Agent skill

Tool Call Permission Gate

by mrmps in mrmps/classifier-dev

A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person…

MITAuto-check passed

Install Tool Call Permission Gate

skills CLI
$ npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mrmps/classifier-dev tool-call-permission-gate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tool-call-permission-gate .claude/skills/tool-call-permission-gate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tool-call-permission-gate
GitHub stars
424
Token cost
~1.5k tokens
SKILL.md length
529 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person…

  • Setting up a PreToolUse hook
  • SKILL.md covers What leaves the machine, The hook, Thresholds and When not to use
  • Calls node, npm and psql; reaches classifier.dev

What it does

Tool Call Permission Gate is an agent skill from mrmps/classifier-dev. A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person already sees, with the command redacted first. Use when setting up a PreToolUse hook.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Model Context Protocol and Bash. The repository describes itself as: Zero-shot text classification over plain HTTP — no API key, no account. One Cloudflare Worker, a CLI, and an MCP server. https://classifier.dev. The licence is MIT.

When your agent uses it

  • Setting up a PreToolUse hook

Example prompts

  • “/tool-call-permission-gate”

What it can do on your machine

Read from SKILL.md and the folder at commit 629df75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • npm
    • psql

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • classifier.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tool Call Permission Gate loads about 1.5k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 529 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mrmps/classifier-dev at commit 629df75, republished under its MIT licence (© mrmps). 529 words, ~1,499 tokens.

Download SKILL.mdSave it as .claude/skills/tool-call-permission-gate/SKILL.md (or your agent's skills folder).
name
tool-call-permission-gate
description
A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person already sees, with the command redacted first. Use when setting up a PreToolUse hook.
license
MIT

A second opinion on every tool call

An allowlist matches strings: rm -rf build and rm -fr ./build are one act in two spellings. Classify what the call would do instead, beside the decision the person is already making. The gate does two things and no more: it refuses a call it is sure is destructive, and it attaches a reason to the question the person gets anyway. An automatic yes is opt-in, below.

What leaves the machine

One string per call: the tool name and its arguments, redacted, cut to 2,000 characters. No file contents, no environment, no repository name. Redaction replaces bearer and basic headers, fields and flags named for a key, token, secret or password, opaque runs of 40 characters or more, hex digests, mail addresses and query strings. A call still holding more than two placeholders is never sent; it goes to the person.

in   Bash: curl -H "authorization: Bearer tok_9f2a" https://api.example.com/orders?key=9f2a
out  Bash: curl -H "authorization: Bearer [redacted]" https://api.example.com/orders?[redacted]
     tool gate: ask - read only, changes nothing 0.99

in   Bash: deploy --token tok_9f2a --secret s3cr3t --user ops@example.com
out  tool gate: ask - mostly redacted, nothing was sent

The service states that it stores no input text and forwards it to the model provider answering the request: https://classifier.dev/privacy. Read that against your policy. If the policy keeps command lines off the network, keep them off: ask the agent's own model the same labels and apply the same rule. Any classifier returning a calibrated confidence fits here; this one needs no account.

The hook

Four labels naming consequence, not category, spelled out because labels are read as language: p0 classifies worse than destructive or irreversible. The hook reads a PreToolUse JSON object or a bare command on stdin and exits 0 allow, 1 ask, 2 block.

js
#!/usr/bin/env node
const LABELS = ["read only, changes nothing", "writes only inside this repository",
  "changes shared state outside this machine", "destructive or irreversible"];
const DENY_AT = 0.9;
const AUTO_ALLOW = process.argv.includes("--auto-allow");   // off by default

const REDACT = [
  [/\b(bearer|basic)\s+[^\s"']+/gi, "$1 [redacted]"],
  [/(--?[\w-]*(?:key|token|secret|password|pwd)[\w-]*)[= ]+"?[^\s",}]+/gi, "$1 [redacted]"],
  [/([\w.-]*(?:key|token|secret|password|pwd)[\w.-]*)\s*[=:]\s*"?[^\s",}]+/gi, "$1=[redacted]"],
  [/\b[A-Za-z0-9_-]{40,}\b/g, "[redacted]"],
  [/\b[0-9a-f]{32,}\b/gi, "[redacted]"],
  [/\b[\w.+-]+@[\w-]+\.[\w.]+\b/g, "[redacted]"],
  [/([?&])[^\s"'`]+/g, "$1[redacted]"],
];
const redact = (s) => REDACT.reduce((t, [re, to]) => t.replace(re, to), s);

