Agent skill

Tool Permission Review

by mohitagw15856 in mohitagw15856/pm-claude-skills

Review what an agent is actually allowed to do before you turn it loose — the tool-by-tool audit (each capability's blast radius), the least-privilege pass that removes what the task doesn't need…

MITAuto-check: notesAgent Workflows

Install Tool Permission Review

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill tool-permission-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills tool-permission-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tool-permission-review .claude/skills/tool-permission-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tool-permission-review
GitHub stars
1.4k
Token cost
~1.6k tokens
SKILL.md length
809 words
Files
1
Skills in repo
1,348
Repo updated
First seen
Licence
MIT

At a glance

Review what an agent is actually allowed to do before you turn it loose — the tool-by-tool audit (each capability's blast radius), the least-privilege pass that removes what the task doesn't need…

  • Works in 5 steps: Inventory by blast radius, not by name:… → Least privilege is the whole game: for… → The dangerous combinations — the… → …
  • Asked review my agents permissions
  • SKILL.md covers What This Skill Produces, Required Inputs, Framework: The Review Rules and Output Format, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Tool Permission Review is an agent skill from mohitagw15856/pm-claude-skills. Review what an agent is actually allowed to do before you turn it loose — the tool-by-tool audit (each capability's blast radius), the least-privilege pass that removes what the task doesn't need, the dangerous-combination check, and the allow/ask/deny tiering. Use when asked review my agent's permissions, what can this agent actually do, lock down my agent's tools, or is this MCP/tool set safe to grant. Produces the permission inventory with blast radius, the least-privilege cuts, the dangerous-combo flags, and…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked review my agents permissions
  • What can this agent actually do
  • Lock down my agents tools
  • Is this MCP/tool set safe to grant

Example prompts

  • “s permissions, what can this agent actually do, lock down my agent”
  • “/tool-permission-review”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Inventory by blast radius, not by name: each capability gets its worst-case — read_file (exposure of anything reachable), run_shell…
  2. Least privilege is the whole game: for each capability, ask "does this task need it?" — a research agent needs read + fetch, not shell or…
  3. The dangerous combinations — the non-obvious risk: capabilities safe alone become exploits together. Read-secrets + any-network =…
  4. Tier the survivors — allow / ask / deny: allow the reversible, low-blast reads and analysis. Ask (human confirmation, details shown) the…
  5. Autonomy shifts every dial toward restriction: a supervised agent can hold more allows because a human is watching; an autonomous one…

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tool Permission Review loads about 1.6k tokens when it runs. Until then it costs about 143 tokens; SKILL.md has 809 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:29
    + any-network* = exfiltration (read the `.env`, POST it out). *Web-fetch + shell* = fetch-and-run (a page tells it to ru

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 809 words, ~1,601 tokens.

Download SKILL.mdSave it as .claude/skills/tool-permission-review/SKILL.md (or your agent's skills folder).
name
tool-permission-review
description
Review what an agent is actually allowed to do before you turn it loose — the tool-by-tool audit (each capability's blast radius), the least-privilege pass that removes what the task doesn't need, the dangerous-combination check, and the allow/ask/deny tiering. Use when asked review my agent's permissions, what can this agent actually do, lock down my agent's tools, or is this MCP/tool set safe to grant. Produces the permission inventory with blast radius, the least-privilege cuts, the dangerous-combo flags, and the allow/ask/deny assignments.

Tool Permission Review Skill

An agent's danger isn't its intelligence — it's its permissions. A brilliant agent that can only read is safe; a mediocre one that can send email, run shell commands, and read your filesystem is a breach waiting for a bad prompt or a hijacked page. Permission review is the security discipline every agent setup skips: inventory what it can actually do (tools, MCP servers, computer use, each with its real blast radius), cut everything the task doesn't need (least privilege — the single highest-leverage security move), flag the combinations that are dangerous together even when each is fine alone, and tier the survivors into allow / ask / deny.

