Agent skill

Forgiveness Confirmation And Prevention

by hashgraph-online in hashgraph-online/awesome-codex-plugins

A skill your agent uses when the user must commit to an irreversible or high-stakes action and reversibility isn't enough — confirmation dialogs, type-to-confirm patterns, password re-entry…

Apache-2.0Auto-check passedBackend & APIs

Install Forgiveness Confirmation And Prevention

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill forgiveness-confirmation-and-prevention -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins forgiveness-confirmation-and-prevention --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/HDeibler/universal-design-principles/plugins/interaction-and-control-principles/skills/forgiveness-confirmation-and-prevention .claude/skills/forgiveness-confirmation-and-prevention && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
forgiveness-confirmation-and-prevention
GitHub stars
1.3k
Token cost
~2.3k tokens
SKILL.md length
861 words
Files
2 (incl. references)
Skills in repo
716
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the user must commit to an irreversible or high-stakes action and reversibility isn't enough — confirmation dialogs, type-to-confirm patterns, password re-entry…

  • Works in 4 steps: The reversibility-first check. Before… → The autopilot test. If a typical user… → The "what would they regret?" test. For… → …
  • The user must commit to an irreversible
  • SKILL.md covers When confirmation is appropriate, Confirmation strength, Type-to-confirm: the canonical… and Re-authentication for…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Forgiveness Confirmation And Prevention is an agent skill from hashgraph-online/awesome-codex-plugins. Use this skill when the user must commit to an irreversible or high-stakes action and reversibility isn't enough — confirmation dialogs, type-to-confirm patterns, password re-entry, two-step authentication for destructive actions, and structural prevention that makes the wrong action impossible. Trigger when designing destructive flows for genuinely-irreversible commitments, when reviewing confirmation fatigue, or when picking between a single confirm dialog and a multi-step verification. Sub-aspect of…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/confirmation-design-research.md`).

It sits in Backend & APIs, covering Authentication. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • The user must commit to an irreversible
  • High-stakes action and reversibility isnt enough — confirmation dialogs
  • Type-to-confirm patterns
  • Password re-entry

Example prompts

  • “/forgiveness-confirmation-and-prevention”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. The reversibility-first check. Before adding any confirmation, ask: can this be made reversible instead? If yes, do that.
  2. The autopilot test. If a typical user would dismiss the confirmation without reading, the confirmation isn't doing its job. Either remove…
  3. The "what would they regret?" test. For irreversible actions, imagine the user a week later realizing they made a mistake. Did the…
  4. The disabled-button question. When you reach for confirmation, ask whether structural prevention (disabling the action when it shouldn't…

What it can do on your machine

Read from SKILL.md and the folder at commit 3e1456a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are html).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Forgiveness Confirmation And Prevention loads about 2.3k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 145 tokens; SKILL.md has 861 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~145
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 3e1456a, republished under its Apache-2.0 licence (© hashgraph-online). 861 words, ~2,306 tokens.

Download SKILL.mdSave it as .claude/skills/forgiveness-confirmation-and-prevention/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
forgiveness-confirmation-and-prevention
description
Use this skill when the user must commit to an irreversible or high-stakes action and reversibility isn't enough — confirmation dialogs, type-to-confirm patterns, password re-entry, two-step authentication for destructive actions, and structural prevention that makes the wrong action impossible. Trigger when designing destructive flows for genuinely-irreversible commitments, when reviewing confirmation fatigue, or when picking between a single confirm dialog and a multi-step verification. Sub-aspect of `forgiveness`; read that first.

Forgiveness through confirmation and prevention

When an action can't be made reversible, the next-best forgiveness is requiring deliberate intent. The user must take an explicit, considered step before the irreversible thing happens. The challenge: confirmation overuse trains users to dismiss it on autopilot, defeating the purpose. Confirmation must be reserved for the moments when it earns its friction.

When confirmation is appropriate

A useful test before adding confirmation: is the action irreversible and high-stakes?

  • Irreversible + high-stakes → confirm. (Account deletion, ownership transfer, large financial transaction.)
  • Reversible + high-stakes → use undo / soft-delete instead. Confirmation here is fatigue-inducing.
  • Irreversible + low-stakes → consider whether it should be reversible. If it must be irreversible, a light confirmation may suffice.
  • Reversible + low-stakes → no confirmation. Just do it; let undo catch mistakes.

Confirmation strength

Match confirmation friction to action severity:

Light confirmation: "Yes / No" dialog
Cancel reservation?
[ Cancel ]   [ Cancel reservation ]

For actions the user clearly initiated, where the dialog mostly catches accidental clicks. The user reads the title, picks an option.

Medium confirmation: dialog with summary
Delete project "Acme Q4"?

This deletes 24 tasks and 8 attached files.

[ Cancel ]   [ Delete project ]

For actions where the user benefits from seeing what they're about to lose. The summary gives them a chance to step back.

Strong confirmation: type-to-confirm
Delete project "Acme Q4"?

This deletes 24 tasks and 8 attached files. Cannot be undone.

