Shared ClosedLoop access and routing policy for local ClosedLoop automation skills.

Apache-2.0Auto-check passedAgent Workflows

Install Cl Policy

skills CLI
$ npx skills add closedloop-ai/claude-plugins --skill cl-policy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install closedloop-ai/claude-plugins cl-policy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/closedloop-ai/claude-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/code/skills/cl-policy .claude/skills/cl-policy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cl-policy
GitHub stars
122
Token cost
~2.3k tokens
SKILL.md length
1,152 words
Files
4 (incl. references)
Skills in repo
43
Repo updated
First seen
Licence
Apache-2.0

At a glance

Shared ClosedLoop access and routing policy for local ClosedLoop automation skills.

  • Works in 8 steps: Use dynamic tool discovery or… → Do not hardcode an MCP prefix such as… → If dynamic discovery is unavailable or… → …
  • Cl-execute needs to discover ClosedLoop tools
  • SKILL.md covers Purpose, ClosedLoop Tool Access, Required Reference and Direct User Authority And…, plus 3 more sections
  • Calls codex; reaches api.closedloop.ai; needs CLOSEDLOOP_API_KEY

What it does

Cl Policy is an agent skill from closedloop-ai/claude-plugins. Shared ClosedLoop access and routing policy for local ClosedLoop automation skills. Use when cl-analyze, cl-split, cl-sweep, or cl-execute needs to discover ClosedLoop tools, select a safe MCP/CLI/API access fallback, resolve product contacts or engineering attention contacts, apply comment tagging and first-person communication rules, load local overrides, or interpret legacy personal-name memory fields.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `agents/openai.yaml`, `references/local-policy.example.md` and `references/local-policy.md`).

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: Open-source Claude Code plugins for multi-agent software delivery. Plan-first SDLC workflow, code review, LLM quality judges, and self-learning — grounded in your codebase… The licence is Apache-2.0.

When your agent uses it

  • Cl-execute needs to discover ClosedLoop tools
  • Select a safe MCP/CLI/API access fallback
  • Resolve product contacts
  • Engineering attention contacts

Example prompts

  • “/cl-policy”

Requirements

  • A credential in CLOSEDLOOP_API_KEY

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Use dynamic tool discovery or tool_search first when the current host
  2. Do not hardcode an MCP prefix such as mcp__closedloop. The prefix depends
  3. If dynamic discovery is unavailable or cannot see the configured server,
  4. If MCP access is still unavailable and CLOSEDLOOP_API_KEY is present, use
  5. Prefer read-only API requests during analysis. Resolve endpoint and payload
  6. Treat an inactive localhost MCP URL, a missing initial registration, or a
  7. Report a genuine access blocker only after applicable discovery, Codex CLI
  8. For ticket intelligence, discover the read-only closedloop-graph MCP by

What it can do on your machine

Read from SKILL.md and the folder at commit 0e20ac0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • codex

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.closedloop.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CLOSEDLOOP_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cl Policy loads about 2.3k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 105 tokens; SKILL.md has 1,152 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~105
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from closedloop-ai/claude-plugins at commit 0e20ac0, republished under its Apache-2.0 licence (© closedloop-ai). 1,152 words, ~2,255 tokens.

Download SKILL.mdSave it as .claude/skills/cl-policy/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
cl-policy
description
Shared ClosedLoop access and routing policy for local ClosedLoop automation skills. Use when cl-analyze, cl-split, cl-sweep, or cl-execute needs to discover ClosedLoop tools, select a safe MCP/CLI/API access fallback, resolve product contacts or engineering attention contacts, apply comment tagging and first-person communication rules, load local overrides, or interpret legacy personal-name memory fields.

CL Policy

Purpose

Provide the shared local access and routing policy for ClosedLoop ticket automation. This skill keeps team-specific names, communication rules, and tool-access fallbacks out of the execution skills, while allowing the skill pack to be shared with either a populated bundled policy or a local machine override.

ClosedLoop Tool Access

When ClosedLoop tools are absent from the initial tool list, do not conclude that ClosedLoop or its MCP server is unavailable.

