Agentsop Streaming Output
agentsope/SkillAlchemy
Enhancement-overlay decision protocol for STREAMING the output of long-running LLM / agent runs from the backend, not just wiring a typing animation in the UI.
Agent skill
by jeremylongshore in jeremylongshore/tons-of-skills-marketplace
Enforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and…
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace langchain-enterprise-rbac --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/langchain-enterprise-rbac .claude/skills/langchain-enterprise-rbac && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "langchain-enterprise-rbac" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/langchain-enterprise-rbac into .claude/skills/langchain-enterprise-rbac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langchain-enterprise-rbac", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/langchain-enterprise-rbacType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace langchain-enterprise-rbac --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/.curated/langchain-enterprise-rbac .agents/skills/langchain-enterprise-rbac && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "langchain-enterprise-rbac" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/langchain-enterprise-rbac into .agents/skills/langchain-enterprise-rbac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langchain-enterprise-rbac", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace langchain-enterprise-rbac --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/.curated/langchain-enterprise-rbac .cursor/skills/langchain-enterprise-rbac && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "langchain-enterprise-rbac" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/langchain-enterprise-rbac into .cursor/skills/langchain-enterprise-rbac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langchain-enterprise-rbac", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jeremylongshore/tons-of-skills-marketplace.git --path skills/.curated/langchain-enterprise-rbac--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace langchain-enterprise-rbac --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/.curated/langchain-enterprise-rbac .gemini/skills/langchain-enterprise-rbac && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "langchain-enterprise-rbac" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/langchain-enterprise-rbac into .gemini/skills/langchain-enterprise-rbac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langchain-enterprise-rbac", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jeremylongshore/tons-of-skills-marketplace langchain-enterprise-rbacInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/.curated/langchain-enterprise-rbac .github/skills/langchain-enterprise-rbac && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "langchain-enterprise-rbac" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/langchain-enterprise-rbac into .github/skills/langchain-enterprise-rbac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langchain-enterprise-rbac", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jeremylongshore/tons-of-skills-marketplace langchain-enterprise-rbac --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/.curated/langchain-enterprise-rbac .opencode/skills/langchain-enterprise-rbac && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "langchain-enterprise-rbac" agent skill from https://github.com/jeremylongshore/tons-of-skills-marketplace/tree/main/skills/.curated/langchain-enterprise-rbac into .opencode/skills/langchain-enterprise-rbac/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "langchain-enterprise-rbac", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
langchain-enterprise-rbacEnforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and…
Langchain Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace. Enforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and structured audit logs. Use when building multi-tenant saas, passing soc2 review, or debugging cross-tenant leak. Trigger with "langchain multi-tenant", "langchain tenant isolation", "langchain rbac", "langchain row-level security", "langchain audit log".
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/audit-log-schema.md`, `references/multi-tenant-regression-tests.md` and `references/one-pager.md`). Compatibility notes: Designed for Claude Code
It sits in Backend & APIs, covering Building AI agents, Authorization and RBAC and Multi-tenancy. It works with LangChain and LangGraph. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBash(python:*)From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
python.langchain.comlangchain-ai.github.iodocs.pinecone.iopostgresql.orgaicpa-cima.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code
From compatibility in the SKILL.md frontmatter.
Langchain Enterprise Rbac loads about 4k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 120 tokens; SKILL.md has 1,333 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 1,333 words, ~3,978 tokens.
.claude/skills/langchain-enterprise-rbac/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.A B2B SaaS team shipped their first RAG feature for two tenants. The factory
code looked innocent: build PineconeVectorStore once at module import with
namespace="acme-corp" (the first tenant), convert it to a retriever, store
it in a module global, reuse on every request. Six weeks later tenant "Initech"
went live. Their first search returned three documents from Acme Corp.
The singleton retriever had captured the Acme namespace at process start.
