Agent skill

Permissions Capabilities

by luxury-yacht in luxury-yacht/app

Work on Luxury Yacht RBAC permission checks, capability descriptors, permission-denied diagnostics, object action availability, YAML/edit/delete/scale/restart gating, and capability tests

GPL-3.0Auto-check passedBackend & APIs

Install Permissions Capabilities

skills CLI
$ npx skills add luxury-yacht/app --skill permissions-capabilities -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install luxury-yacht/app permissions-capabilities --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/luxury-yacht/app.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/permissions-capabilities .claude/skills/permissions-capabilities && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
permissions-capabilities
GitHub stars
444
Token cost
~835 tokens
SKILL.md length
173 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
GPL-3.0

At a glance

Work on Luxury Yacht RBAC permission checks, capability descriptors, permission-denied diagnostics, object action availability, YAML/edit/delete/scale/restart gating, and capability tests

  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Task routes, Entry Points, Procedure and Validation
  • Calls mise
  • Tasks that involve Container orchestration

What it does

Permissions Capabilities is an agent skill from luxury-yacht/app. Work on Luxury Yacht RBAC permission checks, capability descriptors, permission-denied diagnostics, object action availability, YAML/edit/delete/scale/restart gating, and capability tests

Its SKILL.md is about 840 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and Container orchestration. The repository describes itself as: Luxury Yacht - A cross-platform app for managing Kubernetes clusters and resources. The licence is GPL-3.0.

When your agent uses it

  • Tasks that involve Authorization and RBAC
  • Tasks that involve Container orchestration

Example prompts

  • “/permissions-capabilities”

What it can do on your machine

Read from SKILL.md and the folder at commit 09c8d2d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mise

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Permissions Capabilities loads about 835 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 173 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~835

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from luxury-yacht/app at commit 09c8d2d, republished under its GPL-3.0 licence (© luxury-yacht). 173 words, ~835 tokens.

Download SKILL.mdSave it as .claude/skills/permissions-capabilities/SKILL.md (or your agent's skills folder).
name
permissions-capabilities
description
Work on Luxury Yacht RBAC permission checks, capability descriptors, permission-denied diagnostics, object action availability, YAML/edit/delete/scale/restart gating, and capability tests

Permissions And Capabilities

Use this when touching backend RBAC checks, capability services, permission diagnostics, frontend capability hooks, object action availability, YAML/edit gating, delete/scale/restart/trigger/suspend actions, or restricted-RBAC tests.

Task routes

Read only the contracts selected by the change. Follow further links when the changed path crosses that boundary.

ChangeRead
RBAC checks, capability policy, object actions, denied actionspermissions
Object identity, reference construction or resolutionshared-resource-model
Permission-denied domains, stream gates or readinessrefresh-system, fail-fast contract
Namespace-scoped identities, check scope vs source scopenamespace-scope
Permission diagnostic surfacesrefresh-system

Entry Points

  • Backend: backend/capabilities, backend/resource_gateway.go, backend/resource_permission.go, backend/runtime_setting_policies.go (PermissionFetchPolicy), backend/refresh/permissions/resource_requirement.go, backend/refresh/snapshot/permission.go, backend/refresh/system/registrations.go, backend/refresh/system/permission_gate.go, backend/refresh/resourcestream/projection_descriptors.go.
  • Backend action/operation services: backend/resources, backend/object_yaml*.go, backend/portforward*.go, backend/shell_sessions.go.
  • Frontend: frontend/src/core/capabilities (incl. permissionFeatures.ts), frontend/src/shared/actions/objectActionPolicy.ts, frontend/src/shared/hooks/useObjectActions.tsx, frontend/src/shared/components/kubernetes/ActionsMenu.tsx, frontend/src/modules/object-panel/components/ObjectPanel/hooks/useObjectPanelCapabilities.ts, frontend/src/modules/object-panel/components/ObjectPanel/constants.ts, frontend/src/core/refresh/components/diagnostics/diagnosticsPanelConfig.ts.

Procedure

  • Name which evaluator the change touches (refresh domain, UI capability, backend mutation, or several) before editing; each has its own cache and failure behavior.
  • For multi-resource domains, decide all-or-nothing versus partial data explicitly.
  • Restricted-RBAC behavior degrades visibly, never silently hiding domains or actions; a restricted kind cluster is in kind-clusters.

Validation

Use focused checks while iterating:

sh
mise exec -- go test ./backend/capabilities ./backend/refresh/snapshot ./backend/refresh/system ./backend
mise exec -- npm run typecheck --prefix frontend
mise exec -- npm run test --prefix frontend -- capabilities ObjectPanel ActionsMenu diagnostics

© luxury-yacht, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/permissions-capabilities of luxury-yacht/app.

