Agent skill

Abp Authorization

by abpframework in abpframework/abp

ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

LGPL-3.0Auto-check passedBackend & APIs

Install Abp Authorization

skills CLI
$ npx skills add abpframework/abp --skill abp-authorization -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install abpframework/abp abp-authorization --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/abpframework/abp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/abp-authorization .claude/skills/abp-authorization && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
abp-authorization
GitHub stars
14k
Token cost
~1.3k tokens
SKILL.md length
100 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
LGPL-3.0

At a glance

ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

  • Working with permissions
  • SKILL.md covers Permission Definition, Using Permissions, Current User and Multi-Tenancy Permissions, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Role-based access

What it does

Abp Authorization is an agent skill from abpframework/abp. ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side. Use when working with permissions, authorization, role-based access, or security in ABP projects.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and Multi-tenancy. The repository describes itself as: Open-source web application framework for ASP.NET Core! Offers an opinionated architecture to build enterprise software solutions with best practices on top of the .NET. Provides… The licence is LGPL-3.0.

When your agent uses it

  • Working with permissions
  • Role-based access
  • Security in ABP projects

Example prompts

  • “/abp-authorization”

What it can do on your machine

Read from SKILL.md and the folder at commit a54b599. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are csharp).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • abp.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Abp Authorization loads about 1.3k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 100 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from abpframework/abp at commit a54b599, republished under its LGPL-3.0 licence (© abpframework). 100 words, ~1,262 tokens.

Download SKILL.mdSave it as .claude/skills/abp-authorization/SKILL.md (or your agent's skills folder).
name
abp-authorization
description
ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side. Use when working with permissions, authorization, role-based access, or security in ABP projects.

ABP Authorization

Docs: https://abp.io/docs/latest/framework/fundamentals/authorization

Permission Definition

Define permissions in *.Application.Contracts project:

csharp
public static class BookStorePermissions
{
    public const string GroupName = "BookStore";

    public static class Books
    {
        public const string Default = GroupName + ".Books";
        public const string Create = Default + ".Create";
        public const string Edit = Default + ".Edit";
        public const string Delete = Default + ".Delete";
    }
}

Register in provider:

csharp
public class BookStorePermissionDefinitionProvider : PermissionDefinitionProvider
{
    public override void Define(IPermissionDefinitionContext context)
    {
        var bookStoreGroup = context.AddGroup(BookStorePermissions.GroupName, L("Permission:BookStore"));

        var booksPermission = bookStoreGroup.AddPermission(
            BookStorePermissions.Books.Default,
            L("Permission:Books"));

        booksPermission.AddChild(
            BookStorePermissions.Books.Create,
            L("Permission:Books.Create"));

        booksPermission.AddChild(
            BookStorePermissions.Books.Edit,
            L("Permission:Books.Edit"));

        booksPermission.AddChild(
            BookStorePermissions.Books.Delete,
            L("Permission:Books.Delete"));
    }

    private static LocalizableString L(string name)
    {
        return LocalizableString.Create<BookStoreResource>(name);
    }
}

Using Permissions

Declarative (Attribute)
csharp
[Authorize(BookStorePermissions.Books.Create)]
public virtual async Task<BookDto> CreateAsync(CreateBookDto input)
{
    // Only users with Books.Create permission can execute
}
Programmatic Check
csharp
public class BookAppService : ApplicationService
{
    public async Task DoSomethingAsync()
    {
        // Check and throw if not granted
        await CheckPolicyAsync(BookStorePermissions.Books.Edit);

        // Or check without throwing
        if (await IsGrantedAsync(BookStorePermissions.Books.Delete))
        {
            // Has permission
        }
    }
}
Allow Anonymous Access
csharp
[AllowAnonymous]
public virtual async Task<BookDto> GetPublicBookAsync(Guid id)
{
    // No authentication required
}

Current User

Access authenticated user info via CurrentUser property (available in base classes like ApplicationService, DomainService, AbpController):

csharp
public class BookAppService : ApplicationService
{
    public async Task DoSomethingAsync()
    {
        // CurrentUser is available from base class - no injection needed
        var userId = CurrentUser.Id;
        var userName = CurrentUser.UserName;
        var email = CurrentUser.Email;
        var isAuthenticated = CurrentUser.IsAuthenticated;
        var roles = CurrentUser.Roles;
        var tenantId = CurrentUser.TenantId;
    }
}

// In other services, inject ICurrentUser
public class MyService : ITransientDependency
{
    private readonly ICurrentUser _currentUser;
    public MyService(ICurrentUser currentUser) => _currentUser = currentUser;
}
Ownership Validation
csharp
public async Task UpdateMyBookAsync(Guid bookId, UpdateBookDto input)
{
    var book = await _bookRepository.GetAsync(bookId);

    if (book.CreatorId != CurrentUser.Id)
    {
        throw new AbpAuthorizationException();
    }

    // Update book...
}

Multi-Tenancy Permissions

Control permission availability per tenant side:

csharp
bookStoreGroup.AddPermission(
    BookStorePermissions.Books.Default,
    L("Permission:Books"),
    multiTenancySide: MultiTenancySides.Tenant // Only for tenants
);

Options: MultiTenancySides.Host, Tenant, or Both

Feature-Dependent Permissions

csharp
booksPermission.RequireFeatures("BookStore.PremiumFeature");

