the installed version actually exports:

bash
ls node_modules/@robelest/convex-auth/dist/providers/
cat node_modules/@robelest/convex-auth/dist/providers/index.js
cat node_modules/@robelest/convex-auth/dist/component/index.d.ts
As of 0.0.4-preview.30

The published package now matches the docs site for the common cases:

  • Lowercase factory exports from @robelest/convex-auth/providers: github, google, apple, microsoft, password, passkey, credentials, anonymous, device, email, phone, sso, totp, custom.
  • github, google, apple, microsoft are first-party factories with built-in profile fetch. No arctic wrapping required.
  • password is a factory function. Call it as password(), not new Password().
  • createAuth is exported from @robelest/convex-auth/component.
  • Client factory: import { client } from "@robelest/convex-auth/client" (or /browser for the browser-tuned variant). Both require api in SPA mode: client({ convex, api: api.auth }). Omitting api throws "The \api` option is required when `proxyPath` is not set. Pass { api: api.auth }."at firstsignIn/signOut/verifyCodecall. OnlyproxyPath` mode can skip it.
Older releases (legacy notes)
  • 0.0.4-preview.25 and earlier shipped PascalCase classes (Password, OAuth, etc.) and required arctic for OAuth providers.
  • If you find code on the older API, the upgrade path is: bump to ^0.0.4-preview.30, remove arctic, switch OAuth(new GitHub(...), { profile }) to github({ clientId, clientSecret }), and switch new Password() to password().

If the installed version drifts from the docs site, follow the installed exports and note the drift to the user. Do not blindly copy doc examples.

Clarifying questions to ask first

Ask these before editing:

  1. Which branch is source of truth for this task, release or main.
  2. Is this a new integration or an update to an existing auth setup.
  3. Which framework is used: Vite, Next.js, SvelteKit, TanStack Start, Expo web, or other.
  4. Is self hosted portal/static delivery needed now.
  5. Are they okay pinning dependency to a specific Git commit for reproducibility.

Install and dependency strategy

Never assume one install path.

  1. Try package registry lookup:
    • npm view @robelest/convex-auth version
  2. If package is unavailable or blocked, install from GitHub:
    • npm install github:robelest/convex-auth#release
  3. For deterministic builds, pin a commit SHA:
    • npm install github:robelest/convex-auth#<commit-sha>

If the project uses pnpm or bun, translate the same GitHub dependency pinning pattern.

Quick setup (CLI wizard)

The recommended setup flow:

  1. Install @robelest/convex-auth
  2. Start a Convex deployment with convex dev
  3. Run the auth setup wizard

The wizard handles key generation, convex.config.ts, auth.ts, and http.ts automatically.

Core wiring (3 files)

1. Register the component
typescript
// convex/convex.config.ts
import { defineApp } from "convex/server";
import auth from "@robelest/convex-auth/convex.config";

const app = defineApp();
app.use(auth);
export default app;
2. Configure auth
typescript
// convex/auth.ts
import { createAuth } from "@robelest/convex-auth/component";
import { components } from "./_generated/api";
import { github } from "@robelest/convex-auth/providers/github";

const auth = createAuth(components.auth, {
  providers: [
    github({
      clientId: process.env.AUTH_GITHUB_ID!,
      clientSecret: process.env.AUTH_GITHUB_SECRET!,
    }),
  ],
});

export { auth };
export const { signIn, signOut, store } = auth;
3. Wire up HTTP routes
typescript
// convex/http.ts
import { httpRouter } from "convex/server";
import { auth } from "./auth";

const http = httpRouter();
auth.http.add(http);
export default http;

auth.http.add registers OAuth callbacks and JWKS endpoints in one call.

API layers

Client auth flow: signIn, signOut, and store are the only required client-callable auth functions. Frontends use them through client({ convex, api: api.auth }).

Server helpers: auth.user.*, auth.session.*, auth.account.*, auth.group.*, auth.member.*, auth.invite.*, auth.key.*, auth.http.*, auth.group.sso.*, and auth.group.sso.scim.* are server-side helpers for Convex code. They are not automatically public RPC.

