Crush Configuration
charmbracelet/crush
Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.
Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.
$ npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install asgeirtj/system_prompts_leaks fewer-permission-prompts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Anthropic/claude-code/skills/fewer-permission-prompts .claude/skills/fewer-permission-prompts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fewer-permission-prompts" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/Anthropic/claude-code/skills/fewer-permission-prompts into .claude/skills/fewer-permission-prompts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fewer-permission-prompts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/asgeirtj/system_prompts_leaks/tree/main/Anthropic/claude-code/skills/fewer-permission-promptsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install asgeirtj/system_prompts_leaks fewer-permission-prompts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .agents/skills && cp -r skills-src/Anthropic/claude-code/skills/fewer-permission-prompts .agents/skills/fewer-permission-prompts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fewer-permission-prompts" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/Anthropic/claude-code/skills/fewer-permission-prompts into .agents/skills/fewer-permission-prompts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fewer-permission-prompts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install asgeirtj/system_prompts_leaks fewer-permission-prompts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/Anthropic/claude-code/skills/fewer-permission-prompts .cursor/skills/fewer-permission-prompts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fewer-permission-prompts" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/Anthropic/claude-code/skills/fewer-permission-prompts into .cursor/skills/fewer-permission-prompts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fewer-permission-prompts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/asgeirtj/system_prompts_leaks.git --path Anthropic/claude-code/skills/fewer-permission-prompts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install asgeirtj/system_prompts_leaks fewer-permission-prompts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/Anthropic/claude-code/skills/fewer-permission-prompts .gemini/skills/fewer-permission-prompts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fewer-permission-prompts" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/Anthropic/claude-code/skills/fewer-permission-prompts into .gemini/skills/fewer-permission-prompts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fewer-permission-prompts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install asgeirtj/system_prompts_leaks fewer-permission-promptsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .github/skills && cp -r skills-src/Anthropic/claude-code/skills/fewer-permission-prompts .github/skills/fewer-permission-prompts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fewer-permission-prompts" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/Anthropic/claude-code/skills/fewer-permission-prompts into .github/skills/fewer-permission-prompts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fewer-permission-prompts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install asgeirtj/system_prompts_leaks fewer-permission-prompts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/asgeirtj/system_prompts_leaks.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/Anthropic/claude-code/skills/fewer-permission-prompts .opencode/skills/fewer-permission-prompts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fewer-permission-prompts" agent skill from https://github.com/asgeirtj/system_prompts_leaks/tree/main/Anthropic/claude-code/skills/fewer-permission-prompts into .opencode/skills/fewer-permission-prompts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fewer-permission-prompts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fewer-permission-promptsScan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.
Fewer Permission Prompts is an agent skill from asgeirtj/system_prompts_leaks. Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering Human-in-the-loop approvals and MCP servers. It works with Bash, Model Context Protocol and Git. The repository describes itself as: Documented system prompts from Anthropic - Claude Fable 5.1, Opus 5.5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-6-Astra, Codex. Google - Gemini 3.8 Flash, 3.1 Pro… The licence is CC0-1.0.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 60d44cc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitghdockerbunkubectlclaudenodeuvnpmyarnpnpmmakeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, gh, docker, kubectl, uv, npm, yarn and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fewer Permission Prompts loads about 1.9k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 987 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from asgeirtj/system_prompts_leaks at commit 60d44cc, republished under its CC0-1.0 licence (© asgeirtj). 987 words, ~1,935 tokens.
.claude/skills/fewer-permission-prompts/SKILL.md (or your agent's skills folder).Look through my transcripts' MCP and bash tool calls, and based on those, make a prioritized list of patterns that I should add to my permission allowlist to reduce permission prompts. Focus on read-only commands.
The format for permissions is: Bash(foo*), Bash(foo), Bash(foo bar *), mcp__slack__slack_read_thread, etc.
Then, add these to the project .claude/settings.json under permissions.allow.
Locate transcripts. Session transcripts live at ~/.claude/projects/<sanitized-cwd>/*.jsonl. Each line is a JSON object. Tool calls appear as assistant messages with message.content[] entries of type: "tool_use". The name field identifies the tool (e.g. "Bash", "mcp__slack__slack_read_thread"); for Bash, input.command is the shell string.
Scan the recent transcripts across the user's projects dir — not just the current project — so the allowlist reflects their actual usage. Cap the scan at a reasonable number of recent sessions (e.g. 50 most-recently-modified JSONL files) so this stays fast.
Extract tool-call frequencies.
