Agent skill

Fewer Permission Prompts

by asgeirtj in asgeirtj/system_prompts_leaks

Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.

CC0-1.0Auto-check passedAgent Workflows

Install Fewer Permission Prompts

skills CLI
$ npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install asgeirtj/system_prompts_leaks fewer-permission-prompts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Anthropic/claude-code/skills/fewer-permission-prompts .claude/skills/fewer-permission-prompts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fewer-permission-prompts
GitHub stars
69k
Token cost
~1.9k tokens
SKILL.md length
987 words
Files
1
Skills in repo
128
Repo updated
First seen
Licence
CC0-1.0

At a glance

Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.

  • Works in 9 steps: Locate transcripts. Session transcripts… → Extract tool-call frequencies. → Filter to read-only. Keep only commands… → …
  • Tasks that involve Human-in-the-loop approvals
  • Calls git, gh and docker
  • Tasks that involve MCP servers

What it does

Fewer Permission Prompts is an agent skill from asgeirtj/system_prompts_leaks. Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Human-in-the-loop approvals and MCP servers. It works with Bash, Model Context Protocol and Git. The repository describes itself as: Documented system prompts from Anthropic - Claude Fable 5.1, Opus 5.5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-6-Astra, Codex. Google - Gemini 3.8 Flash, 3.1 Pro… The licence is CC0-1.0.

When your agent uses it

  • Tasks that involve Human-in-the-loop approvals
  • Tasks that involve MCP servers

Example prompts

  • “/fewer-permission-prompts”

Requirements

  • Python 3
  • Docker

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Locate transcripts. Session transcripts live at ~/.claude/projects//*.jsonl. Each line is a JSON object. Tool calls appear as assistant…
  2. Extract tool-call frequencies.
  3. Filter to read-only. Keep only commands that don't mutate state. Examples of read-only: ls, cat, pwd, git status, git log, git diff, git…
  4. Drop commands Claude Code already auto-allows. These don't need an allowlist entry — they never prompt. If you see any of these in the…
  5. Pick the pattern form. Use the narrowest pattern that still covers the observed usage
  6. Prioritize. Rank by count descending. Drop anything that appeared fewer than ~3 times — not worth the allowlist entry. Cap the list at the…
  7. Present the prioritized list to the user as a markdown table with columns: rank, pattern, count, one-line description. Example
  8. Merge into .claude/settings.json in the current project (not ~/.claude/settings.json, not .claude/settings.local.json). Create the file if…
  9. Report back. Tell the user what you added (count + a few examples), what was already in the allowlist, and what you skipped and why (e.g…

What it can do on your machine

Read from SKILL.md and the folder at commit 60d44cc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gh
    • docker
    • bun
    • kubectl
    • claude
    • node
    • uv
    • npm
    • yarn
    • pnpm
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, gh, docker, kubectl, uv, npm, yarn and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fewer Permission Prompts loads about 1.9k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 987 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~47
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from asgeirtj/system_prompts_leaks at commit 60d44cc, republished under its CC0-1.0 licence (© asgeirtj). 987 words, ~1,935 tokens.

Download SKILL.mdSave it as .claude/skills/fewer-permission-prompts/SKILL.md (or your agent's skills folder).
name
fewer-permission-prompts
description
Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.

Fewer Permission Prompts

Look through my transcripts' MCP and bash tool calls, and based on those, make a prioritized list of patterns that I should add to my permission allowlist to reduce permission prompts. Focus on read-only commands.

The format for permissions is: Bash(foo*), Bash(foo), Bash(foo bar *), mcp__slack__slack_read_thread, etc.

Then, add these to the project .claude/settings.json under permissions.allow.

Steps

  1. Locate transcripts. Session transcripts live at ~/.claude/projects/<sanitized-cwd>/*.jsonl. Each line is a JSON object. Tool calls appear as assistant messages with message.content[] entries of type: "tool_use". The name field identifies the tool (e.g. "Bash", "mcp__slack__slack_read_thread"); for Bash, input.command is the shell string.

