npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

secure-agent-skills

v0.1.0

Published

Agent skills that enforce secure password and OAuth/OIDC handling on any AI coding agent (Claude Code, OpenCode, Cursor, Copilot, and others).

Readme

secure-agent-skills

Agent skills that enforce secure password and OAuth / OIDC handling on any AI coding agent — Claude Code, OpenCode, Cursor, GitHub Copilot, and anything that reads SKILL.md with YAML frontmatter.

These are security-gate skills. Whenever an agent writes or modifies code that touches a user password, a login, a signup, an OAuth flow, or a token, the skill makes it stop and verify the right primitives (Argon2id / bcrypt / scrypt, per-password salts, server-side pepper, PKCE, exact redirect-URI matching, full token validation, token storage) before finishing. Getting it wrong means account takeover and credential breaches; these skills exist so that doesn't ship.

Skills

| Skill | What it enforces | | --- | --- | | password-security | Hashing (Argon2id / bcrypt / scrypt), per-password random salt, server-side pepper from a secret manager, constant-time verify, no plaintext/fast-hash storage, NIST 800-63B policy, rate limiting, safe reset/change-password flows, breach checking, frontend rules (HTTPS, autocomplete, no persistence). | | oauth-security | Authorization Code + PKCE (no Implicit / ROPC), no client secret in the browser, exact-match redirect URIs, mandatory state + nonce, full ID/Access token validation (iss/aud/exp/signature), rotating refresh tokens with reuse detection, safe token storage (BFF / in-memory / keychain), RP-initiated logout. |

Each skill ships with hard rules, a build sequence, an anti-patterns list (automatic rejections), per-stack library picks, and a 12-point verification checklist the agent must answer before declaring the task done.

Install (one command — no clone needed)

npx secure-agent-skills            # auto-detects your agent and installs both skills

Pick an agent or destination explicitly:

npx secure-agent-skills --agent claude
npx secure-agent-skills --agent opencode --skill password-security
npx secure-agent-skills --dir ./agent-skills --force
npx secure-agent-skills --list
npx secure-agent-skills --dry-run
npx secure-agent-skills --help

| --agent | Target directory | | --- | --- | | claude | ~/.claude/skills/<skill>/SKILL.md (project: ./.claude/skills/) | | opencode | ~/.config/opencode/skill/<skill>/SKILL.md (project: ./.opencode/skill/) | | cursor | ~/.cursor/skills/<skill>/SKILL.md (copied as reference rule) | | copilot | ./.github/copilot-instructions.d/<skill>/SKILL.md | | generic | ./agent-skills/<skill>/SKILL.md |

Requires Node 18+. The installer is dependency-free and cross-platform.

Install manually (no Node)

Each skill is a single self-contained folder. Copy it into your agent's skills directory:

# Claude Code / OpenCode global
git clone https://github.com/lucas/secure-agent-skills.git
cp -r secure-agent-skills/password-security ~/.claude/skills/
cp -r secure-agent-skills/oauth-security   ~/.claude/skills/

Or add it as a git submodule so you get updates:

git submodule add https://github.com/lucas/secure-agent-skills.git .secure-agent-skills
# then symlink/copy the skill folders into your agent's skills dir

Why it's compatible with any agentic AI system

  • Standard format. Every skill is an SKILL.md file with YAML frontmatter (name, description). This is the de-facto Agent Skills format, recognized by Claude Code, OpenCode, and the broader Agent Skills spec.
  • Self-contained. No external resources, no network calls at runtime, no runtime dependencies. A skill is plain prose instructions the model reads when its description matches the task.
  • Provider-neutral content. Recommendations are stack/IdP based (Node, Python, Go, PHP, Auth0, Clerk, Cognito, Keycloak…), not tied to one vendor, framework, or model.
  • Installable everywhere. npx, npm i -g, manual copy, or git submodule — pick what fits your setup.

If your agent doesn't natively load SKILL.md, paste the body of the skill into its rules file (e.g. .cursor/rules/, .github/copilot-instructions.md, .windsurfrules, CLAUDE.md, AGENTS.md). The content works the same.

Suggested repo name

secure-agent-skills (matches the npm package and this folder). Good alternatives if taken:

  • auth-agent-skills — narrower, clearly auth-focused
  • security-agent-skills
  • secure-skills — short
  • agentsec-skills — distinctive, easy to grep

Publishing

npm version patch
npm publish

The files field in package.json ships only the skill folders + the installer + docs.

License

MIT — see LICENSE. Use it, fork it, embed it in your org's agent setup.