Tapd Iteration Init
TencentBlueKing/bk-bcs
迭代执行流水线启动器。分三个阶段执行:信息检查(验证 git 环境、获取迭代信息、 解析迭代分支)→ 恢复检测(已有状态文件时判定恢复策略)→ 新流程初始化(创建分支、 迭代目录和 iteration-state.json)。
Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.
$ npx skills add github/gh-aw --skill restricted-tool-triage -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/gh-aw restricted-tool-triage --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/restricted-tool-triage .claude/skills/restricted-tool-triage && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "restricted-tool-triage" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/restricted-tool-triage into .claude/skills/restricted-tool-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-tool-triage", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/gh-aw/tree/main/.github/skills/restricted-tool-triageType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/gh-aw --skill restricted-tool-triage -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/gh-aw restricted-tool-triage --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/restricted-tool-triage .agents/skills/restricted-tool-triage && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "restricted-tool-triage" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/restricted-tool-triage into .agents/skills/restricted-tool-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-tool-triage", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill restricted-tool-triage -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/gh-aw restricted-tool-triage --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/restricted-tool-triage .cursor/skills/restricted-tool-triage && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "restricted-tool-triage" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/restricted-tool-triage into .cursor/skills/restricted-tool-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-tool-triage", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/gh-aw.git --path .github/skills/restricted-tool-triage--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/gh-aw --skill restricted-tool-triage -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/gh-aw restricted-tool-triage --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/restricted-tool-triage .gemini/skills/restricted-tool-triage && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "restricted-tool-triage" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/restricted-tool-triage into .gemini/skills/restricted-tool-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-tool-triage", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/gh-aw restricted-tool-triageInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/gh-aw --skill restricted-tool-triage -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/restricted-tool-triage .github/skills/restricted-tool-triage && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "restricted-tool-triage" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/restricted-tool-triage into .github/skills/restricted-tool-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-tool-triage", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/gh-aw --skill restricted-tool-triage -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/gh-aw restricted-tool-triage --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/gh-aw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/restricted-tool-triage .opencode/skills/restricted-tool-triage && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "restricted-tool-triage" agent skill from https://github.com/github/gh-aw/tree/main/.github/skills/restricted-tool-triage into .opencode/skills/restricted-tool-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "restricted-tool-triage", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
restricted-tool-triageOperate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.
Restricted Tool Triage is an agent skill from github/gh-aw, published by the product's own GitHub organization. Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development. It works with Bash, Git and Model Context Protocol. The repository describes itself as: GitHub Agentic Workflows. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit eb63040. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Restricted Tool Triage loads about 1.2k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 687 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/gh-aw at commit eb63040, republished under its MIT licence (© github). 687 words, ~1,221 tokens.
.claude/skills/restricted-tool-triage/SKILL.md (or your agent's skills folder).Use this skill whenever you (the agent) are executing inside a gh-aw workflow whose frontmatter declares a narrow tools: allowlist (e.g. a short bash: [...] list, a scoped MCP toolsets, or no read/shell at all) and you hit — or are at risk of hitting — a "permission denied" / tool-denial response from the harness.
gh-aw enforces a hard, non-renewable denial budget per session (commonly 3 denied tool calls). Once the threshold is reached, the harness emits guard.tool_denials_exceeded and aborts the entire session immediately — no further turns, no partial credit, no chance to recover. Treat every tool denial as spending down a scarce budget, not as a way to probe what's allowed.
tools: allowlist.bash: list, restrictive MCP toolsets, or omits edit/bash entirely.Read the allowlist first, before acting. Before issuing any shell/file/MCP command, check the workflow's declared tools: block (frontmatter bash: [...], edit:, MCP toolsets:, etc.) if visible in context, or infer it from the first denial message, which echoes the exact denied command. Do not assume general-purpose shell access is available just because the environment looks like a normal shell.
On the first denial, stop and pivot — do not retry variants. A denial is not a request to try a slightly different phrasing of the same disallowed command (e.g. don't go from git status to git status --short to git diff --stat as three separate attempts). Instead:
git diff --name-only if git diff:* is allowed but git status is not; use the already-available MCP toolset instead of raw read/shell for file or repo introspection).Budget awareness. Assume a low, fixed denial ceiling (verify from harness messages such as "N/M" if shown, e.g. "tool denial 2/3"). Once you're at 1 remaining denial, do not attempt anything speculative — only proceed with actions you are confident are allowed.
