github.com/greenpau/caddy-security
| Skill | Added | Review |
|---|---|---|
testing-and-ci .codex/skills/testing-and-ci/SKILL.md caddy-security repository testing and CI workflow guidance, including Go test command selection, Makefile report targets, Caddyfile parser/adapt fixture tests, runtime resolution fixtures, coverage artifacts, and GitHub Actions build/release/CLA behavior. Use when choosing or running tests, adding or updating test coverage, interpreting CI failures, reproducing GitHub Actions locally, or documenting validation for this Go/Caddy module. | 79 79 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
source-code-management .codex/skills/source-code-management/SKILL.md caddy-security source code management and commit message rules. Use when creating, reviewing, or updating commit messages, especially when the user asks to create a commit message for a change in this repository. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
scripts-and-automation .codex/skills/scripts-and-automation/SKILL.md caddy-security repository automation, Makefile target selection, local build/test/report/coverage commands, local go-authcrunch go.mod replacement shim workflow, asset and documentation update scripts, release/version workflows, generated artifact handling, and guardrails for dependency, devbuild, cleanup, and release actions. Use when choosing, running, documenting, or updating repository scripts and Make targets; troubleshooting CI/build/test automation; coordinating caddy-security development with local go-authcrunch changes; refreshing Caddyfile/config fixtures; deciding whether generated outputs belong in a change; or preparing releases for this Go/Caddy module. | 72 72 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: b96087f | |
configuration .codex/skills/configuration/SKILL.md caddy-security Caddyfile configuration generation for the security app and authenticate or authorize HTTP directives. Use when creating, reviewing, or modifying Caddyfile configs for authentication portals, authorization policies, identity stores, OAuth or SAML identity providers, SSO app providers, users, registration flows, messaging, credentials, secrets, or runtime replacement in this repository. | 79 79 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-users .codex/skills/configuration-users/SKILL.md caddy-security local user account Caddyfile configuration. Use when creating, reviewing, or modifying local identity store user entries, usernames, display names, email addresses, plaintext or bcrypt passwords, overwrite behavior, roles, static API key prefixes and payloads, and secret-backed user attributes. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-sso-app .codex/skills/configuration-sso-app/SKILL.md caddy-security SSO app Caddyfile configuration for Single Sign-On with SAML. Use when creating, reviewing, or modifying sso provider blocks, AWS SAML app drivers, SAML entity IDs, signing certificates, PKCS8 private keys, SSO metadata locations, authentication portal enablement, /apps/sso endpoints, and AWS role naming. | 79 79 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-secrets .codex/skills/configuration-secrets/SKILL.md caddy-security secrets manager Caddyfile configuration. Use when creating, reviewing, or modifying security secrets blocks, external security.secrets modules, static secrets manager examples, AWS secrets manager examples, secret IDs, secret-backed user data, authdbctl-generated password or API key hashes, secret-backed crypto keys, and integration with runtime replacement. | 70 70 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: b96087f | |
configuration-saml-providers .codex/skills/configuration-saml-providers/SKILL.md caddy-security SAML login identity-provider Caddyfile configuration. Use when creating, reviewing, or debugging saml identity provider blocks for authentication portal login, especially Azure AD or JumpCloud SAML IdPs, ACS URLs, IdP metadata and signing certificates, entity IDs, SAML realms, clock-skew issues, role claims, and portal enablement. Do not use for sso provider app-side SAML SSO blocks. | 70 70 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-runtime-resolution .codex/skills/configuration-runtime-resolution/SKILL.md caddy-security runtime replacement guidance for Caddyfile configuration. Use when creating, reviewing, or modifying configs that rely on Caddy replacer placeholders, env placeholders, secrets manager lookups, resolved Caddyfile fixtures, runtime credential resolution, unresolved token checks, or caddyfile_resolve behavior. | 71 71 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-registrations .codex/skills/configuration-registrations/SKILL.md caddy-security user registration Caddyfile configuration. Use when creating, reviewing, or modifying user registration blocks, registration titles and codes, dropbox files, terms and privacy links, accepted email domains, MX checks, email provider wiring, admin notification addresses, and identity store targets. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-oauth-providers .codex/skills/configuration-oauth-providers/SKILL.md caddy-security OAuth and OIDC identity provider Caddyfile configuration. Use when creating, reviewing, or modifying oauth identity provider blocks, Azure, GitHub, Google, LinkedIn, Discord, Facebook, Okta, Cognito, GitLab, Nextcloud, or generic OAuth providers, client IDs and secrets, scopes, id token cookies, icons, PKCE toggles, user group filters, JWKS keys, and portal enablement. | 79 79 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-messaging .codex/skills/configuration-messaging/SKILL.md caddy-security messaging provider Caddyfile configuration. Use when creating, reviewing, or modifying messaging email provider or messaging file provider blocks, SMTP settings, passwordless email, senders, BCC addresses, message templates, root directories, and registration email wiring. