Agent skill

Permission Check

by pedrohcgs in pedrohcgs/claude-code-my-workflow

Diagnose why Claude Code is (or isn't) prompting for permission.

MITAuto-check: notes

Install Permission Check

skills CLI
$ npx skills add pedrohcgs/claude-code-my-workflow --skill permission-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pedrohcgs/claude-code-my-workflow permission-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pedrohcgs/claude-code-my-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/permission-check .claude/skills/permission-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
permission-check
GitHub stars
1.7k
Token cost
~2.6k tokens
SKILL.md length
1,056 words
Files
1
Skills in repo
59
Repo updated
First seen
Licence
MIT

At a glance

Diagnose why Claude Code is (or isn't) prompting for permission.

  • Works in 3 steps: Compute resolved state → Report runtime mode → Flag common failure modes
  • Explicitly confirms — those files may contain unrelated paths
  • SKILL.md covers Purpose, The 6 layers (precedence:…, Privacy contract and Protocol, plus 2 more sections
  • Calls git

What it does

Permission Check is an agent skill from pedrohcgs/claude-code-my-workflow. Diagnose why Claude Code is (or isn't) prompting for permission. By default reads only repo-local layers (CLI project, CLI project-local, VSCode workspace). Host-global layers (CLI user ~/.claude/, VSCode user settings) are read ONLY when the user explicitly confirms — those files may contain unrelated paths or secrets. Use when user says "why is it asking me to approve?", "permission check", "why am I getting prompts?", "bypass isn't working", "check my permissions". Read-only diagnostic.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Visual Studio Code. The repository describes itself as: A ready-to-fork Claude Code template for academics using LaTeX/Beamer + R. Multi-agent review, quality gates, adversarial QA, and replication protocols. The licence is MIT.

When your agent uses it

  • Explicitly confirms — those files may contain unrelated paths
  • User says why is it asking me to approve?
  • Permission check
  • Why am I getting prompts?

Example prompts

  • “why is it asking me to approve?”
  • “permission check”
  • “why am I getting prompts?”
  • “/permission-check”

Requirements

  • Pre-approved tools (allowed-tools): Read, Bash, Glob

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Compute resolved state
  2. Report runtime mode
  3. Flag common failure modes

What it can do on your machine

Read from SKILL.md and the folder at commit ae72617. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Permission Check loads about 2.6k tokens when it runs. Until then it costs about 128 tokens; SKILL.md has 1,056 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~128
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pedrohcgs/claude-code-my-workflow at commit ae72617, republished under its MIT licence (© pedrohcgs). 1,056 words, ~2,564 tokens.

Download SKILL.mdSave it as .claude/skills/permission-check/SKILL.md (or your agent's skills folder).
name
permission-check
description
Diagnose why Claude Code is (or isn't) prompting for permission. By default reads only repo-local layers (CLI project, CLI project-local, VSCode workspace). Host-global layers (CLI user `~/.claude/`, VSCode user settings) are read ONLY when the user explicitly confirms — those files may contain unrelated paths or secrets. Use when user says "why is it asking me to approve?", "permission check", "why am I getting prompts?", "bypass isn't working", "check my permissions". Read-only diagnostic.
allowed-tools
Read, Bash, Glob
argument-hint
(no arguments)
disallowed-tools
Edit, MultiEdit

Permission Check

Purpose

Surface the full permission-mode picture across every layer Claude Code honors, so the user can see at a glance why prompts are (or aren't) firing. Claude Code resolves permission mode from a 6-tier stack; a single misconfigured layer produces silent overrides that are hard to debug by eye.

The 6 layers (precedence: bottom wins)

  1. VSCode user settings — ~/Library/Application Support/Code/User/settings.json (macOS), %APPDATA%/Code/User/settings.json (Windows), ~/.config/Code/User/settings.json (Linux). Key: claudeCode.initialPermissionMode.
  2. VSCode workspace settings — <repo>/.vscode/settings.json. Same key. Wins over user.
  3. CLI user settings — ~/.claude/settings.json. Key: permissions.defaultMode.
  4. CLI project settings — <repo>/.claude/settings.json. Same key. Wins over user.
  5. CLI project-local settings — <repo>/.claude/settings.local.json. Same key. Wins over project.
  6. In-session mode — set at session start from layers 1-5, then mutable via Shift+Tab (CLI) or the mode indicator (VS Code / Desktop); /permissions manages allow/deny rules, not the mode. Authoritative until session ends.

