Agent skill

Flexport Enterprise Rbac

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Map Flexport endpoint-scoped OAuth credentials and MCP role permissions to approved workloads.

MITAuto-check passedBackend & APIs

Install Flexport Enterprise Rbac

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill flexport-enterprise-rbac -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace flexport-enterprise-rbac --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/flexport-enterprise-rbac .claude/skills/flexport-enterprise-rbac && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
flexport-enterprise-rbac
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
420 words
Files
2 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Map Flexport endpoint-scoped OAuth credentials and MCP role permissions to approved workloads.

  • Works in 6 steps: Map business outcomes → Assign separate credentials → Map MCP roles → …
  • Designing enterprise access
  • SKILL.md covers Overview, Prerequisites, Instructions and Authentication, plus 5 more sections
  • Reaches api.flexport.com and mcp.flexport.com

What it does

Flexport Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Map Flexport endpoint-scoped OAuth credentials and MCP role permissions to approved workloads. Use when designing enterprise access, separating duties, reviewing permissions, or replacing shared broad API keys. Trigger with: "Flexport RBAC", "scope Flexport integration", "review Flexport permissions".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/official-docs.md`). Compatibility notes: Requires Flexport administrator involvement, an enterprise identity inventory, and owners for each integration workload.

It sits in Backend & APIs, covering Authorization and RBAC, MCP servers and OAuth and OpenID Connect. It works with Model Context Protocol. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Designing enterprise access
  • Separating duties
  • Reviewing permissions
  • Replacing shared broad API keys

Example prompts

  • “Flexport RBAC”
  • “scope Flexport integration”
  • “review Flexport permissions”
  • “/flexport-enterprise-rbac”

Requirements

  • Compatibility (from SKILL.md): Requires Flexport administrator involvement, an enterprise identity inventory, and owners for each integration workload.
  • Pre-approved tools (allowed-tools): Read, Grep, Write, Edit

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Map business outcomes
  2. Assign separate credentials
  3. Map MCP roles
  4. Control broad keys
  5. Enforce application policy
  6. Review with evidence

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Write
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.flexport.com
    • mcp.flexport.com

    Also links to:

    • developers.flexport.com
    • apidocs.flexport.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Flexport administrator involvement, an enterprise identity inventory, and owners for each integration workload.

    From compatibility in the SKILL.md frontmatter.

Context cost

Flexport Enterprise Rbac loads about 1.1k tokens when it runs, and up to ~1.3k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 420 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 420 words, ~1,082 tokens.

Download SKILL.mdSave it as .claude/skills/flexport-enterprise-rbac/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
flexport-enterprise-rbac
description
Map Flexport endpoint-scoped OAuth credentials and MCP role permissions to approved workloads. Use when designing enterprise access, separating duties, reviewing permissions, or replacing shared broad API keys. Trigger with: "Flexport RBAC", "scope Flexport integration", "review Flexport permissions".
allowed-tools
Read, Grep, Write, Edit
compatibility
Requires Flexport administrator involvement, an enterprise identity inventory, and owners for each integration workload.
version
2.0.0
argument-hint
[workloads-roles-and-endpoints]
model
inherit
effort
high
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, flexport, rbac, governance

Flexport Permission-Aware Access Broker

Overview

Flexport has two access concepts that must not be conflated: OAuth clients select endpoint resources, while MCP tools document allowed account roles. API keys are broad across endpoints and should not be described as selectively scoped.

Prerequisites

  • Workload-to-outcome inventory and accountable owners
  • Current REST endpoint resource and MCP tool permission documentation
  • Credential registry with environment and rotation metadata

Instructions

Step 1: Map business outcomes

List reads, document changes, invoice work, booking commitments, and MCP tools by workload.

Step 2: Assign separate credentials

Create one OAuth client per system and select only required endpoint resources. Create a replacement if new resources are later needed.

Step 3: Map MCP roles

For each MCP tool, record the documented allowed roles and verify the connected user has one; do not infer permission from a REST credential.

Step 4: Control broad keys

Inventory API keys as exceptions, document their all-endpoint blast radius, restrict storage, and plan replacement where OAuth fits.

Step 5: Enforce application policy

Require business authorization above provider permission, especially for bookings, trade records, and sensitive shipment/customs data.

Step 6: Review with evidence

Quarterly or event-driven reviews compare active workloads, credentials, tool use, and owners; revoke orphaned access promptly.

Authentication

REST calls authenticate with a cached OAuth 2.0 client-credentials Bearer token using audience https://api.flexport.com, or an explicitly accepted broad API key. Use distinct credentials per workload and never log credentials or tokens. MCP calls use the authenticated connection to https://mcp.flexport.com/mcp and remain subject to each tool's documented account permissions.

Show full SKILL.md (169 more words)Show less

Tool Discipline

Use Read and Grep for discovery and evidence. Use Write or Edit only for the approved artifact, code, configuration, test, or receipt described by this workflow; do not make an unapproved Flexport-side change.

