Agent skill

New Policy Engine

by open-bias in open-bias/open-bias

Guide for creating a new policy engine under openbias/policy/engines/

Apache-2.0Auto-check passedBackend & APIs

Install New Policy Engine

skills CLI
$ npx skills add open-bias/open-bias --skill new-policy-engine -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install open-bias/open-bias new-policy-engine --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/open-bias/open-bias.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/new-policy-engine .claude/skills/new-policy-engine && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
new-policy-engine
GitHub stars
143
Token cost
~1.3k tokens
SKILL.md length
265 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guide for creating a new policy engine under openbias/policy/engines/

  • Works in 7 steps: Create the engine package → Implement the engine class in engine.py → Export in the engine's __init__.py → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Decision: PolicyEngine vs…, Checklist, Anti-patterns and Reference Files
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

New Policy Engine is an agent skill from open-bias/open-bias. Guide for creating a new policy engine under openbias/policy/engines/

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and LLM guardrails. The repository describes itself as: Open Source policy enforcement proxy: Make your agents follow rules. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Authorization and RBAC
  • Tasks that involve LLM guardrails

Example prompts

  • “/new-policy-engine”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Create the engine package
  2. Implement the engine class in engine.py
  3. Export in the engine's __init__.py
  4. Register the import in openbias/policy/engines/init.py
  5. (Optional) Create a compiler — see openbias/policy/compiler/ for the PolicyCompiler ABC and LLMPolicyCompiler base class. Use…
  6. Add a config example for openbias.yaml
  7. Write tests in tests/policy/engines//

What it can do on your machine

Read from SKILL.md and the folder at commit c680075. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

New Policy Engine loads about 1.3k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 265 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from open-bias/open-bias at commit c680075, republished under its Apache-2.0 licence (© open-bias). 265 words, ~1,301 tokens.

Download SKILL.mdSave it as .claude/skills/new-policy-engine/SKILL.md (or your agent's skills folder).
name
new-policy-engine
description
Guide for creating a new policy engine under openbias/policy/engines/

Creating a New Policy Engine

Decision: PolicyEngine vs StatefulPolicyEngine

  • PolicyEngine — Use when each request/response is evaluated independently against policy. No state transitions between turns. Examples: Judge (compiled-rule evaluation), NeMo (guardrails).
  • StatefulPolicyEngine (from openbias.policy.engines.stateful) — Use when you need to track state transitions across turns (e.g., FSM workflows). Adds classify_response, get_current_state, get_state_history, get_valid_next_states.

If you're unsure, start with PolicyEngine. You can always extend later.

Checklist

  1. Create the engine package

    openbias/policy/engines/<name>/
    ├── __init__.py    # Export engine class
    ├── engine.py      # Engine implementation
    └── compiler.py    # (Optional) NL-to-config compiler
  2. Implement the engine class in engine.py

    python
    from typing import Any, Dict, Optional
    
    from openbias.policy.protocols import (
        EvaluationResult,
        EvaluationStatus,
        ViolationRecord,
        PolicyEngine,
        require_initialized,
    )
    from openbias.policy.registry import register_engine
    
    @register_engine("<name>")
    class MyPolicyEngine(PolicyEngine):
        def __init__(self) -> None:
            self._initialized = False
            self._config: Dict[str, Any] = {}
            self._session_data: Dict[str, Dict[str, Any]] = {}
    
        @property
        def name(self) -> str:
            return "<name>:<variant>"
    
        @property
        def engine_type(self) -> str:
            return "<name>"
    
        async def initialize(self, config: Dict[str, Any]) -> None:
            self._config = config
            # Setup resources, load models, etc.
            self._initialized = True  # CRITICAL: must set this
    
        @require_initialized
        async def evaluate_request(
            self,
            session_id: str,
            request_data: Dict[str, Any],
            context: Optional[Dict[str, Any]] = None,
        ) -> EvaluationResult:
            # Return EvaluationResult(status=EvaluationStatus.ALLOW)
            ...
    
        @require_initialized
        async def evaluate_response(
            self,
            session_id: str,
            response_data: Any,
            request_data: Dict[str, Any],
            context: Optional[Dict[str, Any]] = None,
        ) -> EvaluationResult:
            # This is where most evaluation logic lives
            ...
    
        async def get_session_state(self, session_id: str) -> Optional[Dict[str, Any]]:
            return self._session_data.get(session_id)
    
        async def reset_session(self, session_id: str) -> None:
            self._session_data.pop(session_id, None)
    
        async def shutdown(self) -> None:
            self._session_data.clear()
            self._initialized = False
  3. Export in the engine's __init__.py

    python
    from openbias.policy.engines.<name>.engine import MyPolicyEngine
    
    __all__ = ["MyPolicyEngine"]
  4. Register the import in openbias/policy/engines/__init__.py

    Add a line alongside existing imports:

    python
    from openbias.policy.engines import fsm, nemo, llm, judge, <name>
  5. (Optional) Create a compiler — see openbias/policy/compiler/ for the PolicyCompiler ABC and LLMPolicyCompiler base class. Use @register_compiler("<name>"). Wire it via get_compiler() on your engine.

  6. Add a config example for openbias.yaml

    yaml
    engine: <name>
    <name>:
      some_option: value
  7. Write tests in tests/policy/engines/<name>/

    At minimum: initialization, evaluate_request with ALLOW result, evaluate_response with INTERVENE/BLOCK result, session reset.