Two rules that override the stack (Anthropic's permission-modes docs, re-verified 2026-09-26):

  • Layers 4 and 5 do not honor auto or bypassPermissions as a starting mode. A bypassPermissions there is ignored and the terminal session starts in Manual (default); an auto there is ignored in favour of the built-in default. Every other mode value applies from any layer.
  • The VS Code extension does not read layers 4–5 for its starting mode; it uses claudeCode.initialPermissionMode (which does not accept auto), and a bypass value needs the extension's Allow dangerously skip permissions toggle. With no override, Claude Code ≥ 2.1.283 starts in auto mode.

So check first for "bypass set in the project settings, where it cannot take effect" — then for the mid-session override below.

Key insight: initialPermissionMode only fires at session start. If you toggled mid-session (or the session started before a settings change), the file-level settings are correct but the runtime mode differs. That, and a bypass set only in project settings, are the two usual sources of "bypass isn't working" confusion.

Privacy contract

Host-global settings files (~/.claude/settings.json, VSCode user settings) may contain:

  • Paths to unrelated projects and secrets
  • API keys, tokens, or provider credentials added outside this repo
  • Permission policies set by the user's org or employer

This skill is designed for defense-in-depth: Phase A runs automatically and reads only repo-local files. Phase B reads host-global files only after the user explicitly confirms — never silently. When reporting host-global layers, redact any key that is not directly relevant to permissions.*, claudeCode.*, or allowDangerouslySkipPermissions.

Protocol

Phase A: Repo-local layers (auto-runs)

Read these immediately — they are checked into (or gitignored inside) the repo and do not cross the trust boundary:

bash
VSCODE_WS="${CLAUDE_PROJECT_DIR}/.vscode/settings.json"
CLI_PROJECT="${CLAUDE_PROJECT_DIR}/.claude/settings.json"
CLI_LOCAL="${CLAUDE_PROJECT_DIR}/.claude/settings.local.json"

For each file that exists, extract:

  • VSCode workspace: claudeCode.initialPermissionMode and allowDangerouslySkipPermissions (no claudeCode. prefix — flag the prefixed claudeCode.allowDangerouslySkipPermissions as a silently-ignored typo if you see it)
  • CLI project / project-local: permissions.defaultMode, permissions.allow, permissions.deny

Missing files are fine — report "not present" rather than erroring.

Print the resolved defaultMode from these three layers alone, applying the two override rules above — a bypassPermissions or auto found only in layer 4 or 5 is reported as ignored, not as the resolved mode. If that already explains the prompt behavior (e.g. bypass set only in .claude/settings.json), stop here and surface the diagnosis with the fix: move it to ~/.claude/settings.json, pass --permission-mode bypassPermissions, or use auto mode.

Phase B: Host-global layers (requires explicit user confirmation)

If Phase A is inconclusive — e.g., all repo-local layers agree on bypass but the user is still being prompted — ask the user:

"To complete the diagnosis, I need to read two files outside this repo:

  • ~/.claude/settings.json (CLI user-level)
  • your VSCode user settings (~/Library/Application Support/Code/User/settings.json on macOS; Linux/Windows vary)

These may contain unrelated paths or secrets. I will redact any key that isn't in permissions.*, claudeCode.*, or allowDangerouslySkipPermissions. Proceed?"

Only after the user confirms, read:

bash
# VSCode user (platform-dependent path; try all three)
case "$(uname -s)" in
    Darwin)  VSCODE_USER="${HOME}/Library/Application Support/Code/User/settings.json" ;;
    Linux)   VSCODE_USER="${HOME}/.config/Code/User/settings.json" ;;
    MINGW*|MSYS*|CYGWIN*) VSCODE_USER="${APPDATA}/Code/User/settings.json" ;;
    *)       VSCODE_USER="" ;;
esac

CLI_USER="${HOME}/.claude/settings.json"

When reporting their contents, extract only the relevant keys:

  • CLI user: permissions.defaultMode, permissions.allow, permissions.deny
  • VSCode user: any key starting with claudeCode.

Never print the full file. Redact everything else to (other keys redacted).

Show full SKILL.md (415 more words)Show less
Step 2: Compute resolved state

The resolved defaultMode is the value from the highest-precedence layer that sets it. Report:

  • Which layer won the defaultMode contest.
  • Merged allow list (union across CLI tiers).
  • Merged deny list (union; any deny blocks the action even if allowed elsewhere).
  • Whether VSCode says bypass but CLI says otherwise (or vice versa) — this is a legitimate conflict to flag.
Step 3: Report runtime mode

The live in-session mode is exposed via the status line (see .claude/scripts/statusline.sh). Tell the user:

"If your status line shows a mode badge ([AUTO], [BYPASS], [PLAN], [AUTO-EDIT], [PROMPT]), that is the live in-session mode. If it disagrees with the resolved defaultMode above, either a mid-session toggle (Shift+Tab) changed it, or the resolution above already explains it — e.g. [PROMPT] from a bypass set only in project settings. No badge means Claude Code did not report the mode; the mode indicator in the Claude Code panel shows it."

