github.com/greenpau/caddy-security
| Skill | Added | Review |
|---|---|---|
authentication-portal-api .codex/skills/authentication-portal-api/SKILL.md Build or troubleshoot portal JSON/native login clients, refresh, profile and admin APIs, and public JWKS. Use for HTTP contracts; portal Caddyfile wiring belongs to configuration-authentication. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
break-fix-troubleshooting .codex/skills/break-fix-troubleshooting/SKILL.md Diagnose caddy-security deployment and runtime failures from configs, logs, versions, and HTTP evidence. Use for focused fixes, unresolved support handoffs, or preparing break-fix issue reports. | 67 67 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: a48553d | |
coding-directives .codex/skills/coding-directives/SKILL.md Implement or review caddy-security Go code, Caddy modules, parsers, lifecycle, and HTTP delegation. Use for app/plugin boundaries, authcrunch integration, errors, logging, and code conventions. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration .codex/skills/configuration/SKILL.md Build or review caddy-security Caddyfiles and select focused configuration skills. Use for security app declarations and authenticate/authorize route wiring. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-authentication .codex/skills/configuration-authentication/SKILL.md Configure authentication portals, backend selection, redirect trust, refresh, and portal wiring. Delegates cookies, UI, transforms, crypto, and OIDC provider details to focused skills. | 60 60 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-authentication-cookies .codex/skills/configuration-authentication-cookies/SKILL.md Configure portal cookie names, prefixes, domains, paths, attributes, and refresh overrides. Use for cookie precedence and coordination with authorization token discovery. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-authentication-cross-device .codex/skills/configuration-authentication-cross-device/SKILL.md Configure and verify optional cross-device portal login, QR activation, explicit approval, browser binding, cancellation, and lifecycle through Caddy. Native login and external provider configuration retain their own owners. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-authentication-ui .codex/skills/configuration-authentication-ui/SKILL.md Configure portal UI templates, static assets, themes, languages, links, and custom CSS/JS/HTML. Use for branding and refresh-aware templates; transform-generated links belong to user transforms. | 62 62 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-authentication-user-transforms .codex/skills/configuration-authentication-user-transforms/SKILL.md Configure portal user transforms: matchers, typed claims, role actions, conditional challenges, MFA, and deny rules. Use for authentication-time policy; stored account rules belong to configuration-users. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-authorization .codex/skills/configuration-authorization/SKILL.md Configure authorization policies, ACLs, bypasses, identity headers, JWT verification, remote Basic/API-key auth, and direct OAuth without a portal. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-credentials .codex/skills/configuration-credentials/SKILL.md Configure reusable named username/password credentials for messaging consumers, including optional domains and runtime values. LDAP bind credentials belong to identity stores. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-crypto .codex/skills/configuration-crypto/SKILL.md Configure portal/policy JWT keys, token names and lifetimes, key loading and generation, public-key discovery, and System API encryption keys. Use for signing/verification compatibility and rotation. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-http-integrations .codex/skills/configuration-http-integrations/SKILL.md Mount authenticate and authorize handlers, separate portal and protected routes, align auth URLs, and preserve trusted proxy metadata. Use for path conflicts, split hosts, public JWKS, and route ordering. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-identity-stores .codex/skills/configuration-identity-stores/SKILL.md Configure local or LDAP identity stores, realms, databases, binds, TLS trust, searches, and group mappings. Delegates static account entries to configuration-users. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-logging .codex/skills/configuration-logging/SKILL.md Configure AuthCrunch diagnostic skip rules and explain the Caddy middleware logger boundary. Use for component/message filtering; access logs and authorization outcomes are separate concerns. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-messaging .codex/skills/configuration-messaging/SKILL.md Configure email and file messaging providers, SMTP transport, sender/authentication, templates, and registration delivery wiring. Use to distinguish parsed settings from actual delivery behavior. | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-oauth-applications .codex/skills/configuration-oauth-applications/SKILL.md Register named OAuth clients, manage private registration storage, and configure portal OIDC providers. Owns security oauth/oidc provisioning commands; external login providers and security local are separate. | 56 56 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-oauth-providers .codex/skills/configuration-oauth-providers/SKILL.md Configure external OAuth/OIDC login providers, credentials, scopes, issuer/audience trust, JWKS, PKCE, and portal enablement. Named relying-party registrations and portal OPs belong to OAuth applications. | 63 63 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-registrations .codex/skills/configuration-registrations/SKILL.md Configure local user signup, domain/MX rules, terms, confirmation, dropbox storage, and messaging. Use for registration versus account activation; OAuth client registration is separate. | 63 63 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d | |
configuration-runtime-resolution .codex/skills/configuration-runtime-resolution/SKILL.md Configure and validate Caddy runtime placeholders, secret lookups, encoded instructions, and resolved fixtures. Use to determine which fields resolve and preserve exact values; manager blocks belong to secrets. | 60 60 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a48553d |