Skip to content
Back to skills

Auth Guard

ASecurity

Standardize API credential handling and startup auth checks to prevent \"missing key\" regressions across sessions. Use when an agent repeatedly loses auth state, gets intermittent 401/403 errors after restarts, relies on ad-hoc curl calls, or needs a reusable auth-first pattern for HEARTBEAT.md/AGENTS.md and helper scripts.

  • 33 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 5, 2026
toolspythonrustbashgitapi

Works with

  • api

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add dvcrn/openclaw-skills-marketplace --skill auth-guard --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Auth Guard?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Auth Guard
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dvcrn-auth-guard/badge)](https://www.skillsdirectory.com/skills/dvcrn-auth-guard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: auth-guard
description: "Standardize API credential handling and startup auth checks to prevent \"missing key\" regressions across sessions. Use when an agent repeatedly loses auth state, gets intermittent 401/403 errors after restarts, relies on ad-hoc curl calls, or needs a reusable auth-first pattern for HEARTBEAT.md/AGENTS.md and helper scripts."
---

# Auth Guard

Enforce a deterministic auth path: one credential source, one helper command path, one startup check, one fallback policy.

## Quick Workflow

1. Identify the target service endpoint and current failing flow.
2. Define canonical credential source (env var first, credentials file second).
3. Create/update a helper script in workspace (`.pi/`) that always injects auth.
4. Add a startup/auth-check command that verifies credentials and endpoint access.
5. Update HEARTBEAT.md or AGENTS.md to require helper usage (ban raw unauthenticated calls).
6. Add explicit fallback behavior for unauthorized states.

## Rules to Apply

- Prefer `ENV_VAR` override, then `~/.config/<service>/credentials.json`.
- Never embed secrets in logs, memory notes, or chat responses.
- Never call protected endpoints via raw curl if a helper exists.
- Keep fallback behavior explicit and low-noise.
- Store helper scripts in `workspace/.pi/` for easy reuse.

## Runtime Requirements

- `bash`
- `curl`
- `python3`

Check once before using this skill:

```bash
command -v bash curl python3 >/dev/null
```

## Safety Limits

- Pass only trusted credential paths under `~/.config/<service>/...` by default.
- Do not point `--cred-file` at arbitrary workspace files or unrelated secret stores.
- Keep probe URLs scoped to the target service auth endpoint.

## Startup Auth Check Pattern

Run at session start (or before heartbeat loops):

```bash
bash skills/auth-guard/scripts/auth_check.sh \
  --service moltbook \
  --url 'https://www.moltbook.com/api/v1/feed?sort=new&limit=1' \
  --env-var MOLTBOOK_API_KEY \
  --cred-file "$HOME/.config/moltbook/credentials.json"
```

Expected outcomes:
- `AUTH_OK` → proceed with normal authenticated helper flow.
- `AUTH_MISSING` or `AUTH_FAIL_*` → use defined fallback path and record one concise note.

## Reusable Snippets

Use drop-in policy snippets from:
- `references/snippets.md` (HEARTBEAT + AGENTS + helper policy blocks)

## References

- `references/contract.md` for the full Keychain Contract pattern
- `references/snippets.md` for ready-to-paste operational snippets
- `references/examples.md` for multi-service usage examples (Moltbook, GitHub, Slack)

Files in this skill

  • SKILL.md2.5 KB
  • references/contract.md1.3 KB
  • references/examples.md1.5 KB
  • references/snippets.md1.3 KB
  • scripts/auth_check.sh2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…