Agent skill

Cx Platform Admin

by coralogix in coralogix/cx-cli

A skill your agent uses when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired…

Apache-2.0Auto-check passedBackend & APIs

Install Cx Platform Admin

skills CLI
$ npx skills add coralogix/cx-cli --skill cx-platform-admin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install coralogix/cx-cli cx-platform-admin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/coralogix/cx-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cx-platform-admin .claude/skills/cx-platform-admin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cx-platform-admin
GitHub stars
121
Token cost
~1.8k tokens
SKILL.md length
854 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired…

  • Works in 6 steps: List All Users → List Roles → List Groups and Memberships → …
  • The user asks who has access
  • SKILL.md covers Destructive Operation Safety, CLI Commands, Access Audit Workflow and API Key Rotation, plus 3 more sections
  • Calls jq

What it does

Cx Platform Admin is an agent skill from coralogix/cx-cli. Use this skill when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired keys", "send data keys", "IP allowlist", "IP access restrictions", "check IP whitelist", "add user", "deactivate user", "manage team groups", "user permissions", "role-based access", "manage scopes", "system roles", "API key admin", "team member keys", "group membership", or wants to audit, manage, or configure access controls…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and Access reviews and audit trails. The repository describes itself as: This is the Coralogix CLI. The licence is Apache-2.0.

When your agent uses it

  • The user asks who has access
  • Audit permissions
  • Check user roles
  • Review access controls

Example prompts

  • “who has access”
  • “audit permissions”
  • “check user roles”
  • “/cx-platform-admin”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. List All Users
  2. List Roles
  3. List Groups and Memberships
  4. Inventory API Keys
  5. Check IP Restrictions
  6. Cross-Reference

What it can do on your machine

Read from SKILL.md and the folder at commit c071372. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cx Platform Admin loads about 1.8k tokens when it runs. Until then it costs about 140 tokens; SKILL.md has 854 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~140
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from coralogix/cx-cli at commit c071372, republished under its Apache-2.0 licence (© coralogix). 854 words, ~1,829 tokens.

Download SKILL.mdSave it as .claude/skills/cx-platform-admin/SKILL.md (or your agent's skills folder).
name
cx-platform-admin
description
Use this skill when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired keys", "send data keys", "IP allowlist", "IP access restrictions", "check IP whitelist", "add user", "deactivate user", "manage team groups", "user permissions", "role-based access", "manage scopes", "system roles", "API key admin", "team member keys", "group membership", or wants to audit, manage, or configure access controls for a Coralogix account.
metadata.version
0.1.0

Platform Admin Skill

Use this skill for managing access, authentication, and authorization in Coralogix. It covers API key management, role and scope definitions, user administration, team groups, and IP access restrictions.


Destructive Operation Safety

All write operations (create, update, delete, set-idp, set-active, set-status) require interactive confirmation. The CLI will prompt before executing. To skip the prompt in scripts, pass --yes.

IMPORTANT: NEVER pass --yes without explicit user approval. Before executing any write operation:

  1. Describe the exact operation to the user (what will be created/modified/deleted)
  2. Wait for the user to confirm
  3. Only then execute with --yes

Read-only operations (list, get, search, system, sp-params, send-data-keys) do not require confirmation and can be run freely.

Read-Only Mode

Use --read-only (or CX_READ_ONLY=1) to block all write operations at the CLI level. This is useful for safe exploration - you can query any IAM resource without risk of accidental modifications.

Agent Mode

When running inside an AI agent (Claude Code, Cursor, Codex, etc.), cx automatically detects the agent environment and fails fast on write operations instead of hanging on a stdin prompt. The error message instructs you to get user confirmation first, then re-run with --yes.


