medusa-security skillA
medusa-security is agent-read markdown (skill) from orcaqubits/agentic-commerce-skills-plugins: Secure Medusa v2 applications — authentication strategies, API key types (publishable vs secret), CORS configuration, JWT and cookie secrets, admin vs store auth, and session management. Use when configuring security..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Medusa v2 Security ## Before writing code **Fetch live docs**: 1. Web-search `site:docs.medusajs.com authentication` for auth strategies and API key setup 2. Web-search `site:docs.medusajs.com api key publishable secret` for API key types 3. Web-search `site:docs.medusajs.com CORS configuration` for cross-origin resource sharing 4. Fetch `https://docs.medusajs.com/learn/fundamentals/api-routes/middlewares` for middleware and auth config 5. Web-search `site:docs.medusajs.com medusa-config auth providers` for auth provider registration ## Authentication Architecture ### Admin vs Store Authentication Medusa v2 separates admin and storefront authentication into distinct flows: | Aspect | Admin Auth | Store Auth | |--------|-----------|------------| | **Actor type** | `user` | `customer` | | **API scope** | `/admin/*` routes | `/store/*` routes | | **Default provider** | `emailpass` | `emailpass` | | **Session cookie** | Admin session cookie | Store session cookie | | **API key support** | Secret API key (Bearer) | Publishable API key (header) | | **JWT usage** | Admin JWT token | Customer JWT token | …
Read the whole file at its exact version.
How to install
mdr add orcaqubits/agentic-commerce-skills-plugins/medusa-security@git:20260326.769051fmdr add orcaqubits/agentic-commerce-skills-plugins/medusa-security@sha256:d7e5214e2baab44cPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_pb7ole5bljarcrph)
1 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (7067 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
orcaqubits/agentic-commerce-skills-plugins · 39 stars · license MIT · pushed 2026-09-14 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_pb7ole5bljarcrph GET https://markdownregistry.com/api/v1/resolve?ref=orcaqubits/agentic-commerce-skills-plugins/medusa-security GET https://markdownregistry.com/api/v1/blob/d7e5214e2baab44c38c863eff6ddf7110e8a10839cec7bc4ab4064c56e1c1b33
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.