Skip to content
Back to skills

Auth Expert

ASecurity

Authentication and authorization expert specializing in JWT, OAuth 2.0, session management, RBAC, password security. Use for auth implementation, token management, or security issues.

  • 207 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added February 7, 2026
developmenttypescriptbashnodeapidatabasedevopssecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 9 files and shows the line behind each finding

Scanned February 12, 2026

npx -y skills add NeverSight/skills_feed --skill auth-expert --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Auth Expert?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Auth Expert
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/neversight-auth-expert/badge)](https://www.skillsdirectory.com/skills/neversight-auth-expert)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: auth-expert
description: Authentication and authorization expert specializing in JWT, OAuth 2.0, session management, RBAC, password security. Use for auth implementation, token management, or security issues.
---

# Authentication & Authorization Expert

Expert in JWT, OAuth 2.0, sessions, RBAC, and security best practices.

## When Invoked

### Recommend Specialist and Stop
- **API design patterns**: recommend rest-api-expert
- **Database security**: recommend database-expert  
- **Infrastructure security**: recommend devops-expert

### Environment Detection
```bash
grep -E "passport|jsonwebtoken|next-auth|bcrypt" package.json 2>/dev/null
find . -type f -name "*auth*" -not -path "./node_modules/*" | head -5
```

## Problem Playbooks

### JWT Implementation

**Secure JWT Pattern:**
```typescript
import jwt from 'jsonwebtoken';

const ACCESS_TOKEN_SECRET = process.env.ACCESS_TOKEN_SECRET!;
const ACCESS_TOKEN_EXPIRY = '15m';

function generateTokens(payload: TokenPayload) {
  const accessToken = jwt.sign(payload, ACCESS_TOKEN_SECRET, {
    expiresIn: ACCESS_TOKEN_EXPIRY,
  });
  return { accessToken };
}

function authenticateToken(req: Request, res: Response, next: NextFunction) {
  const token = req.cookies.accessToken || 
    req.headers.authorization?.replace('Bearer ', '');

  if (!token) return res.status(401).json({ error: 'Auth required' });

  try {
    req.user = jwt.verify(token, ACCESS_TOKEN_SECRET);
    next();
  } catch {
    return res.status(401).json({ error: 'Invalid token' });
  }
}
```

### Password Security

```typescript
import bcrypt from 'bcrypt';

const SALT_ROUNDS = 12;

async function hashPassword(password: string): Promise<string> {
  return bcrypt.hash(password, SALT_ROUNDS);
}

async function verifyPassword(plain: string, hashed: string): Promise<boolean> {
  return bcrypt.compare(plain, hashed);
}
```

### RBAC Pattern

```typescript
const ROLES = {
  user: ['read:posts'],
  admin: ['read:posts', 'write:posts', 'delete:posts'],
};

function requirePermission(permission: string) {
  return (req: Request, res: Response, next: NextFunction) => {
    const userRole = req.user?.role;
    if (!ROLES[userRole]?.includes(permission)) {
      return res.status(403).json({ error: 'Forbidden' });
    }
    next();
  };
}
```

## Code Review Checklist

- [ ] Passwords hashed with bcrypt (cost ≥ 12)
- [ ] JWT secrets are strong (256-bit)
- [ ] Cookies are httpOnly, secure, sameSite
- [ ] Rate limiting on login
- [ ] All routes have auth middleware
- [ ] Resource-level authorization

## Anti-Patterns

1. **Storing JWT in localStorage** - Use httpOnly cookies
2. **Weak passwords** - Enforce complexity
3. **No rate limiting** - Prevent brute force
4. **Client-side auth only** - Always validate on server

Files in this skill

  • SKILL.md2.7 KB
  • description_cn.txt153 B
  • description_de.txt224 B
  • description_en.txt184 B
  • description_es.txt229 B
  • description_fr.txt244 B
  • description_ja.txt234 B
  • description_ko.txt195 B
  • description_tw.txt153 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…