Topic · Backend & APIs
Best Authorization and RBAC skills, page 11
Authorization and RBAC skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 481 | Retell AI enterprise rbac — AI voice agent and phone call automation. | jeremylongshore/ | 2.8k | — | ~517 | Automated safety check: Pass | MIT | today |
| 482 | Review and govern Salesforce enterprise access across profiles, permission sets and groups, sharing, field access, OAuth apps, SSO, and privileged roles. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 483 | 483.Warden Iam Build IAM from scratch — roles, policies, service accounts with least privilege. | jeremylongshore/ | 2.8k | — | ~987 | Automated safety check: Notes | MIT | today |
| 484 | 484.Convex Auth Implement Convex authentication and authorization patterns with OIDC providers or Convex Auth. | IgorWarzocha/ | 122 | — | ~744 | Automated safety check: Pass | No licence | 8 mo ago |
| 485 | Inspect and change navigation profiles in MDL — home pages, menus, login and not-found pages, and role-based routing. | mendixlabs/ | 128 | — | ~6.5k | Automated safety check: Pass | Apache-2.0 | today |
| 486 | Cisco ISE posture and policy audit - authorization rules, posture compliance, profiling gaps, TrustSec SGT matrix, active session health. | automateyournetwork/ | 675 | — | ~3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 487 | Security best practices for Micronaut/Kotlin backend including authentication, authorization, input validation, and OWASP prevention. | c0x12c/ | 106 | — | ~672 | Automated safety check: Notes | No licence | 3 mo ago |
| 488 | 488.Spec Commit Internal commit helper for public workflows that already hold explicit commit authorization; creates scoped, value-communicating commits without owning push or PR landing. | leo-kuang-ai/ | 107 | — | ~2.1k | Automated safety check: Notes | MIT | 13 days ago |
| 489 | Internal landing helper for public workflows that already hold explicit commit and landing authorization; commits scoped changes, pushes, and creates or updates a PR with a value-first description. | leo-kuang-ai/ | 107 | — | ~5.6k | Automated safety check: Pass | MIT | 13 days ago |
| 490 | 490.Uniswap V4 Hooks A skill your agent uses when building or reviewing Uniswap V4 hooks, custom AMM logic, dynamic fees, access controls, oracle hooks, return deltas, hook deployment, or hook-specific tests. | ccashwell/ | 131 | — | ~5.2k | Automated safety check: Pass | MIT | 8 days ago |
| 491 | Audit container runtime isolation across namespaces, capabilities, seccomp, mandatory access control, mounts, devices, daemon sockets, cgroups, identity, and host integration. | cyberful/ | 135 | — | ~545 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 492 | Identity and access management: RBAC, least privilege, MFA, quarterly reviews per ISO 27001 A.5.15, A.8.2, A.8.3 | Hack23/ | 239 | — | ~6.8k | Automated safety check: Pass | Apache-2.0 | today |
| 493 | Write a persuasive prior-authorization / medical-necessity letter to an insurer. | mohitagw15856/ | 1.4k | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 494 | 494.Security Review Review a design, PR, or feature for security issues before it ships. | mohitagw15856/ | 1.4k | — | ~973 | Automated safety check: Pass | MIT | today |
| 495 | Dual-platform Cisco ASA and Firepower Threat Defense (FTD) firewall audit with ACL analysis, NAT policy validation, Modular Policy Framework / Access Control Policy evaluation, Snort IPS assessment… | LeoYeAI/ | 2.2k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 496 | 496.K8s Istio Bypass Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能 | wgpsec/ | 1.8k | — | ~727 | Automated safety check: Pass | No licence | 4 days ago |
| 497 | 497.Build Backend Build or modify backend APIs, services, jobs, persistence, and integrations while preserving contracts, authorization, data integrity, and failure behavior. | hashgraph-online/ | 1.2k | — | ~410 | Automated safety check: Pass | Apache-2.0 | today |
| 498 | JWT, OAuth2, SAML, session management, RBAC, ABAC, and MFA implementation | cosmicstack-labs/ | 476 | — | ~523 | Automated safety check: Pass | MIT | 1 mo ago |
| 499 | 499.Better Auth Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. | Microck/ | 403 | — | ~1.8k | Automated safety check: Notes | MIT | 1 mo ago |
| 500 | 500.Manage Roles Manage Harness RBAC roles, role assignments, permissions, and resource groups via MCP v2 tools. | harness/ | 115 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 501 | 501.Page Deliver A skill your agent uses for page-deliver application code generation, page creation, publishing, deployment, going live, MCP enablement, or runtime access/control of deployed HRClaw applications. | infometa/ | 344 | — | ~3.9k | Automated safety check: Pass | No licence | today |
| 502 | 502.Owasp Security Comprehensive OWASP-aligned security guidance across six standards - Top 10 (2021) for web apps, ASVS 5.0, MASVS v2.1.0 for mobile, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the… | davila7/ | 32k | — | ~7.4k | Automated safety check: Warn | MIT | today |
| 503 | 503.Tailnet Policy Author, test, and deploy Tailscale-compatible huJSON policy files for Headscale tailnets — ACLs, Grants, Tags, Auto Approvers, Tailscale SSH rules. | magnus919/ | 113 | — | ~2k | Automated safety check: Pass | MIT | yesterday |
| 504 | 504.JWT Auth A skill your agent uses when implementing JWT authentication in FastAPI or Python projects. | aiskillstore/ | 430 | — | ~1.2k | Automated safety check: Pass | No licence | today |