Show full SKILL.md (123 more words)Show less

Anti-patterns

  • Forgetting self._initialized = True in initialize() — the @require_initialized decorator will reject all evaluate calls.
  • Blocking in evaluate methods — All evaluate methods are async. Use await for I/O. Never block the event loop.
  • Not cleaning up sessions — Implement reset_session properly. The interceptor calls this for TTL-expired sessions.
  • Mutating request_data — Always work on copies. The interceptor may retry with the original.
  • Returning bare strings instead of EvaluationResult — Always return EvaluationResult(status=..., violations=[...]).

Reference Files

FileWhat to look at
openbias/policy/protocols.pyPolicyEngine ABC, EvaluationResult, EvaluationStatus, ViolationRecord
openbias/policy/engines/stateful.pyStatefulPolicyEngine ABC, StateClassificationResult dataclass
openbias/policy/registry.py@register_engine decorator, PolicyEngineRegistry
openbias/policy/engines/__init__.pyWhere to add your import
openbias/policy/engines/fsm/Stateful engine example (smallest engine at ~340 lines)
openbias/policy/engines/nemo/Stateless engine wrapping an external library
openbias/policy/engines/judge/Judge engine example with LLM calls and compiled-rule evaluation

© open-bias, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/new-policy-engine of open-bias/open-bias.

Open the folder on GitHubat commit c680075

Compare with similar skills

New Policy Engine next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

New Policy Engine compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
New Policy Engine this skillopen-bias/open-bias143—~1.3kAutomated safety check: PassApache-2.0
Tool Permission System Designsimbajigege/book2skills183—~2.1kAutomated safety check: PassApache-2.0
Tenuo Agent Authorizationtenuo-ai/tenuo103—~2.3kAutomated safety check: PassApache-2.0
Phoenix Authorization Patternsj-morgan6/elixir-phoenix-guide167—~2.1kAutomated safety check: PassMIT
Aliyun Green Moderationcinience/alicloud-skills397—~728Automated safety check: PassMIT
Walletsaustintgriffith/ethskills295—~1.9kAutomated safety check: NotesNone

Similar skills

  • Tool Permission System Design

    simbajigege/book2skills

    Guides designing a layered permission pipeline for agent tools that decides which calls are allowed, need confirmation or are denied, with scopes and hooks.

    183 GitHub stars~2.1k tokensUpdated 1 mo ago
    AI & LLM EngineeringAuto-check passed
  • Add or retrofit Tenuo authorization for AI-agent tools and effects.

    103 GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Phoenix Authorization Patterns

    j-morgan6/elixir-phoenix-guide

    A skill your agent uses when deciding who may do what — ownership checks, policy modules, scoped queries, role-based access in LiveViews and controllers.

    167 GitHub stars~2.1k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Aliyun Green Moderation

    cinience/alicloud-skills

    A skill your agent uses when managing Alibaba Cloud Content Moderation (Green) via OpenAPI/SDK, including the user needs content moderation resource and policy operations, including…

    397 GitHub stars~728 tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Wallets

    austintgriffith/ethskills

    How to create, manage, and use Ethereum wallets. An agent skill from austintgriffith/ethskills.

    295 GitHub stars~1.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Azure Policy

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Policy — enforcing and auditing governance and security guardrails at scale across Azure with definitions, initiatives, assignments, and remediation tasks.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed

More from open-bias/open-bias

  • Writing Eval Scenarios

    open-bias/open-bias

    Guide for writing eval conversation JSONs and running them through policy engines

    143 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed

Questions about New Policy Engine

What does New Policy Engine do?

Guide for creating a new policy engine under openbias/policy/engines/. New Policy Engine is an agent skill from open-bias/open-bias.

When should I use New Policy Engine?

New Policy Engine fits situations like: tasks that involve Authorization and RBAC; tasks that involve LLM guardrails.

How do I install New Policy Engine in Claude Code?

Run `npx skills add open-bias/open-bias --skill new-policy-engine -a claude-code`. Or copy the skill folder (.claude/skills/new-policy-engine in open-bias/open-bias) into .claude/skills/new-policy-engine in your project. Claude Code loads it when a task matches its description.

How do I install New Policy Engine in Codex?

Run `npx skills add open-bias/open-bias --skill new-policy-engine -a codex`. Or copy the skill folder (.claude/skills/new-policy-engine in open-bias/open-bias) into .agents/skills/new-policy-engine in your project. Codex loads it when a task matches its description.

Can I use New Policy Engine in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add open-bias/open-bias --skill new-policy-engine -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/new-policy-engine, .gemini/skills/new-policy-engine, .github/skills/new-policy-engine and .opencode/skills/new-policy-engine in your project.

What does New Policy Engine need to run?

SKILL.md names no scripts, command-line tools or credentials: New Policy Engine is instructions for the agent only. Our summary lists: Python 3.

Does New Policy Engine access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is New Policy Engine safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does New Policy Engine use?

New Policy Engine is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does New Policy Engine use?

About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to New Policy Engine?

Skills that share tags, products or a category with New Policy Engine: Tool Permission System Design (simbajigege/book2skills, 183 stars), Tenuo Agent Authorization (tenuo-ai/tenuo, 103 stars), Phoenix Authorization Patterns (j-morgan6/elixir-phoenix-guide, 167 stars) and Aliyun Green Moderation (cinience/alicloud-skills, 397 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains New Policy Engine?

open-bias (a GitHub organization) maintains it in open-bias/open-bias, which has 143 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 7, 2026.

Source: open-bias/open-bias on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.