Install
$ agentstack add skill-atomachinskiy-claude-yandex-skills-yandex-auth ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
yandex-auth — единая точка авторизации
Базовый плагин пакета claude-yandex-skills. Без него остальные скиллы (metrika, webmaster, direct, forms и т.д.) не работают — они ходят за токеном сюда.
Как использовать
Первый раз (выпустить токен)
bash plugins/yandex-auth/skills/yandex-auth/scripts/oauth-flow.sh
Что произойдёт:
- Откроется браузер на authorize-странице Яндекса.
- Юзер логинится под нужным аккаунтом и жмёт «Разрешить».
- Скрипт ловит
access_tokenиз адресной строки (юзер копирует и вставляет). - Валидирует через
https://login.yandex.ru/info(узнаёт login + user_id). - Сохраняет в
~/.claude/secrets/yandex-app.jsonс правами 600.
Проверить статус
bash plugins/yandex-auth/skills/yandex-auth/scripts/oauth-flow.sh --status
Покажет аккаунт, дату выпуска и проверит токен живым запросом.
Из других плагинов
Каждый yandex-* плагин в своих скриптах:
. "$HOME/.claude/skills/yandex-auth/scripts/common.sh" # путь после установки
yandex_load_token # экспортирует YANDEX_ACCESS_TOKEN, YANDEX_LOGIN, YANDEX_USER_ID
curl -H "$(yandex_auth_header)" "https://api.metrika.yandex.net/management/v1/counters"
Файл с токеном
~/.claude/secrets/yandex-app.json:
{
"access_token": "...",
"client_id": "2f69a4396d684385a5f6578dd5eb7863",
"issued_at": "2026-05-05T15:30:00Z",
"expires_at_estimate": "2027-05-05T15:30:00Z",
"yandex_login": "andrey...",
"yandex_user_id": "1234567"
}
⚠️ Файл секретный. Права 600. Не коммитить, не пересылать.
Когда токен умер
Yandex implicit-flow токены живут до ~1 года, могут быть отозваны раньше:
- юзер сменил пароль
- юзер вручную отозвал в
https://id.yandex.ru/security/apps - приложение заблокировано Яндексом
Восстановление — oauth-flow.sh ещё раз.
Scope
Scope в authorize-URL не передаём → юзер получает все scope, которые админ вшил в приложение в кабинете oauth.yandex.ru/client/.
Если в приложение добавили новый сервис — старый токен новый scope не покрывает. Нужно переавторизоваться (oauth-flow.sh) — Яндекс выдаст обновлённый токен с расширенным scope.
⚠️ Wordstat scope требует ручной заявки в поддержку Яндекса. Получают не все. Если у юзера нет доступа к Wordstat — общий токен всё равно работает, просто yandex-wordstat будет ловить 403 от Яндекса.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: atomachinskiy
- Source: atomachinskiy/claude-yandex-skills
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.