CLI Commands

API Keys
CommandPurpose
cx iam api-keys listList all API keys
cx iam api-keys get <id>Get a single API key
cx iam api-keys create --from-fileCreate an API key
cx iam api-keys update --from-file <id>Update an API key
cx iam api-keys delete <id>Delete an API key
cx iam api-keys send-data-keysList send-data API keys
cx iam api-keys admin listList all team members' keys
cx iam api-keys admin delete --ids <id1> <id2>Bulk delete keys
cx iam api-keys admin set-status --ids <id1> --active true/falseActivate/deactivate keys
Roles & Scopes
CommandPurpose
cx iam roles listList custom roles
cx iam roles get <id>Get a role definition
cx iam roles create --from-fileCreate a custom role
cx iam roles update --from-file <id>Update a custom role
cx iam roles delete <id>Delete a custom role
cx iam roles systemList system (built-in) roles
cx iam scopes listList all scopes
cx iam scopes get <id>Get a scope definition
cx iam scopes create --from-fileCreate a scope
cx iam scopes update --from-fileUpdate a scope
cx iam scopes delete <id>Delete a scope
Users & Groups
CommandPurpose
cx iam users searchSearch users (optional --query, --status)
cx iam users get <user-id>Get a single user
cx iam users create --from-fileCreate user(s)
cx iam users update --from-fileUpdate user(s)
cx iam users set-status --user-ids <id> --status ACTIVE/INACTIVEActivate/deactivate users
cx iam groups listList all team groups
cx iam groups get <id>Get a group by ID
cx iam groups get-by-name <name>Get a group by name
cx iam groups users <group-id>List users in a group
cx iam groups create --from-fileCreate a group
cx iam groups update --from-file <id>Update a group
cx iam groups delete <id>Delete a group
Show full SKILL.md (364 more words)Show less
IP Access
CommandPurpose
cx iam ip-access getGet IP access settings
cx iam ip-access create --from-fileCreate IP access rules
cx iam ip-access update --from-fileUpdate IP access rules
cx iam ip-access deleteDelete IP access settings

All commands support -o json for structured output and -p <profile> for profile selection.


Access Audit Workflow

Use this workflow to produce a comprehensive access report:

Step 1: List All Users
bash
cx iam users search -o json
cx iam users search -o json | jq '[.[] | {id, name: .user_name, status, role_ids}]'
Step 2: List Roles
bash
cx iam roles list -o json
cx iam roles system -o json

Cross-reference user role IDs with role definitions to understand permissions.

Step 3: List Groups and Memberships
bash
cx iam groups list -o json
cx iam groups list -o json | jq '[.[] | {id, name, member_count: (.members | length)}]'

For each group, check members:

bash
cx iam groups users <group-id> -o json
Step 4: Inventory API Keys
bash
cx iam api-keys list -o json
cx iam api-keys admin list -o json
cx iam api-keys send-data-keys -o json

Identify old or unused keys:

bash
cx iam api-keys list -o json | jq '[.[] | {id, name, created_at, active}] | sort_by(.created_at)'
Step 5: Check IP Restrictions
bash
cx iam ip-access get -o json
Step 6: Cross-Reference

Produce a summary: which users have admin roles, which API keys are old, which groups have broad access.


API Key Rotation

Safe key rotation workflow:

  1. List current keys: cx iam api-keys list -o json
  2. Identify keys to rotate: filter by age or name
  3. Create replacement key: cx iam api-keys create --from-file new-key.json --yes (after user approval)
  4. Deploy the new key to all systems using the old key
  5. Verify the new key works in all integrations
  6. Delete the old key: cx iam api-keys delete <old-key-id> --yes (after user approval)

WARNING: Never delete an API key before its replacement is deployed and verified. Deleting an active key immediately breaks all integrations using it.


Safety Callouts

Deleting API keys breaks any integration using that key immediately. Always create a replacement first.

Deactivating users (cx iam users set-status --status INACTIVE) takes effect immediately. The user loses access with no grace period.

Deleting IP access rules (cx iam ip-access delete) removes all IP restrictions immediately, potentially exposing the account.


Key Principles

  • Audit before modifying - run the full access audit workflow before making changes
  • Never delete keys without replacement - create new key → deploy → verify → delete old
  • Use -o json for structured reports - enables jq filtering for precise access analysis
  • Multi-profile for cross-environment audits - use -p <profile> or --all-profiles to audit staging + production
  • Template from existing - cx iam roles get <id> -o json > role.json before creating new roles

  • cx-cost-optimization - review what API keys are used for and whether they're still needed

© coralogix, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cx-platform-admin of coralogix/cx-cli.

Open the folder on GitHubat commit c071372

Compare with similar skills

Cx Platform Admin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cx Platform Admin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cx Platform Admin this skillcoralogix/cx-cli121—~1.8kAutomated safety check: PassApache-2.0
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Access And Identitycbrock84/headcount2k—~1.1kAutomated safety check: PassMIT
Access Matrixsickn33/agentic-awesome-skills47k1 repos~3.6kAutomated safety check: PassMIT
Adobe Enterprise Rbacjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Fireflies Enterprise Rbacjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT

Similar skills

  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Access And Identity

    cbrock84/headcount

    Designs and audits who can reach what — authentication, authorization models, privileged access, service credentials, and joiner-mover-leaver process.

