E2E
callstack/react-native-pager-view
Agentic end-to-end tests with e2e, the e2e runner. An agent skill from callstack/react-native-pager-view.
A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person…
$ npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mrmps/classifier-dev tool-call-permission-gate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tool-call-permission-gate .claude/skills/tool-call-permission-gate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tool-call-permission-gate" agent skill from https://github.com/mrmps/classifier-dev/tree/main/skills/tool-call-permission-gate into .claude/skills/tool-call-permission-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-call-permission-gate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mrmps/classifier-dev/tree/main/skills/tool-call-permission-gateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mrmps/classifier-dev tool-call-permission-gate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/tool-call-permission-gate .agents/skills/tool-call-permission-gate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tool-call-permission-gate" agent skill from https://github.com/mrmps/classifier-dev/tree/main/skills/tool-call-permission-gate into .agents/skills/tool-call-permission-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-call-permission-gate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mrmps/classifier-dev tool-call-permission-gate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/tool-call-permission-gate .cursor/skills/tool-call-permission-gate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tool-call-permission-gate" agent skill from https://github.com/mrmps/classifier-dev/tree/main/skills/tool-call-permission-gate into .cursor/skills/tool-call-permission-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-call-permission-gate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mrmps/classifier-dev.git --path skills/tool-call-permission-gate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mrmps/classifier-dev tool-call-permission-gate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/tool-call-permission-gate .gemini/skills/tool-call-permission-gate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tool-call-permission-gate" agent skill from https://github.com/mrmps/classifier-dev/tree/main/skills/tool-call-permission-gate into .gemini/skills/tool-call-permission-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-call-permission-gate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mrmps/classifier-dev tool-call-permission-gateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/tool-call-permission-gate .github/skills/tool-call-permission-gate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tool-call-permission-gate" agent skill from https://github.com/mrmps/classifier-dev/tree/main/skills/tool-call-permission-gate into .github/skills/tool-call-permission-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-call-permission-gate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mrmps/classifier-dev tool-call-permission-gate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mrmps/classifier-dev.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/tool-call-permission-gate .opencode/skills/tool-call-permission-gate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tool-call-permission-gate" agent skill from https://github.com/mrmps/classifier-dev/tree/main/skills/tool-call-permission-gate into .opencode/skills/tool-call-permission-gate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-call-permission-gate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tool-call-permission-gateA second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person…
Tool Call Permission Gate is an agent skill from mrmps/classifier-dev. A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person already sees, with the command redacted first. Use when setting up a PreToolUse hook.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It works with Model Context Protocol and Bash. The repository describes itself as: Zero-shot text classification over plain HTTP — no API key, no account. One Cloudflare Worker, a CLI, and an MCP server. https://classifier.dev. The licence is MIT.
Read from SKILL.md and the folder at commit 629df75. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
nodenpmpsqlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
classifier.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tool Call Permission Gate loads about 1.5k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 529 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from mrmps/classifier-dev at commit 629df75, republished under its MIT licence (© mrmps). 529 words, ~1,499 tokens.
.claude/skills/tool-call-permission-gate/SKILL.md (or your agent's skills folder).An allowlist matches strings: rm -rf build and rm -fr ./build are one act
in two spellings. Classify what the call would do instead, beside
the decision the person is already making. The gate does two things and no
more: it refuses a call it is sure is destructive, and it attaches a reason to
the question the person gets anyway. An automatic yes is opt-in, below.
One string per call: the tool name and its arguments, redacted, cut to 2,000 characters. No file contents, no environment, no repository name. Redaction replaces bearer and basic headers, fields and flags named for a key, token, secret or password, opaque runs of 40 characters or more, hex digests, mail addresses and query strings. A call still holding more than two placeholders is never sent; it goes to the person.
in Bash: curl -H "authorization: Bearer tok_9f2a" https://api.example.com/orders?key=9f2a
out Bash: curl -H "authorization: Bearer [redacted]" https://api.example.com/orders?[redacted]
tool gate: ask - read only, changes nothing 0.99
in Bash: deploy --token tok_9f2a --secret s3cr3t --user ops@example.com
out tool gate: ask - mostly redacted, nothing was sentThe service states that it stores no input text and forwards it to the model provider answering the request: https://classifier.dev/privacy. Read that against your policy. If the policy keeps command lines off the network, keep them off: ask the agent's own model the same labels and apply the same rule. Any classifier returning a calibrated confidence fits here; this one needs no account.
