Agent skill

Add Permission

by fullstackhero in fullstackhero/dotnet-starter-kit

Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard.

MITAuto-check passedBackend & APIs

Install Add Permission

skills CLI
$ npx skills add fullstackhero/dotnet-starter-kit --skill add-permission -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fullstackhero/dotnet-starter-kit add-permission --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fullstackhero/dotnet-starter-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/add-permission .claude/skills/add-permission && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-permission
GitHub stars
6.8k
Token cost
~849 tokens
SKILL.md length
280 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard.

  • Works in 5 steps: Server constant… → Gate the endpoint → (admin only) mirror it → …
  • A new endpoint needs authorization
  • SKILL.md covers Step 1 — Server constant…, Step 2 — Gate the endpoint, Step 3 — (admin only) mirror it and Step 4 — (admin only) gate the…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Add Permission is an agent skill from fullstackhero/dotnet-starter-kit. Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard. Use when a new endpoint needs authorization. See modules/identity.md + frontend/admin.md.

Its SKILL.md is about 850 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Project scaffolding and Authorization and RBAC. The repository describes itself as: Production Grade Cloud-Ready .NET 10 Starter Kit (Web API + React Client) with Multitenancy Support, and Clean/Modular Architecture that saves roughly 200+ Development Hours! All… The licence is MIT.

When your agent uses it

  • A new endpoint needs authorization
  • Tasks that involve Project scaffolding
  • Tasks that involve Authorization and RBAC

Example prompts

  • “/add-permission”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Server constant (Modules.{X}.Contracts/Authorization/{X}Permissions.cs)
  2. Gate the endpoint
  3. (admin only) mirror it
  4. (admin only) gate the route
  5. (admin only) seed it in tests

What it can do on your machine

Read from SKILL.md and the folder at commit 0bd98e3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are csharp and typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add Permission loads about 849 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 280 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~849

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fullstackhero/dotnet-starter-kit at commit 0bd98e3, republished under its MIT licence (© fullstackhero). 280 words, ~849 tokens.

Download SKILL.mdSave it as .claude/skills/add-permission/SKILL.md (or your agent's skills folder).
name
add-permission
description
Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard. Use when a new endpoint needs authorization. See modules/identity.md + frontend/admin.md.
argument-hint
[ModuleName] [Resource] [Action]

Add Permission

A permission spans server + the admin app. The dashboard app does not mirror permissions — it reads them from the JWT and relies on the server's 403.

Step 1 — Server constant (Modules.{X}.Contracts/Authorization/{X}Permissions.cs)

Add the constant to the resource group and ensure it's in the module's All collection. Convention: Permissions.{Resource}.{Action}.

csharp
public static class {X}Permissions
{
    public static class {Resources}
    {
        public const string View   = "Permissions.{Resources}.View";
        public const string Create = "Permissions.{Resources}.Create";   // ← new
    }
    public static IReadOnlyList<FshPermission> All { get; } = [ /* … include the new one … */ ];
}

The module already calls PermissionConstants.Register({X}Permissions.All) in ConfigureServices, so a new entry in All is picked up automatically.

Step 2 — Gate the endpoint

csharp
.RequirePermission({X}Permissions.{Resources}.Create);

⚠️ RequiredPermissionAttribute implements IRequiredPermissionMetadata. Never let a second/duplicate of that interface exist — it silently disables all .RequirePermission() gates app-wide. (See .agents/rules/modules/identity.md.)

Step 3 — (admin only) mirror it

clients/admin/src/lib/permissions.ts — add the matching string to the frozen tree (no runtime catalog endpoint exists; mirror by hand):

ts
export const {Module}Permissions = Object.freeze({
  {Resources}: { View: "Permissions.{Resources}.View", Create: "Permissions.{Resources}.Create" },
} as const);

If it should appear in the Role editor UI, add a PERMISSION_CATALOG entry ({ name, description, root?, basic? } under the right category group).

Step 4 — (admin only) gate the route

tsx
{ path: "{resources}/new",
  element: <RouteGuard perms={[{Module}Permissions.{Resources}.Create]}><Create{Resource}Page /></RouteGuard> },

Step 5 — (admin only) seed it in tests

So RouteGuard passes on first paint, add the new permission to the test seed set (ADMIN_PERMS in clients/admin/tests/helpers/shell-mocks.ts, used by seedAuthedSession).

Dashboard

No mirror, no RouteGuard. The JWT carries only role names — the app fetches the permission list from GET /api/v1/identity/permissions at hydration and the server enforces access; a missing permission yields a 403 the UI surfaces. Routes aren't permission-gated; to hide a nav entry, set perm/anyPerm on the item in src/components/layout/nav-data.ts. Permission-gated specs mock GET /identity/permissions with the grants they need (shell mocks stub it to []).

Checklist

  • Server constant added to {X}Permissions and its All collection
  • Endpoint gated with .RequirePermission(...); no duplicate IRequiredPermissionMetadata
  • (admin) mirrored in lib/permissions.ts (+ PERMISSION_CATALOG if role-editor-visible)
  • (admin) route wrapped in <RouteGuard perms={[…]}>; permission added to ADMIN_PERMS test seed
  • Build green; admin test:e2e green

© fullstackhero, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/add-permission of fullstackhero/dotnet-starter-kit.

