Tenuo Agent Authorization
tenuo-ai/tenuo
Add or retrofit Tenuo authorization for AI-agent tools and effects.
A skill your agent uses when administering a Scenario team from an agent through MCP: restricting which models a team or project can run (model access control, allowlist, blocklist), inviting or…
$ npx skills add scenario-labs/skills --skill scenario-team-admin -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install scenario-labs/skills scenario-team-admin --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/scenario-labs/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/scenario-team-admin .claude/skills/scenario-team-admin && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "scenario-team-admin" agent skill from https://github.com/scenario-labs/skills/tree/main/skills/scenario-team-admin into .claude/skills/scenario-team-admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scenario-team-admin", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/scenario-labs/skills/tree/main/skills/scenario-team-adminType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add scenario-labs/skills --skill scenario-team-admin -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install scenario-labs/skills scenario-team-admin --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/scenario-labs/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/scenario-team-admin .agents/skills/scenario-team-admin && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "scenario-team-admin" agent skill from https://github.com/scenario-labs/skills/tree/main/skills/scenario-team-admin into .agents/skills/scenario-team-admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scenario-team-admin", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add scenario-labs/skills --skill scenario-team-admin -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install scenario-labs/skills scenario-team-admin --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/scenario-labs/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/scenario-team-admin .cursor/skills/scenario-team-admin && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "scenario-team-admin" agent skill from https://github.com/scenario-labs/skills/tree/main/skills/scenario-team-admin into .cursor/skills/scenario-team-admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scenario-team-admin", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/scenario-labs/skills.git --path skills/scenario-team-admin--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add scenario-labs/skills --skill scenario-team-admin -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install scenario-labs/skills scenario-team-admin --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/scenario-labs/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/scenario-team-admin .gemini/skills/scenario-team-admin && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "scenario-team-admin" agent skill from https://github.com/scenario-labs/skills/tree/main/skills/scenario-team-admin into .gemini/skills/scenario-team-admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scenario-team-admin", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install scenario-labs/skills scenario-team-adminInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add scenario-labs/skills --skill scenario-team-admin -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/scenario-labs/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/scenario-team-admin .github/skills/scenario-team-admin && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "scenario-team-admin" agent skill from https://github.com/scenario-labs/skills/tree/main/skills/scenario-team-admin into .github/skills/scenario-team-admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scenario-team-admin", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add scenario-labs/skills --skill scenario-team-admin -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install scenario-labs/skills scenario-team-admin --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/scenario-labs/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/scenario-team-admin .opencode/skills/scenario-team-admin && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "scenario-team-admin" agent skill from https://github.com/scenario-labs/skills/tree/main/skills/scenario-team-admin into .opencode/skills/scenario-team-admin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "scenario-team-admin", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
scenario-team-adminA skill your agent uses when administering a Scenario team from an agent through MCP: restricting which models a team or project can run (model access control, allowlist, blocklist), inviting or…
Scenario Team Admin is an agent skill from scenario-labs/skills. Use when administering a Scenario team from an agent through MCP: restricting which models a team or project can run (model access control, allowlist, blocklist), inviting or removing team and project members, changing roles, capping a member's Creative Unit spend, auditing API keys and their roles or scopes, or attributing consumption per user or model. Keywords: governance, model control, consumption cap, spend limit, API key hygiene, team admin, enterprise.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authorization and RBAC. It works with Model Context Protocol. The repository describes itself as: Get production-ready images, video, audio, and 3D from any AI agent: skills that pick the right model, price before spending, and keep characters and brands consistent through… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f6f8ab7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Scenario Team Admin loads about 3.3k tokens when it runs. Until then it costs about 121 tokens; SKILL.md has 1,716 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from scenario-labs/skills at commit f6f8ab7, republished under its MIT licence (© scenario-labs). 1,716 words, ~3,324 tokens.
