Agent skill

Xrk Auth

by xrkseek in xrkseek/XRK-AGT

当你需要解释/排查 HTTP 或 WebSocket 的 401、127 回环例外、API Key 机制时使用;确保业务层不重复鉴权。

MITAuto-check passedBackend & APIs

Install Xrk Auth

skills CLI
$ npx skills add xrkseek/XRK-AGT --skill xrk-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xrkseek/XRK-AGT xrk-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xrkseek/XRK-AGT.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/xrk-auth .claude/skills/xrk-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
xrk-auth
GitHub stars
138
Token cost
~246 tokens
SKILL.md length
61 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

当你需要解释/排查 HTTP 或 WebSocket 的 401、127 回环例外、API Key 机制时使用;确保业务层不重复鉴权。

  • Tasks that involve Realtime and WebSockets
  • SKILL.md covers 文档与代码, 原则, API Key 携带 and Node 26
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Xrk Auth is an agent skill from xrkseek/XRK-AGT. 当你需要解释/排查 HTTP 或 WebSocket 的 401、127 回环例外、API Key 机制时使用;确保业务层不重复鉴权。

Its SKILL.md is about 250 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Realtime and WebSockets. The repository describes itself as: 这是基于多语言所搭建的基于web,工作流,新型算法组件的智能体. The licence is MIT.

When your agent uses it

  • Tasks that involve Realtime and WebSockets

Example prompts

  • “/xrk-auth”

What it can do on your machine

Read from SKILL.md and the folder at commit 63f004e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Xrk Auth loads about 246 tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 61 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~246

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xrkseek/XRK-AGT at commit 63f004e, republished under its MIT licence (© xrkseek). 61 words, ~246 tokens.

Download SKILL.mdSave it as .claude/skills/xrk-auth/SKILL.md (or your agent's skills folder).
name
xrk-auth
description
当你需要解释/排查 HTTP 或 WebSocket 的 401、127 回环例外、API Key 机制时使用;确保业务层不重复鉴权。

文档与代码

  • docs/AUTH.md
  • 门面:src/agent-runtime.js(_authMiddleware、checkApiAuthorization、wsConnect)
  • 实现:src/infrastructure/http/runtime-auth.js、runtime-ws.js、auth.js

原则

  • /api/ 由 HttpApi + AgentRuntime.checkApiAuthorization;公开路由 systemAuth: false。
  • 默认所有客户端须 API Key;server.auth.loopbackExempt===true 时才允许「本机 Host+127」免 Key(公网/反代勿开)。runEnabled=true 时即便 exempt 也强制 Key。
  • 控制台鉴权模式:公开 GET /api/system/auth-mode → requiresKey;禁止用无 Key 打受保护接口靠 401 探测。
  • WS:wsConnect → runtime-ws;AgentRuntime.wsf[path] 可为 { handler, skipAuth: true } 跳过系统 Key。

API Key 携带

Header:X-API-Key、Api-Key、Authorization: Bearer|Token|ApiKey <key>;查询仅 api_key / apiKey。不接受 body 与 token/key 等易撞字段。

Node 26

  • 扩展时判错用 Error.isError,勿 instanceof Error(skill xrk-node-runtime)。
  • 业务 Core 不重复实现鉴权;HTTP 超时仍用 AbortSignal.timeout。

© xrkseek, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .cursor/skills/xrk-auth of xrkseek/XRK-AGT.

Open the folder on GitHubat commit 63f004e

Compare with similar skills

Xrk Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Xrk Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Xrk Auth this skillxrkseek/XRK-AGT138—~246Automated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
Gemini Live API Devgoogle-gemini/gemini-skills4.3k—~4.6kAutomated safety check: PassApache-2.0
Broker Integrationmarketcalls/openalgo2.8k—~4.7kAutomated safety check: NotesAGPL-3.0
Trigger.dev Realtimepapermark/papermark9.2k—~1.7kAutomated safety check: PassCustom licence

Similar skills

  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Broker Integration

    marketcalls/openalgo

    Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.