Optional group SSO RPC: If your app wants client-callable group SSO admin APIs, expose app-owned wrappers such as convex/auth/group.ts.

Available providers

All providers import from @robelest/convex-auth/providers:

typescript
import {
  anonymous,
  apple,
  custom,
  email,
  github,
  google,
  microsoft,
  passkey,
  password,
  phone,
  sso,
  totp,
} from "@robelest/convex-auth/providers";
OAuth providers
ProviderFactoryRequired env vars
GitHubgithub({ clientId, clientSecret })AUTH_GITHUB_ID, AUTH_GITHUB_SECRET
Googlegoogle({ clientId, clientSecret })AUTH_GOOGLE_ID, AUTH_GOOGLE_SECRET
Appleapple({ clientId, teamId, keyId, privateKey })AUTH_APPLE_ID, AUTH_APPLE_TEAM_ID, AUTH_APPLE_KEY_ID, AUTH_APPLE_PRIVATE_KEY
Microsoftmicrosoft({ tenant, clientId, clientSecret? })AUTH_MICROSOFT_TENANT_ID, AUTH_MICROSOFT_ID

All OAuth wrappers derive callback URL from CONVEX_SITE_URL automatically.

Custom OAuth

Use custom() for providers without a first-party wrapper:

typescript
custom({
  id: "discord",
  clientId: process.env.AUTH_DISCORD_ID!,
  clientSecret: process.env.AUTH_DISCORD_SECRET!,
  scopes: ["identify", "email"],
  authorization: { url: "https://discord.com/oauth2/authorize", pkce: "optional" },
  token: { url: "https://discord.com/api/oauth2/token", authMethod: "body" },
  profile: async ({ accessToken }) => {
    const res = await fetch("https://discord.com/api/users/@me", {
      headers: { Authorization: `Bearer ${accessToken}` },
    });
    const user = await res.json();
    return { id: String(user.id), email: user.email, name: user.username };
  },
})
Non-OAuth providers
ProviderFactoryNotes
Passwordpassword()Built-in password auth
Magic linksemail({ from, send })Requires email transport (e.g. Resend)
Passkeyspasskey()WebAuthn based
TOTPtotp({ issuer })Authenticator app codes
Anonymousanonymous()Guest sessions
Phone/SMSphone({ send })Requires SMS transport (e.g. Twilio)
Group SSOsso()Enables OIDC, SAML 2.0, SCIM 2.0

Configuration options

typescript
const auth = createAuth(components.auth, {
  providers: [/* ... */],
  session: {
    totalDurationMs: 30 * 24 * 60 * 60 * 1000,   // 30 days
    inactiveDurationMs: 7 * 24 * 60 * 60 * 1000,  // 7 days
  },
  jwt: {
    durationMs: 60 * 1000,  // 1 minute
  },
  signIn: {
    max_failed_attempts_per_hour: 10,
  },
  callbacks: {
    afterUserCreatedOrUpdated: async (ctx, { userId, existingUser }) => { /* ... */ },
  },
  authorization: {
    roles,  // from defineRoles()
  },
});
OptionTypeDefaultDescription
providersAuthProviderConfig[]requiredAuth methods to enable
session.totalDurationMsnumber30 daysMaximum session lifetime
session.inactiveDurationMsnumbervariesInactive session timeout
jwt.durationMsnumber60sJWT token lifetime
signIn.max_failed_attempts_per_hournumber10Rate limit for failed sign-in attempts
callbacks.afterUserCreatedOrUpdatedfunctionnonePost sign-in hook
authorization.rolesRecord{}App-defined role definitions and grants

Multi-access patterns

Every auth path resolves to the same userId. Three access patterns:

PatternContextHow userId is available
App code (query/mutation/action)auth.ctx()ctx.auth.userId and ctx.auth.user
Raw HTTP (session or API key)auth.http.context(ctx, request)authContext.userId
API key HTTPauth.http.action(...)ctx.key.userId
Show full SKILL.md (547 more words)Show less
Auth-aware custom functions
typescript
// convex/functions.ts
import { customMutation, customQuery } from "convex-helpers/server/customFunctions";
import { mutation, query } from "./_generated/server";
import { auth } from "./auth";

export const authQuery = customQuery(query, auth.ctx());
export const authMutation = customMutation(mutation, auth.ctx());

Use auth.ctx({ optional: true }) when the same handler should work for both guests and signed-in users.

