Official agent skill

Restricted Tool Triage

by github in github/gh-aw

Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.

OfficialMITAuto-check passedDevelopment

Install Restricted Tool Triage

skills CLI
$ npx skills add github/gh-aw --skill restricted-tool-triage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/gh-aw restricted-tool-triage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/restricted-tool-triage .claude/skills/restricted-tool-triage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
restricted-tool-triage
GitHub stars
5.3k
Token cost
~1.2k tokens
SKILL.md length
687 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.

  • Works in 5 steps: Read the allowlist first, before acting.… → On the first denial, stop and pivot — do… → Budget awareness. Assume a low, fixed… → …
  • Development work in your project
  • SKILL.md covers Why this matters, Triggers, Procedure and Verification checklist, plus 1 more section
  • Calls git

What it does

Restricted Tool Triage is an agent skill from github/gh-aw, published by the product's own GitHub organization. Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with Bash, Git and Model Context Protocol. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/restricted-tool-triage”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read the allowlist first, before acting. Before issuing any shell/file/MCP command, check the workflow's declared tools: block…
  2. On the first denial, stop and pivot — do not retry variants. A denial is not a request to try a slightly different phrasing of the same…
  3. Budget awareness. Assume a low, fixed denial ceiling (verify from harness messages such as "N/M" if shown, e.g. "tool denial 2/3"). Once…
  4. Don't misreport scope-as-bug. A restricted toolset is very often an intentional, security-motivated author choice (least-privilege…
  5. Prefer completing partial work over aborting. If some parts of the task can be completed using only allowed tools, finish and report…

What it can do on your machine

Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Restricted Tool Triage loads about 1.2k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 687 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 687 words, ~1,221 tokens.

Download SKILL.mdSave it as .claude/skills/restricted-tool-triage/SKILL.md (or your agent's skills folder).
name
restricted-tool-triage
description
Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.

Restricted Tool Triage

Use this skill whenever you (the agent) are executing inside a gh-aw workflow whose frontmatter declares a narrow tools: allowlist (e.g. a short bash: [...] list, a scoped MCP toolsets, or no read/shell at all) and you hit — or are at risk of hitting — a "permission denied" / tool-denial response from the harness.

Why this matters

gh-aw enforces a hard, non-renewable denial budget per session (commonly 3 denied tool calls). Once the threshold is reached, the harness emits guard.tool_denials_exceeded and aborts the entire session immediately — no further turns, no partial credit, no chance to recover. Treat every tool denial as spending down a scarce budget, not as a way to probe what's allowed.

Triggers

  • A tool call returns "permission denied by workflow tool permissions" or similar.
  • You are about to try a shell/read/write command and are unsure if it's in the declared tools: allowlist.
  • The workflow frontmatter shows a short/explicit bash: list, restrictive MCP toolsets, or omits edit/bash entirely.

Procedure

  1. Read the allowlist first, before acting. Before issuing any shell/file/MCP command, check the workflow's declared tools: block (frontmatter bash: [...], edit:, MCP toolsets:, etc.) if visible in context, or infer it from the first denial message, which echoes the exact denied command. Do not assume general-purpose shell access is available just because the environment looks like a normal shell.

  2. On the first denial, stop and pivot — do not retry variants. A denial is not a request to try a slightly different phrasing of the same disallowed command (e.g. don't go from git status to git status --short to git diff --stat as three separate attempts). Instead:

    • Identify the capability you actually need (e.g. "see which files changed").
    • Map it to a tool/command explicitly present in the allowlist (e.g. use git diff --name-only if git diff:* is allowed but git status is not; use the already-available MCP toolset instead of raw read/shell for file or repo introspection).
    • If no allowed tool can achieve the capability, stop attempting workarounds for that capability and route around it (skip the sub-task, or note the limitation in your output) rather than spending more of the denial budget.
  3. Budget awareness. Assume a low, fixed denial ceiling (verify from harness messages such as "N/M" if shown, e.g. "tool denial 2/3"). Once you're at 1 remaining denial, do not attempt anything speculative — only proceed with actions you are confident are allowed.

  4. Don't misreport scope-as-bug. A restricted toolset is very often an intentional, security-motivated author choice (least-privilege workflow design), not a misconfiguration. Before calling missing_tool / missing_data / equivalent "report a gap" safe-output:

    • Confirm the missing capability is genuinely required to complete the task and has no in-allowlist substitute.
    • Do NOT claim "verify token scopes / repository permissions / credentials" when the actual evidence is a tools: allowlist denial — that phrasing wrongly suggests an infra/auth bug and can prompt maintainers to loosen permissions unnecessarily, which is a security regression.
    • If you do report a gap, name the specific missing tool/capability and cite the exact denied command(s), not a generic "permissions" narrative.
  5. Prefer completing partial work over aborting. If some parts of the task can be completed using only allowed tools, finish and report those, and clearly note what could not be done due to the restricted toolset — rather than continuing to probe disallowed tools until the session is forcibly terminated.

Show full SKILL.md (135 more words)Show less

Verification checklist

  • Did you check the declared tools: allowlist (or infer it from the first denial) before issuing further commands?
  • After any denial, did you switch to a different capability strategy rather than retry a denied command class?
  • Did you stay well under the denial threshold (ideally 0 denials, never risk the last one on a speculative call)?
  • If you reported a missing tool/capability, did you cite the specific denied command(s) instead of a generic "check credentials/permissions" claim?

