Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
30 results
Skill

oauth

Implements OAuth 2.0/2.1 authorization flows in Fastify applications — configures authorization code with PKCE, client credentials, device flow, refresh token rotation, JWT validation, and token intro

by mcollinaskills.sh
Not rated yet
Free
Skill

identity-access-expert

Design authentication and authorisation: OAuth 2.1 and OpenID Connect, session and token handling, RBAC and ABAC, and multi-tenant access control. Use when the user mentions OAuth, OIDC, SAML, SSO, JW

by personamanagmentlayerskills.sh
Not rated yet
Free
Skill

supabase-security-basics

Apply Supabase security best practices: anon vs service_role key separation, RLS enforcement, policy patterns, JWT verification, and API hardening. Use when securing a Supabase project, auditing API k

by jeremylongshoreskills.sh
Not rated yet
Free
Skill

supabase-security-basics

Apply Supabase security best practices: anon vs service_role key separation, RLS enforcement, policy patterns, JWT verification, and API hardening. Use when securing a Supabase project, auditing API k

by jeremylongshoreskills.sh
Not rated yet
Free
Skill

security-patterns

Security patterns for authentication, defense-in-depth, input validation, OWASP Top 10, LLM safety, and PII masking. Use when implementing auth flows, security layers, input sanitization, vulnerabilit

by yonatangrossskills.sh
Not rated yet
Free
Skill

exploiting-jwt-algorithm-confusion-attack

Exploits JWT algorithm confusion where the server's verification library trusts the alg named in the token header, by switching RS256 to HS256 (signing with the RSA public key as HMAC secret), setting

by mukul975skills.sh
Not rated yet
Free
Skill

implementing-jwt-signing-and-verification

Implements secure JWT (RFC 7519) signing and verification using HMAC-SHA256, RSA-PSS, ES256, and EdDSA, including token expiration, claims validation, and defenses against algorithm-confusion, none-al

by mukul975skills.sh
Not rated yet
Free
Skill

performing-jwt-none-algorithm-attack

Execute and test the JWT none algorithm attack, crafting tokens with the alg header set to none using PyJWT and an intercepting proxy (Burp Suite/mitmproxy) to bypass signature verification and forge

by mukul975skills.sh
Not rated yet
Free
Skill

testing-api-authentication-weaknesses

Tests API authentication mechanisms for weaknesses including broken token validation, missing authentication on endpoints, weak password policies, credential stuffing susceptibility, token leakage in

by mukul975skills.sh
Not rated yet
Free
Skill

testing-for-json-web-token-vulnerabilities

Tests JWT implementations for algorithm confusion, "none" algorithm bypass, kid/jku parameter injection, and weak secret exploitation using jwt_tool and Burp Suite's JWT Editor extension, aiming to ac

by mukul975skills.sh
Not rated yet
Free
Skill

testing-jwt-token-security

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

by mukul975skills.sh
Not rated yet
Free
Skill

api-jwt-authenticator

A conceptual skill for securing FastAPI REST APIs with JWT authentication

by aiskillstoreskills.sh
Not rated yet
Free
Skill

frontend-api-client-with-jwt

A conceptual skill for building an API client in Next.js that handles JWT tokens

by aiskillstoreskills.sh
Not rated yet
Free
Skill

darkit-gin

基于 gin-gonic/gin 的企业级 Web 框架增强版,提供开箱即用的 JWT 认证、SSE 实时通信、缓存管理、OpenAPI 文档生成等企业级功能。涵盖选项式路由配置、统一响应格式、中间件管理、安全加固、性能优化等完整开发能力。

by aiskillstoreskills.sh
Not rated yet
Free
Skill

authentication-setup

Design and implement authentication and authorization systems. Use when setting up user login, JWT tokens, OAuth, session management, or role-based access control. Handles password security, token man

by aiskillstoreskills.sh
Not rated yet
Free
Skill

authentication-setup

Design or refactor product authentication setup for web apps and APIs. Use when choosing hosted/framework-native/platform-native/enterprise-add-on/self-hosted auth, sessions vs JWTs, OAuth/social logi

by akillnessskills.sh
Not rated yet
Free
Skill

oauth-oidc-implementer

Expert in implementing OAuth 2.0 and OpenID Connect (OIDC) authentication flows. Specializes in secure token handling, social login integration, API authorization, and identity provider configuration.

by curiositechskills.sh
Not rated yet
Free
Skill

authjs

You are an expert in Auth.js (formerly NextAuth.js), the authentication library for web frameworks. You help developers add sign-in with 80+ OAuth providers (Google, GitHub, Apple, Discord), email/pas

by terminalskillsskills.sh
Not rated yet
Free
Skill

aws-cognito

Implement authentication with Amazon Cognito. Create user pools for sign-up and sign-in, configure identity pools for AWS access, handle JWT tokens, set up social federation with Google and Facebook,

by terminalskillsskills.sh
Not rated yet
Free
Skill

jwt-handler

When the user needs to generate, validate, refresh, or debug JSON Web Tokens. Use when the user mentions "JWT," "access token," "refresh token," "token rotation," "token expiration," "token validation

by terminalskillsskills.sh
Not rated yet
Free
Skill

oauth2-oidc

Assists with implementing OAuth 2.0 and OpenID Connect for secure authentication and authorization. Use when configuring authorization flows, validating tokens, implementing PKCE for public clients, s

by terminalskillsskills.sh
Not rated yet
Free
Skill

API JWT Authenticator

A conceptual skill for securing FastAPI REST APIs with JWT authentication

by majiayu000GitHub
Not rated yet
Free
Skill

crypto-attack-agent

★ AI 优势赛道 — 加密/编码攻击专家。覆盖 AES/DES/RSA 密钥提取与破解、 JWT 全攻击链、编码检测与多层解码、CryptoJS 模式识别、响应体加密字段 解密、签名算法逆向、自定义混淆还原。

by jinyimeng01GitHub
Not rated yet
Free
Skill

testing-for-json-web-token-vulnerabilities

Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and p

by braydos-hGitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.