What This Skill Produces

  • The permission inventory — every tool/capability the agent has, each with its blast radius (what's the worst it enables)
  • The least-privilege cuts — the capabilities the task doesn't need, removed with the reasoning
  • The dangerous-combination flags — the tool pairs that are safe alone and dangerous together (read-secrets + network = exfiltration)
  • The allow/ask/deny tiering — each surviving capability assigned, with ask-gates on the irreversible

Required Inputs

Ask for these if not provided:

  • The full capability list — every tool, MCP server, and native power (file, shell, browser, computer use, network) the agent has or would get; the review needs the actual grant, not the intended use
  • The task — what the agent is for; least privilege is defined against the task, and "convenience" grants are exactly what this removes
  • The environment's sensitivity — a sandbox vs. a machine with production access, real credentials, and company data (blast radius is capability × environment)
  • The autonomy level — supervised or autonomous; autonomous agents need more denied and more gated, because no human catches the misuse live

Framework: The Review Rules

  1. Inventory by blast radius, not by name: each capability gets its worst-case — read_file (exposure of anything reachable), run_shell (arbitrary code = everything), send_email (reaches humans, irreversible), web_fetch (exfiltration channel + injection intake), http_post (data can leave). The name is benign; the blast radius is the truth. Shell and computer-use are the maximal grants — they subsume most others and deserve the hardest scrutiny.
  2. Least privilege is the whole game: for each capability, ask "does this task need it?" — a research agent needs read + fetch, not shell or send; a code-review agent needs read, not write or network. The default failure is granting a broad tool set "so it can handle anything," which maximizes blast radius for a task that used a fraction of it. Remove first, justify what stays.
  3. The dangerous combinations — the non-obvious risk: capabilities safe alone become exploits together. Read-secrets + any-network = exfiltration (read the .env, POST it out). Web-fetch + shell = fetch-and-run (a page tells it to run something). File-write + broad-scope = self-modification or planting. Read-untrusted + send = injection-to-action (read a malicious email, forward the data). The review flags every such pair present and either breaks the combo (drop one) or gates it hard.
  4. Tier the survivors — allow / ask / deny: allow the reversible, low-blast reads and analysis. Ask (human confirmation, details shown) the irreversible and the moderate-blast — sends, writes, purchases, deletes. Deny what the task doesn't need at all, especially shell and unrestricted network unless they're genuinely the point. The tiering is enforced by the tool's permission config, not by trusting the agent to self-restrain.
  5. Autonomy shifts every dial toward restriction: a supervised agent can hold more allows because a human is watching; an autonomous one moves grants toward ask-or-deny, adds rate/volume caps, and keeps the kill-switch (blast-radius-drill) ready — because the whole point of autonomy is that no one's checking each action, which is exactly when over-permission turns into incident.
Show full SKILL.md (217 more words)Show less

Output Format

Tool Permission Review: [agent/task] — env: [sandbox/production]

The Inventory (by blast radius)

CapabilityBlast radius (worst case)Task needs it?

Least-Privilege Cuts

[Removed: capability → why the task doesn't need it]

Dangerous Combinations

[Flagged pairs present → the exploit they enable → break-the-combo or hard-gate]

Allow / Ask / Deny

CapabilityTierGate details (for ask)

Autonomy Adjustments (if autonomous)

[Grants shifted toward ask/deny · rate/volume caps · the kill-switch]

Quality Checks

  • Every capability is inventoried by blast radius, not just named
  • Least privilege was applied — grants trace to a task need or they're cut
  • Dangerous combinations are flagged and broken or gated
  • Every survivor is tiered allow/ask/deny and enforced in config
  • Autonomous setups shifted toward restriction with caps and a kill-switch

Anti-Patterns

  • Do not grant by convenience — every unneeded capability is pure blast radius
  • Do not review tools in isolation — the dangerous combinations are where the exploits live
  • Do not trust the agent to self-restrain — tiers are enforced by config, not by good intentions
  • Do not grant shell or computer-use casually — they subsume most other tools and deserve the hardest deny-by-default
  • Do not give an autonomous agent supervised-grade permissions — no human is checking, so the grants must

Example Trigger Phrases

  • "Review my agent's permissions."
  • "What can this agent actually do?"
  • "Lock down my agent's tools."
  • "Is this MCP/tool set safe to grant?"

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/tool-permission-review of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

Tool Permission Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tool Permission Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tool Permission Review this skillmohitagw15856/pm-claude-skills1.4k—~1.6kAutomated safety check: NotesMIT
Unbrowseunbrowse-ai/unbrowse783—~3.7kAutomated safety check: PassMIT
Gemini SkillWJZ-P/gemini-skill832—~1.1kAutomated safety check: PassMIT
Turnstile Testingjumodada/Drissionpage-MCP-Server487—~1.7kAutomated safety check: PassCustom licence
Triage Security Advisoriesactivepieces/activepieces25k—~3.9kAutomated safety check: PassCustom licence
Lightpandalightpanda-io/agent-skill101—~6kAutomated safety check: PassApache-2.0

Similar skills

  • Unbrowse

    unbrowse-ai/unbrowse

    Search and call websites through Unbrowse's hosted API or remote MCP, reuse indexed site tools, read pages, and learn missing routes in its cloud browser.