  1. Use dynamic tool discovery or tool_search first when the current host explicitly supports dynamic calls. Search by capability, such as ClosedLoop get document, list document comments, document versions, or document relationships. Codex CLI's TUI does not currently execute dynamic tool calls: in that surface, use statically exposed MCP tools or the CLI/API fallback below and never emit a dynamic tool call merely because a skill says to discover by capability.
  2. Do not hardcode an MCP prefix such as mcp__closedloop. The prefix depends on the user's configured MCP server name and may legitimately differ.
  3. If dynamic discovery is unavailable or cannot see the configured server, try the user's Codex CLI MCP configuration before declaring an access blocker.
  4. If MCP access is still unavailable and CLOSEDLOOP_API_KEY is present, use the production ClosedLoop API directly. Load the key silently from the current environment or the user's shell profile; never print, echo, log, serialize, or include it in command output, memory, prompts, or reports.
  5. Prefer read-only API requests during analysis. Resolve endpoint and payload contracts from current repository routes or official current documentation instead of guessing. A ticket slug can be read through GET https://api.closedloop.ai/documents/<slug> in the current platform.
  6. Treat an inactive localhost MCP URL, a missing initial registration, or a stale read-only intelligence index as an access-path issue, not proof of a ClosedLoop outage. Continue through the next valid fallback and state which source established live state.
  7. Report a genuine access blocker only after applicable discovery, Codex CLI MCP, and authenticated API paths have been exhausted or are unavailable.
  8. For ticket intelligence, discover the read-only closedloop-graph MCP by capability rather than by configured server name, using only discovery mechanisms supported by the current host. Treat it as the preferred indexed discovery surface for bounded PRD/plan/ split lineage, dependencies, semantic matches, duplicates, related tickets, and PR overlap, and for codebase intelligence including symbols, files, ownership boundaries, dependencies, call/data paths, co-change history, tests, and blast radius. Its results are not live authority: re-fetch material documents, relationships, comments, and status from ClosedLoop and verify code/PR claims against current repository and GitHub state.
TUI And App Server Compatibility
  • In Codex CLI TUI sessions, do not invoke dynamically discovered tools. The TUI reports Dynamic tool calls are not available in TUI yet and the call cannot complete.
  • Treat an already exposed MCP tool as capability-discovered by its description; do not rediscover it dynamically. When the required MCP is not statically exposed, use codex mcp/configured CLI access or the authenticated API fallback instead.
  • Inter-thread operations in CLI sweeps use the managed App Server session helper. Do not dynamically invoke codex_app or send_message_to_thread from the TUI. Desktop may use its statically available thread tools.

Required Reference

Before making, recommending, or recording blocker communications:

  1. Read references/local-policy.md when it exists.
  2. If references/local-policy.md is absent, read references/local-policy.example.md to understand the required shape, then read $HOME/.closedloop-ai/local-policy.md as the populated local policy.
  3. If both references/local-policy.md and $HOME/.closedloop-ai/local-policy.md exist, read the bundled policy first and the home-directory policy second as a user-local override.
  4. If no populated policy file exists, stop before posting blocker comments, sending direct messages, or launching routing-sensitive automation. Ask the user to create either references/local-policy.md in the shared skill pack or $HOME/.closedloop-ai/local-policy.md.
  5. Do not use references/local-policy.example.md as a live routing policy unless the user explicitly says the example values are the real policy for this environment.
Show full SKILL.md (513 more words)Show less

Direct User Authority And Decision Deduplication

  • Treat the newest direct user instruction for an exact named ticket as current authority over older ticket comments, workflow memory, analysis results, or blocker records. Re-fetch live safety and requirements facts, but never make the user repeat an unchanged approval because a stale record says it is missing.
  • Accept natural-language equivalence; never require a magic phrase. In the context of a known HIGH atomic ticket, instructions such as “proceed with ISS-1234, do not split it,” “work this ticket as one PR,” or an explicit correction that approval was already granted constitute the exact-ticket high-complexity atomic execution override. The user need not repeat the words HIGH, risk, override, or a prescribed sentence. A generic project sweep, assignment, priority, or “keep making progress” remains insufficient.
  • Once an override is accepted, persist it in workflow memory and the ticket record, query/read it back, and pass it to every later analysis/execution gate. Ask again only when the proposed implementation has materially expanded beyond the authorized atomic shape or newly becomes EXTREME; name that concrete delta instead of asking for the old approval again.
  • Treat a direct user ownership statement as routing authority. When the user says they created/own a ticket to fix a technical limitation, classify remaining interface, compatibility, versioning, chunking, validation, or fixture choices as engineering decisions unless they genuinely change unresolved product behavior. Ticket text containing “Product Questions” or a stale Product-tagged comment does not by itself make the ticket a Product blocker. Explain unresolved engineering choices in plain language to the user; do not tag the Product contact unless an independently actionable product decision remains.

Company-Visible Comment Boundary

Treat every ClosedLoop ticket comment as a company-visible product record. Automatic engineering or operational comments are forbidden. Keep complexity, risk, split/execution overrides, credentials/access, local environment, account identity, worker/session/generation/lease/worktree, callback/review/CI mechanics, internal scheduling, automation failures, workflow-memory state, and manual- intervention details in private sweep artifacts and the invoking Codex thread.

Post a comment automatically only for a genuine unresolved Product decision that requires the policy Product contact. Limit it to product behavior, user impact, and the minimum evidence needed to answer the question; exclude all internal automation and access details. Any engineering, operational, recordkeeping, split, or status comment requires an explicit user request for that exact comment on that exact ticket. A sweep invocation, assignment, blocker route, deleted historical comment, or worker recommendation is not authorization. Never recreate a comment the user removed.

Terms

  • Product contact: the ClosedLoop user tag for product blockers.
  • Engineering attention contact: the authenticated or invoking user who should review engineering blockers, high complexity, extreme risk, duplicates, malformed automation results, communication failures, or manual-intervention issues.
  • Sweep owner: the authenticated ClosedLoop user whose assigned tickets are being swept.