Open the folder on GitHubat commit 09c8d2d

Compare with similar skills

Permissions Capabilities next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Permissions Capabilities compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Permissions Capabilities this skillluxury-yacht/app444—~835Automated safety check: PassGPL-3.0
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Implementing Rbac Hardening For Kubernetesmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Auditing Kubernetes Rbac Privilege Escalationmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Gke Workload Identitygoogle/skills21k—~4.4kAutomated safety check: PassApache-2.0
Kubernetes Rbac Analyzerjeremylongshore/tons-of-skills-marketplace2.8k—~590Automated safety check: PassMIT

Similar skills

  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Implementing Rbac Hardening For Kubernetes

    mukul975/Anthropic-Cybersecurity-Skills

    Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Auditing Kubernetes Rbac Privilege Escalation

    mukul975/Anthropic-Cybersecurity-Skills

    Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Official

    Configures and diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or…

    21k GitHub stars~4.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Kubernetes Rbac Analyzer

    jeremylongshore/tons-of-skills-marketplace

    Analyze kubernetes rbac analyzer operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~590 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • K8s Istio Bypass

    wgpsec/AboutSecurity

    Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能

    1.8k GitHub stars~727 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from luxury-yacht/app

All 17 skills in this repo
  • Improve Backend

    luxury-yacht/app

    A skill your agent uses when wanting to systematically improve the Go backend - scans for security vulnerabilities, stability risks, performance issues, and code simplification opportunities, then…

    444 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Improve Frontend

    luxury-yacht/app

    A skill your agent uses when wanting to systematically improve the React/TypeScript frontend - scans for security vulnerabilities, stability risks, performance issues, and code simplification…

    444 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Eliminate representable-but-invalid Luxury Yacht states with discriminated unions, required identity, typed status, validated constructors, or one boundary chokepoint; use for "make impossible…

    444 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Add Resource

    luxury-yacht/app

    Add or extend support for a Kubernetes resource kind across the required catalog, refresh, detail, object-panel, object-map, permission, documentation, and test surfaces

    444 GitHub stars~704 tokensUpdated today
    Auto-check passed
  • App Review

    luxury-yacht/app

    Audit broad Luxury Yacht systems or cross-cutting concerns for structural simplification, hardening, optimization, or refactoring; use for app-wide reviews and phased structural plans, not branch…

    444 GitHub stars~818 tokensUpdated today
    Auto-check passed
  • Browse Tables

    luxury-yacht/app

    Change cluster or namespace views, Browse/catalog surfaces, shared GridTable behavior, filters, pagination, large datasets, metrics columns, or refresh-backed resource tables

    444 GitHub stars~518 tokensUpdated today
    Auto-check passed

Categories

Questions about Permissions Capabilities

What does Permissions Capabilities do?

Work on Luxury Yacht RBAC permission checks, capability descriptors, permission-denied diagnostics, object action availability, YAML/edit/delete/scale/restart gating, and capability tests. Permissions Capabilities is an agent skill from luxury-yacht/app.

When should I use Permissions Capabilities?

Permissions Capabilities fits situations like: tasks that involve Authorization and RBAC; tasks that involve Container orchestration.

How do I install Permissions Capabilities in Claude Code?

Run `npx skills add luxury-yacht/app --skill permissions-capabilities -a claude-code`. Or copy the skill folder (.agents/skills/permissions-capabilities in luxury-yacht/app) into .claude/skills/permissions-capabilities in your project. Claude Code loads it when a task matches its description.

How do I install Permissions Capabilities in Codex?

Run `npx skills add luxury-yacht/app --skill permissions-capabilities -a codex`. Or copy the skill folder (.agents/skills/permissions-capabilities in luxury-yacht/app) into .agents/skills/permissions-capabilities in your project. Codex loads it when a task matches its description.

Can I use Permissions Capabilities in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luxury-yacht/app --skill permissions-capabilities -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/permissions-capabilities, .gemini/skills/permissions-capabilities, .github/skills/permissions-capabilities and .opencode/skills/permissions-capabilities in your project.

What does Permissions Capabilities need to run?

Going by SKILL.md and its folder, Permissions Capabilities needs the command-line tools its instructions call (mise).

Does Permissions Capabilities access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Permissions Capabilities safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Permissions Capabilities use?

Permissions Capabilities is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Permissions Capabilities use?

About 835 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Permissions Capabilities?

Skills that share tags, products or a category with Permissions Capabilities: K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Implementing Rbac Hardening For Kubernetes (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Auditing Kubernetes Rbac Privilege Escalation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Gke Workload Identity (google/skills, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Permissions Capabilities?

luxury-yacht (a GitHub organization) maintains it in luxury-yacht/app, which has 444 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 10, 2026.

Source: luxury-yacht/app on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.