ainative-auth-guideImplement authentication for AINative APIs. Use when (1) Choosing between API key and JWT auth, (2) Registering/logging in users, (3) Refreshing tokens, (4)...
Install via ClawdBot CLI:
clawdbot install urbantech/ainative-auth-guideGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
post → https://api.ainative.studio/api/v1/auth/forgot-passwordCalls external URL not in known-safe list
https://api.ainative.studio/api/v1/public/credits/balanceAI Analysis
The skill provides legitimate authentication guidance for the official AINative API, with all endpoints consistent with its stated purpose. No credential harvesting, hidden instructions, or obfuscation is present.
Audited Apr 16, 2026 · audit v1.0
Generated May 9, 2026
A SaaS company needs to secure its AI API for server-to-server communication. Using API keys allows them to manage access for multiple agents and backend services without user involvement.
A web app wants to offer email/password login and social login via LinkedIn/GitHub. JWT tokens enable persistent sessions and secure access to user-specific resources.
A mobile app experiences frequent token expiration. Implementing the refresh token endpoint ensures seamless user sessions without repeated logins.
A developer building a Next.js admin dashboard needs to protect sensitive routes. Using the provided middleware simplifies authentication for pages like /dashboard and /api/protected.
A platform wants to reduce sign-up friction by allowing users to log in with their LinkedIn or GitHub accounts. The OAuth2 callbacks handle the token exchange securely.
Offer free API keys with rate limits and paid plans with higher quotas. Revenue from subscription fees for API access.
Provide authentication as a service to enterprises, charging based on active users or API calls. Includes Single Sign-On and compliance features.
Monetize by allowing social login in premium tiers. Free tier only email/password, paid tier adds LinkedIn/GitHub OAuth2.
💬 Integration Tip
Start with API keys for server-side or MCP tools, then add JWT for user sessions. Use the Next.js middleware for quick route protection.
Scored May 9, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...