RunnableConfig.configurable["tenant_id"] was being passed in — but the
retriever never read it, because the filter was baked in. Every request for
every tenant hit the same Pinecone namespace. Security review caught it three
days later and put a hold on the SOC2 renewal. This is pain-catalog entry
P33, the single most common cause of cross-tenant leak in LangChain 1.0
production.
This skill fixes it with four workstreams:
tenant_id from RunnableConfig. Never
at module scope. Unit-test with two tenants and assert non-overlap.create_agent at all, so the model cannot call them even if it tries.InMemoryRateLimiter (or a
Redis-backed equivalent) by tenant_id, and check a per-tenant USD budget
before invoking the model.user_id, tenant_id,
chain_name, tools_called, cost_usd, outcome, emitted in both success
and failure paths. Ships to SIEM or BigQuery.Two failure patterns anchor this skill: import-time retriever binding (P33)
and missing audit log on tool failure (the try block logs on success but
the except branch re-raises without emitting, so incident response has no
record of denied tool calls). Pinned: langchain-core 1.0.x,
langgraph 1.0.x, langchain-anthropic 1.0.x, langchain-openai 1.0.x,
langchain-postgres 0.0.15+ (for PGVector RLS), pinecone-client 5.x,
chromadb 0.5.x. Pain-catalog anchors: P33 primary, P18, P24, P31, P37.
langchain-core >= 1.0, < 2.0, langgraph >= 1.0, < 2.0pinecone-client, langchain-postgres
(PGVector), chromadb, or faiss-cpu (single-tenant only — see §Step 2)tid claim, session
cookie, or header — the auth boundary is out of scope for this skill but
assumed correct)Move retriever construction inside the chain or agent invocation, keyed by
config["configurable"]["tenant_id"].
from langchain_core.runnables import RunnableConfig, RunnableLambda
from langchain_pinecone import PineconeVectorStore
# WRONG — retriever bound at import time with first tenant's namespace.
# RETRIEVER = PineconeVectorStore(index_name="rag", namespace="acme-corp",
# embedding=emb).as_retriever(search_kwargs={"k": 4})
# RIGHT — factory called per-request, reads tenant from RunnableConfig.
def retriever_for(config: RunnableConfig):
tenant_id = config["configurable"]["tenant_id"] # required, no default
if not tenant_id:
raise PermissionError("tenant_id missing from RunnableConfig")
store = PineconeVectorStore(
index_name="rag",
namespace=tenant_id, # P33 fix — namespace per-invocation
embedding=emb,
)
return store.as_retriever(search_kwargs={"k": 4})
def retrieve(inputs: dict, config: RunnableConfig):
return retriever_for(config).invoke(inputs["query"])
chain = RunnableLambda(retrieve) | prompt | model
result = chain.invoke({"query": "..."},
config={"configurable": {"tenant_id": "initech"}})No default on tenant_id — a missing tenant must be a hard error, not a silent
fallback. See Retriever-per-request for
factory lifecycle and PGVector RLS / Chroma / FAISS adapters.
| Store | Isolation primitive | Per-tenant latency | Max tenants | Safety notes |
|---|---|---|---|---|
| Pinecone | namespace=tenant_id per query | ~40ms p50 (shared index) | 100,000+ per index | Namespace is the documented isolation boundary; still apply metadata {"tenant_id": tid} as defense in depth |
| PGVector | Postgres row-level security (RLS) on tenant_id column | ~20ms p50 (HNSW index) | Bounded by Postgres row count | Use SET LOCAL app.tenant_id = :tid per transaction; RLS policy USING (tenant_id = current_setting('app.tenant_id')) |
| Chroma | Collection-per-tenant (get_or_create_collection(name=tid)) | ~30ms p50 | ~1,000 before metadata overhead | Good isolation at small scale; collection creation is synchronous — provision lazily but cache the handle per-request |
| FAISS | In-process index-per-tenant | ~5ms p50 (in-memory) | 10-50 practical limit | Poor fit for multi-tenant SaaS — cannot shard across processes, reloads on every deploy, no durable filter. Use for single-tenant evaluation only |
Pinecone scales highest. PGVector with RLS is the strongest primitive when isolation must be auditable at the database layer (RLS is enforced by the server even if application code is bypassed). Chroma is fine for ≤1,000 tenants. FAISS is not a multi-tenant production choice — document so future engineers do not adopt it. See Vector-store isolation for the PGVector RLS DDL and Chroma lifecycle.
