Agent skill

Review Grant

by marin-community in marin-community/marin

Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.

Apache-2.0Auto-check passedDevOps & Cloud

Install Review Grant

skills CLI
$ npx skills add marin-community/marin --skill review-grant -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install marin-community/marin review-grant --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/marin-community/marin.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/review-grant .claude/skills/review-grant && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-grant
GitHub stars
3.9k
Token cost
~1.1k tokens
SKILL.md length
447 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.

  • Works in 6 steps: Fetch the PR → Decrypt the changed principals → Present the grant and get confirmation → …
  • Tasks that involve Infrastructure as code
  • SKILL.md covers 1. Fetch the PR, 2. Decrypt the changed…, 3. Present the grant and get… and 4. Approve, merge, land, plus 2 more sections
  • Calls pulumi, gh and git

What it does

Review Grant is an agent skill from marin-community/marin. Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Pulumi. The repository describes itself as: Open-source framework for the research and development of foundation models. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Infrastructure as code

Example prompts

  • “/review-grant”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Fetch the PR
  2. Decrypt the changed principals
  3. Present the grant and get confirmation
  4. Approve, merge, land
  5. Apply with pulumi up
  6. Confirm on the PR

What it can do on your machine

Read from SKILL.md and the folder at commit c468793. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pulumi
    • gh
    • git
    • uv
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, git and uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Grant loads about 1.1k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 447 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from marin-community/marin at commit c468793, republished under its Apache-2.0 licence (© marin-community). 447 words, ~1,050 tokens.

Download SKILL.mdSave it as .claude/skills/review-grant/SKILL.md (or your agent's skills folder).
name
review-grant
description
Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.

Skill: Review a user grant

A grant PR (usually from the add-grant skill) uses opaque human-NNN references whose emails are KMS ciphertext in iam_data.yaml. This skill reveals the real grant, gets an explicit human confirmation, then lands it and applies it.

Read first:

  • infra/pulumi/README.md — the marin-iac stacks and the pulumi up prerequisites (you need roles/cloudkms.cryptoKeyEncrypterDecrypter on the key and permission to update the marin stack).

Never approve or merge before the user confirms the decrypted grant. The whole point is that a second person sees the actual identity and access before it is applied.

1. Fetch the PR

bash
gh pr view <n> --repo marin-community/marin --json title,body,headRefName,files,url
gh pr checkout <n>          # pull the branch into the worktree
git fetch origin main

Confirm the diff only touches grant surfaces under infra/pulumi/src/iac/gcp/: iam_data.yaml and/or a deploy-target IAM module. If it changes anything else (code, other Pulumi resources), stop and review it as an ordinary PR, not a grant.

2. Decrypt the changed principals

Turn the changed opaque principal references into real emails:

bash
git diff origin/main...HEAD -- infra/pulumi/src/iac/gcp \
  | uv run --package marin-iac --extra deploy \
      python infra/pulumi/iam_principal.py decrypt --diff

Each output line is + user:<email> (added) or - user:<email> (removed). Map each back to the role and resource it sits under in the diff. The decryptor shows the principal; read the surrounding role and container (project_grants, a specific bucket/secret/repository/service account, or a deploy-target module) from the diff hunk.

3. Present the grant and get confirmation

Print a plain-language summary, one line per grant, and ask the user to confirm. For example:

PR #1234 grants:
  + alice@openathena.ai → roles/storage.objectViewer on project hai-gcp-models
  + alice@openathena.ai → IAP viewer on evaldash.oa.dev
  - bob@openathena.ai → roles/bigquery.dataViewer (revoked)
Apply this? (yes/no)

Call out anything that looks off: a broader role than the resource needs, a principal you do not recognize, a domain wildcard, or a revocation that might cut off active access. If the user does not clearly approve, stop and report back — do not merge.

Show full SKILL.md (185 more words)Show less

4. Approve, merge, land

After the user confirms:

bash
gh pr review <n> --repo marin-community/marin --approve
gh pr merge <n> --repo marin-community/marin --squash
git checkout main && git pull origin main   # land the merged change locally

Wait for the merge to land on main and pull it before applying, so pulumi up runs against the committed state.

5. Apply with pulumi up

The change is not live until pulumi up runs — CI never applies. Identify the affected stack(s) from the diff:

  • Any grant surface under infra/pulumi/src/iac/gcp/ → the marin stack in infra/pulumi.

Prompt the user: they can run it themselves, or ask you to. If you run it, per stack:

bash
cd infra/<dir>
pulumi stack select <stack>
pulumi preview      # confirm ONLY the intended grant is added/removed, no other drift
pulumi up

Read the preview before applying. For the marin stack, expect only the IAMMember create/delete for this grant — any NodePool or other unexpected replace/delete means stop and reconcile, exactly as the pulumi README warns. Once up is clean, tell the user the grant is live.

