Agent skill

Knowledge Permissions And Workspace Trust

by echoVic in echoVic/blade-code

覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。

MITAuto-check passedSecurity

Install Knowledge Permissions And Workspace Trust

skills CLI
$ npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install echoVic/blade-code knowledge-permissions-and-workspace-trust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/echoVic/blade-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust .claude/skills/knowledge-permissions-and-workspace-trust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
knowledge-permissions-and-workspace-trust
GitHub stars
181
Token cost
~1.8k tokens
SKILL.md length
447 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。

  • Tasks that involve Computer vision
  • SKILL.md covers Module Structure, Branching Table, Affected Scope and Gotchas, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Web application vulnerabilities

What it does

Knowledge Permissions And Workspace Trust is an agent skill from echoVic/blade-code. 覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。 使用时机:修改工具授权、排查为何调用被自动批准或拒绝、增加项目级可执行资源、处理信任继承、SSRF 或敏感路径。 不包含:配置文件通用合并见 layered-configuration-and-runtime-settings,工具执行阶段与并发见 tool-and-automation-platform/tool-execution-pipeline。 关键词:PermissionChecker, PermissionResolver, ToolApprovalController, WorkspaceTrustService, HookTrustService, SensitiveFileDetector, YOLO, PLAN。

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Computer vision and Web application vulnerabilities. The repository describes itself as: AI-powered CLI coding agent with 20+ built-in tools, MCP support, and multi-model providers. The licence is MIT.

When your agent uses it

  • Tasks that involve Computer vision
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/knowledge-permissions-and-workspace-trust”

What it can do on your machine

Read from SKILL.md and the folder at commit 30f8684. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Knowledge Permissions And Workspace Trust loads about 1.8k tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 447 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from echoVic/blade-code at commit 30f8684, republished under its MIT licence (© echoVic). 447 words, ~1,776 tokens.

Download SKILL.mdSave it as .claude/skills/knowledge-permissions-and-workspace-trust/SKILL.md (or your agent's skills folder).
name
knowledge-permissions-and-workspace-trust
description
覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。 使用时机:修改工具授权、排查为何调用被自动批准或拒绝、增加项目级可执行资源、处理信任继承、SSRF 或敏感路径。 不包含:配置文件通用合并见 layered-configuration-and-runtime-settings,工具执行阶段与并发见 tool-and-automation-platform/tool-execution-pipeline。 关键词:PermissionChecker, PermissionResolver, ToolApprovalController, WorkspaceTrustService, HookTrustService, SensitiveFileDetector, YOLO, PLAN。

Module Structure

权限系统先把工具调用归一化成规则签名,再应用运行模式、Session 审批和路径安全覆盖;Workspace Trust 则在资源加载前决定仓库控制的配置、命令和指令是否可见,外部 Hook 还需要独立摘要信任。

Directory Layout
  • packages/cli/src/config/PermissionChecker.ts — allow/ask/deny 规则和工具签名匹配
  • packages/cli/src/tools/execution/PermissionResolver.ts — 模式、审计 Agent、Session 记忆和敏感路径覆盖
  • packages/cli/src/tools/execution/ToolApprovalController.ts — 串行审批、Hook 审批和 project/session scope
  • packages/cli/src/tools/execution/ToolExecutionGuards.ts — CLI 白黑名单与 worktree 边界
  • packages/cli/src/tools/validation/SensitiveFileDetector.ts — 凭据、环境文件和敏感目录分类
  • packages/cli/src/security/WorkspaceIdentity.ts — canonical project 与 linked worktree trust root
  • packages/cli/src/security/WorkspaceTrustService.ts — 项目来源审阅、继承决策和安全存储
  • packages/cli/src/hooks/HookTrustService.ts — 外部 Hook 配置摘要信任
  • packages/cli/src/hooks/HttpHookSecurity.ts — Hook URL 协议和内网限制
  • packages/cli/src/browser/BrowserSecurity.ts — Browser origin、凭据控件和公开 URL 脱敏
Decision Entry
  • PermissionChecker.check() — 规则级 deny > allow > ask > default ask
  • PermissionResolver.resolveRulePermission() — 审计 Agent、permission mode、Session 记忆和敏感路径的组合入口
  • resolvePermissionDecision() — 规则结果与 PreToolUse Hook 决策的收紧合并
  • WorkspaceTrustService.getStatus() — 计算 not_required | trusted | untrusted | error
  • HookTrustService.getStatus() — 依据外部 Hook canonical digest 判断 trusted | modified

