From ping-identity-agent-plugins
Use this skill whenever the task involves an AI agent, LLM, or agentic workflow interacting with Ping Identity. Triggers: giving an AI agent or LLM a verified machine identity; securing agent-to-API access with client credentials or short-lived tokens; Verified Trust signals or verifiable credentials for AI apps; Identity for AI 5-pillar architecture (Agent Identity, Agent Security, Agent Gateway, Agent Detection, Verified Trust); PingGateway as an MCP gateway for AI agents; CIBA human-in-the-loop approvals for high-risk agent actions; bot detection and AI agent detection with PingOne Protect; delegated tokens for helpdesk AI or workforce AI assistants; 'how do I give my AI agent an identity', 'secure my MCP server', 'token rotation for an autonomous agent'. If the request says 'automated process', 'scheduled job', or 'service account' WITHOUT mentioning AI, LLM, or agent — ask a clarifying question before routing here. If the prompt says only 'agent' or 'authenticate an agent' with no AI/LLM/agentic context — ask a clarifying question, as 'agent' is ambiguous (could mean AI agent, Ping integration agent, or browser user-agent). Also invoke with /ping-identity-for-ai.
How this skill is triggered — by the user, by Claude, or both
Slash command
/ping-identity-agent-plugins:ping-identity-for-aiThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
AI-era identity patterns: Identity for AI, Verified Trust, agent identity, agent security, and AI application authentication.
AI-era identity patterns: Identity for AI, Verified Trust, agent identity, agent security, and AI application authentication.
Invoke explicitly with /ping-identity-for-ai or by saying "use ping-identity-for-ai to...".
ping-foundation.ping-orchestration.ping-app-integration.ping-quickstart.ping-universal-services.A complete AI identity solution typically spans multiple skills:
| Layer | Skill |
|---|---|
| Platform setup and app registration | ping-foundation |
| Auth flow / journey / DaVinci design | ping-orchestration |
| AI identity patterns and Verified Trust | ping-identity-for-ai (this skill) |
| App / SDK integration | ping-app-integration |
Example sequence:
ping-foundation — register the AI agent application and configure the environment.ping-identity-for-ai — design the token scoping and delegation model (this skill).ping-orchestration — build the step-up MFA flow using DaVinci or Journey.ping-app-integration — integrate the OIDC client in the AI application.Complete agent token scoping, Verified Trust signal design, and delegation model here, then hand off to ping-orchestration for step-up MFA flows and ping-app-integration for SDK/OIDC client wiring.
| Task | Curated anchor |
|---|---|
| Overview / strategy for Identity for AI (5-pillar) | references/curated/identity-for-ai-overview.md |
| Register an AI agent as a managed identity | references/curated/agent-security-patterns.md |
| Machine-to-machine auth, token scoping, rotation, revocation | references/curated/agent-security-patterns.md |
| CIBA human-in-the-loop approvals for high-risk agent actions | references/curated/agent-security-patterns.md |
| Bot / agentic AI detection in flows (Protect) | references/curated/agent-security-patterns.md |
| Protect / secure an MCP server (PingGateway) | references/curated/agent-gateway-mcp.md |
| Apply Verified Trust signals or verifiable credentials | references/curated/verified-trust-overview.md |
| Workforce helpdesk AI — delegation + step-up pattern | references/curated/workforce-helpdesk-ai.md |
| AI application end-user authentication (delegated) | references/curated/workforce-helpdesk-ai.md |
Load the anchors identified in Step 1. Stop if the curated anchor is sufficient. Do not load all four anchors unless the user's task explicitly spans all sub-areas.
See references/runtime/mcp-preflight.md for MCP config and Cursor preflight steps.
references/curated/) — load 1–3 max. Stop if sufficient.Curated anchors provide accuracy context — they are not a substitute for the required output. If the task asks for code, a configuration file, or a design document, always produce that artifact. Do not return a prose summary that points at the anchor and stops.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub pingidentity/agent-plugins --plugin ping-identity