Agent skill

Human In The Loop

by seb1n in seb1n/awesome-ai-agent-skills

Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.

MITAuto-check passedAgent Workflows

Install Human In The Loop

skills CLI
$ npx skills add seb1n/awesome-ai-agent-skills --skill human-in-the-loop -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install seb1n/awesome-ai-agent-skills human-in-the-loop --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-engineering/human-in-the-loop .claude/skills/human-in-the-loop && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
human-in-the-loop
GitHub stars
206
Token cost
~2.5k tokens
SKILL.md length
1,215 words
Files
5 (incl. scripts, references, assets)
Skills in repo
101
Repo updated
First seen
Licence
MIT

At a glance

Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.

  • Works in 7 steps: Inventory decisions and effects → Assign the lightest sufficient oversight → Specify the decision package → …
  • Deciding which agent actions require review
  • SKILL.md covers Inputs, Output contract, Workflow and Authorization and safety…, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Human In The Loop is an agent skill from seb1n/awesome-ai-agent-skills. Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows. Use when deciding which agent actions require review, adding approve/reject or dual-control flows, preventing unauthorized autonomous effects, creating decision records, reducing rubber-stamping, or recovering safely from rejected, expired, or failed actions.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts, reference files and assets (for example `agents/openai.yaml`, `assets/approval-policy-template.json` and `references/gate-design-guide.md`).

It sits in Agent Workflows, covering Human-in-the-loop approvals. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.

When your agent uses it

  • Deciding which agent actions require review
  • Adding approve/reject
  • Dual-control flows
  • Preventing unauthorized autonomous effects

Example prompts

  • “/human-in-the-loop”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Inventory decisions and effects
  2. Assign the lightest sufficient oversight
  3. Specify the decision package
  4. Bind identity and approval to the action
  5. Implement a safe state machine
  6. Add escalation and recovery
  7. Verify the controls

What it can do on your machine

Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Human In The Loop loads about 2.5k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 1,215 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 1,215 words, ~2,522 tokens.

Download SKILL.mdSave it as .claude/skills/human-in-the-loop/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
human-in-the-loop
description
Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows. Use when deciding which agent actions require review, adding approve/reject or dual-control flows, preventing unauthorized autonomous effects, creating decision records, reducing rubber-stamping, or recovering safely from rejected, expired, or failed actions.

Human in the Loop

Place human judgment at the decision point where it changes risk. A confirmation dialog alone is not oversight: bind an authorized decision to an understandable, immutable action and preserve evidence of what happened.

Inputs

Collect or infer, and label assumptions for:

  • Agent goal, workflow states, and every action it can propose or execute
  • Effect type, reversibility, value, affected people, and worst credible impact
  • Data sensitivity, regulatory or contractual duties, and organizational risk tolerance
  • Stable requester and approver subject identities, role assignments, policy owner, separation-of-duties rules, and coverage hours
  • Required response time, timeout behavior, escalation contacts, and availability target
  • Evidence an approver needs, including provenance, uncertainty, and alternatives
  • Existing identity, policy, audit, ticketing, and notification systems
  • Failure, retry, cancellation, compensation, and incident paths

Do not invent approver authority or organizational policy. If missing information affects a consequential action, produce a proposed policy and mark it for owner approval.

Output contract

Deliver:

  1. An action inventory and rationale-backed risk tier for each action
  2. A gate policy defining validated predicates, eligible approver roles and distinct subjects, quorum, evidence, expiry, timeout, structured escalation, audit-outage behavior, execution-time reauthorization, compensation, break-glass, and separation of duties
  3. A state machine for prepare, review, decision, execution, failure, and recovery
  4. An approval experience that shows the exact action, material effects, uncertainty, provenance, alternatives, and safe reject/edit paths
  5. An append-only decision record schema and retention/redaction requirements
  6. Implementation or a file-level plan, plus policy and concurrency tests
  7. Verification evidence, unresolved policy decisions, residual risk, and an operational recovery plan

Start from assets/approval-policy-template.json when a machine-readable policy helps. Validate it with scripts/validate_gate_policy.py. Read references/gate-design-guide.md for risk-tier and state-machine guidance.

Workflow

1. Inventory decisions and effects

List each agent action and the object it affects. Separate drafting, previewing, recommending, and reading from committing, sending, publishing, purchasing, deleting, granting access, executing code, or making a high-impact decision.

Record reversibility, scale, sensitivity, external visibility, financial value, time pressure, affected rights, and whether a mistaken action can be contained.

2. Assign the lightest sufficient oversight

Choose one control per risk:

  • Autonomous with audit: bounded, reversible, low-impact actions
  • Notify after action: low-impact actions where rapid awareness is sufficient
  • Review before action: consequential or externally visible actions
  • Step-up approval: value, sensitivity, confidence, anomaly, or scope crosses a threshold
  • Dual control: critical, irreversible, privileged, or regulated actions; require at least two distinct approver subjects by default
  • Prohibited: action exceeds policy or cannot be made acceptably safe

Do not gate every trivial step; excess prompts train users to approve reflexively. Never remove a required gate merely to meet a latency target. Treat critical single-control and requester self-approval as invalid by default. Permit either only through a time-bounded waiver that names the gate and exception type, includes the policy owner's stable subject ID and approval reference, documents rationale and compensating controls, and is explicitly referenced by the gate.

