Agent skill

Security Privileges

by hmislk in hmislk/hmis

Privilege system reference for the HMIS project. An agent skill from hmislk/hmis.

GPL-3.0Auto-check passedBackend & APIs

Install Security Privileges

skills CLI
$ npx skills add hmislk/hmis --skill security-privileges -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hmislk/hmis security-privileges --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hmislk/hmis.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/security-privileges .claude/skills/security-privileges && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-privileges
GitHub stars
236
Token cost
~464 tokens
SKILL.md length
142 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
GPL-3.0

At a glance

Privilege system reference for the HMIS project. An agent skill from hmislk/hmis.

  • Works in 5 steps: Check… → Never rename or edit legacy enum values… → Add to most relevant section, keeping… → …
  • Adding new privileges
  • SKILL.md covers Core Principles, Common Privileges, Adding a New Privilege and Usage in XHTML, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Security Privileges is an agent skill from hmislk/hmis. Privilege system reference for the HMIS project. Use when adding new privileges, implementing access control, working with user roles, checking privilege-based rendering in XHTML, or auditing security controls.

Its SKILL.md is about 460 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC. It works with Java. The repository describes itself as: This is an Open Source Java EE based Hospital Information Management System. The licence is GPL-3.0.

When your agent uses it

  • Adding new privileges
  • Implementing access control
  • Working with user roles
  • Checking privilege-based rendering in XHTML

Example prompts

  • “/security-privileges”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Check src/main/java/com/divudi/core/data/Privileges.java - reuse existing if matching behavior exists
  2. Never rename or edit legacy enum values (backward compatibility)
  3. Add to most relevant section, keeping existing grouping
  4. Update src/main/webapp/admin/users/user_privileges.xhtml for UI assignment
  5. Extend UserPrivilageController.createPrivilegeHolderTreeNodes() for tree rendering

What it can do on your machine

Read from SKILL.md and the folder at commit d5d2020. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are xhtml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Privileges loads about 464 tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 142 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~464

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hmislk/hmis at commit d5d2020, republished under its GPL-3.0 licence (© hmislk). 142 words, ~464 tokens.

Download SKILL.mdSave it as .claude/skills/security-privileges/SKILL.md (or your agent's skills folder).
name
security-privileges
description
Privilege system reference for the HMIS project. Use when adding new privileges, implementing access control, working with user roles, checking privilege-based rendering in XHTML, or auditing security controls.
user-invocable
true

Privilege System Reference

Core Principles

  • Declare privileges in Privileges.java - append to enum without reordering
  • Check in controllers via webUserController.hasPrivilege(...)
  • Assign through UI via User Privileges admin interface; never seed in database
  • Name descriptively so usage is obvious from enum value

Common Privileges

PrivilegeDescription
StockTransactionViewRatesRate/value fields in stock transactions
PharmacyTransferViewRatesRates in pharmacy transfer reports
DevelopersAll bill formats for dev/QA validation

Adding a New Privilege

  1. Check src/main/java/com/divudi/core/data/Privileges.java - reuse existing if matching behavior exists
  2. Never rename or edit legacy enum values (backward compatibility)
  3. Add to most relevant section, keeping existing grouping
  4. Update src/main/webapp/admin/users/user_privileges.xhtml for UI assignment
  5. Extend UserPrivilageController.createPrivilegeHolderTreeNodes() for tree rendering

Usage in XHTML

xhtml
<p:column rendered="#{webUserController.hasPrivilege('PharmacyTransferViewRates')}">
    <h:outputText value="#{item.rate}" />
</p:column>

Testing Checklist

  • Log in WITHOUT the privilege - confirm UI element is hidden/disabled
  • Log in WITH the privilege - verify workflow succeeds end-to-end
  • Document new privilege in release notes

For complete reference, read developer_docs/security/privilege-system.md.

© hmislk, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/security-privileges of hmislk/hmis.