Stop conditions

  • If you reach 2 denials, stop attempting anything not certain to be in the allowlist — finish with only allowed tools and report the limitation.
  • If the required capability has no allowed substitute, do not keep probing; complete what you can and clearly state the constraint in your final output rather than exhausting the denial budget.

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/restricted-tool-triage of github/gh-aw.

Open the folder on GitHubat commit eb63040

Compare with similar skills

Restricted Tool Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Restricted Tool Triage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Restricted Tool Triage this skillgithub/gh-aw5.3k—~1.2kAutomated safety check: PassMIT
Tapd Iteration InitTencentBlueKing/bk-bcs840—~1.3kAutomated safety check: PassCustom licence
Fewer Permission Promptsasgeirtj/system_prompts_leaks69k—~1.9kAutomated safety check: PassCC0-1.0
Dirextalk DeployerYingSuiAI/dirextalk-deployer457—~7.2kAutomated safety check: PassMIT
Cut Releasespiculedata/saiku1.3k—~502Automated safety check: PassApache-2.0
Cursor Composer Task DelegateChachamaru127/claude-code-harness3.2k—~4.4kAutomated safety check: NotesMIT

Similar skills

  • Tapd Iteration Init

    TencentBlueKing/bk-bcs

    迭代执行流水线启动器。分三个阶段执行:信息检查(验证 git 环境、获取迭代信息、 解析迭代分支)→ 恢复检测(已有状态文件时判定恢复策略)→ 新流程初始化(创建分支、 迭代目录和 iteration-state.json)。

    840 GitHub stars~1.3k tokensUpdated 13 days ago
    DevelopmentAuto-check passed
  • Fewer Permission Prompts

    asgeirtj/system_prompts_leaks

    Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.

    69k GitHub stars~1.9k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Dirextalk Deployer

    YingSuiAI/dirextalk-deployer

    Deploy, resume, verify, update, recover, reset, or destroy production Dirextalk services and nodes on AWS, and wire local agent runtimes.

    457 GitHub stars~7.2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Cut Release

    spiculedata/saiku

    Cut a Saiku release via Gitflow — version bump, release branch, PR to main, tag, back-merge, and post-release chores.

    1.3k GitHub stars~502 tokensUpdated today
    DevelopmentAuto-check passed
  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • Liveagent Code Review

    Stack-Cairn/LiveAgent

    Review an open GitHub pull request or the current local branch and working tree with parallel, independent reviewers and evidence-based validation.

    2.2k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed

More from github/gh-aw

All 52 skills in this repo
  • Official

    Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.

    5.3k GitHub starsUsed in 23 repos~2.8k tokens
    Auto-check passed
  • Official

    Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.

    5.3k GitHub stars~6.8k tokensUpdated today
    Auto-check passed
  • Official

    Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.

    5.3k GitHub stars~3.7k tokensUpdated today
    Auto-check passed
  • Official

    Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.

    5.3k GitHub stars~3.8k tokensUpdated today
    Auto-check: warnings
  • Official

    Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.

    5.3k GitHub stars~899 tokensUpdated today
    Auto-check passed
  • Official

    Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.

    5.3k GitHub stars~736 tokensUpdated today
    Auto-check passed

Categories

Questions about Restricted Tool Triage

What does Restricted Tool Triage do?

Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget. Restricted Tool Triage is an agent skill from github/gh-aw, published by the product's own GitHub organization. Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.

When should I use Restricted Tool Triage?

Restricted Tool Triage fits situations like: development work in your project.

How do I install Restricted Tool Triage in Claude Code?

Run `npx skills add github/gh-aw --skill restricted-tool-triage -a claude-code`. Or copy the skill folder (.github/skills/restricted-tool-triage in github/gh-aw) into .claude/skills/restricted-tool-triage in your project. Claude Code loads it when a task matches its description.

How do I install Restricted Tool Triage in Codex?

Run `npx skills add github/gh-aw --skill restricted-tool-triage -a codex`. Or copy the skill folder (.github/skills/restricted-tool-triage in github/gh-aw) into .agents/skills/restricted-tool-triage in your project. Codex loads it when a task matches its description.

Can I use Restricted Tool Triage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill restricted-tool-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/restricted-tool-triage, .gemini/skills/restricted-tool-triage, .github/skills/restricted-tool-triage and .opencode/skills/restricted-tool-triage in your project.

What does Restricted Tool Triage need to run?

Going by SKILL.md and its folder, Restricted Tool Triage needs the command-line tools its instructions call (git).

Does Restricted Tool Triage access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Restricted Tool Triage safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Restricted Tool Triage use?

Restricted Tool Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Restricted Tool Triage use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Restricted Tool Triage?

Skills that share tags, products or a category with Restricted Tool Triage: Tapd Iteration Init (TencentBlueKing/bk-bcs, 840 stars), Fewer Permission Prompts (asgeirtj/system_prompts_leaks, 69k stars), Dirextalk Deployer (YingSuiAI/dirextalk-deployer, 457 stars) and Cut Release (spiculedata/saiku, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Restricted Tool Triage?

github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.