Raw HTTP mixed auth
typescript
http.route({
  path: "/api/data",
  method: "GET",
  handler: httpAction(async (ctx, request) => {
    const authContext = await auth.http.context(ctx, request, { optional: true });
    if (authContext.userId === null) {
      return new Response(JSON.stringify({ error: "Unauthorized" }), { status: 401 });
    }
    const data = await ctx.runQuery(internal.data.forUser, { userId: authContext.userId });
    return Response.json(data);
  }),
});

Authorization patterns

Define roles with grants
typescript
import { defineRoles } from "@robelest/convex-auth/authorization";

export const roles = defineRoles({
  orgAdmin: {
    label: "Organization Admin",
    grants: ["members.create", "members.update", "members.delete", "sso.connection.manage", "scim.manage"],
  },
  support: {
    label: "Support",
    grants: ["members.read", "tickets.manage"],
  },
  member: {
    label: "Member",
    grants: [],
  },
});
Assign roles via memberships
typescript
await auth.member.create(ctx, { userId, groupId: orgId, roleIds: [roles.orgAdmin.id] });
await auth.member.update(ctx, memberId, { roleIds: [roles.support.id] });
await auth.invite.create(ctx, { groupId: orgId, email: "new@example.com", roleIds: [roles.member.id] });
Check grants (not role names)
typescript
// Boolean check
const result = await auth.member.inspect(ctx, { userId: ctx.auth.userId, groupId: orgId });
if (result.grants.includes("members.read")) { /* authorized */ }

// Throwing check
await auth.member.require(ctx, { userId: ctx.auth.userId, groupId: orgId, grants: ["sso.connection.manage"] });

auth.user API

MethodSignatureReturnsDescription
get(ctx, userId)Doc<"User"> | nullFetch user by ID
list(ctx, { where?, limit?, cursor? })Paginated listList users with filtering
update(ctx, userId, data){ userId }Update user fields
viewer(ctx)Doc<"User"> | nullCurrent session user document
delete(ctx, userId, { cascade? }){ userId }Delete user; cascade removes sessions, accounts, memberships, keys
setActiveGroup(ctx, { userId, groupId }){ userId, groupId }Set active group
getActiveGroup(ctx, { userId })Id<"Group"> | nullGet active group ID

Group SSO

Adding sso() to providers enables auth.group.sso.* namespace. Without it, the namespace is a TypeScript error.

ProtocolPurposeNamespace
OIDCOpenID Connect identity provider loginauth.group.sso.oidc
SAML 2.0Security Assertion Markup Language loginauth.group.sso.saml
SCIM 2.0Cross-domain user/group provisioningauth.group.sso.scim

All SSO configuration is per-tenant runtime state stored in the Convex database. No app-level config file needed.

Optional SSO hooks:

typescript
const auth = createAuth(components.auth, {
  providers: [sso()],
  sso: {
    hooks: {
      profileResolved: async ({ protocol, profile }) => profile,
      beforeProvision: async ({ protocol, profile }) => profile,
      afterProvision: async ({ protocol, userId }) => {},
      allowLink: async ({ protocol, userId, profile }) => true,
    },
  },
});

GitHub OAuth setup instructions for end users

Required link: https://github.com/settings/developers

  1. Go to GitHub Developer Settings: https://github.com/settings/developers
  2. Create a new OAuth App.
  3. Set:
    • Homepage URL = app frontend URL (same as SITE_URL)
    • Authorization callback URL = https://<deployment>.convex.site/api/auth/callback/github
  4. Copy Client ID and Client Secret.
  5. Set Convex env vars: AUTH_GITHUB_ID, AUTH_GITHUB_SECRET
  6. Confirm SITE_URL and CONVEX_SITE_URL are configured.
  7. Deploy and test sign in.

