Back to list
SylphxAI

account-security

by SylphxAI

🚀 AI development platform with MEP architecture - stop writing prompts, start building with 90% less typing

4🍴 3📅 Jan 8, 2026

SKILL.md


name: account-security description: Account security - MFA, sessions, recovery. Use when protecting user accounts.

Account Security Guideline

Tech Stack

  • Auth: Better Auth
  • Framework: Next.js (with Turbopack)
  • Database: Neon (Postgres)

Non-Negotiables

  • MFA required for admin/super_admin roles
  • Sensitive actions require step-up re-authentication (password or email OTP)
  • Verified session state must be scoped, time-bound, never implicitly reused
  • Session/device visibility and revocation must exist
  • All security-sensitive actions must be server-enforced and auditable
  • Account recovery must require step-up verification

Context

Account security handles how users manage sessions — visibility, revocation, step-up verification, MFA. Sign-in and SSO live in auth.

This is the SSOT for MFA policy. Admin and other privileged roles reference this.

Driving Questions

  • Can users see all active sessions and revoke them?
  • Is re-authentication required for all sensitive actions?
  • What happens when an account is compromised?
  • How does the recovery flow prevent social engineering?
  • What security events trigger user notification?

Score

Total Score

75/100

Based on repository quality metrics

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

+10
説明文

100文字以上の説明がある

+10
人気

GitHub Stars 100以上

0/15
最近の活動

3ヶ月以内に更新

+5
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

+5
タグ

1つ以上のタグが設定されている

+5

Reviews

💬

Reviews coming soon