Auth Flows banner
kensaurus kensaurus

Auth Flows

Security community

Description

--- description: "Read-only audit of app-layer auth — route×gate matrix, getSession vs getUser, middleware-as-only-gate" argument-hint: "[app or auth path]" --- # Auth-Flows Audit Run the **`audit-auth-flows`** skill: map every protected route to the gate that actually covers it, grep server-side `getSession()` used as authorization, and treat middleware-as-the-only-gate as a finding even after CVE-2025-29927 is patched. **Read-only — do not patch.** Data-layer RLS stays on `plan-rls-audit`.

Installation

Installs to ~/.claude/skills/kensaurus-cursor-kenji-auth-flows/SKILL.md

Terminal
mkdir -p ~/.claude/skills/kensaurus-cursor-kenji-auth-flows && curl -fsSL https://raw.githubusercontent.com/kensaurus/cursor-kenji/HEAD/commands/auth-flows.md -o ~/.claude/skills/kensaurus-cursor-kenji-auth-flows/SKILL.md

Restart Claude Code, or start a new session, for it to be picked up.

Full documentation available on GitHub

View Source Repository