All skills
authentication-security
FoundationJIT onlyUse with analysis-agent, task-agent, or review-agent for task-local authentication lifecycle and recovery risk. Do not use without that decision or as task owner.
- Group
- Security & privacy
- Supported roles
- MainAnalysisTaskReview
- Source
- SKILL.md
Use when
Trigger signals that make this skill the right owner
- secure authentication sessions tokens passwords MFA and account recovery
Do not use when
Anti-triggers — as binding as the triggers above
- no task-local authentication security decision is required
Required inputs
What must be supplied before this skill can decide anything
- current task contract
- selected primary Professional Skill
- task-local trigger evidence
Output contract
What this skill owes the next role
- authentication security review with controls failure cases and audits
Escalation signals
When this skill must hand the decision back
- Authentication weakness compromises identity and downstream authorization
Loaded by
This skill never owns a task. These professionals may pull it in as Layer 3.
Targeted references
Each reference carries its own load condition. None of them enter context by default.
| Reference | Load when | Do not load when | Required by |
|---|---|---|---|
| benchmarks-and-patterns.mdbenchmark-pattern | Credential, session, federation, or recovery controls require mechanism selection. | No authentication lifecycle or assurance boundary changes. | AnalysisTaskReview |
| checklist.mddecision-checklist | Affected flows include compromise, revocation, linking, or step-up denial. | The change cannot issue, renew, recover, or revoke identity. | AnalysisTaskReview |
| evidence-patterns.mdevidence-pattern | Authentication claims need fresh replay, fixation, or redaction proof. | No lifecycle control claim awaits validation. | AnalysisTaskReview |