← Back to list

account-security
by SylphxAI
🚀 AI development platform with MEP architecture - stop writing prompts, start building with 90% less typing
⭐ 4🍴 3📅 Jan 8, 2026
SKILL.md
name: account-security description: Account security - MFA, sessions, recovery. Use when protecting user accounts.
Account Security Guideline
Tech Stack
- Auth: Better Auth
- Framework: Next.js (with Turbopack)
- Database: Neon (Postgres)
Non-Negotiables
- MFA required for admin/super_admin roles
- Sensitive actions require step-up re-authentication (password or email OTP)
- Verified session state must be scoped, time-bound, never implicitly reused
- Session/device visibility and revocation must exist
- All security-sensitive actions must be server-enforced and auditable
- Account recovery must require step-up verification
Context
Account security handles how users manage sessions — visibility, revocation, step-up verification, MFA. Sign-in and SSO live in auth.
This is the SSOT for MFA policy. Admin and other privileged roles reference this.
Driving Questions
- Can users see all active sessions and revoke them?
- Is re-authentication required for all sensitive actions?
- What happens when an account is compromised?
- How does the recovery flow prevent social engineering?
- What security events trigger user notification?
Score
Total Score
75/100
Based on repository quality metrics
✓SKILL.md
SKILL.mdファイルが含まれている
+20
✓LICENSE
ライセンスが設定されている
+10
✓説明文
100文字以上の説明がある
+10
○人気
GitHub Stars 100以上
0/15
✓最近の活動
3ヶ月以内に更新
+5
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
✓タグ
1つ以上のタグが設定されている
+5
Reviews
💬
Reviews coming soon