6. Confirm on the PR

Comment on the merged PR that pulumi up ran and the grant is live, so the requester and any watcher see the change reached production, not just main:

bash
gh pr comment <n> --repo marin-community/marin \
  --body "🤖 \`pulumi up\` on the \`<stack>\` stack succeeded — the grant is live."

An agent comment must begin with 🤖 (see AGENTS.md). If pulumi up did not run (the user is applying it themselves), skip this and let them confirm instead.

© marin-community, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/review-grant of marin-community/marin.

Open the folder on GitHubat commit c468793

Compare with similar skills

Review Grant next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Grant compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Grant this skillmarin-community/marin3.9k—~1.1kAutomated safety check: PassApache-2.0
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Cloudflaredmmulroy/cloudflare-skill727—~1.6kAutomated safety check: PassMIT
Spacectlspacelift-io/spacectl173—~2.3kAutomated safety check: PassMIT
AWS Native Runtime Investigationpulumi/pulumi-aws-native108—~753Automated safety check: PassApache-2.0
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    727 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Spacectl

    spacelift-io/spacectl

    Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.

    173 GitHub stars~2.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • AWS Native Runtime Investigation

    pulumi/pulumi-aws-native

    Official

    Use after triage or repository evidence establishes that an issue involves Pulumi AWS Native runtime behavior across the Pulumi provider protocol, generated CloudFormation metadata, and AWS Cloud…

    108 GitHub stars~753 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    135 GitHub stars~649 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from marin-community/marin

All 41 skills in this repo
  • Noslop

    marin-community/marin

    Deslop, simplify, or review low-value tests and prose only when explicitly requested for a branch or diff.

    3.9k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Use Iris

    marin-community/marin

    Use Iris to submit, inspect, debug, monitor, or recover jobs and tasks; diagnose scheduling and federation; deploy controllers; or reserve dev GPUs and TPUs.

    3.9k GitHub stars~745 tokensUpdated today
    Auto-check passed
  • Launch Rl

    marin-community/marin

    Define, validate, submit, or restart a Marin SkyRL experiment through its artifact main.

    3.9k GitHub stars~894 tokensUpdated today
    Auto-check passed
  • Marina Applet

    marin-community/marin

    Build, validate, publish, update, inspect, query, roll back, or archive a dynamic Marina applet.

    3.9k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Query Finelog

    marin-community/marin

    Query Finelog logs and telemetry for Iris tasks, workers, profiles, training, vLLM, and cross-cluster forwarding.

    3.9k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Trace Pulumi Diff

    marin-community/marin

    Run a read-only preview for a specified Marin infra/pulumi stack and trace each pending resource change to merged pull requests since its latest successful update when that update records a clean…

    3.9k GitHub stars~663 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Review Grant

What does Review Grant do?

Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant. Review Grant is an agent skill from marin-community/marin. Review an explicitly identified marin-iac grant PR that edits IAM data or a deploy-target module, confirm its decrypted principals and roles, then apply only the confirmed grant.

When should I use Review Grant?

Review Grant fits situations like: tasks that involve Infrastructure as code.

How do I install Review Grant in Claude Code?

Run `npx skills add marin-community/marin --skill review-grant -a claude-code`. Or copy the skill folder (.agents/skills/review-grant in marin-community/marin) into .claude/skills/review-grant in your project. Claude Code loads it when a task matches its description.

How do I install Review Grant in Codex?

Run `npx skills add marin-community/marin --skill review-grant -a codex`. Or copy the skill folder (.agents/skills/review-grant in marin-community/marin) into .agents/skills/review-grant in your project. Codex loads it when a task matches its description.

Can I use Review Grant in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marin-community/marin --skill review-grant -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-grant, .gemini/skills/review-grant, .github/skills/review-grant and .opencode/skills/review-grant in your project.

What does Review Grant need to run?

Going by SKILL.md and its folder, Review Grant needs the command-line tools its instructions call (pulumi, gh, git, uv and python). Our summary lists: Python 3.

Does Review Grant access the network?

SKILL.md contains no URLs. Its commands use gh, git and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Review Grant safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Grant use?

Review Grant is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Grant use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Grant?

Skills that share tags, products or a category with Review Grant: Cloudflare (hodgef/apiker, 127 stars), Cloudflare (dmmulroy/cloudflare-skill, 727 stars), Spacectl (spacelift-io/spacectl, 173 stars) and AWS Native Runtime Investigation (pulumi/pulumi-aws-native, 108 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Grant?

marin-community (a GitHub organization) maintains it in marin-community/marin, which has 3,921 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 10, 2026.

Source: marin-community/marin on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.