Open the folder on GitHubat commit 0bd98e3

Compare with similar skills

Add Permission next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add Permission compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add Permission this skillfullstackhero/dotnet-starter-kit6.8k—~849Automated safety check: PassMIT
Add API Resourcewso2/agent-manager105—~1.1kAutomated safety check: PassApache-2.0
Plugin BuilderAIDotNet/NextCoWork638—~2.4kAutomated safety check: PassApache-2.0
ToolJet Marketplace Plugin BuilderToolJet/ToolJet41k—~2.1kAutomated safety check: PassAGPL-3.0
K8s Security PoliciesCybereason-Public/owLSM28011 repos~2kAutomated safety check: PassGPL-2.0
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT

Similar skills

  • Add API Resource

    wso2/agent-manager

    Add or change a REST API resource in agent-manager-service (the Go control plane).

    105 GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Plugin Builder

    AIDotNet/NextCoWork

    Author, package, and debug NextCoWork plugins — the single entry point.

    638 GitHub stars~2.4k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.

    41k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 11 repos~2k tokens
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Builder Smoke Test

    mastra-ai/mastra

    Smoke test the Agent Builder feature branch end-to-end against a hermetic project scaffolded by the skill (linked to the current worktree).

    29k GitHub stars~11k tokensUpdated today
    Testing & QAAuto-check: notes

More from fullstackhero/dotnet-starter-kit

All 11 skills in this repo
  • Add Entity

    fullstackhero/dotnet-starter-kit

    Add a domain entity/aggregate with EF configuration and a migration to an existing FSH module.

    6.8k GitHub stars~1.2k tokensUpdated 7 days ago
    Auto-check passed
  • Add Feature

    fullstackhero/dotnet-starter-kit

    Add a vertical-slice feature (command/query + handler + validator + endpoint) to an existing FSH module.

    6.8k GitHub stars~1.1k tokensUpdated 7 days ago
    Auto-check passed
  • Add Full Slice

    fullstackhero/dotnet-starter-kit

    Build a capability end-to-end — backend vertical slice (Contracts→handler→validator→endpoint) AND the React page wired to it.

    6.8k GitHub stars~783 tokensUpdated 7 days ago
    Auto-check passed
  • Add Integration Event

    fullstackhero/dotnet-starter-kit

    Publish a cross-module integration event via the Outbox and handle it idempotently in another module.

    6.8k GitHub stars~1.1k tokensUpdated 7 days ago
    Auto-check passed
  • Add Module

    fullstackhero/dotnet-starter-kit

    Create a new module (bounded context) — runtime + Contracts projects, IModule, DbContext, permissions, migrations, and the four registration sites.

    6.8k GitHub stars~1.5k tokensUpdated 7 days ago
    Auto-check passed
  • Add React Page

    fullstackhero/dotnet-starter-kit

    Add a list+create page to a React app (clients/admin or clients/dashboard) — API module, page, lazy route, (admin) permission gate, Playwright test.

    6.8k GitHub stars~1.5k tokensUpdated 7 days ago
    Auto-check passed

Questions about Add Permission

What does Add Permission do?

Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard. Add Permission is an agent skill from fullstackhero/dotnet-starter-kit. Add a new permission end-to-end — server constant + endpoint gate, and (admin app) mirror it into the permissions catalog + route guard.

When should I use Add Permission?

Add Permission fits situations like: A new endpoint needs authorization; tasks that involve Project scaffolding; tasks that involve Authorization and RBAC.

How do I install Add Permission in Claude Code?

Run `npx skills add fullstackhero/dotnet-starter-kit --skill add-permission -a claude-code`. Or copy the skill folder (.agents/skills/add-permission in fullstackhero/dotnet-starter-kit) into .claude/skills/add-permission in your project. Claude Code loads it when a task matches its description.

How do I install Add Permission in Codex?

Run `npx skills add fullstackhero/dotnet-starter-kit --skill add-permission -a codex`. Or copy the skill folder (.agents/skills/add-permission in fullstackhero/dotnet-starter-kit) into .agents/skills/add-permission in your project. Codex loads it when a task matches its description.

Can I use Add Permission in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fullstackhero/dotnet-starter-kit --skill add-permission -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-permission, .gemini/skills/add-permission, .github/skills/add-permission and .opencode/skills/add-permission in your project.

What does Add Permission need to run?

SKILL.md names no scripts, command-line tools or credentials: Add Permission is instructions for the agent only.

Does Add Permission access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Add Permission safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add Permission use?

Add Permission is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Add Permission use?

About 849 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Add Permission?

Skills that share tags, products or a category with Add Permission: Add API Resource (wso2/agent-manager, 105 stars), Plugin Builder (AIDotNet/NextCoWork, 638 stars), ToolJet Marketplace Plugin Builder (ToolJet/ToolJet, 41k stars) and K8s Security Policies (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add Permission?

fullstackhero (a GitHub organization) maintains it in fullstackhero/dotnet-starter-kit, which has 6,813 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on September 30, 2026.

Source: fullstackhero/dotnet-starter-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.