    Scan the recent transcripts across the user's projects dir — not just the current project — so the allowlist reflects their actual usage. Cap the scan at a reasonable number of recent sessions (e.g. 50 most-recently-modified JSONL files) so this stays fast.

  2. Extract tool-call frequencies.

    • For Bash calls: parse input.command, take the leading command token (handling sudo, timeout, pipes, &&, env-var prefixes). Record the command + first subcommand pair (e.g. git status, gh pr view, ls, cat).
    • For MCP calls: record the full tool name (e.g. mcp__slack__slack_read_thread).
    • Count occurrences across the scanned transcripts.
  3. Filter to read-only. Keep only commands that don't mutate state. Examples of read-only: ls, cat, pwd, git status, git log, git diff, git show, git branch, rg, grep, find, head, tail, wc, file, which, echo, date, gh pr view, gh pr list, gh pr diff, gh issue view, gh issue list, gh run list, gh run view, gh api (GET), bun run typecheck, bun run lint, bun run test (for tests that don't mutate), docker ps, docker logs, kubectl get, kubectl describe, ps, top, df, du, env, printenv, any MCP tool with read/get/list/search/view in its name.

    Drop anything that writes, deletes, renames, pushes, merges, installs, or runs a build/test that has side effects. When in doubt, leave it out.

    Never allowlist a pattern that grants arbitrary code execution. A wildcard rule for any of these (e.g. Bash(python3:*)) is equivalent to allowing arbitrary code execution. This list is not exhaustive — apply the same rule to anything in the same category:

    • Interpreters: python/python3, node, bun, deno, ruby, perl, php, lua, etc.
    • Shells: bash, sh, zsh, fish, eval, exec, ssh, etc.
    • Package runners: npx, bunx, uvx, uv run, etc.
    • Task-runner wildcards: npm run *, yarn run *, pnpm run *, bun run *, make *, just *, cargo run *, go run *, etc. — an exact Bash(bun run typecheck) is fine, Bash(bun run *) is not
    • gh api *, docker run/exec, kubectl exec, sudo, and similar
  4. Drop commands Claude Code already auto-allows. These don't need an allowlist entry — they never prompt. If you see any of these in the transcripts, skip them; don't suggest them to the user.

    • Always auto-allowed (any args): cal, uptime, cat, head, tail, wc, stat, strings, hexdump, od, nl, id, uname, free, df, du, locale, groups, nproc, basename, dirname, realpath, cut, paste, tr, column, tac, rev, fold, expand, unexpand, fmt, comm, cmp, numfmt, readlink, diff, true, false, sleep, which, type, expr, seq, tsort, pr, echo, ls, cd.
    • Auto-allowed with zero args only: pwd, whoami, alias.
    • Auto-allowed exact forms: claude -h, claude --help, node -v, node --version, python --version, python3 --version, ip addr.
    • Auto-allowed with safe flags only (validated): xargs, file, sed (read-only expressions), sort, man, help, netstat, ps, base64, grep, egrep, fgrep, sha256sum, sha1sum, md5sum, tree, date, hostname, lsof, pgrep, tput, ss, fd, fdfind, aki, rg, jq, uniq, history, arch, ifconfig, pyright, find (blocks -delete/-exec/-execdir/-ok/-okdir/-fprint*/-fls/-files0-from), printf (blocks any -flag), test (blocks -v/-R/-a/-o).
    • All git read-only subcommands: git status, git log, git diff, git show, git blame, git branch, git tag, git remote, git ls-files, git ls-remote, git config --get, git rev-parse, git describe, git stash list, git reflog, git shortlog, git cat-file, git for-each-ref, git worktree list, etc.
    • All gh read-only subcommands: gh pr view, gh pr list, gh pr diff, gh pr checks, gh pr status, gh issue view, gh issue list, gh issue status, gh run view, gh run list, gh workflow list, gh workflow view, gh repo view, gh release view, gh release list, gh api (GET), gh auth status, etc.
    • Docker read-only subcommands: docker ps, docker images, docker logs, docker inspect.