In this codebase, GitHub OAuth is conditionally enabled only when AUTH_GITHUB_ID, AUTH_GITHUB_SECRET, and CONVEX_SITE_URL are present.

Denied session pattern (app-level allowlists)

Provider authentication and app-level authorization are separate decisions. When a user successfully completes OAuth but the app refuses access (allowlist miss, billing gate, role check), do not just redirect or render an "access denied" screen. Sign them out so the auth runtime stops refreshing a session your app does not intend to use:

typescript
useEffect(() => {
  if (isAuthenticated && !isAllowed) {
    void authClient.signOut();
  }
}, [isAuthenticated, isAllowed, authClient]);

Render the denied UI immediately. The sign-out resolves the session in the background. Stash any data you want to display (denied email, reason) in component state before sign-out completes if your UI needs to survive the unauthenticated rerender.

This pattern is what auth.estifanos.com/guides/authorization/ recommends for app-level allowlists. It is the right shape for "only one admin email can use the dashboard, everyone else sees the demo view."

Migration guardrails

When upgrading existing apps:

  1. Snapshot current auth wiring before edits.
  2. Update one surface at a time: config, auth module, then HTTP routes.
  3. Keep old and new API mismatch notes in task output.
  4. Verify sign in flow and callback routes before moving on.
  5. Keep migrations minimal and focused to auth wiring only.

Self hosting decision point

Use get-convex/self-hosting only when:

  • user asks for self hosted static assets, or
  • auth portal hosting requires it in the selected upstream version.

When needed, follow the latest upstream integration docs:

  • https://github.com/get-convex/self-hosting
  • https://raw.githubusercontent.com/get-convex/self-hosting/main/INTEGRATION.md

Output requirements for any task using this skill

Before finishing, always report:

  1. Retrieval timestamp for upstream docs.
  2. Which branch was used as source of truth and why.
  3. Install path selected, npm or GitHub pin, and why.
  4. Exact files changed.
  5. Exact commands the user should run next.

Never claim completion without these five items.

  • https://auth.estifanos.com/getting-started/installation/ (official docs)
  • https://auth.estifanos.com/getting-started/providers/
  • https://auth.estifanos.com/guides/multi-access/
  • https://auth.estifanos.com/guides/authorization/
  • https://auth.estifanos.com/api/user/
  • https://auth.estifanos.com/reference/config/
  • https://auth.estifanos.com/sso/overview/
  • https://github.com/robelest/convex-auth
  • https://github.com/robelest/convex-auth/tree/release
  • https://raw.githubusercontent.com/robelest/convex-auth/main/README.md
  • https://raw.githubusercontent.com/robelest/convex-auth/release/README.md
  • https://github.com/get-convex/self-hosting
  • https://raw.githubusercontent.com/get-convex/self-hosting/main/INTEGRATION.md
  • https://agentskills.io/home

© waynesutton, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in .cursor/skills/robel-auth of waynesutton/markdown-site.

  • SKILL.md
  • scripts/check-upstream.sh

Open the folder on GitHubat commit 3872c59

Compare with similar skills

Robel Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Robel Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Robel Auth this skillwaynesutton/markdown-site628—~4.4kAutomated safety check: PassMIT
Plugin Release CheckVoidenHQ/voiden1.9k—~857Automated safety check: PassApache-2.0
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Chat SDKdatabuddy-analytics/Databuddy1.2k—~2.6kAutomated safety check: PassAGPL-3.0
Dependabot Alerts Updatelivesession/xyd114—~2kAutomated safety check: PassMIT
Release Allpaperboytm/spool592—~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Plugin Release Check

    VoidenHQ/voiden

    A skill your agent uses whenever a plugin under plugins/<name is updated/pushed, or whenever asked to write a changelog/release for the app or a plugin.

    1.9k GitHub stars~857 tokensUpdated today
    Backend & APIsAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Chat SDK

    databuddy-analytics/Databuddy

    Build multi-platform chat bots with Chat SDK (chat npm package).

