Topic · Backend & APIs
Best Authorization and RBAC skills for Claude Code, Codex and other agents.
- skills
- 519
- official
- 56
Authorization and RBAC skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses whenever the user mentions Horizon by name in a Laravel context. | coollabsio/ | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | today |
| 2 | Finds or validates a usable SageMaker execution role before deploying or training, so scripts do not try to create IAM roles they lack permission to create. | huggingface/ | 11k | 1 repo | ~1.8k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 3 | Prepare and, with a verified authenticated publishing route and authorization, publish daily conference-deadline countdown posts for @ccfddl on X/Twitter. | ccfddl/ | 9.4k | — | ~4.2k | Automated safety check: Pass | MIT | today |
| 4 | Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes. | Cybereason-Public/ | 280 | 11 repos | ~2k | Automated safety check: Pass | GPL-2.0 | yesterday |
| 5 | 5.Payload A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API). | payloadcms/ | 45k | 5 repos | ~6.2k | Automated safety check: Pass | MIT | today |
| 6 | Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything. | kubesphere/ | 17k | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 7 | Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Smoke test the Agent Builder feature branch end-to-end against a hermetic project scaffolded by the skill (linked to the current worktree). | mastra-ai/ | 29k | — | ~11k | Automated safety check: Notes | Unknown | today |
| 9 | Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers. | netdata/ | 81k | — | ~2.2k | Automated safety check: Notes | GPL-3.0 | today |
| 10 | Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning. | spokvulcan/ | 114 | 8 repos | ~1.8k | Automated safety check: Pass | MIT | 3 days ago |
| 11 | Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps. | Jeffallan/ | 12k | 1 repo | ~2.1k | Automated safety check: Pass | MIT | 4 days ago |
| 12 | Author, package, and debug NextCoWork plugins — the single entry point. | AIDotNet/ | 638 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 13 | 13.Fedramp Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). | Sushegaad/ | 939 | 1 repo | ~4.4k | Automated safety check: Pass | MIT | 3 days ago |
| 14 | Checklist-driven security review for changes to authentication, authorization, MFA, secrets, input validation and other security-critical code. | ZeroDeng01/ | 1.7k | — | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 15 | Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries. | Tencent/ | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | today |
| 16 | Prepare and deliver Xiaohongshu image posts with automatic relevant/high-potential tag suggestions, optional matching activity selection and required activity tags, plus exact draft, publish-now, or… | Andonywang123/ | 197 | — | ~2.1k | Automated safety check: Pass | No licence | 1 mo ago |
| 17 | 17.UI Audit Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and… | bagofwords1/ | 458 | — | ~2.9k | Automated safety check: Pass | Unknown | yesterday |
| 18 | 18.Ccb Diagnose Diagnose a named CCB agent by combining authoritative runtime and job lineage with deep read-only pane inspection, apply bounded recovery when evidence supports it, verify the result, and request… | SeemSeam/ | 3.5k | — | ~2.1k | Automated safety check: Pass | Unknown | yesterday |
| 19 | Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants. | google/ | 21k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 20 | 20.Cognito AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills. | itsmostafa/ | 1.2k | 1 repo | ~2.3k | Automated safety check: Pass | MIT | 2 days ago |
| 21 | A skill your agent uses when running a previously designed distributed-systems test plan against a real or simulated cluster — driving fault injection, workload, chaos scenarios, linearizability /… | shenli/ | 231 | — | ~5.1k | Automated safety check: Notes | MIT | 2 mo ago |
| 22 | Audit or harden gocron security across Go, pnpm workspaces, containers, authentication, authorization, secrets, command execution, SSRF, and dependency vulnerabilities. | gocronx-team/ | 808 | — | ~690 | Automated safety check: Pass | MIT | 5 days ago |
| 23 | Django access control and IDOR security review. An agent skill from getsentry/skills. | getsentry/ | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | 5 days ago |
| 24 | 24.Caura The agent's persistent long-term memory — the only knowledge that survives across sessions, shared across the fleet under access control. | caura-ai/ | 544 | — | ~6.2k | Automated safety check: Pass | Apache-2.0 | today |
| 25 | 25.Gate Control Canonical VideoStudio review authorization and state-transition policy. | Orkas-AI/ | 497 | — | ~2.7k | Automated safety check: Pass | MIT | 15 days ago |
| 26 | Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. | ynulihao/ | 617 | 9 repos | ~4.4k | Automated safety check: Pass | No licence | 7 mo ago |
| 27 | Creates and manages Link spend requests and retrieves approved one-time-use payment credentials. | stripe/ | 831 | — | ~2.2k | Automated safety check: Pass | MIT | yesterday |