    Source of truth: src/tools/BashTool/readOnlyValidation.ts (READONLY_COMMANDS, READONLY_NOARGS, READONLY_EXACT, COMMAND_ALLOWLIST) and src/utils/shell/readOnlyCommandValidation.ts (GIT_READ_ONLY_COMMANDS, GH_READ_ONLY_COMMANDS, DOCKER_READ_ONLY_COMMANDS, RIPGREP_READ_ONLY_COMMANDS, PYRIGHT_READ_ONLY_COMMANDS). If the user is in this repo and you're unsure whether a command is covered, grep these files rather than guessing.

  5. Pick the pattern form. Use the narrowest pattern that still covers the observed usage:

    • If the user runs many variants (git log, git log --oneline, git log main..HEAD): use Bash(git log *) — note the space before *, which is required for prefix matching to work correctly.
    • If a single exact invocation is common: use Bash(foo) with no wildcard.
    • For MCP: use the full tool name verbatim (no wildcard needed; they're already specific).
    • Never widen a pattern to the point that it conflicts with the rules above (no arbitrary code execution, no mutation/side effects).
  6. Prioritize. Rank by count descending. Drop anything that appeared fewer than ~3 times — not worth the allowlist entry. Cap the list at the top ~20 so the user can skim it.

  7. Present the prioritized list to the user as a markdown table with columns: rank, pattern, count, one-line description. Example:

    #PatternCountNotes
    1Bash(git status *)142repo status checks
    2Bash(gh pr view *)87PR inspection
    3mcp__slack__slack_read_thread54Slack thread reads
  8. Merge into .claude/settings.json in the current project (not ~/.claude/settings.json, not .claude/settings.local.json). Create the file if it doesn't exist. Preserve existing keys and existing entries in permissions.allow; de-duplicate against what's already there; don't remove anything; don't reorder unrelated fields.

  9. Report back. Tell the user what you added (count + a few examples), what was already in the allowlist, and what you skipped and why (e.g. "dropped rm and git push — not read-only; dropped cat/ls/git status — already auto-allowed, no rule needed").

Show full SKILL.md (15 more words)Show less

Do not add anything to permissions.deny or permissions.ask. Do not touch any other settings field.

© asgeirtj, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Anthropic/claude-code/skills/fewer-permission-prompts of asgeirtj/system_prompts_leaks.

Open the folder on GitHubat commit 60d44cc

Compare with similar skills

Fewer Permission Prompts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fewer Permission Prompts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fewer Permission Prompts this skillasgeirtj/system_prompts_leaks69k—~1.9kAutomated safety check: PassCC0-1.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Ask User QuestionMemTensor/MemOS12k—~1kAutomated safety check: PassApache-2.0
Agent Deckasheshgoplani/agent-deck1.1k—~1.8kAutomated safety check: PassMIT
Record Demoapify/mcpc1k—~3.3kAutomated safety check: NotesApache-2.0
Foremergenaw103/foremerge538—~2.4kAutomated safety check: PassApache-2.0

Similar skills

  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Ask User Question

    MemTensor/MemOS

    Shows a question as a modal in the interface to clarify a task, collect a preference or get approval, since the user cannot see terminal output.

    12k GitHub stars~1k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Agent Deck

    asheshgoplani/agent-deck

    agent-deck, the terminal session manager for AI coding agents.

    1.1k GitHub stars~1.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Record Demo

    apify/mcpc

    Official

    Record or regenerate the mcpc demo GIFs (the README hero docs/images/mcpc-demo.gif and the focused tapes in docs/vhs/) with VHS.

    1k GitHub stars~3.3k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check: notes
  • Foremerge

    naw103/foremerge

    Coordinate parallel coding agents with Foremerge's local Git-compatible CLI and MCP server.