Four labels naming consequence, not category, spelled out because labels are
read as language: p0 classifies worse than destructive or irreversible.
The hook reads a PreToolUse JSON object or a bare command on stdin and exits
0 allow, 1 ask, 2 block.
#!/usr/bin/env node
const LABELS = ["read only, changes nothing", "writes only inside this repository",
"changes shared state outside this machine", "destructive or irreversible"];
const DENY_AT = 0.9;
const AUTO_ALLOW = process.argv.includes("--auto-allow"); // off by default
const REDACT = [
[/\b(bearer|basic)\s+[^\s"']+/gi, "$1 [redacted]"],
[/(--?[\w-]*(?:key|token|secret|password|pwd)[\w-]*)[= ]+"?[^\s",}]+/gi, "$1 [redacted]"],
[/([\w.-]*(?:key|token|secret|password|pwd)[\w.-]*)\s*[=:]\s*"?[^\s",}]+/gi, "$1=[redacted]"],
[/\b[A-Za-z0-9_-]{40,}\b/g, "[redacted]"],
[/\b[0-9a-f]{32,}\b/gi, "[redacted]"],
[/\b[\w.+-]+@[\w-]+\.[\w.]+\b/g, "[redacted]"],
[/([?&])[^\s"'`]+/g, "$1[redacted]"],
];
const redact = (s) => REDACT.reduce((t, [re, to]) => t.replace(re, to), s);
async function verdict(call) {
const text = redact(call).slice(0, 2000);
if ((text.match(/\[redacted\]/g) || []).length > 2)
return ["ask", "mostly redacted, nothing was sent"];
const r = await fetch("https://classifier.dev/v1/classify", {
method: "POST",
headers: { "content-type": "application/json" },
body: JSON.stringify({ labels: LABELS, inputs: [text],
instructions: "A coding agent proposes this tool call. Judge only what running it would do." }),
signal: AbortSignal.timeout(4000),
});
if (!r.ok) throw new Error(`classifier ${r.status}`);
const [res] = (await r.json()).results;
const c = res.confidence ?? 0, why = `${res.label} ${c}`;
if (res.label === LABELS[3] && c >= DENY_AT) return ["deny", why];
if (AUTO_ALLOW && c >= DENY_AT && LABELS.indexOf(res.label) < 2) return ["allow", why];
return ["ask", why];
}
(async () => {
let raw = ""; for await (const c of process.stdin) raw += c;
let hook = null; try { hook = JSON.parse(raw); } catch {}
const call = hook?.tool_name
? `${hook.tool_name}: ${JSON.stringify(hook.tool_input)}` : raw.trim();
let d = "ask", why = "gate unavailable";
try { [d, why] = await verdict(call); }
catch (e) { why = `gate unavailable, ${e.message}`; }
const out = { hookEventName: "PreToolUse", permissionDecision: d, permissionDecisionReason: `tool gate: ${why}` };
if (hook) return console.log(JSON.stringify({ hookSpecificOutput: out }));
console.error(`tool gate: ${d} - ${why}`);
process.exit(d === "allow" ? 0 : d === "ask" ? 1 : 2);
})();Register it in .claude/settings.json under hooks.PreToolUse, matcher
Bash|Edit|Write, command node .claude/hooks/gate.js. Codex, Cursor and
OpenCode pass text: the stdin path.
The classifier returns labels, scores and a calibrated confidence, and writes
no prose. Refuse at 0.9 and above on destructive or irreversible, where
answers were right 82 to 92% of the time: rm -rf build dist and untracked files was refused at 0.94, exit 2. Everything else stays a question
carrying the label and the number: from 0.5 to 0.9 that number is the warning,
below 0.5 the gate does not know. A network failure, a 429 or a held-back
command is a question too.
--auto-allow turns a read-only or in-repository answer at 0.9 and above into
a yes. Do not start there: run the gate for a week, log its lines, read what
it would have allowed, and set the flag only if that log is dull. npm test
measured 0.75 and psql prod -c "DROP TABLE orders" 0.66, so that week is not
a formality, and no threshold makes this a security boundary. Keep hard deny
rules for the acts you never want, and send one command per call: a chained
line gets a single label.