    2k GitHub stars~1.1k tokensUpdated 22 days ago
    Backend & APIsAuto-check passed
  • Access Matrix

    sickn33/agentic-awesome-skills

    Access matrix of role-by-module permissions, with per-role scope, confidentiality level and SME tier, as CSV, SQL, JSON Schema or Notion on request.

    47k GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed
  • Adobe Enterprise Rbac

    jeremylongshore/tons-of-skills-marketplace

    Govern Adobe Developer Console roles, product profiles, technical accounts, User Management API automation, and periodic access review.

    2.8k GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Fireflies Enterprise Rbac

    jeremylongshore/tons-of-skills-marketplace

    Govern Fireflies team roles, channels, privacy, sharing, and privileged mutations with current permission and rate-limit checks.

    2.8k GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Instantly Enterprise Rbac

    jeremylongshore/tons-of-skills-marketplace

    Govern Instantly workspace members, API-key scopes, audit logs, and workspace-group delegation.

    2.8k GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed

More from coralogix/cx-cli

All 21 skills in this repo
  • Cx AI Center

    coralogix/cx-cli

    A skill your agent uses for any question or action about the user's AI/GenAI applications or agents — their behavior, prompts/responses, quality, hallucinations, guardrails, security, cost/tokens…

    121 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Cx Alerts

    coralogix/cx-cli

    This skill should be used when the user asks to "manage alerts", "create alert", "list alerts", "delete alert", "check alert status", "enable alert", "disable alert", "investigate firing alerts"…

    121 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Cx Coding Agents

    coralogix/cx-cli

    A skill your agent uses when the user asks about AI Center Coding Agents data, wants to reproduce or extend the Coding Agents dashboards, or asks questions about usage, cost, tokens, sessions…

    121 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Cx Cost Optimization

    coralogix/cx-cli

    A skill your agent uses when the user asks to "check data usage", "list TCO policies", "reduce Coralogix costs", "optimize observability spend", "lower our logging bill", "data budget exceeded"…

    121 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Cx Data Pipeline

    coralogix/cx-cli

    A skill your agent uses when the user asks to "set up parsing", "create parsing rule", "extract fields from logs", "regex extraction", "log parsing", "enrich logs", "add context to logs", "custom…

    121 GitHub stars~3k tokensUpdated 2 days ago
    Auto-check passed
  • Cx Telemetry Querying

    coralogix/cx-cli

    A skill your agent uses for any question involving telemetry data: "investigate an issue", "debug a problem", "find out why something is slow", "check error rates", "analyze user behavior"…

    121 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed

Questions about Cx Platform Admin

What does Cx Platform Admin do?

A skill your agent uses when the user asks "who has access", "audit permissions", "check user roles", "list API keys", "review access controls", "rotate API keys", "create API key", "delete expired…. Cx Platform Admin is an agent skill from coralogix/cx-cli.

When should I use Cx Platform Admin?

Cx Platform Admin fits situations like: the user asks who has access; audit permissions; check user roles; review access controls.

How do I install Cx Platform Admin in Claude Code?

Run `npx skills add coralogix/cx-cli --skill cx-platform-admin -a claude-code`. Or copy the skill folder (skills/cx-platform-admin in coralogix/cx-cli) into .claude/skills/cx-platform-admin in your project. Claude Code loads it when a task matches its description.

How do I install Cx Platform Admin in Codex?

Run `npx skills add coralogix/cx-cli --skill cx-platform-admin -a codex`. Or copy the skill folder (skills/cx-platform-admin in coralogix/cx-cli) into .agents/skills/cx-platform-admin in your project. Codex loads it when a task matches its description.

Can I use Cx Platform Admin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add coralogix/cx-cli --skill cx-platform-admin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cx-platform-admin, .gemini/skills/cx-platform-admin, .github/skills/cx-platform-admin and .opencode/skills/cx-platform-admin in your project.

What does Cx Platform Admin need to run?

Going by SKILL.md and its folder, Cx Platform Admin needs the command-line tools its instructions call (jq).

Does Cx Platform Admin access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cx Platform Admin safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cx Platform Admin use?

Cx Platform Admin is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cx Platform Admin use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cx Platform Admin?

Skills that share tags, products or a category with Cx Platform Admin: Django Access Review (getsentry/skills, 1k stars), Access And Identity (cbrock84/headcount, 2k stars), Access Matrix (sickn33/agentic-awesome-skills, 47k stars) and Adobe Enterprise Rbac (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cx Platform Admin?

coralogix (a GitHub organization) maintains it in coralogix/cx-cli, which has 121 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: coralogix/cx-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.