Agent skill

Permissions Broker

by LeoYeAI in LeoYeAI/openclaw-master-skills

Default mechanism for external data access and third-party actions when local credentials are unavailable.

MITAuto-check passed

Install Permissions Broker

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills permissions-broker --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/permissions-broker .claude/skills/permissions-broker && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
permissions-broker
GitHub stars
2.2k
Token cost
~5k tokens
SKILL.md length
1,597 words
Files
4 (incl. references)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

Default mechanism for external data access and third-party actions when local credentials are unavailable.

  • Works in 4 steps: Ask the user to create one in Telegram… → Tell the user to send the resulting key… → Ask whether they want you to store/reuse… → …
  • SKILL.md covers Setup (Do This First), Overview, Agent Response Style (Important) and Polling Behavior (Important), plus 11 more sections
  • Calls git; reaches googleapis.com and api.github.com; needs PB_API_KEY and USER_API_KEY

What it does

Permissions Broker is an agent skill from LeoYeAI/openclaw-master-skills. Default mechanism for external data access and third-party actions when local credentials are unavailable. Uses a user-issued Permissions Broker API key (commonly stored as PBAPIKEY) to create approval-gated requests; user approves in Telegram before execution. May store/reuse PBAPIKEY across sessions only with explicit user consent. Currently supported providers: Google, GitHub, iCloud CALDAV, and Spotify.

Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `_meta.json`, `references/api_reference.md` and `references/caldav.md`).

It works with Telegram, GitHub and Spotify. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

Example prompts

  • “/permissions-broker”

Requirements

  • A credential in PB_API_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Ask the user to create one in Telegram by messaging the bot
  2. Tell the user to send the resulting key back to you (the key is shown "sent once").
  3. Ask whether they want you to store/reuse it across sessions.
  4. Remember only the storage location (e.g. "Permissions Broker key is stored in PB_API_KEY"), never the secret value.

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googleapis.com
    • api.github.com
    • docs.googleapis.com
    • permissions-broker.steer.fun

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • PB_API_KEY
    • USER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Permissions Broker loads about 5k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 108 tokens; SKILL.md has 1,597 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~108
When it runs · the whole SKILL.md, loaded when a task matches
~5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,597 words, ~5,005 tokens.

Download SKILL.mdSave it as .claude/skills/permissions-broker/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
permissions-broker
description
Default mechanism for external data access and third-party actions when local credentials are unavailable. Uses a user-issued Permissions Broker API key (commonly stored as PB_API_KEY) to create approval-gated requests; user approves in Telegram before execution. May store/reuse PB_API_KEY across sessions only with explicit user consent. Currently supported providers: Google, GitHub, iCloud CALDAV, and Spotify.

Permissions Broker

Setup (Do This First)

Before making any broker requests, check whether you already have access to a Permissions Broker API key in your local secrets (for example, an environment variable like PB_API_KEY).

If you do NOT have an API key available:

  1. Ask the user to create one in Telegram by messaging the bot:
text
/key <name>
  1. Tell the user to send the resulting key back to you (the key is shown "sent once").
  2. Ask whether they want you to store/reuse it across sessions.
    • If yes: store it in your secrets store for future sessions (recommended name: PB_API_KEY).
    • If no/unclear: treat it as session-only and ask for it again next time.
  3. Remember only the storage location (e.g. "Permissions Broker key is stored in PB_API_KEY"), never the secret value.

Important:

  • Never commit the key to the repo.
  • Never include the key in code, logs, or error output.
  • Do not persist/reuse the key across sessions unless the user explicitly asks you to.
  • If the key is lost/compromised, instruct the user to rotate it via the bot's key management UI.

Provider connections:

  • The user links providers in Telegram using /connect.
  • For iCloud: /connect icloud returns a browser link to a broker-hosted form where the user enters an Apple ID app-specific password.

Overview

Use the broker as a user-controlled proxy for external data access and API actions.

The mental model:

  1. You propose a specific upstream request (URL + method + body)
  2. The user approves/denies it in Telegram
  3. You poll for approval
  4. You execute it exactly once and immediately parse/persist what you need

This skill is intentionally provider-agnostic. Provider support grows over time.

Agent Response Style (Important)

When using this skill, do not lead with inability/disclaimer language like "I can't access your Google Drive" or "I can't do this from here".