    538 GitHub stars~2.4k tokensUpdated 6 days ago
    Agent WorkflowsAuto-check passed
  • Puppetmaster Agent Orchestration

    professorpalmer/Puppetmaster

    Operates and supervises Puppetmaster, a multi-agent orchestrator, through its MCP tools or CLI, picking the right verb for edits, reviews, audits and long-running jobs.

    467 GitHub stars~3.2k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from asgeirtj/system_prompts_leaks

All 125 skills in this repo
  • Fleet Manager for Agent Sessions

    asgeirtj/system_prompts_leaks

    Shows one digest of coding-agent sessions across your connected machines and lets you open, read, steer, approve, stop and close them, over Herdr, tmux or MSP.

    69k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Muse Code Product Doctor

    asgeirtj/system_prompts_leaks

    Diagnoses a Muse Code installation's own failures from binary and session evidence, instead of treating the report as an ordinary repository bug.

    69k GitHub stars~3.5k tokensUpdated today
    Auto-check passed
  • DOCX

    asgeirtj/system_prompts_leaks

    A skill your agent uses whenever the user wants to create, read, edit, or manipulate Word documents (.docx) or Word templates (.dotx).

    69k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Agents Project Coordinator

    asgeirtj/system_prompts_leaks

    Runs a goal as a project in which the agent coordinates separate agent threads, judging when to split the work, and interviews you first when nothing can be verified.

    69k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Muse Plugin Creator

    asgeirtj/system_prompts_leaks

    Creates and validates a new native Muse plugin package in the current workspace, limited to five capability families, and leaves installation to you.

    69k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Deep Research

    asgeirtj/system_prompts_leaks

    A skill your agent uses when the user's prompt requires (1) researching a topic across multiple sources, comparing options or alternatives, analyzing trends or history, understanding markets or…

    69k GitHub stars~3.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Fewer Permission Prompts

What does Fewer Permission Prompts do?

Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts. Fewer Permission Prompts is an agent skill from asgeirtj/system_prompts_leaks.json to reduce permission prompts.

When should I use Fewer Permission Prompts?

Fewer Permission Prompts fits situations like: tasks that involve Human-in-the-loop approvals; tasks that involve MCP servers.

How do I install Fewer Permission Prompts in Claude Code?

Run `npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a claude-code`. Or copy the skill folder (Anthropic/claude-code/skills/fewer-permission-prompts in asgeirtj/system_prompts_leaks) into .claude/skills/fewer-permission-prompts in your project. Claude Code loads it when a task matches its description.

How do I install Fewer Permission Prompts in Codex?

Run `npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a codex`. Or copy the skill folder (Anthropic/claude-code/skills/fewer-permission-prompts in asgeirtj/system_prompts_leaks) into .agents/skills/fewer-permission-prompts in your project. Codex loads it when a task matches its description.

Can I use Fewer Permission Prompts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fewer-permission-prompts, .gemini/skills/fewer-permission-prompts, .github/skills/fewer-permission-prompts and .opencode/skills/fewer-permission-prompts in your project.

What does Fewer Permission Prompts need to run?

Going by SKILL.md and its folder, Fewer Permission Prompts needs the command-line tools its instructions call (git, gh, docker, bun, kubectl and claude). Our summary lists: Python 3; Docker.

Does Fewer Permission Prompts access the network?

SKILL.md contains no URLs. Its commands use git, gh, docker, uv and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Fewer Permission Prompts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Fewer Permission Prompts use?

Fewer Permission Prompts is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fewer Permission Prompts use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Fewer Permission Prompts?

Skills that share tags, products or a category with Fewer Permission Prompts: Crush Configuration (charmbracelet/crush, 29k stars), Ask User Question (MemTensor/MemOS, 12k stars), Agent Deck (asheshgoplani/agent-deck, 1.1k stars) and Record Demo (apify/mcpc, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fewer Permission Prompts?

asgeirtj (a GitHub user) maintains it in asgeirtj/system_prompts_leaks, which has 69,280 GitHub stars. The repository holds 128 skills in this directory. The repository was last updated on October 10, 2026.

Source: asgeirtj/system_prompts_leaks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.