If the status line isn't configured, emit a warning and point at .claude/scripts/statusline.sh.

Step 4: Flag common failure modes

Check for and explicitly call out:

  1. Bypass or auto set only in project settings: layers 4–5 cannot set these starting modes. A bypass there starts the session in Manual; an auto there falls back to the built-in default (auto on ≥ 2.1.283). Fix: remove it from the project files and set bypass in user settings or with the CLI flag — or rely on the built-in auto default.
  2. Layer drift: CLI user says bypass but CLI project-local says default → the project-local default wins (it is an honoured value), which explains the prompts.
  3. VSCode-only bypass: VSCode layers say bypass but no CLI layer does → terminal Claude Code will still prompt; the extension honours it only with Allow dangerously skip permissions on.
  4. Empty allowlist + default mode: defaultMode: "default" with empty allow → every tool prompts, as designed.
  5. Stale session: settings are correct but user reports prompts → almost always a session that pre-dates the fix. Advise "Cmd+Shift+P → Developer: Reload Window, then new Claude Code session."
  6. deny wins: any match in a deny list blocks the tool regardless of allow, in every mode including bypass — which is exactly why restricted-data projects use deny rules.

Output format

=== PERMISSION STATE ===

Layer 1 — VSCode user:       bypassPermissions      (allowDangerouslySkipPermissions: true)
Layer 2 — VSCode workspace:  (not set)
Layer 3 — CLI user:          bypassPermissions      (allow: ["*"])
Layer 4 — CLI project:       (not set)              (allow: ["Edit(**)", "Bash(*)", ...])
Layer 5 — CLI project-local: bypassPermissions      NOT HONOURED — a project-layer bypass starts the session in Manual

Resolved defaultMode: default (Manual) — Layer 5's bypass overrides Layer 3 and is not honoured
Merged allow:         Edit(**), Write(**), Bash(*), ...
Merged deny:          (none)

=== RUNTIME ===

Check the status line (or the mode indicator). Expected here: [PROMPT] — the ignored Layer 5 bypass explains it.
Remove the bypass from Layer 5 and keep it in Layer 3 (or rely on auto mode) to get [BYPASS] / [AUTO].
Any other mismatch with the resolved mode is an in-session override — Shift+Tab cycles modes.

=== DIAGNOSIS ===

No layer drift detected. If you are still seeing prompts:
  1. Session is stale (started before settings were applied) — reload window + new session.
  2. VSCode extension bug — check extension version and file an issue.
  3. Tool was previously denied in this session — that denial is remembered. New session clears it.

If any layer disagrees, replace the "No layer drift detected" line with a specific flagged issue.

Notes

  • This skill is read-only. It never modifies settings.
  • If $CLAUDE_PROJECT_DIR is unset, fall back to git rev-parse --show-toplevel.
  • Platform-aware: detect macOS vs Linux vs Windows for the VSCode user path.

© pedrohcgs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/permission-check of pedrohcgs/claude-code-my-workflow.

Open the folder on GitHubat commit ae72617

Compare with similar skills

Permission Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Permission Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Permission Check this skillpedrohcgs/claude-code-my-workflow1.7k—~2.6kAutomated safety check: NotesMIT
Agent Browser CLIvercel-labs/agent-browser44k24 repos~864Automated safety check: PassApache-2.0
Electron App Automationvercel-labs/agent-browser44k5 repos~1.7kAutomated safety check: PassApache-2.0
Microsoft Skill CreatorMicrosoftDocs/mcp1.9k3 repos~2.1kAutomated safety check: PassCC-BY-4.0
Evals Contextzgsm-ai/costrict4.5k1 repos~1.9kAutomated safety check: PassApache-2.0
Ketch1broseidon/ketch7021 repos~3.9kAutomated safety check: PassMIT

Similar skills

  • Agent Browser CLI

    vercel-labs/agent-browser

    Official

    Browser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking…

    44k GitHub starsUsed in 24 repos~864 tokens
    Productivity & AutomationAuto-check passed
  • Electron App Automation

    vercel-labs/agent-browser

    Official

    Automates Electron desktop apps such as VS Code, Slack or Discord by connecting agent-browser to their Chrome DevTools Protocol port.

    44k GitHub starsUsed in 5 repos~1.7k tokens
    Productivity & AutomationAuto-check passed
  • Microsoft Skill Creator

    MicrosoftDocs/mcp

    Official

    Create agent skills for Microsoft technologies using official documentation.