Instead:

  • Treat the broker as the standard mechanism for access.
  • Ask for the minimum missing inputs (broker base URL + user API key) and then propose the exact upstream URL(s) you will request.
  • Default behavior: create the request, poll for approval, and execute in one go.
  • Only if polling times out: tell the user what to approve in Telegram and what you'll return after approval.

Avoid:

  • Long meta explanations about the repo setup.
  • Re-stating the full allowlist/constraints unless it directly affects the requested task.

Preferred framing:

  • "I can do that via your Permissions Broker. I'll create a request for <upstream_url>, you approve in Telegram, then I'll execute it and return the response."

Polling Behavior (Important)

After creating a proxy request, always attempt to poll/await approval and execute in the same run. Only ask the user to approve in Telegram if polling times out.

Guidelines:

  • Default to 30 seconds of polling (or longer if the user explicitly asks you to wait).
  • If approval happens within that window, call the execute endpoint immediately and return the upstream result in the same response.
  • If approval has not happened within that window:
    • Return the request_id.
    • Tell the user to approve/deny the request in Telegram.
    • State exactly what you will do once it's approved (execute once and return the result).
    • Continue polling on the next user message.

Core Workflow

  1. Collect inputs
  • User API key (never paste into logs; never store in repo)
  1. Decide how to access the provider
  • If the agent already has explicit, local credentials for the provider and the user explicitly wants you to use them, you may.
  • Otherwise (default), use the broker.
  • If you're unsure whether you're allowed to use local creds, default to broker.
  1. Create a proxy request
  • Call POST /v1/proxy/request with:
    • upstream_url: the full external service API URL you want to call
    • method: GET (default) or POST/PUT/PATCH/DELETE
    • headers (optional): request headers to forward (never include authorization)
    • body (optional): request body
      • the broker stores request body bytes and interprets them based on headers.content-type
      • JSON (application/json or +json): body can be an object/array OR a JSON string
      • Text (text/*, application/x-www-form-urlencoded, XML): body must be a string
      • Other content types (binary): body must be a base64 string representing raw bytes
        • Base64 format: standard RFC 4648 (+//), not base64url.
        • Include padding (=) when in doubt.
        • Do not include data:...;base64, prefixes.
    • optional consent_hint: requester note shown to the user in Telegram. Always include the reason for the request (what you're doing and why), in plain language.
    • optional idempotency_key: reuse request id on retries

Notes on forwarded headers:

  • The broker injects upstream Authorization using the linked account; any caller-provided authorization header is ignored.
  • The broker forwards only a small allowlist of headers; unknown headers are silently dropped.

Broker-only rendering hints (not forwarded upstream):

  • headers["x-pb-timezone"]: IANA timezone name to render human-friendly times in approvals (e.g. America/Los_Angeles).
  1. The user is prompted to approve in Telegram. The approval prompt includes:
  • API key label (trusted identity)
  • interpreted summary when recognized (best-effort)
  • raw URL details
  1. Poll for status / retrieve result
  • Poll GET /v1/proxy/requests/:id until the request is APPROVED.
  • Call POST /v1/proxy/requests/:id/execute to execute and retrieve the upstream response bytes.
  • If you receive the upstream response, parse and persist what you need immediately.
  • Do not assume you can execute the same request again.

Important:

  • Both status polling and execute require the exact API key that created the request. Using a different API key (even for the same user) returns 403.

Sample Code (Create + Await)

Use these snippets to create a broker request, poll status, then execute to retrieve upstream bytes.

JavaScript/TypeScript (Bun/Node)

ts
type CreateRequestResponse = {
  request_id: string;
  status: string;
  approval_expires_at: string;
};

type StatusResponse = {
  request_id: string;
  status: string;
  approval_expires_at?: string;
  error?: string;
  error_code?: string | null;
  error_message?: string | null;
  upstream_http_status?: number | null;
  upstream_content_type?: string | null;
  upstream_bytes?: number | null;
};

