Agent skill
permission-patterns
Rules for evaluating, classifying, and deduplicating AI tool permissions
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/permission-patterns
SKILL.md
Permission Patterns
Unified patterns for permission safety classification and deduplication. Use these rules to evaluate permissions consistently.
Safety Classification
Classification rules for evaluating permission safety. Use these criteria to categorize permissions consistently.
Classification Rules
ALLOW - Read-Only and Safe Operations
Keywords: list, ls, show, info, view, get, describe, inspect, status, doctor, ping, check, --version, --help
Safe domains: github.com, docker.com, kubernetes.io, python.org, npmjs.com, official documentation sites
ASK - Modifications and Risky Operations
Keywords: update, set, edit, patch, modify, apply, rm, delete, remove, prune, clean, exec, run, eval, push, publish, deploy, kill, stop
Requires user confirmation before execution.
DENY - Irreversible Damage or Security Bypass
Keywords: sudo, chmod 777, dd, file patterns like **/.env, **/*_rsa, **/*.key, **/*secret*
Local addresses: localhost, 127.0.0.1, private IP ranges
Decision Criteria
- Read-only query + no secrets → ALLOW
- Modifies resources + reversible → ASK
- Irreversible or security risk → DENY
- Uncertain → ASK (conservative default)
Domain Coverage
Claude Code's WebFetch(domain:X) uses exact host matching — subdomains are NOT covered by a root domain entry:
github.comdoes NOT coverapi.github.comordocs.github.com— each needs its own entrygithub.iodoes NOT covergithub.github.io— separate entry requiredgithubusercontent.comandraw.githubusercontent.comare separate entries (different hostnames)localhostis separate fromlocalhost:3000(ports are distinct)
Each hostname that needs to be fetched must be listed explicitly.
Local/private addresses always DENY:
localhost,127.0.0.1,192.168.x.x,10.x.x.xranges
Pattern Deduplication
Rules for detecting when a specific permission is already covered by a broader existing pattern.
Coverage Rules
WebFetch Domains
Each hostname must be listed exactly — there is no wildcard or subdomain coverage. Ports are also distinct:
localhostdoes NOT coverlocalhost:3000
File Paths
Broader wildcards cover more specific patterns:
Read(**)covers any Read permissionGlob(**/*)coversGlob(**/*.js),Glob(**/package.json)
Hostname Recommendations
Since WebFetch uses exact host matching, list each hostname explicitly. When multiple hostnames share a
common vendor, add all needed hostnames individually rather than assuming a root domain covers them.
Related Permission Suggestions
When discovering a safe permission, suggest related safe commands in the same family:
docker volume ls→ suggestdocker volume inspectaws s3 ls→ suggestaws s3 sync --dryrunnpm list→ suggestnpm outdated,npm audit
Commands Using This Skill
permissions-analyzeragent - Uses classification and deduplication to filter permissions during discovery/sync-permissionscommand - Indirectly uses this skill through the permissions-analyzer agent
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
Didn't find tool you were looking for?