auth-access-control
Installation
SKILL.md
Auth Access Control
Workflow
- Identify actors, resources, actions, trust boundaries, and tenant scope.
- Enforce authorization server-side near resource access.
- Keep authentication, authorization, and session management separate.
- Handle denied, expired, missing, and malformed credentials consistently.
- Log security-relevant events without exposing secrets.
Rules
- Do not rely on frontend checks for access control.
- Protect cross-tenant and privilege escalation paths.
- Keep token and session lifetimes explicit.
Verification
- Test allowed, denied, unauthenticated, expired, and cross-tenant cases.