Skip it when the policy keeps command lines off the network, when a static deny list already covers the repository, or when the agent runs in a throwaway container.
© mrmps, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/tool-call-permission-gate of mrmps/classifier-dev.
Open the folder on GitHubat commit 629df75
Tool Call Permission Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tool Call Permission Gate this skillmrmps/classifier-dev | 424 | — | ~1.5k | Automated safety check: Pass | MIT | |
| E2Ecallstack/react-native-pager-view | 3.4k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Crush Configurationcharmbracelet/crush | 29k | — | ~3.7k | Automated safety check: Pass | Custom licence | |
| Tradingview MCPatilaahmettaner/tradingview-mcp | 5k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Codegraph Skillsopaco/deepwiki-rs | 3.1k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Record Demoapify/mcpc | 990 | — | ~3.3k | Automated safety check: Notes | Apache-2.0 |
callstack/react-native-pager-view
Agentic end-to-end tests with e2e, the e2e runner. An agent skill from callstack/react-native-pager-view.
charmbracelet/crush
Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.
atilaahmettaner/tradingview-mcp
AI Trading Intelligence — live prices, 30+ technical indicators, backtesting (6 strategies), walk-forward overfitting detection, trade logs, equity curves, licensed news sentiment (Marketaux), and…
sopaco/deepwiki-rs
A skill your agent uses when a coding agent needs symbol relationships, callers, callees, or change impact.
apify/mcpc
Record or regenerate the mcpc demo GIFs (the README hero docs/images/mcpc-demo.gif and the focused tapes in docs/vhs/) with VHS.
JasonMa0012/MooaToon
A skill your agent uses when writing or modifying UE C++ (classes, actors, components, subsystems, interfaces, function libraries) with Rider MCP available.
mrmps/classifier-dev
Sort many texts into your own categories without reading them, using a keyless HTTP API that returns a calibrated confidence per answer.
mrmps/classifier-dev
Pick a browser or desktop agent's next action by choosing among the actions actually on screen instead of inventing one.
mrmps/classifier-dev
Check user-generated text against a written policy before it is published.
mrmps/classifier-dev
Label each context chunk keep, drop or replace-with-a-pointer and pass the survivors through byte for byte instead of summarising, with key-shaped chunks decided locally and never sent, and a…
mrmps/classifier-dev
Label each page of an intake packet with a document type and a page role before extraction runs, so only confident pages reach an extractor and the rest reach a person.
mrmps/classifier-dev
Filter hundreds or thousands of headlines, search results or feed items against a written brief before opening any of them, using a two-stage cascade that spends a fast model on everything and a…
Works with
A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person…. Tool Call Permission Gate is an agent skill from mrmps/classifier-dev. A second opinion on every shell, file and MCP call a coding agent proposes: classify what it would do, refuse the confidently destructive ones, and attach the reason to the confirmation the person already sees, with the command redacted first.
Tool Call Permission Gate fits situations like: setting up a PreToolUse hook.
Run `npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a claude-code`. Or copy the skill folder (skills/tool-call-permission-gate in mrmps/classifier-dev) into .claude/skills/tool-call-permission-gate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a codex`. Or copy the skill folder (skills/tool-call-permission-gate in mrmps/classifier-dev) into .agents/skills/tool-call-permission-gate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mrmps/classifier-dev --skill tool-call-permission-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tool-call-permission-gate, .gemini/skills/tool-call-permission-gate, .github/skills/tool-call-permission-gate and .opencode/skills/tool-call-permission-gate in your project.
Going by SKILL.md and its folder, Tool Call Permission Gate needs the command-line tools its instructions call (node, npm and psql).
SKILL.md names 1 domain. In commands or code: classifier.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Tool Call Permission Gate is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Tool Call Permission Gate: E2E (callstack/react-native-pager-view, 3.4k stars), Crush Configuration (charmbracelet/crush, 29k stars), Tradingview MCP (atilaahmettaner/tradingview-mcp, 5k stars) and Codegraph Skill (sopaco/deepwiki-rs, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mrmps (a GitHub user) maintains it in mrmps/classifier-dev, which has 424 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 7, 2026.
Source: mrmps/classifier-dev on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.