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-identity-stores .codex/skills/configuration-identity-stores/SKILL.md caddy-security local and LDAP identity store Caddyfile configuration. Use when creating, reviewing, or modifying local identity store blocks, LDAP identity store blocks, local user records, store shortcuts, realms, user files, LDAP bind settings, servers, search filters, attributes, groups, recovery settings, support links, fallback roles, and login icons. | 79 79 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-http-integrations .codex/skills/configuration-http-integrations/SKILL.md caddy-security HTTP integration Caddyfile configuration. Use when creating, reviewing, or modifying route-level authenticate and authorize directives, portal and protected route separation, matcher forms, same-host or split-host auth wiring, auth URL routing and alignment, auth-path collisions such as upstream /auth routes, dedicated auth hosts with root-mounted portals, portal-owned path prefixes to avoid, or unnecessary global Caddy directive-order overrides. | 76 76 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-crypto .codex/skills/configuration-crypto/SKILL.md caddy-security crypto directive configuration for authentication portals and authorization policies. Use when creating, reviewing, or debugging crypto Caddyfile lines, JWT signing or verification keys, token names and lifetimes, key IDs, HMAC/RSA/ECDSA key loading, auto-generated keys, env or secrets-backed crypto values, System API crypto keys for remote Basic/API-key authentication, and authenticate/authorize key compatibility. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-credentials .codex/skills/configuration-credentials/SKILL.md caddy-security reusable generic credentials Caddyfile configuration. Use when creating, reviewing, or modifying security credentials blocks for reusable username/password credentials, optional domains, SMTP or email messaging authentication, registration email provider credentials, environment placeholders, or secret-backed credential values. | 76 76 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-authorization .codex/skills/configuration-authorization/SKILL.md caddy-security authorization policy Caddyfile configuration. Use when creating, reviewing, or modifying security authorization policy blocks, route-level authorize directives, ACL rules, allow or deny shortcuts, bypass rules, crypto verification keys, auth redirects, bearer token validation, basic or API key auth proxy settings, user identity fields, and injected claim headers. | 80 80 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: b96087f | |
configuration-authentication .codex/skills/configuration-authentication/SKILL.md caddy-security authentication portal Caddyfile configuration. Use when creating, reviewing, or modifying security authentication portal blocks, route-level authenticate directives, portal crypto, enabled identity stores, OAuth or SAML identity providers, SSO app providers, trusted redirects, source address validation, or portal wiring. For cookies, UI, and user transforms use the focused authentication subskills. | 79 79 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-authentication-user-transforms .codex/skills/configuration-authentication-user-transforms/SKILL.md caddy-security authentication portal user transform Caddyfile configuration. Use when creating, reviewing, or modifying authentication portal transform user blocks, transform matchers, ACL condition syntax, add or overwrite role actions, drop matched role actions, MFA requirements, block or deny transforms, transform UI links, or authcrunch claim replacement placeholders. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-authentication-ui .codex/skills/configuration-authentication-ui/SKILL.md caddy-security authentication portal UI Caddyfile configuration. Use when creating, reviewing, or modifying authentication portal ui blocks, templates, metadata, private links, static assets, themes, languages, logos, auto_redirect_url, custom CSS, custom JavaScript, or custom HTML header injection. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
configuration-authentication-cookies .codex/skills/configuration-authentication-cookies/SKILL.md caddy-security authentication portal cookie Caddyfile configuration. Use when creating, reviewing, or modifying authentication portal cookie directives, cookie domains, paths, lifetimes, SameSite, insecure cookies, guessed or stripped domains, token cookie names, cookie name prefixes, access token cookie validation, or authcrunch cookie defaults. | 73 73 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
coding-directives .codex/skills/coding-directives/SKILL.md caddy-security repository coding standards and implementation directives for Go/Caddy code, including Caddy module boundaries, security app lifecycle, authenticate/authorize plugin behavior, Caddyfile parser patterns, authcrunch integration, runtime replacement and secrets handling, errors, logging, imports, comments, tests, and fixtures. Use when creating, modifying, or reviewing application code in this repository or when deciding coding patterns for Caddyfile directives, Caddy modules, authcrunch config mapping, HTTP handlers, or Go tests. | 73 73 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
break-fix-troubleshooting .codex/skills/break-fix-troubleshooting/SKILL.md caddy-security break-fix triage and support-report workflow. Use when diagnosing reported configuration, deployment, or runtime failures; analyzing Caddyfiles, Caddy logs, redirect loops, login failures, authorization denials, OAuth/OIDC/SAML/LDAP/local-user issues, module-version mismatches, or secret/runtime placeholder problems; preparing GitHub issue Markdown files for .github/ISSUE_TEMPLATE/break-fix.md under tmp/breakfix/; or identifying gaps in repository skills after troubleshooting. | 77 77 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: b96087f | |
authentication-portal-api .codex/skills/authentication-portal-api/SKILL.md caddy-security authentication portal JSON API and admin/server API guidance. Use when building, reviewing, or debugging programmatic login clients, Portal API calls, Accept: application/json behavior, sandbox challenge sequences, /beacon, /whoami JSON/probe/id_token responses, refresh token API behavior, enable admin api, /api/server metadata/realms/info endpoints, and API-oriented authentication troubleshooting. | 80 80 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: b96087f |