auth-nodejs-cloudbase
82Build CloudBase Node Auth Flows
Server-side CloudBase auth work can mix caller identity, user lookup, and custom login details. This skill guides Node.js agents through correct SDK methods and secure backend patterns.
Configure CloudBase Auth Providers
Authentication projects fail when providers, login methods, and publishable keys are not ready. This skill guides Claude, Codex, and Claude Code through CloudBase auth readiness before implementation starts.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "auth-tool-cloudbase" from https://skillstore.io/skills/tencentcloudbase-auth-tool-cloudbase.md and its manifest at https://skillstore.io/api/skills/tencentcloudbase-auth-tool-cloudbase/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "auth-tool-cloudbase". I need email and password login for a CloudBase Web app.
Expected outcome:
The skill would report whether email login is enabled, whether the email provider needs sender configuration, and whether the publishable key is ready before UI work starts.
Using "auth-tool-cloudbase". I want to add Google login to an existing CloudBase app.
Expected outcome:
The skill would identify the static domain for the redirect URL, list the required Google credentials, and recommend confirming provider changes before updating CloudBase.
Using "auth-tool-cloudbase". My app cannot find a publishable key.
Expected outcome:
The skill would guide a lookup for the existing publishable key, explain when creation is appropriate, and warn before creating or deleting API keys.
Most static findings are false positives caused by Markdown backticks, relative documentation links, and documented OAuth or console URLs. The confirmed risks are the skill's legitimate ability to guide email sender setup, API key lifecycle operations, and privileged auth provider changes that require explicit user approval.
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/tencentcloudbase-auth-tool-cloudbase/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/tencentcloudbase-auth-tool-cloudbase?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/tencentcloudbase-auth-tool-cloudbase?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/tencentcloudbase-auth-tool-cloudbase/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/tencentcloudbase-auth-tool-cloudbase.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>tencentcloudbase. (2026). auth-tool-cloudbase security audit report (audit version 2) [Author version 2.23.8]. Skillstore. https://skillstore.io/skills/tencentcloudbase-auth-tool-cloudbase/audits/2@techreport{tencentcloudbase-tencentcloudbase-auth-tool-cloudbase-2026,
author = {tencentcloudbase},
title = {auth-tool-cloudbase security audit report (audit version 2)},
institution = {Skillstore},
year = {2026},
number = {2},
url = {https://skillstore.io/skills/tencentcloudbase-auth-tool-cloudbase/audits/2},
note = {Author version 2.23.8}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "auth-tool-cloudbase security audit report (audit version 2)"
version: "2.23.8"
type: report
authors:
- name: "tencentcloudbase"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/tencentcloudbase-auth-tool-cloudbase/audits/2"
identifiers:
- type: other
value: "skillstore:tencentcloudbase-auth-tool-cloudbase:audit:2"
description: "Skillstore immutable audit report identifier"
Confirm enabled login methods and publishable key availability before building a CloudBase Web auth flow.
Review SMS, email, WeChat, Google, and anonymous provider settings before allowing client authentication.
Check whether a task should modify provider settings, client settings, API keys, or implementation code.
Use this skill to check the current CloudBase login configuration for my selected environment. Tell me which login methods are enabled and what must be configured before implementation.
Use this skill to guide CloudBase email login setup. Confirm the login method, explain the email provider configuration, and ask before making changes.
Use this skill to prepare Google or WeChat login for CloudBase. Identify the redirect URL, required provider credentials, and the safe update sequence.
Use this skill to review my CloudBase auth plan across Web, mini program, Node, and HTTP clients. Separate provider setup tasks from implementation tasks and flag risky changes.
Author
tencentcloudbaseLicense
MIT
Author version
v2.23.8
Skillstore revision
r1
Ref
24b2fe42a456262f3fd0fb3df72e12d9ed2c32ec
Maintenance freshness
7/18/2026
Usage
0 downloads ยท 0 views
File structure
๐ checklist.md
๐ SKILL.md
Build CloudBase Node Auth Flows
Server-side CloudBase auth work can mix caller identity, user lookup, and custom login details. This skill guides Node.js agents through correct SDK methods and secure backend patterns.
Build CloudBase Mini Program Database Features
Mini Program database work requires correct SDK patterns and security rules. This skill guides Claude, Codex, and Claude Code through CloudBase document database tasks.
Build CloudBase AI Backends in Node.js
Backend AI setup often fails when model groups, credits, and SDK methods are guessed. This skill gives CloudBase Node.js patterns, preflight checks, and model enablement steps.
Design Distinctive UI Prototypes
Generic AI interfaces often lack visual direction and platform-aware detail. This skill guides Claude, Codex, and Claude Code to define design intent before building prototypes.
Plan Complex Coding Changes
Large coding changes often fail when scope, design, and acceptance criteria are vague. This skill guides Claude, Codex, and Claude Code through requirements, design, tasks, and staged confirmation.
Add CloudBase AI Models to Web Apps
Browser AI integration can fail when model groups, auth, or Token Credits are not prepared. This skill guides CloudBase preflight, model enabling, and SDK calls for web apps.
Strengthen Security Engineering Decisions
by 89jobrien
Security work often spans architecture, identity, compliance, testing, and response planning. This skill gives Claude, Codex, and Claude Code structured security engineering guidance.
Implement Clerk Authentication Safely
by sickn33
Clerk setup can be error-prone across middleware, server components, organizations, and webhooks. This skill provides focused implementation guidance for secure Next.js authentication flows.
Audit Code for Security Risks
by Barnhardt-Enterprises-Inc
Security-sensitive code is easy to ship with hidden flaws in authentication, input handling, and secrets. This skill gives Claude, Codex, and Claude Code structured security references and scanner guidance for safer reviews.
Protect Next.js Auth Routes
by AayushBaniya2006
Authentication changes often fail when teams mix session APIs and route guards. This skill guides Claude, Codex, and Claude Code toward the project helpers for secure access control.
Build Secure Backend Services
by sickn33
Backend flaws can expose data, accounts, and infrastructure. This skill guides secure implementation and review using established defensive patterns.
Review Web App Security Before Release
by sickn33
Security issues often appear when teams add authentication, APIs, payments, uploads, or sensitive data flows. This skill provides a focused checklist and review prompts for finding common web application risks before deployment.