    783 GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Gemini Skill

    WJZ-P/gemini-skill

    通过 Gemini 官网(gemini.google.com)执行生图、对话等操作。用户提到"生图/画图/绘图/nano banana/nanobanana/生成图片"等关键词时触发。操作方式分三级优先级:首选 MCP 工具 → 次选 Skill 脚本 → 最次连接 Skill 浏览器手动操作(需用户授权)。禁止自行启动外部浏览器访问 Gemini。

    832 GitHub stars~1.1k tokensUpdated 22 days ago
    Agent WorkflowsAuto-check passed
  • Turnstile Testing

    jumodada/Drissionpage-MCP-Server

    A skill your agent uses when testing an authorized Cloudflare Turnstile integration or operating an authorized production challenge with drissionpage-mcp.

    487 GitHub stars~1.7k tokensUpdated 27 days ago
    Agent WorkflowsAuto-check passed
  • Triage Security Advisories

    activepieces/activepieces

    Triage the GitHub privately-reported vulnerability backlog for Activepieces — pull repository security advisories from the Security tab, scope-check against SECURITY.md, deeply validate each…

    25k GitHub stars~3.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Lightpanda

    lightpanda-io/agent-skill

    Lightpanda browser, drop-in replacement for Chrome-based browsing in any AI agent - faster and lighter for tasks without graphical rendering like data retrieval.

    101 GitHub stars~6k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check passed
  • Healthmd CLI

    CodyBontecou/health-md

    Install and operate the standalone Health.md CLI and portable healthmd-mcp server on macOS, Linux, or Windows.

    230 GitHub stars~3.9k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,348 skills in this repo
  • Car Tco

    mohitagw15856/pm-claude-skills

    Compare the total cost of car ownership across buy-new, buy-used, lease, and keep-your-current-car — depreciation, insurance, maintenance ramp, and fuel over a real horizon, not just the monthly…

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Cs Health Scorecard

    mohitagw15856/pm-claude-skills

    Build a customer health scorecard for a specific account. An agent skill from mohitagw15856/pm-claude-skills.

    1.4k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Fire Number

    mohitagw15856/pm-claude-skills

    Compute a financial-independence (FIRE) target and years-to-reach with every assumption labeled as an assumption — plus a sensitivity table instead of a single false-precision answer.

    1.4k GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Tool Permission Review

What does Tool Permission Review do?

Review what an agent is actually allowed to do before you turn it loose — the tool-by-tool audit (each capability's blast radius), the least-privilege pass that removes what the task doesn't need…. Tool Permission Review is an agent skill from mohitagw15856/pm-claude-skills. Review what an agent is actually allowed to do before you turn it loose — the tool-by-tool audit (each capability's blast radius), the least-privilege pass that removes what the task doesn't need, the dangerous-combination check, and the allow/ask/deny tiering.

When should I use Tool Permission Review?

Tool Permission Review fits situations like: asked review my agents permissions; what can this agent actually do; lock down my agents tools; is this MCP/tool set safe to grant.

How do I install Tool Permission Review in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill tool-permission-review -a claude-code`. Or copy the skill folder (skills/tool-permission-review in mohitagw15856/pm-claude-skills) into .claude/skills/tool-permission-review in your project. Claude Code loads it when a task matches its description.

How do I install Tool Permission Review in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill tool-permission-review -a codex`. Or copy the skill folder (skills/tool-permission-review in mohitagw15856/pm-claude-skills) into .agents/skills/tool-permission-review in your project. Codex loads it when a task matches its description.

Can I use Tool Permission Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill tool-permission-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tool-permission-review, .gemini/skills/tool-permission-review, .github/skills/tool-permission-review and .opencode/skills/tool-permission-review in your project.

What does Tool Permission Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Tool Permission Review is instructions for the agent only.

Does Tool Permission Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Tool Permission Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Tool Permission Review use?

Tool Permission Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tool Permission Review use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tool Permission Review?

Skills that share tags, products or a category with Tool Permission Review: Unbrowse (unbrowse-ai/unbrowse, 783 stars), Gemini Skill (WJZ-P/gemini-skill, 832 stars), Turnstile Testing (jumodada/Drissionpage-MCP-Server, 487 stars) and Triage Security Advisories (activepieces/activepieces, 25k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tool Permission Review?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,434 GitHub stars. The repository holds 1,348 skills in this directory. The repository was last updated on October 9, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.