| 28 | Create and update QuickStack Elysia REST API routes using the project's established /api/v1 route conventions. | biersoeckli/ | 361 | — | ~1.1k | Automated safety check: Pass | GPL-3.0 | yesterday |
| 29 | 29.Tyro Framework-maintainer skill for the Tyro Laravel authorization package | hasinhayder/ | 685 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 30 | 30.Ron Auth Implement identity and authorization boundaries in Rust on Nails applications. | bionic-gpt/ | 2.4k | — | ~667 | Automated safety check: Pass | Apache-2.0 | today |
| 31 | Build and risk-screen a compact role-based method shortlist for a mathematical-modeling subquestion. | zhnnky329/ | 1.1k | — | ~1.6k | Automated safety check: Pass | MIT | 13 days ago |
| 32 | Handles Laravel Pulse setup, configuration, and custom card development. | MineTrax/ | 115 | 1 repo | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 33 | Implements SoundCloud OAuth 2.1 flows — Authorization Code with PKCE and Client Credentials — including token refresh and secure credential storage. | soundcloud/ | 257 | — | ~562 | Automated safety check: Pass | No licence | 7 days ago |
| 34 | API route implementation patterns with RLS, validation, and error handling. Use when creating API routes, implementing CRUD endpoints, adding… | bybren-llc/ | 421 | — | ~1.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 35 | Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys. | greenpau/ | 2.3k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 36 | Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard. | fullstackhero/ | 6.8k | — | ~849 | Automated safety check: Pass | MIT | 7 days ago |
| 37 | Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost. | trypostit/ | 676 | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 38 | Prepare, publish, verify, or recover a cloakbrowser-mcp release only when the user explicitly requests release work. | swimmwatch/ | 161 | — | ~1.9k | Automated safety check: Pass | MIT | 5 days ago |
| 39 | A skill your agent uses when designing data schemas, implementing sharing workflows, or auditing access control in Jazz applications. | garden-co/ | 2.5k | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 40 | SPD V1 Batch. An agent skill from flaqai/backlink_skills. | flaqai/ | 750 | — | ~1.7k | Automated safety check: Pass | MIT | 13 days ago |
| 41 | Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. | microsoft/ | 255 | 1 repo | ~6.7k | Automated safety check: Pass | MIT | today |
| 42 | Design, audit, document, refactor, and implement NestJS CRUD Automator resources using @elsikora/nestjs-crud-automator. | ElsiKora/ | 261 | — | ~6.7k | Automated safety check: Pass | MIT | 14 days ago |
| 43 | Add or retrofit Tenuo authorization for AI-agent tools and effects. | tenuo-ai/ | 101 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 44 | Guide for writing eval conversation JSONs and running them through policy engines | open-bias/ | 143 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 4 mo ago |
| 45 | Specifies how a GenLayer Intelligent Contract decision about an agent's performance becomes an ERC-7710 revocation or policy change, through a relayer or bridge and an EVM controller. | internet-court/ | 6.4k | 1 repo | ~2.2k | Automated safety check: Pass | Unknown | 1 mo ago |
| 46 | Sentry-specific security review based on real vulnerability history. | getsentry/ | 45k | — | ~2.3k | Automated safety check: Notes | Unknown | today |
| 47 | Audit GitBook integrations for script injection, sensitive-data access, unsafe requests, authorization gaps, and manifest or dependency risk. | GitbookIO/ | 131 | — | ~1.2k | Automated safety check: Pass | No licence | 2 days ago |
| 48 | How Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/. | home-operations/ | 113 | — | ~2.5k | Automated safety check: Pass | AGPL-3.0 | yesterday |
Questions, answered from the data.
What is the best Authorization and RBAC skill?
Configuring Horizon from coollabsio/coolify ranks first of the 519 Authorization and RBAC skills listed here, with the highest score: its repository has 63k GitHub stars, 4 other GitHub owners carry a copy, its SKILL.md loads about 898 tokens and it passes the automated safety check with no findings. Next come SageMaker IAM Role Preflight and Ccfddl X Posts.
Which Authorization and RBAC skills are official?
56 of the 519 Authorization and RBAC skills are official, published by the vendor's own GitHub organization: SageMaker IAM Role Preflight, Google Cloud PAM Helper, Django Access Review, Create Payment Credential, Microsoft Foundry and 51 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Backend & APIs
- Backend development928
- REST APIs783
- Authentication646
- OAuth and OpenID Connect482
- Webhooks460
- OpenAPI specifications439
- Smart contracts404
- Third-party API integration348
- GraphQL343
- Caching327
- Event-driven systems311
- Microservices303
- API design281
- Realtime and WebSockets277
- File uploads and storage276
- Rate limiting257
- Serverless229
- Transactional email165
- Background jobs156
- gRPC and Protobuf149
- Search implementation117
- Multi-tenancy93
- Payments and billing57