Agent skill

Access Control Patterns

by ccashwell in ccashwell/evm-cortex

Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

MITAuto-check passedBackend & APIs

Install Access Control Patterns

skills CLI
$ npx skills add ccashwell/evm-cortex --skill access-control-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccashwell/evm-cortex access-control-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/access-control-patterns .claude/skills/access-control-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
access-control-patterns
GitHub stars
131
Token cost
~1.8k tokens
SKILL.md length
178 words
Files
1
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

  • Implementing role-based permissions
  • SKILL.md covers Ownable2Step (Preferred over…, Role-Based Access Control, AccessManager (OpenZeppelin 5.x) and Timelock Pattern, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Emergency controls

What it does

Access Control Patterns is an agent skill from ccashwell/evm-cortex. Access control design patterns for Solidity protocols. Use when implementing role-based permissions, timelocks, emergency controls, or multi-sig requirements. Covers Ownable2Step, AccessControl, AccessManager, timelock patterns, and emergency pause.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC. It works with Solidity. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.

When your agent uses it

  • Implementing role-based permissions
  • Emergency controls
  • Multi-sig requirements

Example prompts

  • “/access-control-patterns”

What it can do on your machine

Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Access Control Patterns loads about 1.8k tokens when it runs. Until then it costs about 68 tokens; SKILL.md has 178 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 178 words, ~1,820 tokens.

Download SKILL.mdSave it as .claude/skills/access-control-patterns/SKILL.md (or your agent's skills folder).
name
access-control-patterns
description
Access control design patterns for Solidity protocols. Use when implementing role-based permissions, timelocks, emergency controls, or multi-sig requirements. Covers Ownable2Step, AccessControl, AccessManager, timelock patterns, and emergency pause.

Access Control Patterns

Ownable2Step (Preferred over Ownable)

Two-step ownership transfer prevents accidental transfer to a wrong address.

solidity
import {Ownable2Step, Ownable} from "@openzeppelin/contracts/access/Ownable2Step.sol";

contract Treasury is Ownable2Step {
    constructor(address initialOwner) Ownable(initialOwner) {}

    function withdrawFunds(address to, uint256 amount) external onlyOwner {
        if (to == address(0)) revert ZeroAddress();
        (bool success,) = to.call{value: amount}("");
        if (!success) revert TransferFailed();
    }
}

// Transfer flow:
// 1. Current owner calls transferOwnership(newOwner)
// 2. newOwner calls acceptOwnership()
// 3. Ownership transferred only after step 2

Role-Based Access Control

For protocols needing multiple permission levels.

solidity
import {AccessControl} from "@openzeppelin/contracts/access/AccessControl.sol";

contract Protocol is AccessControl {
    bytes32 public constant OPERATOR_ROLE = keccak256("OPERATOR_ROLE");
    bytes32 public constant GUARDIAN_ROLE = keccak256("GUARDIAN_ROLE");
    bytes32 public constant TREASURY_ROLE = keccak256("TREASURY_ROLE");

    constructor(address admin) {
        _grantRole(DEFAULT_ADMIN_ROLE, admin);
    }

    function updateParameters(uint256 newFee) external onlyRole(OPERATOR_ROLE) {
        // routine parameter updates
    }

    function emergencyPause() external onlyRole(GUARDIAN_ROLE) {
        _pause();
    }

    function withdrawFees(address to) external onlyRole(TREASURY_ROLE) {
        // treasury management
    }
}
Role Hierarchy Template
DEFAULT_ADMIN_ROLE (multisig/timelock)
├── OPERATOR_ROLE (parameter updates, routine operations)
├── GUARDIAN_ROLE (emergency pause, circuit breakers)
├── TREASURY_ROLE (fee collection, fund management)
├── UPGRADER_ROLE (proxy upgrades — timelock only)
└── MINTER_ROLE (token minting — restricted)
Custom Role Admin
solidity
constructor(address admin) {
    _grantRole(DEFAULT_ADMIN_ROLE, admin);

    // OPERATOR_ROLE is managed by DEFAULT_ADMIN_ROLE (default)
    // GUARDIAN can manage itself (guardians can add/remove other guardians)
    _setRoleAdmin(GUARDIAN_ROLE, GUARDIAN_ROLE);

    // MINTER is managed by OPERATOR (operators control minters)
    _setRoleAdmin(MINTER_ROLE, OPERATOR_ROLE);
}