Never bind every tool to every agent and trust the model to pick the right one. Build the agent inside the request handler with only the tools the user's role permits.
from langgraph.prebuilt import create_agent
# Map role -> allowed tool names. Owned by IAM config, not the skill.
ROLE_TOOLS: dict[str, set[str]] = {
"viewer": {"search_docs"},
"editor": {"search_docs", "create_note"},
"admin": {"search_docs", "create_note", "delete_note", "export_audit"},
}
ALL_TOOLS = {t.name: t for t in [search_docs, create_note, delete_note, export_audit]}
def agent_for(user_role: str, tenant_id: str):
allowed = ROLE_TOOLS.get(user_role, set())
tools = [ALL_TOOLS[n] for n in allowed if n in ALL_TOOLS]
# Forbidden tools are not passed in — the model never sees them.
return create_agent(model, tools=tools)
agent = agent_for(user_role="viewer", tenant_id="initech")
# viewer has no delete_note -> the agent cannot call it.Add a denylist for dangerous argument patterns (SQL with DROP / TRUNCATE,
shell with rm -rf / sudo, URLs to internal metadata endpoints) via a
pre_model_hook or tool wrapper — allowlist bounds which tools run,
denylist bounds what arguments they accept. See
Role-scoped tool allowlist.
Per-tenant limits prevent one tenant's runaway job from exhausting shared model
capacity. Rate-limit detail is covered in langchain-rate-limits; cost-budget
detail in langchain-cost-tuning. The only RBAC-specific requirement here:
limiter key must include tenant_id — never a process-global singleton.
# Sketch only — see langchain-rate-limits for production implementation.
_limiters: dict[str, InMemoryRateLimiter] = {}
def limiter_for(tenant_id: str) -> InMemoryRateLimiter:
if tenant_id not in _limiters:
# Tier lookup — different plans get different budgets.
rps = TENANT_TIER_LIMITS.get(tenant_id, 1.0) # 1.0 rps = free-tier default
_limiters[tenant_id] = InMemoryRateLimiter(requests_per_second=rps)
return _limiters[tenant_id]For multi-process deployments use a Redis-backed limiter — InMemoryRateLimiter
is per-process only, so 1 rps × 8 workers = 8 rps aggregate.
The audit log is the record of truth during an incident. Emit on both success
and failure paths. The common bug is logging in the try block only — when a
tool raises, the except branch re-raises without emitting, so the incident
responder has no record of the denied call.
import json
import time
import uuid
from contextlib import contextmanager
@contextmanager
def audit(ctx: dict):
started = time.monotonic()
trace_id = str(uuid.uuid4())
record = {**ctx, "trace_id": trace_id, "outcome": "pending"}
try:
yield record
record["outcome"] = record.get("outcome", "success")
except Exception as exc:
record["outcome"] = "error"
record["error_class"] = type(exc).__name__
record["error_message"] = str(exc)[:500] # truncate — no PII leakage
raise
finally:
record["latency_ms"] = int((time.monotonic() - started) * 1000) # 1000 ms per second
print(json.dumps(record)) # or a SIEM / BigQuery client
ctx = {
"user_id": "u_42",
"tenant_id": "initech",
"chain_name": "rag-qa-v3",
"role": "viewer",
}
with audit(ctx) as record:
result = chain.invoke(inputs, config={"configurable": ctx})
record["tools_called"] = [m.name for m in result.get("tool_calls", [])]
record["input_tokens"] = result["usage"]["input_tokens"]
record["output_tokens"] = result["usage"]["output_tokens"]
record["cost_usd"] = cost_of(result["usage"])The try / finally pattern guarantees emission even when the chain raises.