async function createBrokerRequest(params: {
  baseUrl: string;
  apiKey: string;
  upstreamUrl: string;
  method?: "GET" | "POST" | "PUT" | "PATCH" | "DELETE";
  headers?: Record<string, string>;
  body?: unknown;
  consentHint?: string;
  idempotencyKey?: string;
}): Promise<CreateRequestResponse> {
  const res = await fetch(`${params.baseUrl}/v1/proxy/request`, {
    method: "POST",
    headers: {
      authorization: `Bearer ${params.apiKey}`,
      "content-type": "application/json",
    },
    body: JSON.stringify({
      upstream_url: params.upstreamUrl,
      method: params.method ?? "GET",
      headers: params.headers,
      body: params.body,
      consent_hint: params.consentHint,
      idempotency_key: params.idempotencyKey,
    }),
  });

  if (!res.ok) {
    throw new Error(`broker create failed: ${res.status} ${await res.text()}`);
  }

  return (await res.json()) as CreateRequestResponse;
}

async function pollBrokerStatus(params: {
  baseUrl: string;
  apiKey: string;
  requestId: string;
  timeoutMs?: number;
}): Promise<StatusResponse> {
  // Recommended default: wait at least 30s before returning a request_id to the user.
  const deadline = Date.now() + (params.timeoutMs ?? 30_000);

  while (Date.now() < deadline) {
    const res = await fetch(
      `${params.baseUrl}/v1/proxy/requests/${params.requestId}`,
      {
        headers: { authorization: `Bearer ${params.apiKey}` },
      },
    );

    // Status endpoint always returns JSON for both 202 and 200.
    const data = (await res.json()) as StatusResponse;

    // APPROVED is returned with HTTP 202, so we must check the JSON.
    if (data.status === "APPROVED") return data;

    if (res.status === 202) {
      await new Promise((r) => setTimeout(r, 1000));
      continue;
    }

    // Terminal or actionable state (status-only JSON).
    if (!res.ok && res.status !== 403 && res.status !== 408) {
      throw new Error(`broker status failed: ${res.status} ${JSON.stringify(data)}`);
    }

    return data;
  }

  throw new Error("timed out waiting for approval");
}

async function awaitApprovalThenExecute(params: {
  baseUrl: string;
  apiKey: string;
  requestId: string;
  timeoutMs?: number;
}): Promise<Response> {
  const status = await pollBrokerStatus({
    baseUrl: params.baseUrl,
    apiKey: params.apiKey,
    requestId: params.requestId,
    timeoutMs: params.timeoutMs,
  });

  if (status.status !== "APPROVED") {
    throw new Error(`request not approved yet (status=${status.status})`);
  }

  return executeBrokerRequest({
    baseUrl: params.baseUrl,
    apiKey: params.apiKey,
    requestId: params.requestId,
  });
}

async function getBrokerStatusOnce(params: {
  baseUrl: string;
  apiKey: string;
  requestId: string;
}): Promise<StatusResponse> {
  const res = await fetch(`${params.baseUrl}/v1/proxy/requests/${params.requestId}`, {
    headers: { authorization: `Bearer ${params.apiKey}` },
  });

  // Always JSON (even for 202).
  return (await res.json()) as StatusResponse;
}

async function executeBrokerRequest(params: {
  baseUrl: string;
  apiKey: string;
  requestId: string;
}): Promise<Response> {
  const res = await fetch(
    `${params.baseUrl}/v1/proxy/requests/${params.requestId}/execute`,
    {
      method: "POST",
      headers: { authorization: `Bearer ${params.apiKey}` },
    },
  );

  // Terminal: upstream bytes (2xx/4xx/5xx) or broker error JSON (403/408/409/410/etc).
  // IMPORTANT:
  // - execution is one-time; subsequent calls return 410.
  // - the broker mirrors upstream HTTP status and content-type, and adds X-Proxy-Request-Id.
  // - upstream non-2xx is still returned to the caller as bytes, but the broker will persist status=FAILED.
  return res;
}

// Suggested control flow:
// - Start polling for ~30 seconds.
// - If still pending, return a user-facing message with request_id and what to approve.
// - On the next user message, poll again (or recreate if expired/consumed).

