Home / nahid-sparktales / agent-dispatcher · skills/security/auth-security/SKILL.md · GitHub

auth-security skillA

auth-security is agent-read markdown (skill) from nahid-sparktales/agent-dispatcher: Attack and harden an existing auth surface — session fixation and rotation, token verification, horizontal and vertical privilege escalation, password reset and account recovery, MFA bypass. Use when reviewing login, session, token, reset, invite, impersonation or role-elevation code, when someone reports seeing another user's data or an account takeover, or when auth changes are about to ship. Not for designing the login mechanism or permission model in the first place (authentication, authoriz.

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Auth security

Auth code is reviewed by the person who wrote it and trusted by everyone else. This procedure
looks for the specific ways it fails: identity taken from the wrong place, a session that outlives
the reason it was issued, and a recovery flow that is a second, weaker login nobody audited.

## When this fires

A credential-handling path is being reviewed, changed, or doubted — login, logout, refresh,
session storage, tokens, reset, invite, impersonation, role change, MFA. Also fires on a report of
one account reaching another's data. It does not fire when the mechanism is still being designed,
or when the question is what a caller may do rather than whether the system knows who they are.

## Procedure

1. **Confirm what you are allowed to touch, before touching it.** Name the environment and get it
   agreed. Reading code needs no permission; sending crafted requests does. Testing against
   production, another tenant, or anyone's real account stops and asks — every time, including
   when the fix looks obvious.
2. **Map the surface.** Enumerate every route that issues, accepts, refreshes or revokes a
…

Read the whole file at its exact version.

How to install

Latest version
mdr add nahid-sparktales/agent-dispatcher/auth-security@git:20260919.a0d4f55
Exact content
mdr add nahid-sparktales/agent-dispatcher/auth-security@sha256:107f4b07a56d6a11

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_dbluzmuuvcgc22jq.svg)](https://markdownregistry.com/a/art_dbluzmuuvcgc22jq)

0 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260919.a0d4f55 latest2026-09-19 a0d4f55 7,656 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (7656 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

nahid-sparktales/agent-dispatcher · 49 stars · license MIT · pushed 2026-09-23 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_dbluzmuuvcgc22jq
GET https://markdownregistry.com/api/v1/resolve?ref=nahid-sparktales/agent-dispatcher/auth-security
GET https://markdownregistry.com/api/v1/blob/107f4b07a56d6a11179d03713c44f9c3afaf758a03c05ffc369d1e93e848feeb

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from nahid-sparktales/agent-dispatcher

agent-dispatcher skill
nahid-sparktales/agent-dispatcher · skills/agent-dispatcher/SKILL.md · Route work to a specialist role and load its task-specific guidance. Use when the user invokes /agent-dispatcher, names…
git:20260920.c183eff · audit A · 49 stars
agent-design skill
nahid-sparktales/agent-dispatcher · skills/ai/agent-design/SKILL.md · Scope an agent or subagent before it is built — the one job it owns, the smallest tool set that closes that job, what…
git:20260919.a0d4f55 · audit A · 49 stars
agent-evals skill
nahid-sparktales/agent-dispatcher · skills/ai/agent-evals/SKILL.md · Build an eval suite that can actually detect a regression — cases pulled from real traffic, graders that check…
git:20260919.a0d4f55 · audit A · 49 stars
context-engineering skill
nahid-sparktales/agent-dispatcher · skills/ai/context-engineering/SKILL.md · Decide what actually occupies the model's window — progressive disclosure through an index, retrieval versus inlining…
git:20260919.a0d4f55 · audit A · 49 stars
llm-observability skill
nahid-sparktales/agent-dispatcher · skills/ai/llm-observability/SKILL.md · See what an agent actually did — one trace per run with nested model, tool and retrieval spans, token and latency…
git:20260919.a0d4f55 · audit A · 49 stars
mcp-design skill
nahid-sparktales/agent-dispatcher · skills/ai/mcp-design/SKILL.md · Build an MCP server, or bring an existing one into a project — choosing the transport, deciding which tools, resources…
git:20260919.a0d4f55 · audit A · 49 stars
memory-design skill
nahid-sparktales/agent-dispatcher · skills/ai/memory-design/SKILL.md · Decide what an agent should remember, which layer holds it, who it is scoped to, and how a stale or contradicted memory…
git:20260919.a0d4f55 · audit A · 49 stars
model-routing skill
nahid-sparktales/agent-dispatcher · skills/ai/model-routing/SKILL.md · Pick a model per job and degrade sensibly when one fails — a quality bar per call site, candidates compared on the same…
git:20260919.a0d4f55 · audit A · 49 stars
prompt-engineering skill
nahid-sparktales/agent-dispatcher · skills/ai/prompt-engineering/SKILL.md · Write or revise a prompt so it holds up — output contract, instruction placement, examples that earn their place, an…
git:20260919.a0d4f55 · audit A · 49 stars
prompt-injection-defense skill
nahid-sparktales/agent-dispatcher · skills/ai/prompt-injection-defense/SKILL.md · Treat everything an agent reads but did not author as data rather than instructions — an explicit trust boundary, a…
git:20260919.a0d4f55 · audit A · 49 stars
retrieval-rag skill
nahid-sparktales/agent-dispatcher · skills/ai/retrieval-rag/SKILL.md · Build and fix retrieval that actually returns the right passage — structure-aware chunking, one pinned embedding model…
git:20260919.a0d4f55 · audit A · 49 stars
structured-output skill
nahid-sparktales/agent-dispatcher · skills/ai/structured-output/SKILL.md · Get parseable, trustworthy structured results out of a model — schema design, the enforcement mechanism the provider…
git:20260919.a0d4f55 · audit A · 49 stars

Every file in nahid-sparktales/agent-dispatcher

Other files named auth-security

auth-security skill
majiayu000/spellbook · skills/auth-security/SKILL.md · OAuth 2.1 + JWT authentication security best practices. Use when implementing auth, API authorization, token…
git:20260605.a09e45c · audit A · 285 stars

Browse by kind, by grade A, or by owner.