.claude/skills/scenario-team-admin/SKILL.md (or your agent's skills folder).Enterprise teams govern Scenario from the same agent that generates on it: which models anyone may run, who is on the team and in which projects, how much each member may spend, and which API keys exist with which roles. Every tool here is catalog-only: scenario_tools_search returns the schema and lane, and scenario_tool_execute_read / write / delete runs it with {name, parameters}, scope ids inside parameters (see the scenario skill). Two facts decide most failures before any argument does: the identity behind the call, since team-level writes need a human team admin over OAuth and refuse API keys, and the list mode the team runs, since the same model-access edit means the opposite thing in blocklist and allowlist mode. teams_list already tells you both: each team row carries modelsManagement, its model lists, plan, and context.userRole. A credential that reaches one team and one project has its scope; more than one is a stop-and-list, per the scenario skill. If a sibling skill named here is missing from your available skills, ask the user to install it (npx skills add scenario-labs/skills --skill <name>); unattended, proceed from tool schemas and flag the gap.
| Task | Tool | Lane | Notes |
|---|---|---|---|
| Read model access | model_access_get | read | Mode plus the team's active list; project_id adds that project's list alongside it |
| Change model access | model_access_update | write | level team or project; exactly one of add_models, remove_models |
| Team roster | team_members_list | read | Members and pending invitations |
| Invite | team_members_add | write | 1 to 32 emails, role, optional project_ids joined on acceptance |
| Roles and spend caps | team_members_update | write | member_ids 1 to 32; role and/or max_consumption |
| Remove from the team | team_members_remove | delete | Also withdraws invitations; access ends immediately |
| Project roster | project_members_list, _add, _update, _remove | read, write, delete | Roles admin (Owner), editor (Contributor), reader (Viewer) |
| API keys | api_keys_list, api_key_get, api_key_update, api_key_delete | read, write, delete | Project scope; api_key_create returns the portal link and nothing else |
| Who spent what | usage | read (default tools) | Per-user and per-model consumption in the default response |
model_access_get returns models_management and only the mode's active list; the inactive stored list is never surfaced. In blocklist mode (the default) every catalog model is available except those on the team or project blocklist, and the two lists block as a union. In allowlist mode a model is available only when it sits on both the team and the project allowlist; a project with an empty allowlist denies every model, and a project with no allowlist configured falls back to the team list.
model_access_update edits whichever list the mode makes active, so add_models blocks in blocklist mode and allows in allowlist mode: read the mode first, every time. Switching the mode is not available through MCP; it lives in the web app's team settings, so locking a team down to an approved set starts with the user flipping to allowlist there. Unattended, that switch is a stop-and-report: log that the lock waits on it and the exact calls that follow, and take the blocklist-safe partial (blocking the named unwanted models at project level), saying that other projects stay open. Narrowing a list the credential can edit is in scope when the task states the target set: remove_models runs after the adds succeed, so the list never ends empty. level: "team" needs a team admin over OAuth, and the server refuses API keys on that endpoint. level: "project" takes the projects to edit in projects (1 to 200) and needs the admin role on every one of them: one unauthorized project fails the whole request and nothing updates, and a single-project key can only edit its own project's list. project_id on the call is tenant context for OAuth sessions, never the target. In allowlist mode a project admin can add only models already on the team allowlist (a project list narrows the catalog, never widens it), removing a base model from a team allowlist cascade-removes the trained models built on it, and a team-level add validates every id, one unknown id failing the whole call. updated: false means the diff was a no-op, not an error. A blocked model disappears from what members can run, and the error a member sees when running one anyway is a restriction, not moderation (see scenario-moderation).
team_members_update takes member_ids from team_members_list and sets role (admin or member), max_consumption, or both. The cap is in Creative Units over the current billing period: a value of zero or more caps, -1 is unlimited, and null clears the per-member override so the team-wide default applies. Roles can be set by a team admin over OAuth or a team-scoped API key with the team.members.manage scope; caps need a real team admin, and a key that tries is refused per member. Demoting the last admin fails server-side. The bulk member tools process one row at a time and report an outcome per member; a response with status: "partial" is finished by calling again with its remaining list.
team_members_add invites 1 to 32 emails at role (default member) and joins them to project_ids on acceptance; outcomes are invited, failed, or skipped with the reason (already a member, already invited, seat limit reached). project_id on the call grants nothing. Like role changes, inviting takes a team admin over OAuth or a team-scoped key with team.members.manage; a project-scoped key gets a permission error. A pending invitation carries no member id, so its cap waits for acceptance. project_members_add takes people already on the team, as user ids or emails (emails need team_id to resolve), with a required project role.
