forge-authlisted
Install: claude install-skill seroneyemmanuel4-afk/fullstack-forge-skill
# forge-auth: Authentication
## Purpose
Inspect identity proofing, credentials, sessions, recovery, federation, and reauthentication controls.
Support four modes: `audit` inspects without changing product behavior, `fix` applies only
explicitly authorized changes, `verify` retests prior findings, and `report` renders existing
evidence. If no mode is supplied, use `audit`.
## Trigger conditions
Use this module when a request names `forge-auth`, asks about authentication, or
discovery finds an applicable boundary. Run it from the repository root after project discovery.
## When it applies
- Applications identifying users, services, or administrators
## When it does not apply
- Truly anonymous static content with no privileged operation
Do not silently skip it. Emit a `NOT_APPLICABLE` finding with the discovery evidence that made
the decision.
## Inputs from project discovery
- authentication provider and middleware
- session configuration
- account routes
Prefer `.forge/project-profile.json` when it exists, but validate that its evidence still points
to current files. Read `../fullstack-forge/references/PROTOCOL.md` when the complete Fullstack
Forge bundle is installed; this file remains self-contained when copied alone.
## Inspection procedure
1. Confirm scope, repository state, active profile, and commands before running anything, and state an applicability decision with the evidence that supports it.
2. Trace registration, login, and logout end to end, recordi