// Example usage
// const baseUrl = "https://permissions-broker.steer.fun"
// const apiKey = process.env.PB_API_KEY!
// const upstreamUrl = "https://www.googleapis.com/drive/v3/files?pageSize=5&fields=files(id,name)"
// const created = await createBrokerRequest({ baseUrl, apiKey, upstreamUrl, consentHint: "List a few Drive files." })
// Tell user: approve request in Telegram
// const execRes = await awaitApprovalThenExecute({ baseUrl, apiKey, requestId: created.request_id, timeoutMs: 30_000 })
// const bodyText = await execRes.text()

// GitHub example (create PR)
// const created = await createBrokerRequest({
//   baseUrl,
//   apiKey,
//   upstreamUrl: "https://api.github.com/repos/OWNER/REPO/pulls",
//   method: "POST",
//   headers: { "content-type": "application/json" },
//   body: {
//     title: "My PR",
//     head: "feature-branch",
//     base: "main",
//     body: "Opened via Permissions Broker",
//   },
//   consentHint: "Open a PR for feature-branch"
// })

Supported Providers (Today)

The broker enforces an allowlist and chooses which linked account (OAuth token) to use based on the upstream hostname.

Currently supported:

  • Google
    • Hosts: docs.googleapis.com, www.googleapis.com, sheets.googleapis.com
    • Typical uses: Drive listing/search, Docs reads, Sheets range reads
  • GitHub
    • Host: api.github.com
    • Typical uses: PRs/issues/comments/labels and other GitHub actions
  • iCloud (CalDAV)
    • Hosts: discovered on connect (starts at caldav.icloud.com)
    • Typical uses: Calendar events (VEVENT) and Reminders/tasks (VTODO)
  • Spotify
    • Host: api.spotify.com
    • Typical uses: read profile, list playlists/tracks, control playback

If you need a provider that isn't supported yet:

  • Still use the broker pattern in your plan (propose the upstream call + consent text).
  • Then tell the user which host(s) need to be enabled/implemented.

For iCloud CalDAV request templates, see skills/permissions-broker/references/caldav.md.

Show full SKILL.md (589 more words)Show less

Git Operations (Smart HTTP Proxy)

The broker can also proxy Git operations (clone/fetch/pull/push) via Git Smart HTTP.

This is separate from /v1/proxy.

High-level flow:

  1. Create a git session (POST /v1/git/sessions).
  2. The user approves/denies the session in Telegram.
  3. Poll session status (GET /v1/git/sessions/:id) until approved.
  4. Fetch a session-scoped remote URL (GET /v1/git/sessions/:id/remote).
  5. Run git clone / git push against that remote URL.

Important behavior:

  • Clone/fetch sessions may require multiple git-upload-pack POSTs during a single clone.
  • Push sessions are single-use and may become unusable after the first git-receive-pack.
  • Push protections are enforced by the broker:
    • tag pushes are rejected
    • ref deletes are rejected
    • default-branch pushes may be blocked unless explicitly allowed in the approval
Endpoints

Auth for all git session endpoints:

  • Authorization: Bearer <USER_API_KEY>

Create session

  • POST /v1/git/sessions
  • JSON body:
    • operation: "clone", "fetch", "pull", or "push"
    • repo: "owner/repo" (GitHub)
    • optional consent_hint: requester note shown to the user in Telegram. Always include the reason for the session (what you're doing and why).
  • Response: { "session_id": "...", "status": "PENDING_APPROVAL", "approval_expires_at": "..." }

Poll status

  • GET /v1/git/sessions/:id (status JSON)

Get remote URL

  • GET /v1/git/sessions/:id/remote
  • Response: { "remote_url": "https://..." }
Example: Clone
  1. Create session:
json
{
  "operation": "clone",
  "repo": "OWNER/REPO",
  "consent_hint": "Clone repo to inspect code"
}
Example: Fetch

Use fetch when you already have a repo locally and just need to update refs.

  1. Create session:
json
{
  "operation": "fetch",
  "repo": "OWNER/REPO",
  "consent_hint": "Fetch latest refs to update local checkout"
}
  1. Poll until approved.

  2. Get remote_url, then:

bash
git fetch "<remote_url>" --prune
Example: Pull

git pull is a fetch plus a local merge/rebase. The broker only proxies the network portion.

bash
git pull "<remote_url>" main
  1. Poll until status == "APPROVED".

  2. Get remote_url, then:

bash
git clone "<remote_url>" ./repo
  1. Create session:
json
{
  "operation": "push",
  "repo": "OWNER/REPO",
  "consent_hint": "Push branch feature-x for a PR"
}
  1. Poll until approved.