Required fields: user_id, tenant_id, chain_name, outcome, latency_ms,
trace_id. Recommended: tools_called, input_tokens, output_tokens,
cost_usd, role. See Audit-log schema for
the full catalog, JSON example, SIEM / BigQuery ingestion, and query recipes.
The test that would have caught P33 on day one. Seed two tenants with distinct documents, run a golden query as each, assert non-overlap on retrieved IDs.
import pytest
@pytest.fixture
def two_tenant_store():
seed("acme", ["acme-doc-1", "acme-doc-2"])
seed("initech", ["initech-doc-1", "initech-doc-2"])
yield
cleanup(["acme", "initech"])
def test_tenant_isolation(two_tenant_store):
acme_hits = chain.invoke({"query": "q"}, config={"configurable": {"tenant_id": "acme"}})
initech_hits = chain.invoke({"query": "q"}, config={"configurable": {"tenant_id": "initech"}})
acme_ids = {d.id for d in acme_hits["documents"]}
initech_ids = {d.id for d in initech_hits["documents"]}
assert acme_ids.isdisjoint(initech_ids), \
f"CROSS-TENANT LEAK: overlap={acme_ids & initech_ids}"
assert all("acme" in doc_id for doc_id in acme_ids)
assert all("initech" in doc_id for doc_id in initech_ids)Run in CI on every PR. A regression to import-time retriever binding fails immediately. See Multi-tenant regression tests for fixtures covering tool-allowlist violation, audit-log completeness, and rate-limiter scoping.
RunnableConfig.configurable["tenant_id"]tenant_id, never a process globaluser_id, tenant_id, chain_name, outcome,
latency_ms, trace_id)| Error / symptom | Cause | Fix |
|---|---|---|
| Tenant A's docs returned to Tenant B after deploy | Singleton retriever bound at import (P33) | Move to per-request factory keyed by config["configurable"]["tenant_id"] (Step 1) |
KeyError: 'tenant_id' in retriever factory | Caller forgot to pass configurable | Fail fast with PermissionError; never default to a tenant |
permission denied for relation documents on PGVector | RLS policy enabled but session variable not set | SET LOCAL app.tenant_id = :tid inside the transaction |
| Agent calls a tool the user's role should not have | Every tool bound at agent construction | Build agent per-request with only role-permitted tools (Step 3) |
| Audit log missing entries for errored invocations | Log emitted inside try only, not finally | Move emit to finally block (Step 5) |
| Shared rate limit trips all tenants when one misbehaves | Process-global InMemoryRateLimiter | Key limiter by tenant_id; use Redis-backed for multi-process (Step 4) |
| Cross-tenant leak regression ships to prod | No two-tenant CI test | Add the Step 6 fixture; run on every PR |
| Audit log contains raw PII from prompts | Logging inputs verbatim | Log field names / token counts / IDs only; never log raw message content |
Combines all six steps: retriever-per-request, Pinecone namespace isolation, role-scoped tools, per-tenant rate limit, audit-log context manager, regression test. Assembly is ~80 lines. See Retriever-per-request.
Wrap the old singleton, add the factory alongside, route by feature flag, ship the regression test first, flip the flag, delete the singleton. Typical migration window: 1-2 sprints. See Multi-tenant regression tests.
Stream each record to BigQuery per the Audit-log schema. Recipes: "tool calls by user X in last 24h", "tenants with >1% error rate", "highest-spend tenants".
RunnableConfigcreate_agentdocs/pain-catalog.md (primary P33; adjacent P18, P24, P31, P37)langchain-rate-limits (per-tenant limiters), langchain-cost-tuning (per-tenant budgets), langchain-security-basics (input redaction upstream of audit log)© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in skills/.curated/langchain-enterprise-rbac of jeremylongshore/tons-of-skills-marketplace.