Permission Management

Grant/revoke permissions programmatically:

csharp
public class MyService : ITransientDependency
{
    private readonly IPermissionManager _permissionManager;

    public async Task GrantPermissionToUserAsync(Guid userId, string permissionName)
    {
        await _permissionManager.SetForUserAsync(userId, permissionName, true);
    }

    public async Task GrantPermissionToRoleAsync(string roleName, string permissionName)
    {
        await _permissionManager.SetForRoleAsync(roleName, permissionName, true);
    }
}

Security Best Practices

  • Never trust client input for user identity
  • Use CurrentUser property (from base class) or inject ICurrentUser
  • Validate ownership in application service methods
  • Filter queries by current user when appropriate
  • Don't expose sensitive fields in DTOs

© abpframework, LGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/abp-authorization of abpframework/abp.

Open the folder on GitHubat commit a54b599

Compare with similar skills

Abp Authorization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Abp Authorization compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Abp Authorization this skillabpframework/abp14k—~1.3kAutomated safety check: PassLGPL-3.0
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Arandu Shared Modules Guidearandu-io/arandu281—~1.8kAutomated safety check: PassMIT
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
Backend AI Guidelablup/backend.ai-webui1331 repos~1.8kAutomated safety check: PassLGPL-3.0
Arandu Policy and Grantsarandu-io/arandu281—~1.4kAutomated safety check: PassMIT

Similar skills

  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.

    281 GitHub stars~1.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Backend AI Guide

    lablup/backend.ai-webui

    Expert guide for Backend.AI distributed computing platform. An agent skill from lablup/backend.ai-webui.

    133 GitHub starsUsed in 1 repo~1.8k tokens
    Backend & APIsAuto-check passed
  • Arandu Policy and Grants

    arandu-io/arandu

    Explains authorization in an Arandu Go application: write a Policy, get a security.Grant through security.Authorize, re-authorize each row, and keep tenant isolation.

    281 GitHub stars~1.4k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Cognee Permissions

    topoteretes/cognee

    A skill your agent uses when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific…

    32k GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed

More from abpframework/abp

All 18 skills in this repo
  • Abp Angular

    abpframework/abp

    ABP Angular UI patterns - generate-proxy, ListService, PermissionGuard, abpLocalization pipe, ConfirmationService, ToasterService, ConfigStateService.

    14k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Abp App Nolayers

    abpframework/abp

    ABP Single-Layer (No-Layers / nolayers) application template - single project structure, feature-based file organization, no separate Domain/Application.Contracts projects.

    14k GitHub stars~575 tokensUpdated today
    Auto-check passed
  • Abp Application Layer

    abpframework/abp

    ABP Application Services, DTOs, CRUD service, object mapping (Mapperly/AutoMapper), validation, error handling.

    14k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Abp Blazor

    abpframework/abp

    ABP Blazor UI patterns - AbpComponentBase, AbpCrudPageBase, DataGrid, IMenuContributor, Message/Notify, Validations, JavaScript interop.

    14k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Abp CLI

    abpframework/abp

    ABP CLI commands - generate-proxy, install-libs, add-package-ref, new-module, install-module, abp update, abp clean, abp suite generate.

    14k GitHub stars~633 tokensUpdated today
    Auto-check passed
  • Abp Core

    abpframework/abp

    Core ABP Framework conventions - module system, DI registration, base classes (ApplicationService, DomainService), IClock, BusinessException, localization, async patterns.

    14k GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Abp Authorization

What does Abp Authorization do?

ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side. Abp Authorization is an agent skill from abpframework/abp. ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

When should I use Abp Authorization?

Abp Authorization fits situations like: working with permissions; role-based access; security in ABP projects.

How do I install Abp Authorization in Claude Code?

Run `npx skills add abpframework/abp --skill abp-authorization -a claude-code`. Or copy the skill folder (.agents/skills/abp-authorization in abpframework/abp) into .claude/skills/abp-authorization in your project. Claude Code loads it when a task matches its description.

How do I install Abp Authorization in Codex?

Run `npx skills add abpframework/abp --skill abp-authorization -a codex`. Or copy the skill folder (.agents/skills/abp-authorization in abpframework/abp) into .agents/skills/abp-authorization in your project. Codex loads it when a task matches its description.

Can I use Abp Authorization in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add abpframework/abp --skill abp-authorization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/abp-authorization, .gemini/skills/abp-authorization, .github/skills/abp-authorization and .opencode/skills/abp-authorization in your project.

What does Abp Authorization need to run?

SKILL.md names no scripts, command-line tools or credentials: Abp Authorization is instructions for the agent only.

Does Abp Authorization access the network?

SKILL.md names 1 domain. As links in the text: abp.io. This is read from the text; nothing was executed.

Is Abp Authorization safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Abp Authorization use?

Abp Authorization is published under the LGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Abp Authorization use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Abp Authorization?

Skills that share tags, products or a category with Abp Authorization: Django Access Review (getsentry/skills, 1k stars), Arandu Shared Modules Guide (arandu-io/arandu, 281 stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars) and Backend AI Guide (lablup/backend.ai-webui, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Abp Authorization?

abpframework (a GitHub organization) maintains it in abpframework/abp, which has 14,443 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 8, 2026.

Source: abpframework/abp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.