Branching Table

工具/规则条件defaultautoEditplanyolo
未匹配的 ReadOnly自动允许自动允许自动允许自动允许
未匹配的 Write请求确认自动允许拒绝自动允许
未匹配的 Execute请求确认请求确认拒绝自动允许
显式 allow 的 Write/Execute允许允许仍拒绝允许
显式 deny 的普通工具调用拒绝拒绝拒绝当前实现先被模式改写为允许
verification/review Agent 的写入或变异命令拒绝拒绝拒绝在模式覆盖前拒绝
中高敏感文件路径allow 会降为 ask,其余高敏感请求拒绝allow 会降为 ask,其余高敏感请求拒绝写操作先拒绝模式 allow 仍会降为 ask

Affected Scope

  • packages/cli/src/tools/execution/ — 每次工具调用的规则、Hook、审批和 safety override
  • packages/cli/src/agent/runtime/SessionRuntime.ts — Session 权限模式恢复与 workspace 规则装配
  • packages/cli/src/config/ConfigManager.ts — 可信项目权限、环境和可执行配置的过滤
  • packages/cli/src/plugins/ — 未信任项目的插件发现和启用阻断
  • packages/cli/src/skills/ 与 packages/cli/src/slash-commands/custom/ — 项目 Skill/命令的 trust gate
  • packages/cli/src/hooks/ — Folder Trust 之外的外部 Hook 摘要信任和 HTTP 安全
  • packages/cli/src/browser/ — URL/origin 分类、凭据控件和远端副作用审批
  • packages/cli/src/server/routes/permission.ts 与 packages/cli/src/server/routes/workspaceTrust.ts — Web 审批和信任操作

Gotchas

  • 生产 PermissionResolver 在普通工具路径中先处理 yolo,因此会把 PermissionChecker 的显式 deny 改写为 allow;之后只有 Hook 或路径 safety override 能再次收紧,不能根据旧的辅助测试假定 deny 一定高于 yolo (packages/cli/src/tools/execution/PermissionResolver.ts, packages/cli/tests/unit/config-security/permissions/permission-modes.test.ts)
  • 高敏感文件不会因普通 allow 或 yolo 直接放行:已有 allow 会被降为 ask,未获 allow 的高敏感访问直接 deny;危险系统路径始终 deny (packages/cli/src/tools/execution/PermissionResolver.ts)
  • PreToolUse Hook 修改参数后会重建 invocation、重跑 worktree 隔离并重新计算规则决策;只检查原始参数会漏掉 Hook 引入的路径或命令风险 (packages/cli/src/tools/execution/ToolExecutor.ts)
  • Hook 决策只能收紧已有规则:rule deny 不可被 Hook allow 放宽,rule ask 也不可被 Hook allow 跳过;双方都是 ask 时保留 Hook 的场景化原因 (packages/cli/src/tools/execution/PermissionResolver.ts, packages/cli/tests/unit/tooling/tools/execution/permission-resolver.test.ts)
  • 非交互表面没有 confirmationHandler 时,ask 不是隐式允许;除 yolo 外会返回结构化权限拒绝 (packages/cli/src/tools/execution/ToolApprovalController.ts)
  • project scope 审批写入目标 workspace 的 .blade/settings.local.json,而不是服务器启动 cwd;工具没有 abstractPermissionRule() 或返回空串时不得持久化宽泛授权 (packages/cli/src/tools/execution/ToolApprovalController.ts, git:7b34bd7e)
  • Session scope 记忆只绑定当前 permissionSignature,参数变化会形成新签名并再次审批;project scope 才会写可复用抽象规则 (packages/cli/src/tools/execution/ToolApprovalController.ts, packages/cli/src/tools/execution/SessionApprovalStore.ts)
  • Folder Trust 不等于 Hook Trust;仅含 Hook 的 settings 不触发 Folder Trust,但 command/http/prompt Hook 仍需按完整外部配置摘要单独批准,任何摘要变化都会进入 modified (packages/cli/src/security/WorkspaceTrustService.ts, packages/cli/src/hooks/HookTrustService.ts)
  • linked worktree 的 trust root 会映射到 common checkout 并保留 monorepo 子路径;直接用临时 worktree 绝对路径存决策会产生重复或错误信任身份 (packages/cli/src/security/WorkspaceIdentity.ts)
  • trust store 或 decision 文件的 owner、权限、schema、符号链接任一不符都会返回 error/fail closed;不要用普通 JSON 写入替代服务的 0600 原子写 (packages/cli/src/security/WorkspaceTrustService.ts)
  • Hook HTTP allowlist 命中会同时绕过 HTTPS、loopback 和私网限制;新增通配 host 时必须把它视为完整网络信任,而不只是域名过滤 (packages/cli/src/hooks/HttpHookSecurity.ts)
  • Browser URL 禁止内嵌 credentials,并把 query value 投影成 [redacted];日志或审批预览不应绕过 projectBrowserUrl() 输出原始查询参数 (packages/cli/src/browser/BrowserSecurity.ts)
Show full SKILL.md (115 more words)Show less