Removal is the delete lane and immediate: team_members_remove ends the person's access everywhere and withdraws pending invitations, project_members_remove leaves team membership and other projects untouched. List first, confirm the exact names with the user, then remove; unattended, remove only the members the task instructions name.
api_keys_list and api_key_get are project-scoped and return each key's id, api_key_id, name, status, scope, role, projects, and creation date, plus a manage_keys_url; team-scoped keys are not attached to projects and never appear here, only in the portal. api_key_update changes a key's role to admin, editor, reader, or a custom ;-separated scope list (the reference's example is assets.read;models.run); name, status, and usage limits are portal-only, and a limit takes an Enterprise plan and a human admin. Creation is deliberately not an MCP operation: api_key_create returns the portal link, the secret is shown once there, and it never passes through the conversation (the scenario skill's rule on secrets holds here). api_key_delete takes the key as key_id (either the id or the api_key_id from the listing), cannot be undone, needs a project admin, and refuses the key the current session is authenticated with: list, confirm the exact key with the user, then delete; unattended, delete only a key the task instructions name and exactly one key matches.
usage is in the default toolset and returns a summary by default: headline CU totals, per-user consumption, per-model CU and job counts sorted descending, and per-asset-kind counts, bounded by start_date and end_date (ISO dates); project_id filters the figures, so a single-project credential ranks spend inside that project, not across the team. An undated call returns project-lifetime figures, so always pass the range: totals and the per-user consumption rows (userId, total) follow start_date and end_date, and a member ranking comes from those rows. The per-day series (include: ["usages.daily"] per usage type, ["modelUsages.daily"] per model) carry no user dimension; nsfwUsages adds moderation totals and activity the raw event log. Never attribute spend by adding up your own calls. Read consumption before setting caps: both are in CU over the billing period, and a cap below what a member has already spent stops them at once.
scenario_tools_search with query="model access", then query="team members": schemas and lanes for the calls below.scenario_tool_execute_read with name: "model_access_get", parameters: {"team_id", "project_id"}. The team is in blocklist mode, so "only these three models" is not expressible: tell the user to switch the team to allowlist in the web app's team settings, then re-read; unattended, log the gap with the calls below and stop, blocking any models the task names as unwanted at project level in the meantime.scenario_tool_execute_write with name: "model_access_update", parameters: {"team_id", "project_id", "level": "team", "add_models": [<the three ids>]}; this is the call that needs the caller to be a team admin over OAuth (context.userRole on the teams_list row says whether they are). Then the project: level: "project", projects: [<project id>], the same add_models, which succeeds only because the team list now carries them.scenario_tool_execute_read with name: "team_members_list": the two contractors' member ids. scenario_tool_execute_write with name: "team_members_update", parameters: {"team_id", "project_id", "member_ids": [<two ids>], "max_consumption": 2000}. On status: "partial", call again with remaining.scenario_tool_execute_read with name: "api_keys_list" for the project. A render-farm key running as admin is narrowed with api_key_update, role: "assets.read;models.run", and any key nobody can account for is deleted only after the user confirms it by name.model_access_get with project_id shows the project list configured with the three ids; later in the period, usage with the date range and include: ["usages.daily"] shows the contractors' consumption against the cap.models_management: add_models blocks in one mode and allows in the other.arguments instead of parameters on the executor: dropped silently and surfaced as a scope error (see scenario).team.members.manage key: it can change roles, not caps.usage call as the period's spend: its figures are project-lifetime. Pass start_date and end_date, rank members from the dated consumption rows, and use the per-day series only to cross-check a period total, since it carries no user dimension.api_keys_list to show team-scoped keys: they exist only in the portal.project_id to team_members_add to grant project access: project_ids grants; project_id is tenant context.api_key_delete refuses the session's own key.© scenario-labs, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/scenario-team-admin of scenario-labs/skills.