| 505 | 505.Auth Patterns A skill your agent uses when implementing authentication (JWT, sessions, OAuth), authorization (RBAC, ABAC), password hashing, MFA, or security best practices for backend services. | MadAppGang/ | 284 | — | ~2.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 506 | A skill your agent uses when orchestrating multi-agent code analysis with claudemem. | MadAppGang/ | 284 | — | ~2.6k | Automated safety check: Notes | MIT | 6 mo ago |
| 507 | 507.Phy Cors Audit CORS (Cross-Origin Resource Sharing) misconfiguration auditor. | LeoYeAI/ | 2.2k | — | ~6.7k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 508 | PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。 | wgpsec/ | 1.8k | — | ~767 | Automated safety check: Notes | No licence | 4 days ago |
| 509 | Design a real harness for an agentic system using Claude Code-inspired patterns. | hashgraph-online/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 510 | 510.Graymatter Install and use GrayMatter as an OpenClaw skill that provides primary durable memory, shared object-graph state, and authenticated access to the live api-docs schema via api-0. | hashgraph-online/ | 1.2k | — | ~8.6k | Automated safety check: Pass | AGPL-3.0 | today |
| 511 | 511.Review Security Review application and infrastructure changes for exploitable security risks by tracing assets, trust boundaries, attacker-controlled input, authorization, sensitive data, and dangerous sinks. | hashgraph-online/ | 1.2k | — | ~601 | Automated safety check: Pass | Apache-2.0 | today |
| 512 | 512.Idor Testing Insecure direct object reference testing for broken access control | NeoTheCapt/ | 142 | — | ~793 | Automated safety check: Pass | No licence | 2 mo ago |
| 513 | Sub-skill: Implement Auth.md for agent registration discovery. | majiayu000/ | 666 | 1 repo | ~697 | Automated safety check: Pass | MIT | today |
| 514 | 当出现注册/登录/找回密码/验证码/绑定手机/实名认证/OAuth/SSO/2FA/JWT等认证功能,前后端分离应用出现路由守卫/前端鉴权绕过,或发现ID可替换、角色参数可控、租户ID可控、接口存在越权迹象时调用。负责认证绕过、前端鉴权绕过、会话安全、验证码安全、水平/垂直越权、多租户隔离、密码重置、加密与随机性弱点分析。 | zhaji2333/ | 113 | — | ~1.3k | Automated safety check: Pass | MIT | 23 days ago |
| 515 | Build secure, reusable data access patterns with DTOs, taint checks, and colocated authorization in Next.js. | HoangNguyen0403/ | 571 | — | ~575 | Automated safety check: Pass | MIT | today |
| 516 | 516.Uipath Admin UiPath Admin via uip admin — Identity Server (users, groups, robot accounts, external OAuth2 apps, secrets, PATs, SMTP), Authorization (custom roles, role assignments, permission catalog… | UiPath/ | 167 | — | ~6.9k | Automated safety check: Notes | MIT | today |
| 517 | Guidance for Microsoft Entra Conditional Access (CA) and multifactor authentication — the Zero Trust policy engine that enforces grant/block decisions based on user, device, location, app, and risk… | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 518 | Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation… | vinayaklatthe/ | 175 | — | ~2.3k | Automated safety check: Pass | MIT | 3 mo ago |
| 519 | 519.Defender Xdr Guidance for Microsoft Defender XDR — the unified extended detection and response suite that correlates signals across endpoints, identities, email, and cloud apps into prioritised incidents with… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 520 | Guidance for Microsoft Entra Permissions Management (CIEM) — discovers, right-sizes, and monitors permissions across Microsoft Azure, AWS, and Google Cloud. | vinayaklatthe/ | 175 | — | ~1.7k | Automated safety check: Pass | MIT | 3 mo ago |
| 521 | Guidance for the Microsoft unified security operations platform that brings Microsoft Sentinel, Microsoft Defender XDR, Security Copilot, Threat Intelligence, and Microsoft Security Exposure… | vinayaklatthe/ | 175 | — | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 522 | Manages privacy compliance for employee background checks including criminal record processing under Art. | mukul975/ | 295 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 523 | Governs biometric data processing for employee timekeeping and access control under Art. | mukul975/ | 295 | — | ~4k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 524 | Implements HIPAA Security Rule technical safeguards under 45 CFR §164.312 for electronic protected health information. | mukul975/ | 295 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 525 | GDPR Article 28(2) sub-processor approval workflow management. | mukul975/ | 295 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 526 | 526.API Organization Explains the standardized API organization pattern for this codebase. | aiskillstore/ | 430 | — | ~3k | Automated safety check: Pass | No licence | today |
| 527 | 527.Auth Authentication and access control skill for Next.js 15 + Supabase applications. | aiskillstore/ | 430 | — | ~1.6k | Automated safety check: Pass | No licence | today |
| 528 | A skill your agent uses when working with Next.js App Router tasks - creating pages in /app/, setting up dynamic routes ([id]/page.tsx), implementing nested layouts/templates (layout.tsx)… | aiskillstore/ | 430 | — | ~2.5k | Automated safety check: Pass | No licence | today |
Explore related skills
Category
More topics in Backend & APIs
- Backend development927
- REST APIs801
- Webhooks689
- Authentication649
- OAuth and OpenID Connect493
- OpenAPI specifications450
- Third-party API integration409
- Smart contracts390
- GraphQL389
- Rate limiting379
- Caching349
- Event-driven systems312
- Microservices303
- File uploads and storage292
- API design283
- Realtime and WebSockets281
- Serverless257
- Transactional email160
- Background jobs158
- gRPC and Protobuf144
- Search implementation140
- Multi-tenancy120
- Payments and billing56