Architecture

  • 工具权限执行顺序为参数/白黑名单验证 → worktree 边界 → 规则与模式 → PreToolUse Hook → 参数变更后重新检查 → 规则/Hook 合并 → 串行人工审批 → scarce execution permit (packages/cli/src/tools/execution/ToolExecutor.ts)
  • Workspace Trust 审阅 package scripts、项目配置、插件、命令、Skills、Agents 和项目指令,但只投影受限摘要;环境变量只暴露名称,URL 去掉 query/credential (packages/cli/src/security/WorkspaceTrustService.ts)
  • Workspace 决策按最具体祖先生效,父目录 trust 可继承,子目录 revoke 可覆盖;决策身份是 canonical trust root 的 SHA-256 (packages/cli/src/security/WorkspaceTrustService.ts)

Decisions

  • 验证/代码审查 Agent 的只读边界在 permission mode 之前执行,即使父 Session 是 yolo,也只能运行经过语义识别的只读或验证命令 (packages/cli/src/tools/execution/PermissionResolver.ts)
  • 项目 Hook 使用独立 digest 信任而不是复用 Folder Trust,防止仓库在已信任后悄悄修改可执行 Hook (packages/cli/src/hooks/HookTrustService.ts, git:a172a7c)
  • trust/identity 缓存改为有界 LRU,防止长期多项目服务因历史 workspace 数量持续保留策略状态 (packages/cli/src/security/WorkspaceIdentity.ts, packages/cli/src/security/WorkspaceTrustService.ts, git:dff75aca, git:47ca3370)

Branching Behavior

  • 无敏感项目来源时状态为 not_required;存在敏感来源但无有效决策时为 untrusted;读取 trust store 失败时为 error,后二者均不得加载项目执行资源 (packages/cli/src/security/WorkspaceTrustService.ts)
  • 不可信项目配置中的普通字段被忽略,但 Hook 字段仍可进入独立摘要审阅,disableAllHooks=true 还可作为单向收紧生效 (packages/cli/src/config/ConfigManager.ts)
  • 普通只读 Bash 在规则默认为 ask 时可由语义分类自动放行,但显式 deny 仍先命中;verification Agent 还要求无后台执行、无 env 覆盖且 cwd 位于 workspace 内 (packages/cli/src/tools/execution/PermissionResolver.ts)
  • Browser public、private-network 和 loopback origin 会形成不同审批签名;交互还绑定 canonical expectedOrigin,页面跳转后不能复用旧快照权限 (packages/cli/src/browser/BrowserSecurity.ts, packages/cli/src/tools/execution/ToolApprovalController.ts)
  • Trust/Revoke 后先发布过滤后的启动配置,再断开 MCP 和重建 workspace 资源,避免旧可执行资源在新策略下继续被发现 (packages/cli/src/security/reloadWorkspaceTrust.ts, packages/cli/tests/unit/security/reload-workspace-trust.test.ts)

© echoVic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust of echoVic/blade-code.

Open the folder on GitHubat commit 30f8684

Compare with similar skills

Knowledge Permissions And Workspace Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Knowledge Permissions And Workspace Trust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Knowledge Permissions And Workspace Trust this skillechoVic/blade-code181—~1.8kAutomated safety check: PassMIT
AI LLM Agent Securityzhaji2333/CkSKILLS114—~4.7kAutomated safety check: WarnMIT
Hunt LLM AIelementalsouls/Claude-BugHunter4.8k—~4kAutomated safety check: WarnMIT
Moai Ref LLM Securitymodu-ai/moai-adk1.2k—~4.5kAutomated safety check: PassApache-2.0
Hunt LLMEncod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0

Similar skills

  • AI LLM Agent Security

    zhaji2333/CkSKILLS

    当目标为 LLM 应用/Chatbot/智能客服/AI 助手/Copilot/Agent/RAG 知识库/多模态模型,或发现用户输入进入大模型提示、工具调用、知识库检索、对话记忆、文件解析,或需要测试提示词注入/越狱逃逸/System Prompt 泄露/训练数据与敏感信息泄露/RAG 检索污染/Agent 记忆污染/工具滥用与命令执行/SSRF/沙箱逃逸时调用。负责 OWASP LLM…

    114 GitHub stars~4.7k tokensUpdated 25 days ago
    SecurityAuto-check: warnings
  • Hunt LLM AI

    elementalsouls/Claude-BugHunter

    Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10).

    4.8k GitHub stars~4k tokensUpdated yesterday
    SecurityAuto-check: warnings
  • Moai Ref LLM Security

    modu-ai/moai-adk

    AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…

    1.2k GitHub stars~4.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Hunt LLM

    Encod3d-Sec/TORCH

    LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage.