Bash calls: parse input.command, take the leading command token (handling sudo, timeout, pipes, &&, env-var prefixes). Record the command + first subcommand pair (e.g. git status, gh pr view, ls, cat).mcp__slack__slack_read_thread).Filter to read-only. Keep only commands that don't mutate state. Examples of read-only: ls, cat, pwd, git status, git log, git diff, git show, git branch, rg, grep, find, head, tail, wc, file, which, echo, date, gh pr view, gh pr list, gh pr diff, gh issue view, gh issue list, gh run list, gh run view, gh api (GET), bun run typecheck, bun run lint, bun run test (for tests that don't mutate), docker ps, docker logs, kubectl get, kubectl describe, ps, top, df, du, env, printenv, any MCP tool with read/get/list/search/view in its name.
Drop anything that writes, deletes, renames, pushes, merges, installs, or runs a build/test that has side effects. When in doubt, leave it out.
Never allowlist a pattern that grants arbitrary code execution. A wildcard rule for any of these (e.g. Bash(python3:*)) is equivalent to allowing arbitrary code execution. This list is not exhaustive — apply the same rule to anything in the same category:
python/python3, node, bun, deno, ruby, perl, php, lua, etc.bash, sh, zsh, fish, eval, exec, ssh, etc.npx, bunx, uvx, uv run, etc.npm run *, yarn run *, pnpm run *, bun run *, make *, just *, cargo run *, go run *, etc. — an exact Bash(bun run typecheck) is fine, Bash(bun run *) is notgh api *, docker run/exec, kubectl exec, sudo, and similarDrop commands Claude Code already auto-allows. These don't need an allowlist entry — they never prompt. If you see any of these in the transcripts, skip them; don't suggest them to the user.
cal, uptime, cat, head, tail, wc, stat, strings, hexdump, od, nl, id, uname, free, df, du, locale, groups, nproc, basename, dirname, realpath, cut, paste, tr, column, tac, rev, fold, expand, unexpand, fmt, comm, cmp, numfmt, readlink, diff, true, false, sleep, which, type, expr, seq, tsort, pr, echo, ls, cd.pwd, whoami, alias.claude -h, claude --help, node -v, node --version, python --version, python3 --version, ip addr.xargs, file, sed (read-only expressions), sort, man, help, netstat, ps, base64, grep, egrep, fgrep, sha256sum, sha1sum, md5sum, tree, date, hostname, lsof, pgrep, tput, ss, fd, fdfind, aki, rg, jq, uniq, history, arch, ifconfig, pyright, find (blocks -delete/-exec/-execdir/-ok/-okdir/-fprint*/-fls/-files0-from), printf (blocks any -flag), test (blocks -v/-R/-a/-o).git status, git log, git diff, git show, git blame, git branch, git tag, git remote, git ls-files, git ls-remote, git config --get, git rev-parse, git describe, git stash list, git reflog, git shortlog, git cat-file, git for-each-ref, git worktree list, etc.gh pr view, gh pr list, gh pr diff, gh pr checks, gh pr status, gh issue view, gh issue list, gh issue status, gh run view, gh run list, gh workflow list, gh workflow view, gh repo view, gh release view, gh release list, gh api (GET), gh auth status, etc.docker ps, docker images, docker logs, docker inspect.Source of truth: src/tools/BashTool/readOnlyValidation.ts (READONLY_COMMANDS, READONLY_NOARGS, READONLY_EXACT, COMMAND_ALLOWLIST) and src/utils/shell/readOnlyCommandValidation.ts (GIT_READ_ONLY_COMMANDS, GH_READ_ONLY_COMMANDS, DOCKER_READ_ONLY_COMMANDS, RIPGREP_READ_ONLY_COMMANDS, PYRIGHT_READ_ONLY_COMMANDS). If the user is in this repo and you're unsure whether a command is covered, grep these files rather than guessing.
Pick the pattern form. Use the narrowest pattern that still covers the observed usage:
git log, git log --oneline, git log main..HEAD): use Bash(git log *) — note the space before *, which is required for prefix matching to work correctly.Bash(foo) with no wildcard.Prioritize. Rank by count descending. Drop anything that appeared fewer than ~3 times — not worth the allowlist entry. Cap the list at the top ~20 so the user can skim it.
Present the prioritized list to the user as a markdown table with columns: rank, pattern, count, one-line description. Example:
| # | Pattern | Count | Notes |
|---|---|---|---|
| 1 | Bash(git status *) | 142 | repo status checks |
| 2 | Bash(gh pr view *) | 87 | PR inspection |
| 3 | mcp__slack__slack_read_thread | 54 | Slack thread reads |
Merge into .claude/settings.json in the current project (not ~/.claude/settings.json, not .claude/settings.local.json). Create the file if it doesn't exist. Preserve existing keys and existing entries in permissions.allow; de-duplicate against what's already there; don't remove anything; don't reorder unrelated fields.