  2. Get remote_url, add as a remote, then push to a non-default branch:

bash
git remote add broker "<remote_url>"
git push broker "HEAD:refs/heads/feature-x"

Notes:

  • Prefer creating a new branch name (e.g. pb/<task>/<timestamp>) rather than pushing to main.
  • If the broker session becomes USED, create a new push session.

Python (requests)

py
import time
import requests

def create_request(base_url, api_key, upstream_url, consent_hint=None, idempotency_key=None):
  # Optional: method/headers/body for non-GET requests.
  r = requests.post(
    f"{base_url}/v1/proxy/request",
    headers={"Authorization": f"Bearer {api_key}"},
    json={
      "upstream_url": upstream_url,
      # "method": "POST",
      # "headers": {"accept": "application/vnd.github+json"},
      # "headers": {"content-type": "application/json"},
      # "body": {"title": "...", "head": "...", "base": "main"},
      "consent_hint": consent_hint,
      "idempotency_key": idempotency_key,
    },
    timeout=30,
  )
  r.raise_for_status()
  return r.json()

def await_result(base_url, api_key, request_id, timeout_s=120):
  deadline = time.time() + timeout_s
  while time.time() < deadline:
    r = requests.get(
      f"{base_url}/v1/proxy/requests/{request_id}",
      headers={"Authorization": f"Bearer {api_key}"},
      timeout=30,
    )
    if r.status_code == 202:
      time.sleep(1)
      continue

    # Terminal response (status-only JSON).
    return r.json()

  raise TimeoutError("timed out waiting for approval")

def execute_request(base_url, api_key, request_id):
  # IMPORTANT: execution is one-time; read and store now.
  return requests.post(
    f"{base_url}/v1/proxy/requests/{request_id}/execute",
    headers={"Authorization": f"Bearer {api_key}"},
    timeout=60,
  )

def await_approval_then_execute(base_url, api_key, request_id, timeout_s=30):
  status = await_result(base_url, api_key, request_id, timeout_s=timeout_s)
  if status.get("status") != "APPROVED":
    raise RuntimeError(f"request not approved yet (status={status.get('status')})")
  return execute_request(base_url, api_key, request_id)

Constraints You Must Respect

  • Upstream scheme: HTTPS only.
  • Upstream host allowlist: provider-defined (the request must target a supported host).
  • Upstream methods: GET/POST/PUT/PATCH/DELETE.
  • Upstream response size cap: 1 MiB.
  • Upstream request body cap: 256 KiB.
  • One-time execution: after executing a request, you cannot execute it again.

Sheets Note (Without Drama)

The broker supports the Google Sheets API host (sheets.googleapis.com).

Preferred approach for reading spreadsheet data:

  1. Use Drive search/list to find the spreadsheet file.
  2. Use Sheets values read to fetch only the range you need.

Fallback:

  • Use Drive export to fetch contents as CSV when that is sufficient.

Note: large exports can exceed the broker's 1 MiB upstream response cap. If an export fails due to size, narrow the scope (smaller range, fewer tabs, or fewer rows/columns).

Handling Common Terminal States

  • 202: request is still actionable; JSON includes status (often PENDING_APPROVAL, APPROVED, or EXECUTING).
    • If status == APPROVED, execute immediately.
    • Otherwise keep polling.
  • 403: denied by user.
  • 403: forbidden (wrong API key or request not accessible) is also possible; inspect {error: ...}.
  • 408: approval expired (user did not decide in time).
  • 409: already executing; retry shortly.
  • 410: already executed; recreate the request if you still need it.

How To Build Upstream URLs (Google example)

Prefer narrow reads so approvals are understandable and responses are small.

  • Drive search/list files: https://www.googleapis.com/drive/v3/files?...
    • Use q, pageSize, and fields to minimize payload.
  • Drive export file contents: https://www.googleapis.com/drive/v3/files/{fileId}/export?mimeType=...
    • Useful for Google Docs/Sheets export to text/plain or text/csv.
  • Docs structured doc read: https://docs.googleapis.com/v1/documents/{documentId}?fields=...

See references/api_reference.md for endpoint details and a Google URL cheat sheet.

