Agent skill

Human Approval

by Prismer-AI in Prismer-AI/PrismerCloud

Request human approval before performing a SAFETY-CRITICAL, IRREVERSIBLE, or SCOPE-EXPANDING action — submit a structured context (action, scope, risk, consequence) plus options, then STOP the…

MITAuto-check passedDevOps & Cloud

Install Human Approval

skills CLI
$ npx skills add Prismer-AI/PrismerCloud --skill human-approval -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Prismer-AI/PrismerCloud human-approval --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Prismer-AI/PrismerCloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/sdk/cloud/catalog/skills/human-approval .claude/skills/human-approval && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
human-approval
GitHub stars
1.6k
Token cost
~2.2k tokens
SKILL.md length
979 words
Files
1
Skills in repo
88
Repo updated
First seen
Licence
MIT

At a glance

Request human approval before performing a SAFETY-CRITICAL, IRREVERSIBLE, or SCOPE-EXPANDING action — submit a structured context (action, scope, risk, consequence) plus options, then STOP the…

  • Works in 6 steps: Summarize the action in one sentence —… → Provide context — recent state, related… → Spell out risk and consequence — what… → …
  • Just produce the output
  • SKILL.md covers When to use, Not when to use, Skill scope guard (v2.0.8) and CLI Reference, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Human Approval is an agent skill from Prismer-AI/PrismerCloud. Request human approval before performing a SAFETY-CRITICAL, IRREVERSIBLE, or SCOPE-EXPANDING action — submit a structured context (action, scope, risk, consequence) plus options, then STOP the current turn. The platform redispatches the agent after the human decides. NEVER use for routine deliverables (writing docs / generating files / summarising chats / answering questions / explaining concepts / read-only tool calls) — those are pre-authorized; just produce the output. The 5-minute-rollback litmus test…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The licence is MIT.

When your agent uses it

  • Just produce the output

Example prompts

  • “/human-approval”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Summarize the action in one sentence — what will happen, on what resource, with what permission.
  2. Provide context — recent state, related artifacts, why this came up now.
  3. Spell out risk and consequence — what breaks if this is wrong, what's reversible, what's not, who else is affected.
  4. Provide options when binary approve/reject is insufficient. Options must be mutually understandable and independently actionable (each is…
  5. Submit the approval request. Capture the returned approvalId.
  6. Stop the current turn. Don't ask follow-up questions, don't start the action, don't speculate about the answer. The platform will…

What it can do on your machine

Read from SKILL.md and the folder at commit e5d9444. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Human Approval loads about 2.2k tokens when it runs. Until then it costs about 198 tokens; SKILL.md has 979 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~198
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Prismer-AI/PrismerCloud at commit e5d9444, republished under its MIT licence (© Prismer-AI). 979 words, ~2,230 tokens.

Download SKILL.mdSave it as .claude/skills/human-approval/SKILL.md (or your agent's skills folder).
name
human-approval
description
Request human approval before performing a SAFETY-CRITICAL, IRREVERSIBLE, or SCOPE-EXPANDING action — submit a structured context (action, scope, risk, consequence) plus options, then STOP the current turn. The platform redispatches the agent after the human decides. NEVER use for routine deliverables (writing docs / generating files / summarising chats / answering questions / explaining concepts / read-only tool calls) — those are pre-authorized; just produce the output. The 5-minute-rollback litmus test applies: if the wrong outcome can be undone in <5 minutes by editing or deleting, it is NOT approval-eligible. Routine misuse (intro/explain/summarise/file-generation) burns the user's attention budget and is a contract violation. Executes via `cloud approval` CLI.
scope
common

Human Approval

Autonomous by default (release203). Agents operate autonomously. Do NOT request approval for routine tool use, running commands, or delivering artifacts (cloud deliver). Only use this skill for genuinely high-risk actions, and only when your role is explicitly configured for it. If your approvalPolicy is autonomous, you should essentially never reach for this skill — just do the work and report the result.

Anti-confabulation rule. NEVER claim to be "waiting for human approval" / "等待人工确认" unless you ACTUALLY invoked the approval tool (cloud approval request / prismer.approval.request_human_approval) and received a real approvalId. Narrating an approval pause you never triggered is a hallucination — it strands the user with a phantom gate that nothing will ever clear.

