AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Yandex Auth

skill-atomachinskiy-claude-yandex-skills-yandex-auth · by atomachinskiy

|

No reviews yet
0 installs
28 views
0.0% view→install

Install

$ agentstack add skill-atomachinskiy-claude-yandex-skills-yandex-auth

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-atomachinskiy-claude-yandex-skills-yandex-auth)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
4mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Yandex Auth? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

yandex-auth — единая точка авторизации

Базовый плагин пакета claude-yandex-skills. Без него остальные скиллы (metrika, webmaster, direct, forms и т.д.) не работают — они ходят за токеном сюда.

Как использовать

Первый раз (выпустить токен)

bash plugins/yandex-auth/skills/yandex-auth/scripts/oauth-flow.sh

Что произойдёт:

  1. Откроется браузер на authorize-странице Яндекса.
  2. Юзер логинится под нужным аккаунтом и жмёт «Разрешить».
  3. Скрипт ловит access_token из адресной строки (юзер копирует и вставляет).
  4. Валидирует через https://login.yandex.ru/info (узнаёт login + user_id).
  5. Сохраняет в ~/.claude/secrets/yandex-app.json с правами 600.

Проверить статус

bash plugins/yandex-auth/skills/yandex-auth/scripts/oauth-flow.sh --status

Покажет аккаунт, дату выпуска и проверит токен живым запросом.

Из других плагинов

Каждый yandex-* плагин в своих скриптах:

. "$HOME/.claude/skills/yandex-auth/scripts/common.sh"  # путь после установки
yandex_load_token   # экспортирует YANDEX_ACCESS_TOKEN, YANDEX_LOGIN, YANDEX_USER_ID

curl -H "$(yandex_auth_header)" "https://api.metrika.yandex.net/management/v1/counters"

Файл с токеном

~/.claude/secrets/yandex-app.json:

{
  "access_token": "...",
  "client_id": "2f69a4396d684385a5f6578dd5eb7863",
  "issued_at": "2026-05-05T15:30:00Z",
  "expires_at_estimate": "2027-05-05T15:30:00Z",
  "yandex_login": "andrey...",
  "yandex_user_id": "1234567"
}

⚠️ Файл секретный. Права 600. Не коммитить, не пересылать.

Когда токен умер

Yandex implicit-flow токены живут до ~1 года, могут быть отозваны раньше:

  • юзер сменил пароль
  • юзер вручную отозвал в https://id.yandex.ru/security/apps
  • приложение заблокировано Яндексом

Восстановление — oauth-flow.sh ещё раз.

Scope

Scope в authorize-URL не передаём → юзер получает все scope, которые админ вшил в приложение в кабинете oauth.yandex.ru/client/.

Если в приложение добавили новый сервис — старый токен новый scope не покрывает. Нужно переавторизоваться (oauth-flow.sh) — Яндекс выдаст обновлённый токен с расширенным scope.

⚠️ Wordstat scope требует ручной заявки в поддержку Яндекса. Получают не все. Если у юзера нет доступа к Wordstat — общий токен всё равно работает, просто yandex-wordstat будет ловить 403 от Яндекса.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.