AccessManager (OpenZeppelin 5.x)

Centralized permission management for complex protocols with multiple contracts.

solidity
import {AccessManager} from "@openzeppelin/contracts/access/manager/AccessManager.sol";
import {AccessManaged} from "@openzeppelin/contracts/access/manager/AccessManaged.sol";

contract Vault is AccessManaged {
    constructor(address manager) AccessManaged(manager) {}

    function setFee(uint256 fee) external restricted {
        // AccessManager checks if msg.sender has permission for this function
    }
}

// In the AccessManager:
// 1. Define roles (groups of addresses)
// 2. Assign function permissions to roles
// 3. Optionally add execution delays per role

Timelock Pattern

Critical operations should have a time delay, giving users time to react.

solidity
struct TimelockOperation {
    bytes32 id;
    address target;
    uint256 value;
    bytes data;
    uint256 readyTimestamp;
    bool executed;
}

uint256 public constant MIN_DELAY = 2 days;

mapping(bytes32 => TimelockOperation) public operations;

function schedule(
    address target,
    uint256 value,
    bytes calldata data,
    uint256 delay
) external onlyRole(OPERATOR_ROLE) returns (bytes32 id) {
    if (delay < MIN_DELAY) revert DelayTooShort(delay, MIN_DELAY);

    id = keccak256(abi.encode(target, value, data, block.timestamp));

    operations[id] = TimelockOperation({
        id: id,
        target: target,
        value: value,
        data: data,
        readyTimestamp: block.timestamp + delay,
        executed: false
    });

    emit OperationScheduled(id, target, value, data, block.timestamp + delay);
}

function execute(bytes32 id) external onlyRole(OPERATOR_ROLE) {
    TimelockOperation storage op = operations[id];

    if (op.readyTimestamp == 0) revert OperationNotFound();
    if (op.executed) revert AlreadyExecuted();
    if (block.timestamp < op.readyTimestamp) revert NotReady(op.readyTimestamp);

    op.executed = true;

    (bool success,) = op.target.call{value: op.value}(op.data);
    if (!success) revert ExecutionFailed();

    emit OperationExecuted(id);
}

Emergency Pause

solidity
import {Pausable} from "@openzeppelin/contracts/utils/Pausable.sol";

contract Vault is Pausable, AccessControl {
    bytes32 public constant GUARDIAN_ROLE = keccak256("GUARDIAN_ROLE");

    // Guardians can pause immediately (no timelock)
    function pause() external onlyRole(GUARDIAN_ROLE) {
        _pause();
    }

    // Unpausing requires higher privilege (admin/timelock)
    function unpause() external onlyRole(DEFAULT_ADMIN_ROLE) {
        _unpause();
    }

    function deposit(uint256 amount) external whenNotPaused {
        // ...
    }

    // Withdrawals may remain enabled during pause
    function emergencyWithdraw() external {
        // always available — user safety
    }
}
Pause Design Principles
  • Pause should be fast: Guardian can pause without timelock
  • Unpause should be slower: Requires admin/multisig to prevent premature resume
  • Withdrawals should survive pause: Users must always be able to exit
  • Automatic unpause: Consider a max pause duration to prevent permanent lockout

Multi-Sig Requirements

For critical operations, require multiple signatures or approvals.

solidity
mapping(bytes32 => uint256) public approvalCount;
mapping(bytes32 => mapping(address => bool)) public hasApproved;

uint256 public constant REQUIRED_APPROVALS = 3;

function approve(bytes32 operationId) external onlyRole(OPERATOR_ROLE) {
    if (hasApproved[operationId][msg.sender]) revert AlreadyApproved();

    hasApproved[operationId][msg.sender] = true;
    approvalCount[operationId] += 1;

    emit Approved(operationId, msg.sender, approvalCount[operationId]);
}

function execute(bytes32 operationId) external onlyRole(OPERATOR_ROLE) {
    if (approvalCount[operationId] < REQUIRED_APPROVALS) {
        revert InsufficientApprovals(approvalCount[operationId], REQUIRED_APPROVALS);
    }
    // ...
}

Access Control Checklist

  • Ownable2Step over Ownable for single-owner contracts
  • AccessControl for multi-role protocols
  • Role hierarchy documented and enforced
  • Critical operations behind timelock (upgrades, parameter changes)
  • Emergency pause available to guardian role (no timelock)
  • Unpause requires higher privilege than pause
  • Withdrawals remain functional during pause
  • No single EOA controls critical functions — use multisig
  • Role grants/revokes emit events for monitoring
  • renounceRole considered for immutability guarantees post-setup

© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/access-control-patterns of ccashwell/evm-cortex.