Output

  • Scoped decision or implementation artifact
  • Redacted operation and validation receipt
  • Failure, rollback, and follow-up ownership record

Return a machine-reviewable receipt in this shape; adapt the operation values, but never place credentials or provider payloads in it:

yaml
surface: rest-v3
operation: shipment-read
decision: approved
outcome: verified
evidence:
  release_sha: recorded-out-of-band
  provider_reference: redacted
rollback_owner: logistics-platform

Examples

A tracking service gets shipment-only OAuth resources, while an MCP booking assistant runs for a Member with an application-level approver gate. Neither inherits the invoice importer's credential.

Error Handling

FailureResponse
Endpoint permission absentCreate a replacement scoped client after approval; do not reuse a broad key.
MCP role insufficientRoute to an authorized operator or redesign the task as read-only.
Credential owner departedSuspend and reassign or rotate before continued use.
Shared key discoveredContain its storage and migrate workloads to distinct credentials.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/.curated/flexport-enterprise-rbac of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/official-docs.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Flexport Enterprise Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Flexport Enterprise Rbac compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Flexport Enterprise Rbac this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Notion MCP Skillholon-run/uxc116—~1.2kAutomated safety check: PassMIT
Xquik MCPXquik-dev/x-twitter-scraper2111 repos~997Automated safety check: PassMIT
Tenuo Agent Authorizationtenuo-ai/tenuo103—~2.3kAutomated safety check: PassApache-2.0
Frontmcp Auth UIagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0
MCP Dart Streamable HTTPleehack/mcp_dart116—~2kAutomated safety check: PassMIT

Similar skills

  • Notion MCP Skill

    holon-run/uxc

    Operate Notion workspace content through Notion MCP using the UXC CLI, including search, fetch, users/teams lookup, page/database creation and updates, and comments.

    116 GitHub stars~1.2k tokensUpdated 26 days ago
    Backend & APIsAuto-check passed
  • Xquik MCP

    Xquik-dev/x-twitter-scraper

    Connect, verify, and troubleshoot Xquik's remote MCP server.

    211 GitHub starsUsed in 1 repo~997 tokens
    Backend & APIsAuto-check passed
  • Add or retrofit Tenuo authorization for AI-agent tools and effects.

    103 GitHub stars~2.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Frontmcp Auth UI

    agentfront/frontmcp

    A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • MCP Dart Streamable HTTP

    leehack/mcp_dart

    A skill your agent uses when serving an MCP server over HTTP with mcpdart or connecting to a remote one: StreamableMcpServer setup, Host and Origin allowlists (DNS rebinding protection), CORS for…

    116 GitHub stars~2k tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Atlassian

    sanjay3290/ai-skills

    Manage Jira issues and Confluence wiki pages in Atlassian Cloud.

    432 GitHub stars~1.6k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Flexport Enterprise Rbac

What does Flexport Enterprise Rbac do?

Map Flexport endpoint-scoped OAuth credentials and MCP role permissions to approved workloads. Flexport Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Map Flexport endpoint-scoped OAuth credentials and MCP role permissions to approved workloads.

When should I use Flexport Enterprise Rbac?

Flexport Enterprise Rbac fits situations like: designing enterprise access; separating duties; reviewing permissions; replacing shared broad API keys.

How do I install Flexport Enterprise Rbac in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill flexport-enterprise-rbac -a claude-code`. Or copy the skill folder (skills/.curated/flexport-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/flexport-enterprise-rbac in your project. Claude Code loads it when a task matches its description.

How do I install Flexport Enterprise Rbac in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill flexport-enterprise-rbac -a codex`. Or copy the skill folder (skills/.curated/flexport-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/flexport-enterprise-rbac in your project. Codex loads it when a task matches its description.

Can I use Flexport Enterprise Rbac in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill flexport-enterprise-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/flexport-enterprise-rbac, .gemini/skills/flexport-enterprise-rbac, .github/skills/flexport-enterprise-rbac and .opencode/skills/flexport-enterprise-rbac in your project.

What does Flexport Enterprise Rbac need to run?

SKILL.md names no scripts, command-line tools or credentials: Flexport Enterprise Rbac is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Grep, Write, Edit. Compatibility (from SKILL.md): Requires Flexport administrator involvement, an enterprise identity inventory, and owners for each integration workload..

Does Flexport Enterprise Rbac access the network?

SKILL.md names 4 domains. In commands or code: api.flexport.com and mcp.flexport.com; the agent is likely to contact these when it follows the instructions. As links in the text: developers.flexport.com and apidocs.flexport.com. This is read from the text; nothing was executed.

Is Flexport Enterprise Rbac safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Flexport Enterprise Rbac use?

Flexport Enterprise Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Flexport Enterprise Rbac use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 222 tokens, read only when the agent opens those files.

What are the alternatives to Flexport Enterprise Rbac?

Skills that share tags, products or a category with Flexport Enterprise Rbac: Notion MCP Skill (holon-run/uxc, 116 stars), Xquik MCP (Xquik-dev/x-twitter-scraper, 211 stars), Tenuo Agent Authorization (tenuo-ai/tenuo, 103 stars) and Frontmcp Auth UI (agentfront/frontmcp, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Flexport Enterprise Rbac?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.