Some actions need a human in the loop before they execute: production deploys, large credit spend, deleting data, scope-expanding decisions. This skill submits a structured request and halts the current turn. The platform stores the request, notifies the human, and redispatches the agent with the decision when the human responds — you don't poll, you don't re-ask in the same turn.

When to use

  • Production-impacting action: deploy, schema change, infra reconfig, payment send.
  • Irreversible: delete files, drop tables, revoke keys, close accounts.
  • Scope-expanding: the task as-stated implies more changes than the user originally agreed to.
  • High credit cost: any operation that would spend > expected budget.
  • Authority-elevating: granting access, changing roles, modifying ACLs.

Not when to use

  • Routine clarifying questions ("what column name do you want?") — just ask in chat.
  • Choosing between two equivalent options where the user clearly didn't care — pick one and proceed.
  • When the user already explicitly approved this action in the current conversation — proceed.

Skill scope guard (v2.0.8)

The "Not when to use" list above is the load-bearing rule. As of release 2.0.8 we tightened it because routine deliverables (write a doc, summarise a chat, draft a slide deck, answer a question) were incorrectly triggering approval gates — the user got a yellow "等待 人工确认" banner for a request as simple as "@ceo 给我介绍一下产品 PDF", which is a deliverable request, not a scope-expansion.

The following 8 categories are never approval-eligible. Run them directly and report the result in the same turn:

CategoryWhy it's not approval-eligibleUse instead
Writing a document / generating a report / outputting PDF, DOCX, PPTX, XLSX, CSVThe user asked for the deliverable; gating it is anti-UX.Call office-artifacts and ship.
Summarising a conversation / writing meeting notesPure synthesis from data the user already has.Reply in chat.
Answering a question / explaining a conceptThe user invited the answer by asking.Reply in chat.
Asking the user for a preference ("Chinese or English?")A chat question is the correct affordance.Ask in chat — human-approval is overkill.
Choosing model parameters / temperature / sampling styleInternal agent decision; users don't have context to judge.Decide and proceed; mention the choice in the reply.
Naming files / picking output pathsInternal agent decision; reversible by renaming.Pick sensible defaults; let user override if asked.
Internal brainstorming / scoring multiple candidatesThe user asked for the winner, not the deliberation.Do the work, surface the winner.
Calling read-only MCP tools (search, web fetch, file read)No side effect; trivially reversible.Call directly.

The litmus test: "If this step turns out wrong, can I roll it back in under 5 minutes by editing or deleting something?"

  • If yes → not approval-eligible. Ship it.
  • If no → safety-critical / irreversible / scope-expanding → approval-eligible.

Mis-using human-approval for routine work burns the user's attention budget, breaks chat flow, and signals lack of agent confidence — all three are real costs. The role templates (Team Manager / engineer / marketer / researcher / verifier) carry an explicit operatingPrinciples line as of 2.0.8: "Never trigger human-approval for routine deliverables".

Show full SKILL.md (375 more words)Show less

CLI Reference

Anchor required. POST /api/im/approvals rejects requests with neither taskId nor conversationId, because the platform needs a target to deliver the human decision to. Every invocation MUST pass one of --task-id or --conversation-id.

bash
# Linked to a task — the platform resumes the task on decision (preferred for marketplace / agent flows)
cloud approval request-human \
  --task-id <taskId> \
  --action "approve marketplace task completion" \
  --context "Result: scan-deps found 3 CVEs. Report attached." \
  --risk "Releases 10-credit escrow to the assignee."

# Linked to a conversation — the decision is posted back as a chat message
cloud approval request-human \
  --conversation-id <conversationId> \
  --action "delete branch feat/old-experiment" \
  --context "Last commit 2025-12-10. Merged into main. Local copy preserved." \
  --risk "Irreversible. No remote backup; force-pushed commits would be lost."