    2.8k GitHub stars~4.7k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Trigger.dev Realtime

    papermark/papermark

    Shows how to subscribe to Trigger.dev task runs from the backend and from React for progress indicators, live dashboards, AI response streams and approval waits.

    9.2k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Spider King

    aoyunyang/spider-king-skill

    Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.

    509 GitHub stars~7.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from xrkseek/XRK-AGT

All 12 skills in this repo
  • Immersive Short Video

    xrkseek/XRK-AGT

    Produce immersive vertical short videos (口播/科普/产品讲解) without AI-slop aesthetics.

    138 GitHub stars~1k tokensUpdated 10 days ago
    Auto-check passed
  • Xrk Crawl

    xrkseek/XRK-AGT

    当你需要开发/排查 HTTP 抓取、SSRF、Playwright 受控浏览器、本地字体增强截图,或判断 webfetch 与 browser 工作流如何选型时使用。

    138 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check passed
  • Xrk HTTP API

    xrkseek/XRK-AGT

    当你需要开发或排查 HTTP API(core//http/.js)、理解 HttpApi 基类、HttpApiLoader、业务层约定时使用。

    138 GitHub stars~569 tokensUpdated 10 days ago
    Auto-check passed
  • Xrk Node Runtime

    xrkseek/XRK-AGT

    编写或审查 core/src 代码时,确保使用 Node 26 稳定 API,禁止旧写法(fetch/exec/错误/二进制)。AI 改 Core 前必读。

    138 GitHub stars~907 tokensUpdated 10 days ago
    Auto-check passed
  • Xrk GitHub Research

    xrkseek/XRK-AGT

    在 GitHub 搜索成熟开源实现、对比方案、读 issue/PR 时使用。架构选型、unfamiliar 领域、找业界最佳实践时主动调用。

    138 GitHub stars~202 tokensUpdated 10 days ago
    Auto-check passed
  • Xrk LLM

    xrkseek/XRK-AGT

    当你需要配置/新增/排查 LLM 提供商(OpenAI/Azure/Gemini/Anthropic/Ollama/各类兼容网关)时使用;确保 YAML/Schema/代码一致。

    138 GitHub stars~304 tokensUpdated 10 days ago
    Auto-check passed

Categories

Questions about Xrk Auth

What does Xrk Auth do?

当你需要解释/排查 HTTP 或 WebSocket 的 401、127 回环例外、API Key 机制时使用;确保业务层不重复鉴权。. Xrk Auth is an agent skill from xrkseek/XRK-AGT.

When should I use Xrk Auth?

Xrk Auth fits situations like: tasks that involve Realtime and WebSockets.

How do I install Xrk Auth in Claude Code?

Run `npx skills add xrkseek/XRK-AGT --skill xrk-auth -a claude-code`. Or copy the skill folder (.cursor/skills/xrk-auth in xrkseek/XRK-AGT) into .claude/skills/xrk-auth in your project. Claude Code loads it when a task matches its description.

How do I install Xrk Auth in Codex?

Run `npx skills add xrkseek/XRK-AGT --skill xrk-auth -a codex`. Or copy the skill folder (.cursor/skills/xrk-auth in xrkseek/XRK-AGT) into .agents/skills/xrk-auth in your project. Codex loads it when a task matches its description.

Can I use Xrk Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xrkseek/XRK-AGT --skill xrk-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/xrk-auth, .gemini/skills/xrk-auth, .github/skills/xrk-auth and .opencode/skills/xrk-auth in your project.

What does Xrk Auth need to run?

SKILL.md names no scripts, command-line tools or credentials: Xrk Auth is instructions for the agent only.

Does Xrk Auth access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Xrk Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Xrk Auth use?

Xrk Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Xrk Auth use?

About 246 tokens (SKILL.md is roughly 984 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Xrk Auth?

Skills that share tags, products or a category with Xrk Auth: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Use Yaak (mountain-loop/yaak, 19k stars), Gemini Live API Dev (google-gemini/gemini-skills, 4.3k stars) and Broker Integration (marketcalls/openalgo, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Xrk Auth?

xrkseek (a GitHub user) maintains it in xrkseek/XRK-AGT, which has 138 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 1, 2026.

Source: xrkseek/XRK-AGT on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.