async function verdict(call) {
  const text = redact(call).slice(0, 2000);
  if ((text.match(/\[redacted\]/g) || []).length > 2)
    return ["ask", "mostly redacted, nothing was sent"];
  const r = await fetch("https://classifier.dev/v1/classify", {
    method: "POST",
    headers: { "content-type": "application/json" },
    body: JSON.stringify({ labels: LABELS, inputs: [text],
      instructions: "A coding agent proposes this tool call. Judge only what running it would do." }),
    signal: AbortSignal.timeout(4000),
  });
  if (!r.ok) throw new Error(`classifier ${r.status}`);
  const [res] = (await r.json()).results;
  const c = res.confidence ?? 0, why = `${res.label} ${c}`;
  if (res.label === LABELS[3] && c >= DENY_AT) return ["deny", why];
  if (AUTO_ALLOW && c >= DENY_AT && LABELS.indexOf(res.label) < 2) return ["allow", why];
  return ["ask", why];
}

(async () => {
  let raw = ""; for await (const c of process.stdin) raw += c;
  let hook = null; try { hook = JSON.parse(raw); } catch {}
  const call = hook?.tool_name
    ? `${hook.tool_name}: ${JSON.stringify(hook.tool_input)}` : raw.trim();
  let d = "ask", why = "gate unavailable";
  try { [d, why] = await verdict(call); }
  catch (e) { why = `gate unavailable, ${e.message}`; }
  const out = { hookEventName: "PreToolUse", permissionDecision: d, permissionDecisionReason: `tool gate: ${why}` };
  if (hook) return console.log(JSON.stringify({ hookSpecificOutput: out }));
  console.error(`tool gate: ${d} - ${why}`);
  process.exit(d === "allow" ? 0 : d === "ask" ? 1 : 2);
})();

Register it in .claude/settings.json under hooks.PreToolUse, matcher Bash|Edit|Write, command node .claude/hooks/gate.js. Codex, Cursor and OpenCode pass text: the stdin path.

Show full SKILL.md (212 more words)Show less

Thresholds

The classifier returns labels, scores and a calibrated confidence, and writes no prose. Refuse at 0.9 and above on destructive or irreversible, where answers were right 82 to 92% of the time: rm -rf build dist and untracked files was refused at 0.94, exit 2. Everything else stays a question carrying the label and the number: from 0.5 to 0.9 that number is the warning, below 0.5 the gate does not know. A network failure, a 429 or a held-back command is a question too.

--auto-allow turns a read-only or in-repository answer at 0.9 and above into a yes. Do not start there: run the gate for a week, log its lines, read what it would have allowed, and set the flag only if that log is dull. npm test measured 0.75 and psql prod -c "DROP TABLE orders" 0.66, so that week is not a formality, and no threshold makes this a security boundary. Keep hard deny rules for the acts you never want, and send one command per call: a chained line gets a single label.

When not to use

Skip it when the policy keeps command lines off the network, when a static deny list already covers the repository, or when the agent runs in a throwaway container.

© mrmps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/tool-call-permission-gate of mrmps/classifier-dev.

Open the folder on GitHubat commit 629df75

Compare with similar skills

Tool Call Permission Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tool Call Permission Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tool Call Permission Gate this skillmrmps/classifier-dev424—~1.5kAutomated safety check: PassMIT
E2Ecallstack/react-native-pager-view3.4k1 repos~2.1kAutomated safety check: PassMIT
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Tradingview MCPatilaahmettaner/tradingview-mcp5k—~1.3kAutomated safety check: PassMIT
Codegraph Skillsopaco/deepwiki-rs3.1k—~1.1kAutomated safety check: PassMIT
Record Demoapify/mcpc990—~3.3kAutomated safety check: NotesApache-2.0

Similar skills

  • E2E

    callstack/react-native-pager-view

    Agentic end-to-end tests with e2e, the e2e runner. An agent skill from callstack/react-native-pager-view.