# With explicit options (multi-choice)
cloud approval request-human \
  --conversation-id <conversationId> \
  --action "deploy v1.8.2 to prod" \
  --context "All gates green, 9/9 webhook tests pass, test env stable 48h." \
  --risk "Touches payment webhook. Rollback ETA 5min via git revert + redeploy." \
  --options "deploy-now" "deploy-tomorrow-morning" "wait-for-manual-smoke-test"

Workflow

  1. Summarize the action in one sentence — what will happen, on what resource, with what permission.
  2. Provide context — recent state, related artifacts, why this came up now.
  3. Spell out risk and consequence — what breaks if this is wrong, what's reversible, what's not, who else is affected.
  4. Provide options when binary approve/reject is insufficient. Options must be mutually understandable and independently actionable (each is a thing the agent can do without further clarification).
  5. Submit the approval request. Capture the returned approvalId.
  6. Stop the current turn. Don't ask follow-up questions, don't start the action, don't speculate about the answer. The platform will redispatch you when the human decides.

Operating Rules

  • Do not proceed with the gated action in the same turn after requesting approval. This is the load-bearing rule. The platform will redispatch the agent with the decision; running the action now defeats the gate.
  • Do not hide material risks or irreversible effects from the approval context. The human is approving based on what you wrote — incomplete framing is worse than no gate.
  • Keep options mutually understandable and actionable. "Approve" / "Approve with conditions" / "Reject" is fine. "Maybe" / "Let me think" is not — that's not a decision the human can choose.
  • Use this for safety-critical decisions, not routine clarification. Asking the user "what label do you prefer?" via human-approval is overkill and burns their attention budget.
  • Link to a task (--task-id) when the approval gates a task's progression. The platform resumes the task automatically when the human approves.
  • If the user already explicitly approved this exact action earlier in the conversation, skip the gate. Repeated approval-prompts for the same authorized action feel broken.

Output reporting

After submitting:

Submitted approval request <approvalId> for "<action>". Stopping this turn. The platform will redispatch when the human decides.

When the agent is redispatched with the decision, the next turn's input includes the approval result. Don't re-issue the request — read the decision and act on it (or report rejection back to the user).

Backing capabilities (D22 mapping)

Replaces this v1.x built-in skill: approval-request-human.

© Prismer-AI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in sdk/cloud/catalog/skills/human-approval of Prismer-AI/PrismerCloud.

Open the folder on GitHubat commit e5d9444

Compare with similar skills

Human Approval next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Human Approval compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Human Approval this skillPrismer-AI/PrismerCloud1.6k—~2.2kAutomated safety check: PassMIT
Auto tmux Operatortradecatlabs/vibe-coding-cn17k—~4.7kAutomated safety check: PassMIT
Myclaw BackupLeoYeAI/openclaw-backup659—~1.8kAutomated safety check: PassMIT
Trigger.dev Cost Savings Auditpapermark/papermark9.2k—~1.3kAutomated safety check: PassCustom licence
OpenRig Upgrade Proceduremvschwarz/openrig6.6k—~2.9kAutomated safety check: PassApache-2.0
Docs Corpus Auditmicrosoft/apm4k—~2.6kAutomated safety check: PassMIT

Similar skills

  • Auto tmux Operator

    tradecatlabs/vibe-coding-cn

    Operates tmux sessions like an administrator: reads pane output, sends keys, inspects many panes at once, and coordinates multiple AI terminals through a swarm state script, built on oh-my-tmux.

    17k GitHub stars~4.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Myclaw Backup

    LeoYeAI/openclaw-backup

    Backup and restore all OpenClaw configuration, agent memory, skills, and workspace data.

    659 GitHub stars~1.8k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Audits Trigger.dev tasks, schedules and run history for wasteful machine sizes, retries, polling and cron frequency to cut spend.

    9.2k GitHub stars~1.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • OpenRig Upgrade Procedure

    mvschwarz/openrig

    Walks an agent through upgrading the OpenRig CLI and daemon one observed step at a time, keeping live seats alive and reconciling managed plugin files.

    6.6k GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docs Corpus Audit

    microsoft/apm

    Official

    A skill your agent uses to run a holistic regrounding pass on the entire microsoft/apm documentation corpus against current source code, page-by-page, and emit surgical fixes for stale claims.

    4k GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Thememoria

    matrixorigin/memoria

    Use Memoria as OpenClaw's durable memory slot. An agent skill from matrixorigin/memoria.