Open the folder on GitHubat commit d5d2020

Compare with similar skills

Security Privileges next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Privileges compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Privileges this skillhmislk/hmis236—~464Automated safety check: PassGPL-3.0
Springboot Securityaffaan-m/ECC275k5 repos~2kAutomated safety check: PassMIT
Spring Security JWTrrezartprebreza/spring-boot-skills298—~1.7kAutomated safety check: PassMIT
Security Sensitive Path InstrumenterArabelaTso/Skills-4-SE253—~1.1kAutomated safety check: PassApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Sap Cap Capiresecondsky/sap-skills462—~4.4kAutomated safety check: PassGPL-3.0

Similar skills

  • Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

    275k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check passed
  • Spring Security JWT

    rrezartprebreza/spring-boot-skills

    A skill your agent uses when an application issues and validates its own first-party JWT access and refresh tokens, including authentication filters, password encoding, RBAC, and method security.

    298 GitHub stars~1.7k tokensUpdated 17 days ago
    Backend & APIsAuto-check passed
  • Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime.

    253 GitHub stars~1.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Sap Cap Capire

    secondsky/sap-skills

    SAP Cloud Application Programming Model (CAP) development skill using Capire documentation.

    462 GitHub stars~4.4k tokensUpdated 3 days ago
    DatabasesAuto-check passed
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed

More from hmislk/hmis

All 33 skills in this repo
  • API Usage

    hmislk/hmis

    Reference for calling existing HMIS REST APIs. An agent skill from hmislk/hmis.

    236 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Application configuration options reference for the HMIS project.

    236 GitHub stars~474 tokensUpdated today
    Auto-check passed
  • Caveman

    hmislk/hmis

    Ultra-compressed communication mode. An agent skill from hmislk/hmis.

    236 GitHub starsUsed in 21 repos~946 tokens
    Auto-check passed
  • Database Guide

    hmislk/hmis

    MySQL database development guide for the HMIS project. An agent skill from hmislk/hmis.

    236 GitHub stars~664 tokensUpdated today
    Auto-check passed
  • Demo Video

    hmislk/hmis

    A skill your agent uses when asked to make a demo, training, how-to or tutorial video with sound or voice-over showing an HMIS function or configuration (e.g.

    236 GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • Deploy QA

    hmislk/hmis

    Sync development into QA/testing environment branches (QA1-QA4, local RH staging) via PR + merge on GitHub.

    236 GitHub stars~2.1k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Security Privileges

What does Security Privileges do?

Privilege system reference for the HMIS project. An agent skill from hmislk/hmis. Security Privileges is an agent skill from hmislk/hmis. Privilege system reference for the HMIS project.

When should I use Security Privileges?

Security Privileges fits situations like: adding new privileges; implementing access control; working with user roles; checking privilege-based rendering in XHTML.

How do I install Security Privileges in Claude Code?

Run `npx skills add hmislk/hmis --skill security-privileges -a claude-code`. Or copy the skill folder (.codex/skills/security-privileges in hmislk/hmis) into .claude/skills/security-privileges in your project. Claude Code loads it when a task matches its description.

How do I install Security Privileges in Codex?

Run `npx skills add hmislk/hmis --skill security-privileges -a codex`. Or copy the skill folder (.codex/skills/security-privileges in hmislk/hmis) into .agents/skills/security-privileges in your project. Codex loads it when a task matches its description.

Can I use Security Privileges in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hmislk/hmis --skill security-privileges -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-privileges, .gemini/skills/security-privileges, .github/skills/security-privileges and .opencode/skills/security-privileges in your project.

What does Security Privileges need to run?

SKILL.md names no scripts, command-line tools or credentials: Security Privileges is instructions for the agent only.

Does Security Privileges access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Privileges safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Privileges use?

Security Privileges is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Privileges use?

About 464 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Privileges?

Skills that share tags, products or a category with Security Privileges: Springboot Security (affaan-m/ECC, 275k stars), Spring Security JWT (rrezartprebreza/spring-boot-skills, 298 stars), Security Sensitive Path Instrumenter (ArabelaTso/Skills-4-SE, 253 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Privileges?

hmislk (a GitHub organization) maintains it in hmislk/hmis, which has 236 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 8, 2026.

Source: hmislk/hmis on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.