Agent skill

Approvals

by grandamenium in grandamenium/cortextos

You are about to take an action that affects the outside world, cannot be undone, or involves real people — and you have not yet received explicit permission.

MITAuto-check passedProductivity & Automation

Install Approvals

skills CLI
$ npx skills add grandamenium/cortextos --skill approvals -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grandamenium/cortextos approvals --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grandamenium/cortextos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/community/skills/approvals .claude/skills/approvals && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
approvals
GitHub stars
101
Token cost
~915 tokens
SKILL.md length
204 words
Files
1
Skills in repo
55
Repo updated
First seen
Licence
MIT

At a glance

You are about to take an action that affects the outside world, cannot be undone, or involves real people — and you have not yet received explicit permission.

  • Works in 5 steps: Create the approval → Block your task on the approval → Notify the user → …
  • Tasks that involve Email management
  • SKILL.md covers When to Use, Full Workflow, Re-pinging and Listing Pending Approvals, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Approvals is an agent skill from grandamenium/cortextos. You are about to take an action that affects the outside world, cannot be undone, or involves real people — and you have not yet received explicit permission. This includes: sending any email or message to a real person, deploying code to production, posting on social media, making a purchase or financial commitment, deleting files or data, merging a PR to main, or publishing anything publicly. Stop, create an approval, block your task, and notify the user. Do not proceed until you receive the approval decision…

Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering Email management. The licence is MIT.

When your agent uses it

  • Tasks that involve Email management

Example prompts

  • “/approvals”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Create the approval
  2. Block your task on the approval
  3. Notify the user
  4. Wait for inbox notification
  5. Act on the decision

What it can do on your machine

Read from SKILL.md and the folder at commit 6f93838. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Approvals loads about 915 tokens when it runs. Until then it costs about 135 tokens; SKILL.md has 204 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~135
When it runs · the whole SKILL.md, loaded when a task matches
~915

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grandamenium/cortextos at commit 6f93838, republished under its MIT licence (© grandamenium). 204 words, ~915 tokens.

Download SKILL.mdSave it as .claude/skills/approvals/SKILL.md (or your agent's skills folder).
name
approvals
description
You are about to take an action that affects the outside world, cannot be undone, or involves real people — and you have not yet received explicit permission. This includes: sending any email or message to a real person, deploying code to production, posting on social media, making a purchase or financial commitment, deleting files or data, merging a PR to main, or publishing anything publicly. Stop, create an approval, block your task, and notify the user. Do not proceed until you receive the approval decision in your inbox.
triggers
need approval, create approval, request approval, approval needed, needs sign-off, needs permission, before deploying, before sending email, before deleting…

Approvals

Before any external, irreversible, or high-stakes action — stop and create an approval. The user decides. You execute only after they approve.


When to Use

Action typeRequires approval?
Sending emails to real peopleYES
Deploying code to productionYES
Posting on social mediaYES
Making financial commitmentsYES
Deleting data (files, DB rows, records)YES
Merging to main branchYES
Any action visible to external partiesYES
Internal work (writing files, creating tasks, research)NO

Full Workflow

1. Create the approval
bash
APPR_ID=$(cortextos bus create-approval \
  "<what you want to do>" \
  "<category>" \
  "<context: draft content, target, why needed>")
echo "APPR_ID=$APPR_ID"

Categories: external-comms | financial | deployment | data-deletion | other

2. Block your task on the approval
bash
cortextos bus update-task "$TASK_ID" blocked
cortextos bus log-event task task_blocked info --meta "{\"task_id\":\"$TASK_ID\",\"blocked_by\":\"$APPR_ID\",\"reason\":\"awaiting approval\"}"
3. Notify the user
bash
cortextos bus send-telegram "$CTX_TELEGRAM_CHAT_ID" \
  "Approval needed: <title> — check dashboard or reply to approve/reject"
4. Wait for inbox notification

When the user decides, you receive an inbox message:

approval_id: appr_xxx
decision: approved | rejected
note: <user's note>
5. Act on the decision

Approved:

bash
# Unblock task
cortextos bus update-task "$TASK_ID" in_progress "Approval received — executing"
# Execute the action
# Complete the task
cortextos bus complete-task "$TASK_ID" --result "<what was done>"

Rejected:

bash
cortextos bus complete-task "$TASK_ID" --result "Cancelled — approval rejected: <note>"

Re-pinging

If an approval is still pending after 4 hours during day mode, send one re-ping:

bash
cortextos bus send-telegram "$CTX_TELEGRAM_CHAT_ID" \
  "Reminder: approval for '<title>' is still pending. No rush, just flagging."

Send only ONE re-ping. Do not spam.


Listing Pending Approvals

bash
cortextos bus list-approvals --format json

Critical Rules

  1. Create approval BEFORE starting the action — never take the action first and ask forgiveness
  2. Always block your task pointing to the approval ID — so work isn't lost while waiting
  3. Never assume approval — if you don't have an inbox confirmation, you don't have approval
  4. One re-ping max — after 4h, ping once and wait

© grandamenium, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in community/skills/approvals of grandamenium/cortextos.

