More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Repair Agent Permissions, Approvals & Action Boundaries

    1

    Repair Agent Permissions, Approvals & Action Boundaries is a bounded ToolForge Labs workflow.

    $8.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    Repair Agent Permissions, Approvals & Action Boundaries

    Repair Agent Permissions, Approvals & Action Boundaries

    Example session with this skill installed

    Our internal agent can read tickets, update records, and trigger a deployment tool. Read actions should be automatic, updates need team scope, and deployments require explicit human approval. We found traces where an old approval was reused after the deployment parameters changed. Repair the permission/approval boundary without granting broader access.

    • Read your context and instructions
    • Compiled the repair agent permissions
    • Generated the document

    The likely issue is a contract mismatch around agent permissions, least privilege, approval gates, delegated actions, scoped credentials, tool authority, escalation, session state, audit trails, and revocation. I would first define the invariant: Every executed action must be authorized at execution time for the exact principal, tenant, tool, operation and normalized parameters; approval cannot be treated as a reusable blanket permission. Then I would trace the smallest owning boundary, apply or propose a bounded repair/review step, and add deterministic normal, boundary, failure and replay tests. The workflow preserves existing authorization and business policy, user consent, separation of duties, credential boundaries, and destructive-action safeguards. If repository/workspace files are available, the findings can be mapped to exact paths and focused local validation; with partial evidence, the result stays an explicit diagnosis/evidence map with assumptions and no invented execution claims.

    repair-agent-permissions-approvals-actio.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Enforce least-privilege access for agent-accessible CLI tools and APIs.Implement human-in-the-loop approval gates for high-risk agent actions.Fix broken credential delegation and session freshness in agentic workflows.Generate deterministic test fixtures for validating security boundaries.

    About this skill

    Repair Agent Permissions, Approvals & Action Boundaries is a bounded ToolForge Labs workflow. Diagnose, review, and repair agent permissions, least privilege, approval gates, delegated actions, scoped credentials, tool authority, escalation, session state, audit trails, and revocation. Works from full repositories/workspaces or partial evidence. Produces bounded fixes or evidence gates with deterministic validation while preserving existing product/security policy and avoiding invented execution claims. It works from a full repository/workspace or partial evidence such as snippets, logs, configuration, traces, documents, tickets, and architecture notes. The skill separates verified facts from assumptions, avoids invented execution claims, and produces concrete repair/review steps with focused deterministic validation or traceable evidence.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 13 days ago

    • Passed all security checks, Safe to install

    Listed13 days ago

    What's inside

    Frequently Asked Questions