Usage

ClosedLoop automation skills should load this policy at the start of routing-sensitive work and use the policy terms in outputs and memory records. Do not hardcode the engineering attention contact's personal name in skill instructions, structured schemas, or memory field names.

For a shareable zip, include references/local-policy.example.md. Include references/local-policy.md only when the recipient should inherit that populated team policy.

© closedloop-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/code/skills/cl-policy of closedloop-ai/claude-plugins.

  • SKILL.md
  • agents/openai.yaml
  • references/local-policy.example.md
  • references/local-policy.md

Open the folder on GitHubat commit 0e20ac0

Compare with similar skills

Cl Policy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cl Policy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cl Policy this skillclosedloop-ai/claude-plugins122—~2.3kAutomated safety check: PassApache-2.0
MCP Server Builderanthropics/skills180k62 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k5 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official37k11 repos~3.1kAutomated safety check: PassApache-2.0
Fastmcp Client CLIPrefectHQ/fastmcp28k1 repos~823Automated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 62 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 5 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Fastmcp Client CLI

    PrefectHQ/fastmcp

    Query and invoke tools on MCP servers using fastmcp list and fastmcp call.

    28k GitHub starsUsed in 1 repo~823 tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated today
    Agent WorkflowsAuto-check passed

More from closedloop-ai/claude-plugins

All 43 skills in this repo
  • Codex Review

    closedloop-ai/claude-plugins

    Run Codex to review a plan file and return structured feedback with a verdict.

    122 GitHub stars~1.4k tokensUpdated today
    Auto-check: notes
  • Critic Cache

    closedloop-ai/claude-plugins

    Check if critic reviews are still valid before re-running Phase 2.5 critics.

    122 GitHub stars~528 tokensUpdated today
    Auto-check: notes
  • Cross Repo Cache

    closedloop-ai/claude-plugins

    Check if cross-repo coordinator results can be reused, avoiding redundant Sonnet agent launches.

    122 GitHub stars~683 tokensUpdated today
    Auto-check: notes
  • Eval Cache

    closedloop-ai/claude-plugins

    Check for a cached plan-evaluation.json result before launching the plan-evaluator agent.

    122 GitHub stars~516 tokensUpdated today
    Auto-check: notes
  • Find Plugin File

    closedloop-ai/claude-plugins

    This skill should be used when needing to locate files within the Claude Code plugins cache directory (~/.claude/plugins/cache).

    122 GitHub stars~812 tokensUpdated today
    Auto-check passed
  • Gh Monitor PR

    closedloop-ai/claude-plugins

    Start a detached GitHub pull-request monitor that wakes the exact launching Codex Desktop or CLI root through the managed Codex App Server when review, CI, conflict, merge-queue, closure, readiness…

    122 GitHub stars~5.1k tokensUpdated today
    Auto-check passed

Categories

Questions about Cl Policy

What does Cl Policy do?

Shared ClosedLoop access and routing policy for local ClosedLoop automation skills. Cl Policy is an agent skill from closedloop-ai/claude-plugins. Shared ClosedLoop access and routing policy for local ClosedLoop automation skills.

When should I use Cl Policy?

Cl Policy fits situations like: cl-execute needs to discover ClosedLoop tools; select a safe MCP/CLI/API access fallback; resolve product contacts; engineering attention contacts.

How do I install Cl Policy in Claude Code?

Run `npx skills add closedloop-ai/claude-plugins --skill cl-policy -a claude-code`. Or copy the skill folder (plugins/code/skills/cl-policy in closedloop-ai/claude-plugins) into .claude/skills/cl-policy in your project. Claude Code loads it when a task matches its description.

How do I install Cl Policy in Codex?

Run `npx skills add closedloop-ai/claude-plugins --skill cl-policy -a codex`. Or copy the skill folder (plugins/code/skills/cl-policy in closedloop-ai/claude-plugins) into .agents/skills/cl-policy in your project. Codex loads it when a task matches its description.

Can I use Cl Policy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add closedloop-ai/claude-plugins --skill cl-policy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cl-policy, .gemini/skills/cl-policy, .github/skills/cl-policy and .opencode/skills/cl-policy in your project.

What does Cl Policy need to run?

Going by SKILL.md and its folder, Cl Policy needs the command-line tools its instructions call (codex) and credentials named CLOSEDLOOP_API_KEY. Our summary lists: A credential in CLOSEDLOOP_API_KEY.

Does Cl Policy access the network?

SKILL.md names 1 domain. In commands or code: api.closedloop.ai; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cl Policy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cl Policy use?

Cl Policy is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cl Policy use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Cl Policy?

Skills that share tags, products or a category with Cl Policy: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars) and Fastmcp Client CLI (PrefectHQ/fastmcp, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cl Policy?

closedloop-ai (a GitHub organization) maintains it in closedloop-ai/claude-plugins, which has 122 GitHub stars. The repository holds 43 skills in this directory. The repository was last updated on October 7, 2026.

Source: closedloop-ai/claude-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.