Open the folder on GitHubat commit f8f3301

Compare with similar skills

Access Control Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Access Control Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Access Control Patterns this skillccashwell/evm-cortex131—~1.8kAutomated safety check: PassMIT
Entry Point Analyzeralt-research2/SolidityGuard104—~959Automated safety check: PassCustom licence
Solidity Vulnerability Scanneralt-research2/SolidityGuard104—~1.6kAutomated safety check: NotesCustom licence
Smart Contract Auditelophanto/EloPhanto106—~2.7kAutomated safety check: PassCustom licence
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
K8s Security PoliciesCybereason-Public/owLSM28011 repos~2kAutomated safety check: PassGPL-2.0

Similar skills

  • Entry Point Analyzer

    alt-research2/SolidityGuard

    Analyzes Solidity contract entry points to map attack surface.

    104 GitHub stars~959 tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Solidity Vulnerability Scanner

    alt-research2/SolidityGuard

    Comprehensive Solidity contract security scanner detecting 104 vulnerability patterns across reentrancy, access control, arithmetic, DeFi, proxy, and token categories.

    104 GitHub stars~1.6k tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes
  • Smart Contract Audit

    elophanto/EloPhanto

    A skill your agent uses when reviewing a Solidity, Vyper, or Rust (Solana/Anchor) smart contract for paid audit work or pre-launch sanity check.

    106 GitHub stars~2.7k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 11 repos~2k tokens
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed

More from ccashwell/evm-cortex

All 89 skills in this repo
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 7 days ago
    Auto-check passed
  • Aave Integration

    ccashwell/evm-cortex

    A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.

    131 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check passed
  • Anvil Patterns

    ccashwell/evm-cortex

    A skill your agent uses when running a local Ethereum node with Anvil.

    131 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check passed
  • Audit Breadth Scan

    ccashwell/evm-cortex

    A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

    131 GitHub stars~1.4k tokensUpdated 7 days ago
    Auto-check passed
  • Audit Depth Analysis

    ccashwell/evm-cortex

    A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.

    131 GitHub stars~1.6k tokensUpdated 7 days ago
    Auto-check passed
  • Audit Prep

    ccashwell/evm-cortex

    A skill your agent uses when preparing a codebase for security audit.

    131 GitHub stars~1.4k tokensUpdated 7 days ago
    Auto-check passed

Works with

Categories

Questions about Access Control Patterns

What does Access Control Patterns do?

Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex. Access Control Patterns is an agent skill from ccashwell/evm-cortex. Access control design patterns for Solidity protocols.

When should I use Access Control Patterns?

Access Control Patterns fits situations like: implementing role-based permissions; emergency controls; multi-sig requirements.

How do I install Access Control Patterns in Claude Code?

Run `npx skills add ccashwell/evm-cortex --skill access-control-patterns -a claude-code`. Or copy the skill folder (skills/access-control-patterns in ccashwell/evm-cortex) into .claude/skills/access-control-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Access Control Patterns in Codex?

Run `npx skills add ccashwell/evm-cortex --skill access-control-patterns -a codex`. Or copy the skill folder (skills/access-control-patterns in ccashwell/evm-cortex) into .agents/skills/access-control-patterns in your project. Codex loads it when a task matches its description.

Can I use Access Control Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill access-control-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/access-control-patterns, .gemini/skills/access-control-patterns, .github/skills/access-control-patterns and .opencode/skills/access-control-patterns in your project.

What does Access Control Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: Access Control Patterns is instructions for the agent only.

Does Access Control Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Access Control Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Access Control Patterns use?

Access Control Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Access Control Patterns use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Access Control Patterns?

Skills that share tags, products or a category with Access Control Patterns: Entry Point Analyzer (alt-research2/SolidityGuard, 104 stars), Solidity Vulnerability Scanner (alt-research2/SolidityGuard, 104 stars), Smart Contract Audit (elophanto/EloPhanto, 106 stars) and Configuring Horizon (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Access Control Patterns?

ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.

Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.