Skip to content
Back to skills

Authentication Security

ASecurity

Use with analysis-agent, task-agent, or review-agent for task-local authentication lifecycle and recovery risk. Do not use without that decision or as task owner.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 8, 2026
securitysecurity

Works with

  • cli

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 22, 2026

npx -y skills add machenjie/rd-skills --skill authentication-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Authentication Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Authentication Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/machenjie-authentication-security/badge)](https://www.skillsdirectory.com/skills/machenjie-authentication-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: authentication-security
description: "Use with analysis-agent, task-agent, or review-agent for task-local authentication lifecycle and recovery risk. Do not use without that decision or as task owner."
---

# authentication-security

## Registry Trigger

**Use when**

- secure authentication sessions tokens passwords MFA and account recovery

**Do not use when**

- no task-local authentication security decision is required

## Skill Role

Own authentication lifecycle, recovery, linking, federation, and compromise.

## High-Value Rules

- Select controls from threat/provider/client/policy evidence.
- Define lifecycle, recovery/linking/federation, and compromise outcomes.
- Select one active named Reference.

## Anti-Patterns

- Local success is insufficient.

## Stop Conditions

- Stop on unclear controls, exceptions, or takeover risk.

## Output Contract

- authentication security review with controls failure cases and audits

## Targeted References

| Path | Type | Load when | Do not load when | Required by | Required output |
|---|---|---|---|---|---|
| [benchmarks and patterns](references/benchmarks-and-patterns.md) | benchmark-pattern | Credential, session, federation, or recovery controls require mechanism selection | No authentication lifecycle or assurance boundary changes | analysis-agent, task-agent, review-agent | option-comparison, selected-approach |
| [checklist](references/checklist.md) | decision-checklist | Affected flows include compromise, revocation, linking, or step-up denial | The change cannot issue, renew, recover, or revoke identity | analysis-agent, task-agent, review-agent | checklist-result, residual-risk |
| [evidence patterns](references/evidence-patterns.md) | evidence-pattern | Authentication claims need fresh replay, fixation, or redaction proof | No lifecycle control claim awaits validation | analysis-agent, task-agent, review-agent | evidence-record, proof-limit, residual-risk |

Files in this skill

  • SKILL.md3.5 KB
  • examples/example-output.md573 B
  • references/benchmarks-and-patterns.md3.3 KB
  • references/checklist.md1.6 KB
  • references/evidence-patterns.md5.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…