Agent skill

Security Permissions

by bkywksj in bkywksj/knowledge-base

Tauri 安全与权限管理技能,指导 Capabilities 配置和安全最佳实践. An agent skill from bkywksj/knowledge-base.

Custom licenceAuto-check passed

Install Security Permissions

skills CLI
$ npx skills add bkywksj/knowledge-base --skill security-permissions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bkywksj/knowledge-base security-permissions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bkywksj/knowledge-base.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/security-permissions .claude/skills/security-permissions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-permissions
GitHub stars
330
Token cost
~2.5k tokens
SKILL.md length
484 words
Files
1
Skills in repo
37
Repo updated
First seen
Licence
Custom licence

At a glance

Tauri 安全与权限管理技能,指导 Capabilities 配置和安全最佳实践. An agent skill from bkywksj/knowledge-base.

  • Works in 9 steps: 安装对应插件 → 注册插件 → 声明权限 → …
  • SKILL.md covers Tauri 2.x 安全模型, 当前项目权限配置, 完整权限清单(按需添加) and 项目权限添加指南, plus 4 more sections
  • Calls pnpm

What it does

Security Permissions is an agent skill from bkywksj/knowledge-base. Tauri 安全与权限管理技能,指导 Capabilities 配置和安全最佳实践。 触发场景: - 需要配置 Capabilities 权限 - 需要理解 Tauri 安全模型 - 需要处理 CSP(内容安全策略) - 功能不可用可能是权限问题 触发词: 权限、Capabilities、安全、CSP、permission、安全策略、sandbox

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Tauri. The repository describes itself as: 本地优先的知识库桌面应用。Markdown 编辑器 + 全文搜索(FTS5) + 双向链接 / 知识图谱;多端同步(WebDAV / S3 / 同步盘,单笔记粒度增量 + 自动双向调度,含整库 ZIP 备份);AI 问答与智能规划(OpenAI 兼容 / Ollama / 自定义 provider,工具调用框架);支持导入 .md / .txt /…

Example prompts

  • “/security-permissions”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. 安装对应插件
  2. 注册插件
  3. 声明权限
  4. 最小权限原则
  5. 无边框窗口权限
  6. 作用域限制
  7. 不暴露敏感操作
  8. Command 验证
  9. 不信任前端数据

What it can do on your machine

Read from SKILL.md and the folder at commit 1eeff20. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Permissions loads about 2.5k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 484 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 484 words (~2,477 tokens).

“Tauri 2.x 引入了 Capabilities 系统,取代了 v1 的 allowlist。每个 API 和插件功能都需要显式声明权限。”

— opening of SKILL.md by bkywksj, Custom licence
name
security-permissions

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .codex/skills/security-permissions of bkywksj/knowledge-base.

Open the folder on GitHubat commit 1eeff20

Compare with similar skills

Security Permissions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Permissions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Permissions this skillbkywksj/knowledge-base330—~2.5kAutomated safety check: PassCustom licence
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
Yaak Changelogmountain-loop/yaak19k—~1.6kAutomated safety check: PassMIT
Native Feel Cross Platform Desktopyetone/native-feel-skill1.9k1 repos~1.5kAutomated safety check: PassMIT
Ccgui Plugin Creatorzhukunpenglinyutong/desktop-cc-gui4.5k—~1.3kAutomated safety check: PassNone
Tabularis Local PR ReviewTabularisDB/tabularis5.1k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Yaak Changelog

    mountain-loop/yaak

    Create or edit Yaak changelogs. An agent skill from mountain-loop/yaak.