Report back. Tell the user what you added (count + a few examples), what was already in the allowlist, and what you skipped and why (e.g. "dropped rm and git push — not read-only; dropped cat/ls/git status — already auto-allowed, no rule needed").
Do not add anything to permissions.deny or permissions.ask. Do not touch any other settings field.
© asgeirtj, CC0-1.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in Anthropic/claude-code/skills/fewer-permission-prompts of asgeirtj/system_prompts_leaks.
Open the folder on GitHubat commit 60d44cc
Fewer Permission Prompts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fewer Permission Prompts this skillasgeirtj/system_prompts_leaks | 69k | — | ~1.9k | Automated safety check: Pass | CC0-1.0 | |
| Crush Configurationcharmbracelet/crush | 29k | — | ~3.7k | Automated safety check: Pass | Custom licence | |
| Ask User QuestionMemTensor/MemOS | 12k | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| Agent Deckasheshgoplani/agent-deck | 1.1k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Record Demoapify/mcpc | 1k | — | ~3.3k | Automated safety check: Notes | Apache-2.0 | |
| Foremergenaw103/foremerge | 538 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 |
charmbracelet/crush
Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.
MemTensor/MemOS
Shows a question as a modal in the interface to clarify a task, collect a preference or get approval, since the user cannot see terminal output.
asheshgoplani/agent-deck
agent-deck, the terminal session manager for AI coding agents.
apify/mcpc
Record or regenerate the mcpc demo GIFs (the README hero docs/images/mcpc-demo.gif and the focused tapes in docs/vhs/) with VHS.
naw103/foremerge
Coordinate parallel coding agents with Foremerge's local Git-compatible CLI and MCP server.
professorpalmer/Puppetmaster
Operates and supervises Puppetmaster, a multi-agent orchestrator, through its MCP tools or CLI, picking the right verb for edits, reviews, audits and long-running jobs.
asgeirtj/system_prompts_leaks
Shows one digest of coding-agent sessions across your connected machines and lets you open, read, steer, approve, stop and close them, over Herdr, tmux or MSP.
asgeirtj/system_prompts_leaks
Diagnoses a Muse Code installation's own failures from binary and session evidence, instead of treating the report as an ordinary repository bug.
asgeirtj/system_prompts_leaks
A skill your agent uses whenever the user wants to create, read, edit, or manipulate Word documents (.docx) or Word templates (.dotx).
asgeirtj/system_prompts_leaks
Runs a goal as a project in which the agent coordinates separate agent threads, judging when to split the work, and interviews you first when nothing can be verified.
asgeirtj/system_prompts_leaks
Creates and validates a new native Muse plugin package in the current workspace, limited to five capability families, and leaves installation to you.
asgeirtj/system_prompts_leaks
A skill your agent uses when the user's prompt requires (1) researching a topic across multiple sources, comparing options or alternatives, analyzing trends or history, understanding markets or…
Works with
Categories
Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts. Fewer Permission Prompts is an agent skill from asgeirtj/system_prompts_leaks.json to reduce permission prompts.
Fewer Permission Prompts fits situations like: tasks that involve Human-in-the-loop approvals; tasks that involve MCP servers.
Run `npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a claude-code`. Or copy the skill folder (Anthropic/claude-code/skills/fewer-permission-prompts in asgeirtj/system_prompts_leaks) into .claude/skills/fewer-permission-prompts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a codex`. Or copy the skill folder (Anthropic/claude-code/skills/fewer-permission-prompts in asgeirtj/system_prompts_leaks) into .agents/skills/fewer-permission-prompts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add asgeirtj/system_prompts_leaks --skill fewer-permission-prompts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fewer-permission-prompts, .gemini/skills/fewer-permission-prompts, .github/skills/fewer-permission-prompts and .opencode/skills/fewer-permission-prompts in your project.
Going by SKILL.md and its folder, Fewer Permission Prompts needs the command-line tools its instructions call (git, gh, docker, bun, kubectl and claude). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Its commands use git, gh, docker, uv and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fewer Permission Prompts is published under the CC0-1.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fewer Permission Prompts: Crush Configuration (charmbracelet/crush, 29k stars), Ask User Question (MemTensor/MemOS, 12k stars), Agent Deck (asheshgoplani/agent-deck, 1.1k stars) and Record Demo (apify/mcpc, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
asgeirtj (a GitHub user) maintains it in asgeirtj/system_prompts_leaks, which has 69,280 GitHub stars. The repository holds 128 skills in this directory. The repository was last updated on October 10, 2026.
Source: asgeirtj/system_prompts_leaks on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.