3. Specify the decision package

Show the approver:

  • Plain-language intent and why the gate triggered
  • Target identity and normalized parameters
  • Before/after diff or exact proposed payload
  • Expected effects, affected parties, cost, and reversibility
  • Evidence sources, provenance, freshness, uncertainty, and known gaps
  • Policy basis, alternatives, and what reject, edit, or timeout will do

Hide secrets and minimize personal data. Make the primary reject/cancel path as usable as approve.

4. Bind identity and approval to the action

Authenticate the approver and authorize their role independently of the model. Model roles and stable approver subjects separately so a two-role requirement cannot silently resolve to one person. Create a canonical representation or digest of actor, tenant, action, target, material parameters, policy version, expiry, and nonce. Approval applies only to that immutable proposal.

Invalidate approval after any material edit, expiry, policy change, target change, or relevant state change. Prevent self-approval where separation of duties applies. Do not interpret silence, message receipt, or a generic prior consent as approval.

5. Implement a safe state machine

Use explicit transitions such as:

prepared -> pending_review -> approved | rejected | expired | cancelled

approved -> executing -> completed | failed | compensation_pending

Make transitions atomic and idempotent. Recheck authorization and preconditions immediately before execution. Consume one-time approvals exactly once. Handle concurrent approvers, duplicate callbacks, stale screens, retries, and partial downstream failures.

Show full SKILL.md (525 more words)Show less
6. Add escalation and recovery

Define machine-readable reminders, escalation subjects or roles, maximum attempts, maximum wait, exhaustion behavior, and out-of-office coverage. Default timeouts to deny, cancel, or escalate—not approve. Specify whether an audit-store outage fails closed or uses a short, signed buffer; critical actions fail closed. Reauthorize identity, role, policy, proposal digest, target state, and expiry immediately before execution.

Define compensation as automatic, manual, required-but-unavailable, or not-applicable, with an owner and procedure reference. Treat break-glass as a distinct, strongly authenticated path with at least two named subjects, narrow scope, short expiry, reason capture, immediate alerting, and after-action review.

For rejection, preserve the proposal and reason without executing. For execution failure, stop unsafe retries, mark the true state, invoke a tested compensating action when one exists, notify the owner, and preserve redacted evidence.

7. Verify the controls

Test:

  • Each action lands in the expected risk tier and gate
  • Unauthorized, wrong-tenant, and self-approving actors are denied
  • Approval fails after parameter, target, state, policy, or expiry changes
  • Duplicate approvals and callbacks cannot execute twice
  • Reject, edit, cancel, timeout, escalation, and unavailable-approver paths
  • Quorum, distinct-subject, self-approval, owner-waiver, and separation-of-duties behavior under concurrent decisions
  • Execution-time reauthorization and changed preconditions
  • Escalation exhaustion, audit-storage outage, partial failure, compensation, break-glass, and incident notification
  • Decision records contain required evidence but no secrets
  • Usability with representative approvers, including comprehension and error rates

Report commands, simulations, and observed results. Do not claim that human review is effective without exercising both policy logic and the approval experience.

Authorization and safety boundaries

  • Designing a gate does not authorize the underlying action; do not execute, send, publish, deploy, purchase, delete, or grant access unless separately authorized.
  • Never allow a model to fabricate, impersonate, or infer a human approval.
  • Enforce identity, authorization, quorum, and approval binding outside model-generated text.
  • Do not expose secrets or unnecessary personal data to approvers, logs, notifications, or test fixtures.
  • Fail closed for missing identity, ambiguous or malformed predicates, stale state, expired approval or waiver, wrong tenant, invalid quorum, insufficient distinct subjects, or unavailable audit storage on high-risk actions.
  • Avoid dark patterns, preselected approval, urgency manipulation, and bundles that hide materially different actions.
  • Do not use human review to legitimize discriminatory, unlawful, or otherwise prohibited decisions.

Realistic examples

Refund agent

Allow autonomous refunds below $50 only for verified duplicate charges. Require a support manager above $50 and finance plus support above $1,000. Show order history, policy basis, amount, destination, and fraud signals. Bind approval to order, amount, destination, and policy version; test duplicates, changed payment destination, timeout, and partial processor failure.

Communications agent

Let the agent draft customer updates but require the account owner to approve the exact recipients, subject, body digest, attachments, and send time. Any edit invalidates approval. A rejected draft returns to editing; an expired approval cannot send. Audit the decision without storing attachment contents in the decision log.

Completion check

Finish only when every consequential action has a documented policy, predicates are structurally validated, approver roles resolve to sufficient distinct subjects, critical single-control or self-approval is rejected unless an active owner-approved waiver exists, approvals cannot be replayed or silently broadened, escalation/audit-outage/reauthorization/compensation/break-glass paths work, and the audit trail plus residual risk are explicit.

© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in agent-engineering/human-in-the-loop of seb1n/awesome-ai-agent-skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/approval-policy-template.json
  • references/gate-design-guide.md
  • scripts/validate_gate_policy.py

Open the folder on GitHubat commit 75865a5

Compare with similar skills

Human In The Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Human In The Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Human In The Loop this skillseb1n/awesome-ai-agent-skills206—~2.5kAutomated safety check: PassMIT
Show Me Your Work Decision Logcursor/plugins10k8 repos~1.6kAutomated safety check: PassNone
Darwin Skill Optimizeralchaincyf/darwin-skill6.2k1 repos~4.7kAutomated safety check: PassMIT
Loop Constraints Enforcercobusgreyling/loop-engineering11k1 repos~475Automated safety check: NotesMIT
Ask User QuestionMemTensor/MemOS12k—~1kAutomated safety check: PassApache-2.0
PUA High-Agency Governancetanweai/pua20k—~502Automated safety check: PassMIT

Similar skills

  • Official

    Keeps a TSV decision log for long or unattended agent runs, one row per decision with what, why, evidence and result, so a reviewer can check the work later.

    10k GitHub starsUsed in 8 repos~1.6k tokens
    Agent WorkflowsAuto-check passed
  • Darwin Skill Optimizer

    alchaincyf/darwin-skill

    Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.

    6.2k GitHub starsUsed in 1 repo~4.7k tokens
    Agent WorkflowsAuto-check passed
  • Loop Constraints Enforcer

    cobusgreyling/loop-engineering

    Loads a project's loop-constraints.md before any other action and blocks pushes, edits or merges that violate the rules it defines.

    11k GitHub starsUsed in 1 repo~475 tokens
    Agent WorkflowsAuto-check: notes
  • Ask User Question

    MemTensor/MemOS

    Shows a question as a modal in the interface to clarify a task, collect a preference or get approval, since the user cannot see terminal output.

    12k GitHub stars~1k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Pushes an agent to keep verifying and changing approach after repeated failures, using a diagnosis line, evidence-based completion and confirmation before risky edits.

    20k GitHub stars~502 tokensUpdated 29 days ago
    Agent WorkflowsAuto-check passed
  • Agentmemory Forget

    rohitg00/agentmemory

    Deletes chosen memories from agentmemory only after showing the matches and getting an explicit yes, for privacy requests and cleanup of outdated notes.

    29k GitHub stars~612 tokensUpdated today
    Agent WorkflowsAuto-check passed

More from seb1n/awesome-ai-agent-skills

All 101 skills in this repo
  • Agent Red Teaming

    seb1n/awesome-ai-agent-skills

    Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.

    206 GitHub stars~2.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • MCP Server Building

    seb1n/awesome-ai-agent-skills

    Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • PDF Processing

    seb1n/awesome-ai-agent-skills

    Inspect, extract, OCR, create, merge, split, reorder, rotate, annotate, fill, redact, compress, secure, and verify PDF documents while preserving source files and visual fidelity.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Supply Chain Audit

    seb1n/awesome-ai-agent-skills

    Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.

    206 GitHub stars~2.4k tokensUpdated 2 mo ago
    Auto-check passed
  • Spreadsheet Analysis

    seb1n/awesome-ai-agent-skills

    Inspect, profile, clean, reconcile, analyze, visualize, and verify spreadsheet data while preserving formulas, formatting, types, and source files.

    206 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Human In The Loop

What does Human In The Loop do?

Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows. Human In The Loop is an agent skill from seb1n/awesome-ai-agent-skills. Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.

When should I use Human In The Loop?

Human In The Loop fits situations like: deciding which agent actions require review; adding approve/reject; dual-control flows; preventing unauthorized autonomous effects.

How do I install Human In The Loop in Claude Code?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill human-in-the-loop -a claude-code`. Or copy the skill folder (agent-engineering/human-in-the-loop in seb1n/awesome-ai-agent-skills) into .claude/skills/human-in-the-loop in your project. Claude Code loads it when a task matches its description.

How do I install Human In The Loop in Codex?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill human-in-the-loop -a codex`. Or copy the skill folder (agent-engineering/human-in-the-loop in seb1n/awesome-ai-agent-skills) into .agents/skills/human-in-the-loop in your project. Codex loads it when a task matches its description.

Can I use Human In The Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill human-in-the-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/human-in-the-loop, .gemini/skills/human-in-the-loop, .github/skills/human-in-the-loop and .opencode/skills/human-in-the-loop in your project.

What does Human In The Loop need to run?

Going by SKILL.md and its folder, Human In The Loop needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Human In The Loop access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Human In The Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Human In The Loop use?

Human In The Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Human In The Loop use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Human In The Loop?

Skills that share tags, products or a category with Human In The Loop: Show Me Your Work Decision Log (cursor/plugins, 10k stars), Darwin Skill Optimizer (alchaincyf/darwin-skill, 6.2k stars), Loop Constraints Enforcer (cobusgreyling/loop-engineering, 11k stars) and Ask User Question (MemTensor/MemOS, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Human In The Loop?

seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 101 skills in this directory. The repository was last updated on August 9, 2026.

Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.