Open the folder on GitHubat commit 6f93838

Compare with similar skills

Approvals next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Approvals compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Approvals this skillgrandamenium/cortextos101—~915Automated safety check: PassMIT
Garden Inboxpaperclipai/paperclip100k—~1.1kAutomated safety check: PassMIT
Continuetelegramdesktop/tdesktop33k2 repos~9.4kAutomated safety check: PassGPL-3.0
Process Inboxtelegramdesktop/tdesktop33k1 repos~5.4kAutomated safety check: PassGPL-3.0
Process InboxTDesktop-x64/tdesktop3k—~4.3kAutomated safety check: PassGPL-3.0
Career-Ops Gmail Lead Plugincareer-ops-hq/career-ops74k—~233Automated safety check: NotesMIT

Similar skills

  • Garden Inbox

    paperclipai/paperclip

    Scan a Paperclip user's Mine inbox, classify reversible archive candidates, request checkbox confirmation, and archive only accepted selections.

    100k GitHub stars~1.1k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Continue

    telegramdesktop/tdesktop

    Continue autonomous Telegram Desktop development from the shared ai-tdesktop repository.

    33k GitHub starsUsed in 2 repos~9.4k tokens
    Productivity & AutomationAuto-check passed
  • Process Inbox

    telegramdesktop/tdesktop

    Process the local ignored ai-tdesktop inbox into durable, independently testable Telegram Desktop task records while task execution worktrees remain active.

    33k GitHub starsUsed in 1 repo~5.4k tokens
    Productivity & AutomationAuto-check passed
  • Process Inbox

    TDesktop-x64/tdesktop

    Process the local ignored ai-tdesktop inbox into durable, independently testable Telegram Desktop task records while task execution worktrees remain active.

    3k GitHub stars~4.3k tokensUpdated 20 days ago
    Productivity & AutomationAuto-check passed
  • Career-Ops Gmail Lead Plugin

    career-ops-hq/career-ops

    Pulls job leads from a Gmail label into the career-ops pipeline, extracting job URLs from DMARC-passing emails and de-duplicating against existing leads.

    74k GitHub stars~233 tokensUpdated today
    Productivity & AutomationAuto-check: notes
  • Atomicmail

    Atomic-Mail/atomic-mail-agentic

    Read and write email through the Atomic Mail from an AI agent.

    266 GitHub starsUsed in 1 repo~2k tokens
    Productivity & AutomationAuto-check passed

More from grandamenium/cortextos

All 55 skills in this repo
  • Cortext Self Diagnosis

    grandamenium/cortextos

    Diagnose cortextOS itself when the framework misbehaves — an agent has gone silent or wedged, agents are crash-looping, Telegram or agent-to-agent messages are not arriving, crons did not fire, an…

    101 GitHub stars~3.7k tokensUpdated 18 days ago
    Auto-check passed
  • Activity Channel

    grandamenium/cortextos

    You have completed something significant and want the whole org — all agents and the user — to know about it.

    101 GitHub stars~624 tokensUpdated 18 days ago
    Auto-check passed
  • Agentcard Purchase

    grandamenium/cortextos

    You need to make a purchase on behalf of the user — buy a SaaS subscription, pay for an API, purchase a domain, or any transaction requiring a credit card.

    101 GitHub stars~1.1k tokensUpdated 18 days ago
    Auto-check passed
  • Claude To Codex Migration

    grandamenium/cortextos

    Migrate ANY cortextOS agent from the claude-code runtime to the live codex-app-server runtime.

    101 GitHub stars~12k tokensUpdated 18 days ago
    Auto-check: warnings
  • Bus Reference

    grandamenium/cortextos

    Complete cortextos bus CLI reference - all available commands with examples.

    101 GitHub stars~3.8k tokensUpdated 18 days ago
    Auto-check passed
  • Business News Monitor

    grandamenium/cortextos

    Daily cron-driven scan of news/forums/social in a domain to surface market shifts, new competitors, regulatory changes, and net-new opportunities.

    101 GitHub stars~1.3k tokensUpdated 18 days ago
    Auto-check passed

Questions about Approvals

What does Approvals do?

You are about to take an action that affects the outside world, cannot be undone, or involves real people — and you have not yet received explicit permission. Approvals is an agent skill from grandamenium/cortextos. You are about to take an action that affects the outside world, cannot be undone, or involves real people — and you have not yet received explicit permission.

When should I use Approvals?

Approvals fits situations like: tasks that involve Email management.

How do I install Approvals in Claude Code?

Run `npx skills add grandamenium/cortextos --skill approvals -a claude-code`. Or copy the skill folder (community/skills/approvals in grandamenium/cortextos) into .claude/skills/approvals in your project. Claude Code loads it when a task matches its description.

How do I install Approvals in Codex?

Run `npx skills add grandamenium/cortextos --skill approvals -a codex`. Or copy the skill folder (community/skills/approvals in grandamenium/cortextos) into .agents/skills/approvals in your project. Codex loads it when a task matches its description.

Can I use Approvals in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grandamenium/cortextos --skill approvals -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/approvals, .gemini/skills/approvals, .github/skills/approvals and .opencode/skills/approvals in your project.

What does Approvals need to run?

SKILL.md names no scripts, command-line tools or credentials: Approvals is instructions for the agent only.

Does Approvals access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Approvals safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Approvals use?

Approvals is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Approvals use?

About 915 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Approvals?

Skills that share tags, products or a category with Approvals: Garden Inbox (paperclipai/paperclip, 100k stars), Continue (telegramdesktop/tdesktop, 33k stars), Process Inbox (telegramdesktop/tdesktop, 33k stars) and Process Inbox (TDesktop-x64/tdesktop, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Approvals?

grandamenium (a GitHub user) maintains it in grandamenium/cortextos, which has 101 GitHub stars. The repository holds 55 skills in this directory. The repository was last updated on September 23, 2026.

Source: grandamenium/cortextos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.