    329 GitHub stars~1.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes

More from echoVic/blade-code

All 38 skills in this repo
  • Base64 Parser

    echoVic/blade-code

    Base64 编解码工具,支持编码/解码文本、JSON、二进制文件,自动检测格式,支持批量处理. An agent skill from echoVic/blade-code.

    181 GitHub stars~545 tokensUpdated 12 days ago
    Auto-check: notes
  • Code Review

    echoVic/blade-code

    Review frontend code for best practices, bugs, and improvements.

    181 GitHub stars~377 tokensUpdated 12 days ago
    Auto-check: notes
  • GitHub Explorer

    echoVic/blade-code

    Explore and summarize popular GitHub projects. An agent skill from echoVic/blade-code.

    181 GitHub stars~434 tokensUpdated 12 days ago
    Auto-check passed
  • 覆盖 Session 级 LSP 配置快照、stdio 进程、文档同步、语义查询、诊断回注、崩溃恢复 和子 Session 继承。进入条件:新增语言服务器、修改 LSP 工具、排查诊断缺失/重复、 处理 worktree 或 ACP 差异、修复进程泄漏或 transport 代际问题。不包含:VS Code 扩展桥接(见…

    181 GitHub stars~1.9k tokensUpdated 12 days ago
    Auto-check passed
  • 覆盖 SkillRegistry、SKILL.md 延迟加载、自定义命令 Markdown 解析、来源覆盖、插件 命名空间、Session 快照和模型/用户调用入口。进入条件:新增 Skill 或命令字段、调整 发现优先级、调试 /command 或 Skill 工具、修改 Prompt 元数据或消费者集成。不包含: 插件安装生命周期(见…

    181 GitHub stars~2.1k tokensUpdated 12 days ago
    Auto-check passed
  • Covers 领域能力如何包装成内置工具、getBuiltinTools 的 Session 依赖注入、ToolSearch 延迟激活,以及 Goal/Task/Team/Plan/Skill/LSP/MCP/Web/Config/Worktree 适配边界。

    181 GitHub stars~2.1k tokensUpdated 12 days ago
    Auto-check passed

Questions about Knowledge Permissions And Workspace Trust

What does Knowledge Permissions And Workspace Trust do?

覆盖工具 allow/ask/deny、四种 permission mode、审批持久化、Workspace/Hook Trust、敏感文件以及 Hook/Browser 网络边界。. Knowledge Permissions And Workspace Trust is an agent skill from echoVic/blade-code.

When should I use Knowledge Permissions And Workspace Trust?

Knowledge Permissions And Workspace Trust fits situations like: tasks that involve Computer vision; tasks that involve Web application vulnerabilities.

How do I install Knowledge Permissions And Workspace Trust in Claude Code?

Run `npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a claude-code`. Or copy the skill folder (.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust in echoVic/blade-code) into .claude/skills/knowledge-permissions-and-workspace-trust in your project. Claude Code loads it when a task matches its description.

How do I install Knowledge Permissions And Workspace Trust in Codex?

Run `npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a codex`. Or copy the skill folder (.trae/knowledges/workspace-policy-and-shared-foundations/permissions-and-workspace-trust in echoVic/blade-code) into .agents/skills/knowledge-permissions-and-workspace-trust in your project. Codex loads it when a task matches its description.

Can I use Knowledge Permissions And Workspace Trust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add echoVic/blade-code --skill knowledge-permissions-and-workspace-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/knowledge-permissions-and-workspace-trust, .gemini/skills/knowledge-permissions-and-workspace-trust, .github/skills/knowledge-permissions-and-workspace-trust and .opencode/skills/knowledge-permissions-and-workspace-trust in your project.

What does Knowledge Permissions And Workspace Trust need to run?

SKILL.md names no scripts, command-line tools or credentials: Knowledge Permissions And Workspace Trust is instructions for the agent only.

Does Knowledge Permissions And Workspace Trust access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Knowledge Permissions And Workspace Trust safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Knowledge Permissions And Workspace Trust use?

Knowledge Permissions And Workspace Trust is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Knowledge Permissions And Workspace Trust use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Knowledge Permissions And Workspace Trust?

Skills that share tags, products or a category with Knowledge Permissions And Workspace Trust: AI LLM Agent Security (zhaji2333/CkSKILLS, 114 stars), Hunt LLM AI (elementalsouls/Claude-BugHunter, 4.8k stars), Moai Ref LLM Security (modu-ai/moai-adk, 1.2k stars) and Hunt LLM (Encod3d-Sec/TORCH, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Knowledge Permissions And Workspace Trust?

echoVic (a GitHub user) maintains it in echoVic/blade-code, which has 181 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 27, 2026.

Source: echoVic/blade-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.