To confirm, type the project name below:
[ Acme Q4__________ ]

[ Cancel ]   [ Delete project ]   (button enabled only when name matches)

For irreversible high-stakes actions. The user must actively type the resource name, breaking autopilot. The button stays disabled until the confirmation matches.

Strongest: re-authentication
This action requires re-authentication.
Enter your password to continue.

[ Password__________ ]

[ Cancel ]   [ Continue ]

For account-affecting actions: deleting account, changing email, transferring ownership, viewing audit logs. Re-authentication catches both autopilot mistakes and someone-else-using-my-session attacks.

Type-to-confirm: the canonical pattern for irreversible action

html
<dialog id="delete-dialog">
  <h2>Delete workspace "Acme Inc"?</h2>
  <p>
    This permanently deletes the workspace, all 47 projects, all 12 members'
    access, and 3.2 GB of files. This cannot be undone.
  </p>
  <p>To confirm, type the workspace name below:</p>
  <input id="confirm" placeholder="Acme Inc" autocomplete="off" />
  <div class="actions">
    <button onclick="closeDialog()">Cancel</button>
    <button id="confirm-btn" disabled class="destructive">
      Delete workspace permanently
    </button>
  </div>
</dialog>

<script>
const input = document.getElementById('confirm');
const btn = document.getElementById('confirm-btn');
input.addEventListener('input', () => {
  btn.disabled = input.value !== workspace.name;
});
</script>

What this achieves:

  • The dialog must be opened deliberately.
  • The consequences are stated plainly.
  • The user must type — an active gesture that breaks autopilot.
  • The button is disabled until the typed name matches, so even autopilot Enter doesn't trigger.

For actions that should genuinely never happen by accident, this stack is appropriate.

Re-authentication for security-sensitive operations

html
<button onclick="requireReauthThen('delete-account')">
  Delete account
</button>

<dialog id="reauth-dialog">
  <h2>Confirm your identity</h2>
  <p>For your security, please re-enter your password to continue.</p>
  <input type="password" id="reauth-password" autofocus />
  <div class="actions">
    <button onclick="closeDialog()">Cancel</button>
    <button id="reauth-submit">Continue</button>
  </div>
</dialog>

Use re-authentication when:

  • The action affects security or billing.
  • The action affects other users' access.
  • The action would be devastating if performed by someone with stolen session access.
  • Compliance requires it.

The cost: an extra password entry. The benefit: a second opportunity for the user to reconsider, plus protection against session theft.

Structural prevention (the highest forgiveness)

Stronger than any confirmation: making the wrong action impossible.

Disable the action when invalid

A "Submit" button disabled when the form has errors. The user can't trigger the failure path. (Pair with inline error explanations so the user knows what's missing — see affordance-false-and-anti.)

Type-restricted inputs

<input type="email"> rejects non-email format. <input type="number"> rejects non-numeric. <input type="tel"> shows a numeric keyboard on mobile. Each is structural prevention of certain input errors.

Constraint by selection rather than typing

A <select> for state names prevents typos that a free-text field would allow. A date picker prevents impossible dates. A typeahead constrained to known values prevents misspelled selections.

Physical / hardware analogies

The USB-C connector that can't be inserted upside-down. The pill organizer that shows visual state. The medical injector that can't deliver a dangerous dose.

Required-field marking + blocked submit
html
<form>
  <label>Email <span class="required">*</span>
    <input type="email" required />
  </label>
  <button>Submit</button>
</form>

The browser blocks submission with focus on the missing field. Native scaffolding for prevention.

Show full SKILL.md (361 more words)Show less

Anti-patterns

  • Confirmation fatigue. "Are you sure you want to save? / open? / apply?" Every routine action confirmed. Users dismiss everything on autopilot.
  • Pre-selected destructive option. A confirm dialog with the destructive button as default Enter target. Users who hit Enter without reading commit the destruction.
  • Trivial type-to-confirm. Forcing users to type "DELETE" for a routine archive operation. Heavy friction for low-stakes action.
  • Hidden cancellation path. A confirm dialog with no Esc, no backdrop dismiss, just two buttons. The user feels trapped.
  • Confirmation as the only forgiveness. Apps where every destructive action is confirmed but nothing is reversible. Confirmation alone is insufficient — users still make mistakes.
  • Sneaky double-negatives. "Are you sure you don't want to keep your account?" Users misread; mistakes happen.

Calibrating friction to stakes

A useful framing: every confirmation step is a tax. Ask whether the tax is worth it for this specific action.

ActionReversibilityStakesRecommended confirmation
SaveReversibleLowNone
Apply filterReversibleLowNone
Archive itemReversible (toast undo)LowNone
Delete (soft)Recoverable in trashMediumNone
Empty trashIrreversibleMediumLight dialog
Delete projectIrreversibleHighStrong dialog with summary
Delete accountIrreversibleVery highType-to-confirm + reauth
Transfer ownershipIrreversibleVery highType-to-confirm + reauth + email verification

Each step up the friction ladder should correspond to a step up in stakes.