    19k GitHub stars~1.6k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Native Feel Cross Platform Desktop

    yetone/native-feel-skill

    A skill your agent uses when the user is designing, prototyping, or rewriting a desktop app that must run on multiple OSes (macOS + Windows, optionally Linux) AND feel indistinguishable from a…

    1.9k GitHub starsUsed in 1 repo~1.5k tokens
    DevelopmentAuto-check passed
  • Ccgui Plugin Creator

    zhukunpenglinyutong/desktop-cc-gui

    为 CC GUI 桌面客户端创建、修改、迭代插件(Tier-0 声明式 CSS/JSON,或 Tier-1 单文件 ESM)。当用户要"做一个插件 / 给 CC GUI 加个功能 / 改输入框或界面样式 / 加设置页、侧边栏或状态栏入口 / 加面板页签或命令面板命令 / 把某套工作流包装成插件 / 改一下我做过的那个插件",或提到 ccgui 插件、插件目录、从本地目录安装插件时使用。

    4.5k GitHub stars~1.3k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Tabularis Local PR Review

    TabularisDB/tabularis

    Reviews a Tabularis pull request locally, judging the diff against the repo's rule files, verifying every claim in its description against the code, and running its tests on the real branch.

    5.1k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Skills Creator

    Stack-Cairn/LiveAgent

    Create or update LiveAgent runtime skills. An agent skill from Stack-Cairn/LiveAgent.

    2.2k GitHub stars~821 tokensUpdated today
    Auto-check passed

More from bkywksj/knowledge-base

All 37 skills in this repo
  • Collaborating With Codex

    bkywksj/knowledge-base

    当用户明确点名要用 OpenAI Codex CLI 协同时使用此 Skill,把指定任务委托给 Codex 执行并整合结果。

    330 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Collaborating With Gemini

    bkywksj/knowledge-base

    当用户明确点名要用 Google Gemini CLI 协同时使用此 Skill,把指定任务委托给 Gemini 执行并整合结果。

    330 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Profile Integration

    bkywksj/knowledge-base

    用于本项目中与 ai-profile crate 相关的开发:模型服务预置、ai.profile 导入导出、「获取」零成本验证、上下文窗口限额。

    330 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • API Development

    bkywksj/knowledge-base

    Tauri Command (IPC API) 开发技能,指导如何设计和实现 Rust Command 供前端调用. An agent skill from bkywksj/knowledge-base.

    330 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Architecture Design

    bkywksj/knowledge-base

    Tauri 架构设计技能,指导双进程架构下的模块拆分和代码组织. An agent skill from bkywksj/knowledge-base.

    330 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Brainstorm

    bkywksj/knowledge-base

    当需要探索方案、头脑风暴、创意思维时自动使用此 Skill. An agent skill from bkywksj/knowledge-base.

    330 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Works with

Questions about Security Permissions

What does Security Permissions do?

Tauri 安全与权限管理技能,指导 Capabilities 配置和安全最佳实践. An agent skill from bkywksj/knowledge-base. Security Permissions is an agent skill from bkywksj/knowledge-base.

How do I install Security Permissions in Claude Code?

Run `npx skills add bkywksj/knowledge-base --skill security-permissions -a claude-code`. Or copy the skill folder (.codex/skills/security-permissions in bkywksj/knowledge-base) into .claude/skills/security-permissions in your project. Claude Code loads it when a task matches its description.

How do I install Security Permissions in Codex?

Run `npx skills add bkywksj/knowledge-base --skill security-permissions -a codex`. Or copy the skill folder (.codex/skills/security-permissions in bkywksj/knowledge-base) into .agents/skills/security-permissions in your project. Codex loads it when a task matches its description.

Can I use Security Permissions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bkywksj/knowledge-base --skill security-permissions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-permissions, .gemini/skills/security-permissions, .github/skills/security-permissions and .opencode/skills/security-permissions in your project.

What does Security Permissions need to run?

Going by SKILL.md and its folder, Security Permissions needs the command-line tools its instructions call (pnpm).

Does Security Permissions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Permissions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Permissions use?

Security Permissions has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Security Permissions use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Permissions?

Skills that share tags, products or a category with Security Permissions: Use Yaak (mountain-loop/yaak, 19k stars), Yaak Changelog (mountain-loop/yaak, 19k stars), Native Feel Cross Platform Desktop (yetone/native-feel-skill, 1.9k stars) and Ccgui Plugin Creator (zhukunpenglinyutong/desktop-cc-gui, 4.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Permissions?

bkywksj (a GitHub user) maintains it in bkywksj/knowledge-base, which has 330 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on October 10, 2026.

Source: bkywksj/knowledge-base on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.