<!-- xid: A7691B2D3457 --> <a id="xid-A7691B2D3457"></a>
Scanned 9/12/2026
Install to Claude Code
npx -y skills add synthaicode/XRefKit --skill auth_constraint_derivation --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Auth Constraint Derivation?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/synthaicode-auth-constraint-derivation)More formats (shields.io, HTML) on the badges page.
<!-- xid: A7691B2D3457 -->
<a id="xid-A7691B2D3457"></a>
# Skill: auth_constraint_derivation
## Purpose
Derive requirement confirmation gates from authentication and authorization
structure before access behavior is completed implicitly.
## Required Knowledge (XID)
- [Constraint derivation framework](../../../../knowledge/packs/constraint-derivation/110_constraint_derivation_framework.md#xid-81A6C4E2B190)
- [Auth constraint derivation catalog](../../../../knowledge/packs/constraint-derivation/170_auth_constraint_derivation_catalog.md#xid-8B14D9E70326)
- [Working area policy](../../../../docs/policies/014_working_area_policy.md#xid-111D282CA0EA)
## Optional References
- [Primary derivation output template](../references/primary_derivation_output_template.md#xid-FF9A33B945ED)
## Inputs
- auth design docs, role matrices, permission models, and account rules
## Outputs
- AACD-prefixed derivation basis table written to a Markdown file
- grouped requirement confirmation list
- session or permission matrices where required
- written output path
## Startup
- Confirm the input contains authentication or authorization structure.
- Load the framework and the auth catalog.
- Identify session, role, tenant, client-auth, and account-lifecycle surfaces.
- Determine the output path:
- default: `work/constraint_derivation/YYYY-MM-DD_auth_constraint_derivation_<topic>.md`
- otherwise use the user-specified path
## Execution
1. Enumerate authentication, authorization, client-auth, and account-management elements.
2. Apply the auth catalog and assign `AACD-` ids.
3. Expand permission or session matrices where the design exposes those axes.
4. Group the results by auth surface.
5. Keep unresolved security behavior explicit instead of assuming safe defaults.
6. Write the result by using `references/primary_derivation_output_template.md` or an equivalent structure.
## Monitoring and Control
- Do not infer permission behavior from UI visibility alone.
- Stop if session-expiry, role gaps, or tenant-boundary behavior is left implicit.
- Preserve explicit traceability from each AACD item back to the access structure.
## Closure
- Return the AACD table and grouped unresolved items.
- Highlight any session or permission gaps blocking implementation.
- Return the written output path.
## Reporting Contract (共通報告)
- reporting_profile: summary_first
Use the shared [Skill Reporting Contract](../../../../docs/core/contracts/081_skill_reporting_contract.md#xid-6B2D9F4A1C73) in the final report. Start with these headings in this order:
1. Status — done, partial, blocked, or escalated
2. Result — what was produced or decided
3. Evidence — output, evidence, checks, or XIDs
4. Open Items — unresolved unknowns, risks, judgments, or なし
5. Handoff — next owner and next action, or なし
Keep this summary-first section visible before Skill-specific detail; do not omit empty sections.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!