Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Auth Status

CSecurity

Check CLI and ADC logins across providers: expiry, scopes, re-login commands.

10 stars
0 votes
0 copies
0 views
Added 10/4/2026
ai-agentsrustgobashawsgcpgitapidocumentation

Works with

cliapi

Security Analysis

C63/100
criticalAccesses sensitive system or user directories
criticalSends environment variables or credentials to an external URL

Pro shows the line behind each finding and how to fix it

Scanned 10/6/2026

$npx -y skills add fmind/dot --skill auth-status --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Auth Status?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Auth Status
[![Security: C — Skills Directory](https://www.skillsdirectory.com/api/skills/fmind-auth-status/badge)](https://www.skillsdirectory.com/skills/fmind-auth-status)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: auth-status
description: "Check CLI and ADC logins across providers: expiry, scopes, re-login commands."
license: MIT
metadata:
  kind: task
  author: Médéric HURIER (Fmind)
  source: github.com/fmind/dot/tree/main/skills/auth-status
  created: "2026-10-04"
  updated: "2026-10-05"
---

# Auth Status

Answer "am I logged in, until when, and what must I run?" with read-only probes, then hand the user the exact interactive command. `dot doctor --deep` owns the workstation probes; this skill adds the remaining connectors, scope coverage, and recovery. [dot-cli authentication](../dot-cli/references/authentication.md) owns login policy, scopes, and account overrides; each connector skill owns its provider's account selection.

## Workflow

1. **Run the workstation probes**: `dot doctor --deep --json` checks GitHub, the gcloud CLI, ADC, and Workspace with bounded probes and never prints tokens. Read only the auth group; `condition` distinguishes `unauthenticated` from `broken` (state unknown) and flags `insecure` when gh keeps its token in plaintext `hosts.yml`.

   ```bash
   dot doctor --deep --json | jq -c '.checks[] | select(.group == "auth") | {name, status, condition, details}'
   ```

1. **Check scope coverage**: compare granted scopes with the configured policy (`dot config show`, keys `auth.github.scopes`, `auth.workspace.scopes`, and `auth.gcp.adc_scopes`). GitHub lists them in `gh auth status --active --hostname github.com` (the token is masked); Workspace in `gws auth status | jq '{user, token_valid, has_refresh_token, scopes}'`. A missing scope needs a new login even when the probe passes.
1. **Probe other named connectors**: only those the task or user names, each read-only with its exit status checked:

   | Provider     | Probe                                                                                       | Recovery                                                 |
   | ------------ | ------------------------------------------------------------------------------------------- | -------------------------------------------------------- |
   | Colab        | `colab --auth adc sessions` (allocates no VM; inspect stderr before trusting an empty list) | `dot login colab`                                        |
   | Hugging Face | `hf auth whoami`                                                                            | `hf auth login`                                          |
   | Kaggle       | `kaggle competitions list --page-size 1 >/dev/null`                                         | `kaggle auth login`                                      |
   | AWS SSO      | `aws sts get-caller-identity --profile <profile> --no-cli-pager`                            | `aws sso login --profile <profile>`                      |
   | Databricks   | `databricks auth profiles` (validates each profile)                                         | `databricks auth login --host <url> --profile <profile>` |
   | Atlassian    | `acli auth status`; API-token Jira: `acli jira auth status`                                 | `acli auth login`                                        |

1. **Report only provider-exposed expiry**: AWS SSO sessions: `jq -r '.expiresAt // empty' ~/.aws/sso/cache/*.json` (never print the file). Google access tokens refresh hourly; `invalid_grant` or "reauthentication" means the refresh token expired or an organization session policy requires login. Hugging Face tokens do not expire unless revoked. Otherwise write "unknown"; never infer expiry from file dates.
1. **Check environment overrides**: environment credentials win over stored logins. Report presence only, never values:

   ```bash
   for name in GH_TOKEN GITHUB_TOKEN GOOGLE_APPLICATION_CREDENTIALS CLOUDSDK_AUTH_ACCESS_TOKEN_FILE \
     GOOGLE_WORKSPACE_CLI_TOKEN GEMINI_API_KEY GOOGLE_API_KEY HF_TOKEN KAGGLE_API_TOKEN \
     AWS_PROFILE AWS_ACCESS_KEY_ID AWS_SESSION_TOKEN DATABRICKS_HOST DATABRICKS_TOKEN DATABRICKS_CLIENT_SECRET; do
     [ -n "$(printenv "$name")" ] && echo "$name is set"
   done
   ```

1. **Report and hand off**: one table of provider, account (no token), status, scopes gap, expiry, and next action. Browser logins are interactive: give each as `! <command>` for the user to run in the session, preferring `dot login all` or `dot login github|workspace|gcp|colab` over native commands. When the user says they logged in, re-run only the failed probes.

## Gotchas

- **Never print secrets**: no `print-access-token`, `hf auth token`, `kaggle auth print-access-token`, `kaggle config view`, `aws configure export-credentials`, or `--show-token` in a transcript; dot's probes capture token output internally.
- **Exit 0 is not proof**: `gh auth status --json` and Colab can succeed while reporting a failure; read the state and stderr.
- **Native ADC logins drop configured scopes**: a native ADC login (`gcloud auth application-default login`, `gcloud auth login --update-adc`) replaces the grant and drops the Colab and BigQuery read-only scopes; `dot login gcp|colab` request `auth.gcp.adc_scopes`, which keeps them. Run `dot login colab` to restore them ([Colab ADC](../dot-cli/references/authentication.md#colab-adc)).
- **Probing is read-only**: logging in, switching accounts, adding scopes, or editing `dot` configuration needs the user.

## Documentation

- [gh auth status](https://cli.github.com/manual/gh_auth_status) · [gcloud auth](https://cloud.google.com/sdk/gcloud/reference/auth) · [AWS SSO](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-sso.html)
- Companion skills: [dot-cli](../dot-cli/SKILL.md) (login and setup), [gcloud](../gcloud/SKILL.md), [gh](../gh/SKILL.md), [gws](../gws/SKILL.md), [colab](../colab/SKILL.md).

Attribution

fmindfmind
View sourceSee grades on GitHubMore from fmind →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →