secure-agent-skills
v0.1.0
Published
Agent skills that enforce secure password and OAuth/OIDC handling on any AI coding agent (Claude Code, OpenCode, Cursor, Copilot, and others).
Maintainers
Readme
secure-agent-skills
Agent skills that enforce secure password and OAuth / OIDC handling on any AI coding agent — Claude Code, OpenCode, Cursor, GitHub Copilot, and anything that reads SKILL.md with YAML frontmatter.
These are security-gate skills. Whenever an agent writes or modifies code that touches a user password, a login, a signup, an OAuth flow, or a token, the skill makes it stop and verify the right primitives (Argon2id / bcrypt / scrypt, per-password salts, server-side pepper, PKCE, exact redirect-URI matching, full token validation, token storage) before finishing. Getting it wrong means account takeover and credential breaches; these skills exist so that doesn't ship.
Skills
| Skill | What it enforces |
| --- | --- |
| password-security | Hashing (Argon2id / bcrypt / scrypt), per-password random salt, server-side pepper from a secret manager, constant-time verify, no plaintext/fast-hash storage, NIST 800-63B policy, rate limiting, safe reset/change-password flows, breach checking, frontend rules (HTTPS, autocomplete, no persistence). |
| oauth-security | Authorization Code + PKCE (no Implicit / ROPC), no client secret in the browser, exact-match redirect URIs, mandatory state + nonce, full ID/Access token validation (iss/aud/exp/signature), rotating refresh tokens with reuse detection, safe token storage (BFF / in-memory / keychain), RP-initiated logout. |
Each skill ships with hard rules, a build sequence, an anti-patterns list (automatic rejections), per-stack library picks, and a 12-point verification checklist the agent must answer before declaring the task done.
Install (one command — no clone needed)
npx secure-agent-skills # auto-detects your agent and installs both skillsPick an agent or destination explicitly:
npx secure-agent-skills --agent claude
npx secure-agent-skills --agent opencode --skill password-security
npx secure-agent-skills --dir ./agent-skills --force
npx secure-agent-skills --list
npx secure-agent-skills --dry-run
npx secure-agent-skills --help| --agent | Target directory |
| --- | --- |
| claude | ~/.claude/skills/<skill>/SKILL.md (project: ./.claude/skills/) |
| opencode | ~/.config/opencode/skill/<skill>/SKILL.md (project: ./.opencode/skill/) |
| cursor | ~/.cursor/skills/<skill>/SKILL.md (copied as reference rule) |
| copilot | ./.github/copilot-instructions.d/<skill>/SKILL.md |
| generic | ./agent-skills/<skill>/SKILL.md |
Requires Node 18+. The installer is dependency-free and cross-platform.
Install manually (no Node)
Each skill is a single self-contained folder. Copy it into your agent's skills directory:
# Claude Code / OpenCode global
git clone https://github.com/lucas/secure-agent-skills.git
cp -r secure-agent-skills/password-security ~/.claude/skills/
cp -r secure-agent-skills/oauth-security ~/.claude/skills/Or add it as a git submodule so you get updates:
git submodule add https://github.com/lucas/secure-agent-skills.git .secure-agent-skills
# then symlink/copy the skill folders into your agent's skills dirWhy it's compatible with any agentic AI system
- Standard format. Every skill is an
SKILL.mdfile with YAML frontmatter (name,description). This is the de-facto Agent Skills format, recognized by Claude Code, OpenCode, and the broader Agent Skills spec. - Self-contained. No external resources, no network calls at runtime, no runtime dependencies. A skill is plain prose instructions the model reads when its
descriptionmatches the task. - Provider-neutral content. Recommendations are stack/IdP based (Node, Python, Go, PHP, Auth0, Clerk, Cognito, Keycloak…), not tied to one vendor, framework, or model.
- Installable everywhere.
npx,npm i -g, manual copy, or git submodule — pick what fits your setup.
If your agent doesn't natively load SKILL.md, paste the body of the skill into its rules file (e.g. .cursor/rules/, .github/copilot-instructions.md, .windsurfrules, CLAUDE.md, AGENTS.md). The content works the same.
Suggested repo name
secure-agent-skills (matches the npm package and this folder). Good alternatives if taken:
auth-agent-skills— narrower, clearly auth-focusedsecurity-agent-skillssecure-skills— shortagentsec-skills— distinctive, easy to grep
Publishing
npm version patch
npm publishThe files field in package.json ships only the skill folders + the installer + docs.
License
MIT — see LICENSE. Use it, fork it, embed it in your org's agent setup.