Open the folder on GitHubat commit f6f8ab7
Scenario Team Admin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Scenario Team Admin this skillscenario-labs/skills | 946 | — | ~3.3k | Automated safety check: Pass | MIT | |
| Tenuo Agent Authorizationtenuo-ai/tenuo | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Frontmcp Auth UIagentfront/frontmcp | 146 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Frontmcp Authoritiesagentfront/frontmcp | 146 | — | ~7.1k | Automated safety check: Pass | Apache-2.0 | |
| Workosusenotra/notra | 256 | — | ~6.2k | Automated safety check: Pass | AGPL-3.0 | |
| Manage Dashboard WidgetsPostHog/posthog | 40k | — | ~2.3k | Automated safety check: Pass | Custom licence |
tenuo-ai/tenuo
Add or retrofit Tenuo authorization for AI-agent tools and effects.
agentfront/frontmcp
A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…
agentfront/frontmcp
A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.
usenotra/notra
A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…
PostHog/posthog
Guides PostHog engineers through dashboard widget platform work — ship a new widgettype (WIDGETREGISTRY, catalog, runwidgets, WidgetCard) or update a shipped type (config, query, layout, RBAC, tile…
aws/agent-toolkit-for-aws
Create managed Iceberg tables using Amazon S3 Tables (s3tables API namespace) with automatic compaction and snapshot management.
scenario-labs/skills
A skill your agent uses when drawing or animating with Grease Pencil in Blender 5.x from Python: 2D or 2.5D illustration, frame-by-frame animation, a cutout or part-based 2D character, strokes with…
scenario-labs/skills
A skill your agent uses when grooming hair or fur in Blender with hair curves, such as a character hairstyle, animal fur, procedural fur in geometry nodes, or hair cards and mesh hair for games.
scenario-labs/skills
A skill your agent uses when lighting, rendering or compositing in Blender: light a character, product or hero shot, interior at dusk or night, three-point or motivated lighting, sun and sky, HDRI…
scenario-labs/skills
A skill your agent uses when creating a ChatGPT pet or Codex pet with Scenario: hatching an animated companion from a text idea, a character, mascot or brand cue, or reference photos and art; making…
scenario-labs/skills
A skill your agent uses when animating characters or scenes in Godot 4.7: AnimationPlayer clips and RESET, AnimationTree state machines and blend spaces built in code, Mixamo or glTF import, loop…
scenario-labs/skills
A skill your agent uses when adding or fixing sound in Godot 4.7: audio buses and effects, volume sliders, 'too many sounds', combat audio with hundreds of enemies, sounds clipping or distorting, 3D…
Works with
Categories
A skill your agent uses when administering a Scenario team from an agent through MCP: restricting which models a team or project can run (model access control, allowlist, blocklist), inviting or…. Scenario Team Admin is an agent skill from scenario-labs/skills. Use when administering a Scenario team from an agent through MCP: restricting which models a team or project can run (model access control, allowlist, blocklist), inviting or removing team and project members, changing roles, capping a member's Creative Unit spend, auditing API keys and their roles or scopes, or attributing consumption per user or model.
Scenario Team Admin fits situations like: administering a Scenario team from an agent through MCP: restricting which models a team; project can run (model access control; removing team and project members; capping a members Creative Unit spend.
Run `npx skills add scenario-labs/skills --skill scenario-team-admin -a claude-code`. Or copy the skill folder (skills/scenario-team-admin in scenario-labs/skills) into .claude/skills/scenario-team-admin in your project. Claude Code loads it when a task matches its description.
Run `npx skills add scenario-labs/skills --skill scenario-team-admin -a codex`. Or copy the skill folder (skills/scenario-team-admin in scenario-labs/skills) into .agents/skills/scenario-team-admin in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add scenario-labs/skills --skill scenario-team-admin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scenario-team-admin, .gemini/skills/scenario-team-admin, .github/skills/scenario-team-admin and .opencode/skills/scenario-team-admin in your project.
Going by SKILL.md and its folder, Scenario Team Admin needs the command-line tools its instructions call (npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Scenario Team Admin is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Scenario Team Admin: Tenuo Agent Authorization (tenuo-ai/tenuo, 103 stars), Frontmcp Auth UI (agentfront/frontmcp, 146 stars), Frontmcp Authorities (agentfront/frontmcp, 146 stars) and Workos (usenotra/notra, 256 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
scenario-labs (a GitHub organization) maintains it in scenario-labs/skills, which has 946 GitHub stars. The repository holds 146 skills in this directory. The repository was last updated on October 10, 2026.
Source: scenario-labs/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.