    1.2k GitHub stars~2.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Automatically fetch and fix Dependabot security alerts by querying GitHub REST API for open alerts, identifying vulnerable packages, researching secure versions, and updating package.json files…

    114 GitHub stars~2k tokensUpdated 15 days ago
    DevelopmentAuto-check passed
  • Release All

    paperboytm/spool

    Publish the complete Spool CLI release train: synchronized versions, npm packages, the GitHub release, and the matching production web deployment.

    592 GitHub stars~1.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Create Release

    lablup/backend.ai-webui

    Create a release branch, tag, and GitHub release for Backend.AI WebUI.

    133 GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed

More from waynesutton/markdown-site

All 17 skills in this repo
  • Convex Self Hosting

    waynesutton/markdown-site

    Integrate Convex static self hosting into existing apps using the latest upstream instructions from get-convex/self-hosting every time.

    628 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Migration Helper

    waynesutton/markdown-site

    Plan and execute Convex schema migrations safely, including adding fields, creating tables, and data transformations.

    628 GitHub starsUsed in 1 repo~958 tokens
    Auto-check passed
  • Convex Return Validators

    waynesutton/markdown-site

    Guide for when to use and when not to use return validators in Convex functions.

    628 GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Convex Doctor

    waynesutton/markdown-site

    Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories.

    628 GitHub stars~1.9k tokensUpdated 4 mo ago
    Auto-check passed
  • Convex Quickstart

    waynesutton/markdown-site

    Initialize a new Convex project from scratch or add Convex to an existing app.

    628 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check: notes
  • Convex Setup Auth

    waynesutton/markdown-site

    Set up Convex authentication with proper user management, identity mapping, and access control patterns.

    628 GitHub stars~1.4k tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Robel Auth

What does Robel Auth do?

Integrate and maintain Robelest Convex Auth in apps by always checking upstream before implementation. Robel Auth is an agent skill from waynesutton/markdown-site. Integrate and maintain Robelest Convex Auth in apps by always checking upstream before implementation.

When should I use Robel Auth?

Robel Auth fits situations like: adding auth setup; updating auth wiring; migrating between upstream patterns; troubleshooting @robelest/convex-auth behavior across projects.

How do I install Robel Auth in Claude Code?

Run `npx skills add waynesutton/markdown-site --skill robel-auth -a claude-code`. Or copy the skill folder (.cursor/skills/robel-auth in waynesutton/markdown-site) into .claude/skills/robel-auth in your project. Claude Code loads it when a task matches its description.

How do I install Robel Auth in Codex?

Run `npx skills add waynesutton/markdown-site --skill robel-auth -a codex`. Or copy the skill folder (.cursor/skills/robel-auth in waynesutton/markdown-site) into .agents/skills/robel-auth in your project. Codex loads it when a task matches its description.

Can I use Robel Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waynesutton/markdown-site --skill robel-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/robel-auth, .gemini/skills/robel-auth, .github/skills/robel-auth and .opencode/skills/robel-auth in your project.

What does Robel Auth need to run?

Going by SKILL.md and its folder, Robel Auth needs a shell for the scripts in its folder, the command-line tools its instructions call (npm and bash) and credentials named AUTH_GITHUB_SECRET, AUTH_GOOGLE_SECRET, AUTH_APPLE_KEY_ID and AUTH_APPLE_PRIVATE_KEY. Our summary lists: Node.js; A Bash shell; A credential in AUTH_GITHUB_SECRET; A credential in AUTH_GOOGLE_SECRET.

Does Robel Auth access the network?

SKILL.md names 5 domains. In commands or code: auth.estifanos.com, github.com, raw.githubusercontent.com, discord.com and agentskills.io; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Robel Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Robel Auth use?

Robel Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Robel Auth use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Robel Auth?

Skills that share tags, products or a category with Robel Auth: Plugin Release Check (VoidenHQ/voiden, 1.9k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Chat SDK (databuddy-analytics/Databuddy, 1.2k stars) and Dependabot Alerts Update (livesession/xyd, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Robel Auth?

waynesutton (a GitHub user) maintains it in waynesutton/markdown-site, which has 628 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on May 20, 2026.

Source: waynesutton/markdown-site on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.