Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Getnote Auth

ASecurity

连接和诊断得到大脑 MCP 授权,并查看开放平台调用额度。用户说“连接/登录得到大脑”“为什么不能用”“查看额度或限额”时使用。

45 stars
0 votes
0 copies
0 views
Added 9/23/2026
securityapi

Works with

apimcp

Security Analysis

A100/100

Scanned 9/23/2026

$npx -y skills add ahang1598/doubao-workbuddy-qwenwork-skills --skill getnote-auth --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Getnote Auth?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Getnote Auth
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ahang1598-getnote-auth/badge)](https://www.skillsdirectory.com/skills/ahang1598-getnote-auth)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: getnote-auth
description: 连接和诊断得到大脑 MCP 授权,并查看开放平台调用额度。用户说“连接/登录得到大脑”“为什么不能用”“查看额度或限额”时使用。
---

# 得到大脑连接与额度

WorkBuddy 通过连接器内置的 OAuth 2.1 + PKCE 流程管理登录态,不要求用户提供 API Key、Cookie、Authorization 或其他凭证。

## 连接与恢复

- 首次调用需要授权时,引导用户在 WorkBuddy 的连接器界面点击“连接”,然后只在浏览器授权页确认。
- 浏览器授权完成后,继续原请求;不要索要、展示或记录授权码、access token、refresh token、state 或 PKCE verifier。
- 工具返回 `missing_token`、`invalid token`、`token is inactive` 或其他明确认证错误时,说明授权已失效,引导用户重新连接;不要反复重试原请求。
- 网络错误或 `dependency_failure` 不等同于授权失效。仅在结果标记可重试时稍后重试一次,并保留返回的 `request_id`。
- WorkBuddy 自动刷新 access token;不要自行实现 Token 存储、续期或交换。

## 查询额度

用户询问 API/MCP 限额,或工具返回限流错误时调用 `get_quota`。分别展示返回的 `read`、`write`、`write_note` 桶及其日/月 `limit`、`used`、`remaining`、`reset_at`;不要合并或自行换算不同额度桶。

所有 MCP 调用与其他开放平台调用共享服务端日/月额度。空列表是成功结果,不是额度耗尽;只根据明确限流错误或 `get_quota` 返回值判断。

Attribution

ahang1598ahang1598
View sourceSee grades on GitHubMore from ahang1598 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →