skill-creator
78Create Better Claude Skills
Skill authors need a repeatable process for turning workflows into useful AI skills. This skill provides clear steps for examples, resource planning, metadata, packaging, and iteration.
Build Secure Supabase Authentication
Authentication mistakes can expose accounts and tenant data. This skill provides Next.js 15 and Supabase patterns for sessions, route protection, roles, and family isolation.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "auth" from https://skillstore.io/skills/bom-98-auth.md and its manifest at https://skillstore.io/api/skills/bom-98-auth/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "auth". Protect the dashboard and every child route.
Expected outcome:
Using "auth". Review a family settings update for tenant isolation.
Expected outcome:
Using "auth". Assess the registration flow before production release.
Expected outcome:
The flow needs sensitive-data redesign. Remove SSNs and similar personal data from auth metadata, minimize collection, and use protected storage.
All 62 static findings are false positives caused by Markdown formatting, documentation examples, placeholder URLs, and auth schema descriptions. No command execution, reconnaissance, environment-file reading, or live network request exists in the reviewed skill files. One high-severity semantic issue remains: the registration design stores SSNs and other sensitive personal data in Supabase user metadata.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/bom-98-auth/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/bom-98-auth?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/bom-98-auth?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/bom-98-auth/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/bom-98-auth.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>BOM-98. (2026). auth security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/bom-98-auth/audits/9@techreport{bom-98-bom-98-auth-2026,
author = {BOM-98},
title = {auth security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/bom-98-auth/audits/9},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "auth security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "BOM-98"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/bom-98-auth/audits/9"
identifiers:
- type: other
value: "skillstore:bom-98-auth:audit:9"
description: "Skillstore immutable audit report identifier"
Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
chachamaru127-auth
2026-09-09
azeem-2-auth
2026-09-09
bom-98-auth
2026-09-09
Add server-side authentication checks to pages, layouts, and Server Actions using the documented helper patterns.
Check admin controls, tenant membership validation, token verification, and protected data paths.
Structure household membership, user roles, and data access around Supabase authentication and row-level security.
Protect the [page path] Server Component. Use the documented authentication helper and redirect unauthenticated users to [login path].
Review the [action name] Server Action. Add server-side user validation, preserve expected errors, and explain each authorization boundary.
Implement [feature] for admins in the current family. Enforce authentication, active status, role, and family membership before database access.
Audit the complete authentication flow for [application]. Trace registration, OAuth, cookies, token refresh, roles, tenant isolation, and sensitive data handling.
Author
BOM-98License
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Ref
a39a91716eadede5f4cdefd78178fed4e837a128
Maintenance freshness
7/24/2026
Usage
4 downloads ยท 384 views
File structure
Create Better Claude Skills
Skill authors need a repeatable process for turning workflows into useful AI skills. This skill provides clear steps for examples, resource planning, metadata, packaging, and iteration.
Build Modern React and Next.js Frontends
Modern frontend projects need consistent architecture, data fetching, state, styling, and loading patterns. This skill provides practical React, Next.js, TypeScript, MUI, shadcn/ui, Supabase, and TanStack Query guidance.
Organize Type-Safe API Layers
Scattered endpoint definitions create duplicated URLs, inconsistent authentication, and weak type contracts. This skill applies a five-file TypeScript pattern with centralized endpoints and Supabase-aware clients.
Implement Clerk Authentication Safely
by sickn33
Clerk setup can be error-prone across middleware, server components, organizations, and webhooks. This skill provides focused implementation guidance for secure Next.js authentication flows.
Build CloudBase Node Auth Flows
by tencentcloudbase
Server-side CloudBase auth work can mix caller identity, user lookup, and custom login details. This skill guides Node.js agents through correct SDK methods and secure backend patterns.
Strengthen Security Engineering Decisions
by 89jobrien
Security work often spans architecture, identity, compliance, testing, and response planning. This skill gives Claude, Codex, and Claude Code structured security engineering guidance.
Set Up Convex Authentication
by get-convex
Convex auth setup can fail when provider wiring, environment variables, and backend checks do not match. This skill guides the correct provider flow and adds verified Convex authentication patterns.
Design Production-Ready APIs
by AutumnsGrove
Inconsistent API contracts create integration errors and costly migrations. This skill guides REST, GraphQL, OpenAPI, authentication, versioning, validation, and documentation decisions.
Build Fullstack Apps With Senior Guidance
by alirezarezvani
Fullstack projects often need consistent setup, architecture choices, and quality checks. This skill provides scripts and references for React, Next.js, Node.js, GraphQL, and PostgreSQL work.