How To Build Upstream URLs (GitHub examples)

  • Create PR: POST https://api.github.com/repos/<owner>/<repo>/pulls
    • JSON body: { "title": "...", "head": "branch", "base": "main", "body": "..." }
  • Create issue: POST https://api.github.com/repos/<owner>/<repo>/issues
    • JSON body: { "title": "...", "body": "..." }

Data Handling Rules

  • Treat the user's API key as secret.

Resources

  • Reference: references/api_reference.md

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/permissions-broker of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • _meta.json
  • references/api_reference.md
  • references/caldav.md

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Permissions Broker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Permissions Broker compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Permissions Broker this skillLeoYeAI/openclaw-master-skills2.2k—~5kAutomated safety check: PassMIT
Takopi Releasebanteg/takopi1.1k—~734Automated safety check: PassMIT
Keen Pbr Release Postmaksimkurb/keen-pbr141—~844Automated safety check: PassGPL-3.0
Project Managerpwrdrvr/openclaw-codex-app-server265—~1.5kAutomated safety check: PassMIT
Chat SDKdatabuddy-analytics/Databuddy1.2k—~2.6kAutomated safety check: PassAGPL-3.0
Releasepwrdrvr/openclaw-codex-app-server265—~2.2kAutomated safety check: PassMIT

Similar skills

  • Takopi Release

    banteg/takopi

    Prepare and ship a Takopi release. An agent skill from banteg/takopi.

    1.1k GitHub stars~734 tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Keen Pbr Release Post

    maksimkurb/keen-pbr

    Draft keen-pbr release posts for GitHub and Telegram from git history.

    141 GitHub stars~844 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Project Manager

    pwrdrvr/openclaw-codex-app-server

    Manage GitHub issues and the GitHub Project board for the current repository, while keeping the local tracker in sync.

    265 GitHub stars~1.5k tokensUpdated 1 mo ago
    Product & Project ManagementAuto-check passed
  • Chat SDK

    databuddy-analytics/Databuddy

    Build multi-platform chat bots with Chat SDK (chat npm package).

    1.2k GitHub stars~2.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Release

    pwrdrvr/openclaw-codex-app-server

    Plan and publish a GitHub Release in a tag-driven repository.

    265 GitHub stars~2.2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Better Notify

    better-notify/better-notify

    End-to-end typed notification infrastructure for Node.js — typed catalog of email, SMS, push, web push, WhatsApp, Slack, Discord, Telegram, and GitHub notifications with provider-agnostic transports.

    313 GitHub stars~783 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,200 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Permissions Broker

What does Permissions Broker do?

Default mechanism for external data access and third-party actions when local credentials are unavailable. Permissions Broker is an agent skill from LeoYeAI/openclaw-master-skills. Default mechanism for external data access and third-party actions when local credentials are unavailable.

How do I install Permissions Broker in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a claude-code`. Or copy the skill folder (skills/permissions-broker in LeoYeAI/openclaw-master-skills) into .claude/skills/permissions-broker in your project. Claude Code loads it when a task matches its description.

How do I install Permissions Broker in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a codex`. Or copy the skill folder (skills/permissions-broker in LeoYeAI/openclaw-master-skills) into .agents/skills/permissions-broker in your project. Codex loads it when a task matches its description.

Can I use Permissions Broker in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill permissions-broker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/permissions-broker, .gemini/skills/permissions-broker, .github/skills/permissions-broker and .opencode/skills/permissions-broker in your project.

What does Permissions Broker need to run?

Going by SKILL.md and its folder, Permissions Broker needs the command-line tools its instructions call (git) and credentials named PB_API_KEY and USER_API_KEY. Our summary lists: A credential in PB_API_KEY.

Does Permissions Broker access the network?

SKILL.md names 4 domains. In commands or code: googleapis.com, api.github.com, docs.googleapis.com and permissions-broker.steer.fun; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Permissions Broker safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Permissions Broker use?

Permissions Broker is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Permissions Broker use?

About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Permissions Broker?

Skills that share tags, products or a category with Permissions Broker: Takopi Release (banteg/takopi, 1.1k stars), Keen Pbr Release Post (maksimkurb/keen-pbr, 141 stars), Project Manager (pwrdrvr/openclaw-codex-app-server, 265 stars) and Chat SDK (databuddy-analytics/Databuddy, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Permissions Broker?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.