Don't misreport scope-as-bug. A restricted toolset is very often an intentional, security-motivated author choice (least-privilege workflow design), not a misconfiguration. Before calling missing_tool / missing_data / equivalent "report a gap" safe-output:
tools: allowlist denial — that phrasing wrongly suggests an infra/auth bug and can prompt maintainers to loosen permissions unnecessarily, which is a security regression.Prefer completing partial work over aborting. If some parts of the task can be completed using only allowed tools, finish and report those, and clearly note what could not be done due to the restricted toolset — rather than continuing to probe disallowed tools until the session is forcibly terminated.
tools: allowlist (or infer it from the first denial) before issuing further commands?© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/restricted-tool-triage of github/gh-aw.
Open the folder on GitHubat commit eb63040
Restricted Tool Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Restricted Tool Triage this skillgithub/gh-aw | 5.3k | — | ~1.2k | Automated safety check: Pass | MIT | |
| Tapd Iteration InitTencentBlueKing/bk-bcs | 840 | — | ~1.3k | Automated safety check: Pass | Custom licence | |
| Fewer Permission Promptsasgeirtj/system_prompts_leaks | 69k | — | ~1.9k | Automated safety check: Pass | CC0-1.0 | |
| Dirextalk DeployerYingSuiAI/dirextalk-deployer | 457 | — | ~7.2k | Automated safety check: Pass | MIT | |
| Cut Releasespiculedata/saiku | 1.3k | — | ~502 | Automated safety check: Pass | Apache-2.0 | |
| Cursor Composer Task DelegateChachamaru127/claude-code-harness | 3.2k | — | ~4.4k | Automated safety check: Notes | MIT |
TencentBlueKing/bk-bcs
迭代执行流水线启动器。分三个阶段执行:信息检查(验证 git 环境、获取迭代信息、 解析迭代分支)→ 恢复检测(已有状态文件时判定恢复策略)→ 新流程初始化(创建分支、 迭代目录和 iteration-state.json)。
asgeirtj/system_prompts_leaks
Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.
YingSuiAI/dirextalk-deployer
Deploy, resume, verify, update, recover, reset, or destroy production Dirextalk services and nodes on AWS, and wire local agent runtimes.
spiculedata/saiku
Cut a Saiku release via Gitflow — version bump, release branch, PR to main, tag, back-merge, and post-release chores.
Chachamaru127/claude-code-harness
Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.
Stack-Cairn/LiveAgent
Review an open GitHub pull request or the current local branch and working tree with parallel, independent reviewers and evidence-based validation.
github/gh-aw
Drives a real browser from the command line with playwright-cli to open pages, interact, mock requests, save state and work with Playwright tests.
github/gh-aw
Designs and verifies a deterministic grader that measures whether a GitHub Agentic Workflow run reached its real-world or repository outcome.
github/gh-aw
Scaffolds, edits, reloads and debugs a canvas extension that the GitHub Copilot CLI can open in its side panel.
github/gh-aw
Drives an open pull request to merge-ready from inside a GitHub Copilot cloud agent, resolving review threads and local checks concurrently, without merging or retriggering CI.
github/gh-aw
Bumps gh-aw's pinned gh-aw-firewall version, rebuilds generated artifacts, and flags upstream spec or schema changes that need follow-up work.
github/gh-aw
Guide to the console struct tag system in gh-aw: headers, titles, number and cost formats, omitempty, and how structs, slices and maps render in the terminal.
Works with
Categories
Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget. Restricted Tool Triage is an agent skill from github/gh-aw, published by the product's own GitHub organization. Operate safely and efficiently inside a gh-aw workflow with a restricted tools/bash allowlist, and correctly triage tool-denial events before they exhaust the session's denial budget.
Restricted Tool Triage fits situations like: development work in your project.
Run `npx skills add github/gh-aw --skill restricted-tool-triage -a claude-code`. Or copy the skill folder (.github/skills/restricted-tool-triage in github/gh-aw) into .claude/skills/restricted-tool-triage in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/gh-aw --skill restricted-tool-triage -a codex`. Or copy the skill folder (.github/skills/restricted-tool-triage in github/gh-aw) into .agents/skills/restricted-tool-triage in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/gh-aw --skill restricted-tool-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/restricted-tool-triage, .gemini/skills/restricted-tool-triage, .github/skills/restricted-tool-triage and .opencode/skills/restricted-tool-triage in your project.
Going by SKILL.md and its folder, Restricted Tool Triage needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Restricted Tool Triage is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Restricted Tool Triage: Tapd Iteration Init (TencentBlueKing/bk-bcs, 840 stars), Fewer Permission Prompts (asgeirtj/system_prompts_leaks, 69k stars), Dirextalk Deployer (YingSuiAI/dirextalk-deployer, 457 stars) and Cut Release (spiculedata/saiku, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/gh-aw, which has 5,350 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.
Source: github/gh-aw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.