extension-oql
82Expose Canister Data Through OQL
Structured canister data is difficult for intelligence agents to query safely. This skill adds OQL entities, schema discovery, query execution, relationships, and per-entity authorization.
Add User Approval to Caffeine AI Apps
Applications need a controlled process for granting access to protected features. This skill guides backend approval checks, admin decisions, and frontend approval workflows.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "extension-user-approval" from https://skillstore.io/skills/caffeinelabs-extension-user-approval.md and its manifest at https://skillstore.io/api/skills/caffeinelabs-extension-user-approval/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "extension-user-approval". Plan approval support for a new Caffeine AI application.
Expected outcome:
The plan installs the authorization prerequisite, initializes approval state, adds required endpoints, protects features, and builds user and administrator views.
Using "extension-user-approval". Review which backend actions need administrator protection.
Expected outcome:
Approval decisions and approval-list access require administrator permission. Approval requests remain available to signed-in users, while protected features require approval.
Using "extension-user-approval". Describe the frontend states for an unapproved user.
Expected outcome:
The interface checks current status, offers an approval request when appropriate, shows the latest state, and blocks protected features until approval.
All 13 static findings are false positives caused by Markdown code fences, inline code, a documentation URL, and a relative documentation link. The skill contains no shell execution, runtime network request, path traversal operation, prompt injection, or other semantic security issue.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/caffeinelabs-extension-user-approval/audits/3?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/caffeinelabs-extension-user-approval?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/caffeinelabs-extension-user-approval?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/caffeinelabs-extension-user-approval/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/caffeinelabs-extension-user-approval.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>caffeinelabs. (2026). extension-user-approval security audit report (audit version 3) [Author version 0.1.5]. Skillstore. https://skillstore.io/skills/caffeinelabs-extension-user-approval/audits/3@techreport{caffeinelabs-caffeinelabs-extension-user-approval-2026,
author = {caffeinelabs},
title = {extension-user-approval security audit report (audit version 3)},
institution = {Skillstore},
year = {2026},
number = {3},
url = {https://skillstore.io/skills/caffeinelabs-extension-user-approval/audits/3},
note = {Author version 0.1.5}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "extension-user-approval security audit report (audit version 3)"
version: "0.1.5"
type: report
authors:
- name: "caffeinelabs"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/caffeinelabs-extension-user-approval/audits/3"
identifiers:
- type: other
value: "skillstore:caffeinelabs-extension-user-approval:audit:3"
description: "Skillstore immutable audit report identifier"
Add approval requests and protected feature access to a new Caffeine AI application.
Apply administrator and approval checks to public Motoko functions.
Design user status screens and an administrator dashboard for reviewing access requests.
Add the user approval extension to my Caffeine AI application. Identify prerequisites and outline the backend and frontend changes.
Integrate approval state into my Motoko actor. Add the required endpoints and protect administrator operations with authorization checks.
Create a frontend approval flow for pending, approved, and rejected users. Include request access and administrator review states.
Review my complete Caffeine AI approval integration. Check every public function, administrator action, frontend state, and role interaction for authorization gaps.
Author
caffeinelabsLicense
MIT
Author version
v0.1.5
Skillstore revision
r2
Ref
a39a91716eadede5f4cdefd78178fed4e837a128
Maintenance freshness
7/24/2026
Usage
1 downloads · 0 views
File structure
📄 SKILL.md
Expose Canister Data Through OQL
Structured canister data is difficult for intelligence agents to query safely. This skill adds OQL entities, schema discovery, query execution, relationships, and per-entity authorization.
Build TMDb Movie and TV Features
Movie and TV integrations often fail because generated clients hide authentication, response shapes, and unsupported operations. This skill gives Caffeine developers a tested implementation path for catalog reads, credential handling, and service limits.
Troubleshoot Motoko Migration Failures
Motoko migration errors can conflict with current source code and put deployed state at risk. This reference explains diagnostics and forward-only repairs while preserving migration history.
Query OQL Canisters with the ICP CLI
Writing OQL queries requires exact schema names, JSON types, Candid escaping, and careful pagination. This skill provides practical patterns for reliable, read-only canister queries.
Add Object Storage to Caffeine AI Apps
Large files need storage beyond Internet Computer canister limits. This skill guides Caffeine AI projects through backend integration, browser uploads, cached display, downloads, and troubleshooting.
Add Camera Capture to React Apps
Web camera integration requires permission handling, preview state, and device controls. This skill guides Claude, Codex, and Claude Code through the provided React hook.
Set Up Convex Authentication
by get-convex
Convex auth setup can fail when provider wiring, environment variables, and backend checks do not match. This skill guides the correct provider flow and adds verified Convex authentication patterns.
Build Secure Payload CMS Applications
by payloadcms
Payload CMS projects combine complex schemas, hooks, queries, and access rules. This skill provides focused TypeScript patterns for building and troubleshooting them.
Manage Lark Wiki Spaces and Content
by larksuite
Managing Lark Wiki structures and access through raw API calls is slow and error-prone. This skill guides authenticated listing, creation, movement, copying, deletion, and member administration.
Harden AWS IAM Access with Least Privilege
by sickn33
Overly broad IAM access increases cloud security risk and complicates audits. This skill provides focused checks, policy guidance, and hardening steps for AWS identities.
Audit Firestore Security Rules
by firebase
Firestore rules often miss update bypasses, ownership checks, and validation gaps. This skill guides Claude, Codex, or Claude Code through a focused security review.
Review Cultural Data Practices
by Acurioustractor
Sensitive stories can be mishandled when consent, access, and ownership rules are unclear. This skill guides reviews using OCAP, sensitivity levels, and approval workflows.