    1.9k GitHub starsUsed in 3 repos~2.1k tokens
    Agent WorkflowsAuto-check passed
  • Evals Context

    zgsm-ai/costrict

    Provides context about the CoStrict evals system structure in this monorepo.

    4.5k GitHub starsUsed in 1 repo~1.9k tokens
    AI & LLM EngineeringAuto-check passed
  • Ketch

    1broseidon/ketch

    Research skill for ketch — a fast stateless CLI for web search, OSS code search, curated library docs, page scraping, and site crawling; an optional MCP server exists for operators who want it, but…

    702 GitHub starsUsed in 1 repo~3.9k tokens
    Data & AnalyticsAuto-check passed
  • Make Custom Agent

    dotnet/efcore

    Official

    Create custom GitHub Copilot agents. An agent skill from dotnet/efcore.

    15k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed

More from pedrohcgs/claude-code-my-workflow

All 59 skills in this repo
  • Devils Advocate

    pedrohcgs/claude-code-my-workflow

    Adversarial 5-7 question challenge to a deck's pedagogical choices — ordering, prerequisites, cognitive load, motivation.

    1.7k GitHub starsUsed in 2 repos~641 tokens
    Auto-check passed
  • Vaccinate

    pedrohcgs/claude-code-my-workflow

    Qualify a check before it is allowed to clear anything — prove it can detect the failure it is meant to catch.

    1.7k GitHub stars~2.1k tokensUpdated 13 days ago
    Auto-check: notes
  • Compile Latex

    pedrohcgs/claude-code-my-workflow

    Compile a Beamer LaTeX slide deck with XeLaTeX (3 passes + bibtex).

    1.7k GitHub starsUsed in 1 repo~492 tokens
    Auto-check: notes
  • Context Status

    pedrohcgs/claude-code-my-workflow

    Show current context status and session health. An agent skill from pedrohcgs/claude-code-my-workflow.

    1.7k GitHub starsUsed in 1 repo~613 tokens
    Auto-check: notes
  • Capture Environment

    pedrohcgs/claude-code-my-workflow

    Snapshot the computational environment for a replication package — detects the analysis stack (R / Stata / Python) and emits the right lockfiles (renv.lock + sessionInfo.txt, requirements.txt /…

    1.7k GitHub stars~2.8k tokensUpdated 13 days ago
    Auto-check: notes
  • Checkpoint

    pedrohcgs/claude-code-my-workflow

    Save a structured state snapshot before stopping or handing off.

    1.7k GitHub stars~2.8k tokensUpdated 13 days ago
    Auto-check: notes

Questions about Permission Check

What does Permission Check do?

Diagnose why Claude Code is (or isn't) prompting for permission. Permission Check is an agent skill from pedrohcgs/claude-code-my-workflow. Diagnose why Claude Code is (or isn't) prompting for permission.

When should I use Permission Check?

Permission Check fits situations like: explicitly confirms — those files may contain unrelated paths; user says why is it asking me to approve?; permission check; why am I getting prompts?.

How do I install Permission Check in Claude Code?

Run `npx skills add pedrohcgs/claude-code-my-workflow --skill permission-check -a claude-code`. Or copy the skill folder (.claude/skills/permission-check in pedrohcgs/claude-code-my-workflow) into .claude/skills/permission-check in your project. Claude Code loads it when a task matches its description.

How do I install Permission Check in Codex?

Run `npx skills add pedrohcgs/claude-code-my-workflow --skill permission-check -a codex`. Or copy the skill folder (.claude/skills/permission-check in pedrohcgs/claude-code-my-workflow) into .agents/skills/permission-check in your project. Codex loads it when a task matches its description.

Can I use Permission Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pedrohcgs/claude-code-my-workflow --skill permission-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/permission-check, .gemini/skills/permission-check, .github/skills/permission-check and .opencode/skills/permission-check in your project.

What does Permission Check need to run?

Going by SKILL.md and its folder, Permission Check needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Read, Bash, Glob.

Does Permission Check access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Permission Check safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Permission Check use?

Permission Check is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Permission Check use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Permission Check?

Skills that share tags, products or a category with Permission Check: Agent Browser CLI (vercel-labs/agent-browser, 44k stars), Electron App Automation (vercel-labs/agent-browser, 44k stars), Microsoft Skill Creator (MicrosoftDocs/mcp, 1.9k stars) and Evals Context (zgsm-ai/costrict, 4.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Permission Check?

pedrohcgs (a GitHub user) maintains it in pedrohcgs/claude-code-my-workflow, which has 1,655 GitHub stars. The repository holds 59 skills in this directory. The repository was last updated on September 27, 2026.

Source: pedrohcgs/claude-code-my-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.