    3.4k GitHub starsUsed in 1 repo~2.1k tokens
    Testing & QAAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Tradingview MCP

    atilaahmettaner/tradingview-mcp

    AI Trading Intelligence — live prices, 30+ technical indicators, backtesting (6 strategies), walk-forward overfitting detection, trade logs, equity curves, licensed news sentiment (Marketaux), and…

    5k GitHub stars~1.3k tokensUpdated 2 days ago
    Business, Finance & HRAuto-check passed
  • Codegraph Skill

    sopaco/deepwiki-rs

    A skill your agent uses when a coding agent needs symbol relationships, callers, callees, or change impact.

    3.1k GitHub stars~1.1k tokensUpdated 25 days ago
    Auto-check passed
  • Record Demo

    apify/mcpc

    Official

    Record or regenerate the mcpc demo GIFs (the README hero docs/images/mcpc-demo.gif and the focused tapes in docs/vhs/) with VHS.

    990 GitHub stars~3.3k tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • Ue Code Authoring

    JasonMa0012/MooaToon

    A skill your agent uses when writing or modifying UE C++ (classes, actors, components, subsystems, interfaces, function libraries) with Rider MCP available.

    750 GitHub stars~1.9k tokensUpdated 21 days ago
    DevelopmentAuto-check: notes

More from mrmps/classifier-dev

All 21 skills in this repo
  • Bulk Classify

    mrmps/classifier-dev

    Sort many texts into your own categories without reading them, using a keyless HTTP API that returns a calibrated confidence per answer.

    424 GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Computer Use Action Picker

    mrmps/classifier-dev

    Pick a browser or desktop agent's next action by choosing among the actions actually on screen instead of inventing one.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Content Moderation Gate

    mrmps/classifier-dev

    Check user-generated text against a written policy before it is published.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Label each context chunk keep, drop or replace-with-a-pointer and pass the survivors through byte for byte instead of summarising, with key-shaped chunks decided locally and never sent, and a…

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Document Intake Routing

    mrmps/classifier-dev

    Label each page of an intake packet with a document type and a page role before extraction runs, so only confident pages reach an extractor and the rest reach a person.

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Headline Filter Map Reduce

    mrmps/classifier-dev

    Filter hundreds or thousands of headlines, search results or feed items against a written brief before opening any of them, using a two-stage cascade that spends a fast model on everything and a…

    424 GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about Tool Call Permission Gate

What does Tool Call Permission Gate do?

A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person…. Tool Call Permission Gate is an agent skill from mrmps/classifier-dev. A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person already sees, with the command redacted first.

When should I use Tool Call Permission Gate?

Tool Call Permission Gate fits situations like: setting up a PreToolUse hook.

How do I install Tool Call Permission Gate in Claude Code?

Run `npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a claude-code`. Or copy the skill folder (skills/tool-call-permission-gate in mrmps/classifier-dev) into .claude/skills/tool-call-permission-gate in your project. Claude Code loads it when a task matches its description.

How do I install Tool Call Permission Gate in Codex?

Run `npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a codex`. Or copy the skill folder (skills/tool-call-permission-gate in mrmps/classifier-dev) into .agents/skills/tool-call-permission-gate in your project. Codex loads it when a task matches its description.

Can I use Tool Call Permission Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tool-call-permission-gate, .gemini/skills/tool-call-permission-gate, .github/skills/tool-call-permission-gate and .opencode/skills/tool-call-permission-gate in your project.

What does Tool Call Permission Gate need to run?

Going by SKILL.md and its folder, Tool Call Permission Gate needs the command-line tools its instructions call (node, npm and psql).

Does Tool Call Permission Gate access the network?

SKILL.md names 1 domain. In commands or code: classifier.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Tool Call Permission Gate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tool Call Permission Gate use?

Tool Call Permission Gate is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tool Call Permission Gate use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tool Call Permission Gate?

Skills that share tags, products or a category with Tool Call Permission Gate: E2E (callstack/react-native-pager-view, 3.4k stars), Crush Configuration (charmbracelet/crush, 29k stars), Tradingview MCP (atilaahmettaner/tradingview-mcp, 5k stars) and Codegraph Skill (sopaco/deepwiki-rs, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tool Call Permission Gate?

mrmps (a GitHub user) maintains it in mrmps/classifier-dev, which has 424 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.

Source: mrmps/classifier-dev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.