Heuristics

  1. The reversibility-first check. Before adding any confirmation, ask: can this be made reversible instead? If yes, do that.
  2. The autopilot test. If a typical user would dismiss the confirmation without reading, the confirmation isn't doing its job. Either remove it or make it harder to dismiss without reading.
  3. The "what would they regret?" test. For irreversible actions, imagine the user a week later realizing they made a mistake. Did the confirmation do enough to prevent that?
  4. The disabled-button question. When you reach for confirmation, ask whether structural prevention (disabling the action when it shouldn't apply) would work better.
  • forgiveness (parent).
  • forgiveness-undo-and-soft-delete — the preferred alternative when reversibility is possible.
  • affordance-false-and-anti — disabled states and structural prevention.
  • constraint — input constraints prevent invalid actions.
  • expectation-effect — confirmation buttons in unexpected positions surprise users.
  • accessibility-understandable (process) — confirmation flows must be operable for all users.

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in plugins/HDeibler/universal-design-principles/plugins/interaction-and-control-principles/skills/forgiveness-confirmation-and-prevention of hashgraph-online/awesome-codex-plugins.

  • SKILL.md
  • references/confirmation-design-research.md

Open the folder on GitHubat commit 3e1456a

Compare with similar skills

Forgiveness Confirmation And Prevention next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Forgiveness Confirmation And Prevention compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Forgiveness Confirmation And Prevention this skillhashgraph-online/awesome-codex-plugins1.3k—~2.3kAutomated safety check: PassApache-2.0
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Gitnexus Exploringaws-samples/sample-kolya-br-proxy10612 repos~749Automated safety check: PassMIT-0
Supabasecurvenote/curvenote1705 repos~2.2kAutomated safety check: PassCustom licence

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Gitnexus Exploring

    aws-samples/sample-kolya-br-proxy

    Official

    A skill your agent uses when the user asks how code works, wants to understand architecture, trace execution flows, or explore unfamiliar parts of the codebase.

    106 GitHub starsUsed in 12 repos~749 tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    170 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from hashgraph-online/awesome-codex-plugins

All 715 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Categories

Questions about Forgiveness Confirmation And Prevention

What does Forgiveness Confirmation And Prevention do?

A skill your agent uses when the user must commit to an irreversible or high-stakes action and reversibility isn't enough — confirmation dialogs, type-to-confirm patterns, password re-entry…. Forgiveness Confirmation And Prevention is an agent skill from hashgraph-online/awesome-codex-plugins. Use this skill when the user must commit to an irreversible or high-stakes action and reversibility isn't enough — confirmation dialogs, type-to-confirm patterns, password re-entry, two-step authentication for destructive actions, and structural prevention that makes the wrong action impossible.

When should I use Forgiveness Confirmation And Prevention?

Forgiveness Confirmation And Prevention fits situations like: the user must commit to an irreversible; high-stakes action and reversibility isnt enough — confirmation dialogs; type-to-confirm patterns; password re-entry.

How do I install Forgiveness Confirmation And Prevention in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill forgiveness-confirmation-and-prevention -a claude-code`. Or copy the skill folder (plugins/HDeibler/universal-design-principles/plugins/interaction-and-control-principles/skills/forgiveness-confirmation-and-prevention in hashgraph-online/awesome-codex-plugins) into .claude/skills/forgiveness-confirmation-and-prevention in your project. Claude Code loads it when a task matches its description.

How do I install Forgiveness Confirmation And Prevention in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill forgiveness-confirmation-and-prevention -a codex`. Or copy the skill folder (plugins/HDeibler/universal-design-principles/plugins/interaction-and-control-principles/skills/forgiveness-confirmation-and-prevention in hashgraph-online/awesome-codex-plugins) into .agents/skills/forgiveness-confirmation-and-prevention in your project. Codex loads it when a task matches its description.

Can I use Forgiveness Confirmation And Prevention in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill forgiveness-confirmation-and-prevention -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/forgiveness-confirmation-and-prevention, .gemini/skills/forgiveness-confirmation-and-prevention, .github/skills/forgiveness-confirmation-and-prevention and .opencode/skills/forgiveness-confirmation-and-prevention in your project.

What does Forgiveness Confirmation And Prevention need to run?

SKILL.md names no scripts, command-line tools or credentials: Forgiveness Confirmation And Prevention is instructions for the agent only.

Does Forgiveness Confirmation And Prevention access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Forgiveness Confirmation And Prevention safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Forgiveness Confirmation And Prevention use?

Forgiveness Confirmation And Prevention is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Forgiveness Confirmation And Prevention use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.1k tokens, read only when the agent opens those files.

What are the alternatives to Forgiveness Confirmation And Prevention?

Skills that share tags, products or a category with Forgiveness Confirmation And Prevention: Fortify Development (coollabsio/coolify, 63k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Gitnexus Exploring (aws-samples/sample-kolya-br-proxy, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Forgiveness Confirmation And Prevention?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,267 GitHub stars. The repository holds 716 skills in this directory. The repository was last updated on October 10, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.