    610 GitHub stars~728 tokensUpdated today
    DevOps & CloudAuto-check passed

More from Prismer-AI/PrismerCloud

All 88 skills in this repo
  • Prismer Google Workspace

    Prismer-AI/PrismerCloud

    Gives an agent account-scoped access to Gmail, Calendar, Drive, Contacts, Docs and Sheets through the gws CLI or a bundled Python client.

    1.6k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check passed
  • Prismer Skill Creator

    Prismer-AI/PrismerCloud

    Walks an agent through creating, importing, editing, validating, testing and publishing Prismer Skills with a fixed workflow and bundled scripts.

    1.6k GitHub stars~2.6k tokensUpdated 10 days ago
    Auto-check: notes
  • Himalaya Email CLI

    Prismer-AI/PrismerCloud

    Operates a mailbox from the terminal with the external Himalaya CLI over IMAP, SMTP, Notmuch or Sendmail, separate from any built-in email gateway adapter.

    1.6k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Prismer Image Generation

    Prismer-AI/PrismerCloud

    Generates one image from a text prompt with a bundled Node.js helper and delivers it once as the attachment to the current Prismer reply.

    1.6k GitHub stars~1.4k tokensUpdated 10 days ago
    Auto-check passed
  • Manim Explainer Videos

    Prismer-AI/PrismerCloud

    Produces 3Blue1Brown-style explainer animations with Manim Community Edition for math, algorithms, equations and architecture diagrams, with planning and rendering references.

    1.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed
  • Prismer Role Builder

    Prismer-AI/PrismerCloud

    Creates or updates Prismer role templates from a persona, SOP or job description, and turns a role into a working agent that runs its first task through a bundled script.

    1.6k GitHub stars~2.3k tokensUpdated 10 days ago
    Auto-check: notes

Questions about Human Approval

What does Human Approval do?

Request human approval before performing a SAFETY-CRITICAL, IRREVERSIBLE, or SCOPE-EXPANDING action — submit a structured context (action, scope, risk, consequence) plus options, then STOP the…. Human Approval is an agent skill from Prismer-AI/PrismerCloud. Request human approval before performing a SAFETY-CRITICAL, IRREVERSIBLE, or SCOPE-EXPANDING action — submit a structured context (action, scope, risk, consequence) plus options, then STOP the current turn.

When should I use Human Approval?

Human Approval fits situations like: just produce the output.

How do I install Human Approval in Claude Code?

Run `npx skills add Prismer-AI/PrismerCloud --skill human-approval -a claude-code`. Or copy the skill folder (sdk/cloud/catalog/skills/human-approval in Prismer-AI/PrismerCloud) into .claude/skills/human-approval in your project. Claude Code loads it when a task matches its description.

How do I install Human Approval in Codex?

Run `npx skills add Prismer-AI/PrismerCloud --skill human-approval -a codex`. Or copy the skill folder (sdk/cloud/catalog/skills/human-approval in Prismer-AI/PrismerCloud) into .agents/skills/human-approval in your project. Codex loads it when a task matches its description.

Can I use Human Approval in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Prismer-AI/PrismerCloud --skill human-approval -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/human-approval, .gemini/skills/human-approval, .github/skills/human-approval and .opencode/skills/human-approval in your project.

What does Human Approval need to run?

SKILL.md names no scripts, command-line tools or credentials: Human Approval is instructions for the agent only.

Does Human Approval access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Human Approval safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Human Approval use?

Human Approval is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Human Approval use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Human Approval?

Skills that share tags, products or a category with Human Approval: Auto tmux Operator (tradecatlabs/vibe-coding-cn, 17k stars), Myclaw Backup (LeoYeAI/openclaw-backup, 659 stars), Trigger.dev Cost Savings Audit (papermark/papermark, 9.2k stars) and OpenRig Upgrade Procedure (mvschwarz/openrig, 6.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Human Approval?

Prismer-AI (a GitHub organization) maintains it in Prismer-AI/PrismerCloud, which has 1,555 GitHub stars. The repository holds 88 skills in this directory. The repository was last updated on September 30, 2026.

Source: Prismer-AI/PrismerCloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.