Open the folder on GitHubat commit cfae287
Langchain Enterprise Rbac next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Langchain Enterprise Rbac this skilljeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~4k | Automated safety check: Pass | MIT | |
| Agentsop Streaming Outputagentsope/SkillAlchemy | 436 | — | ~5.3k | Automated safety check: Pass | MIT | |
| Mem0 Platform SDKmem0ai/mem0 | 67k | 1 repos | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| LangSmith Trace DebuggingComposioHQ/awesome-claude-skills | 77k | 8 repos | ~2.7k | Automated safety check: Pass | None | |
| Add Example AgentGetBindu/Bindu | 10k | — | ~1.1k | Automated safety check: Notes | Custom licence | |
| Failproof AI SDK IntegrationFailproofAI/failproofai | 5.3k | — | ~6k | Automated safety check: Pass | Custom licence |
agentsope/SkillAlchemy
Enhancement-overlay decision protocol for STREAMING the output of long-running LLM / agent runs from the backend, not just wiring a typing animation in the UI.
mem0ai/mem0
Adds persistent memory to AI apps with the Mem0 Python and TypeScript SDKs: store, search, update and delete user memories, with framework integrations.
ComposioHQ/awesome-claude-skills
Debugs LangChain and LangGraph agents by pulling recent execution traces with the langsmith-fetch CLI and reporting errors, tool calls, timings and token use.
GetBindu/Bindu
Add a new self-contained example agent under examples/. An agent skill from GetBindu/Bindu.
FailproofAI/failproofai
Helps instrument a custom Python or TypeScript agent to record events for Failproof AI, verify what gets written, and run an evaluator worker that scores the runs.
TencentEdgeOne/edgeone-makers-tools
Migrate existing AI agent projects (LangChain, LangGraph, OpenAI Agents SDK, Claude Agent SDK, CrewAI) to EdgeOne Makers platform conventions.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
jeremylongshore/tons-of-skills-marketplace
Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.
jeremylongshore/tons-of-skills-marketplace
Execute proactive auto-loading: automatically detects and loads agents.md files.
jeremylongshore/tons-of-skills-marketplace
Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.
jeremylongshore/tons-of-skills-marketplace
Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.
Categories
Enforce tenant isolation and role-based access across LangChain 1.0 chains and LangGraph 1.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and…. Langchain Enterprise Rbac is an agent skill from jeremylongshore/tons-of-skills-marketplace.0 agents — per-request retriever construction, tenant-scoped rate limits, role-scoped tool allowlists, and structured audit logs.
Langchain Enterprise Rbac fits situations like: building multi-tenant saas; passing soc2 review; debugging cross-tenant leak; with langchain multi-tenant.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a claude-code`. Or copy the skill folder (skills/.curated/langchain-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/langchain-enterprise-rbac in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a codex`. Or copy the skill folder (skills/.curated/langchain-enterprise-rbac in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/langchain-enterprise-rbac in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill langchain-enterprise-rbac -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/langchain-enterprise-rbac, .gemini/skills/langchain-enterprise-rbac, .github/skills/langchain-enterprise-rbac and .opencode/skills/langchain-enterprise-rbac in your project.
SKILL.md names no scripts, command-line tools or credentials: Langchain Enterprise Rbac is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(python:*). Compatibility (from SKILL.md): Designed for Claude Code.
SKILL.md names 5 domains. As links in the text: python.langchain.com, langchain-ai.github.io, docs.pinecone.io, postgresql.org and aicpa-cima.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Langchain Enterprise Rbac is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 9.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Langchain Enterprise Rbac: Agentsop Streaming Output (agentsope/SkillAlchemy, 436 stars), Mem0 Platform SDK (mem0ai/mem0, 67k stars), LangSmith Trace Debugging (ComposioHQ/awesome-claude-skills, 77k stars) and Add Example Agent (GetBindu/Bindu, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.
Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.