Agent skill

Kode Permissions Debugging

by shareAI-lab in shareAI-lab/Kode-CLI

Troubleshoots Kode permission prompts and denials, including allowlists, command-level tool limits, dontAsk mode and subagent inheritance, without loosening permissions.

Apache-2.0Auto-check passedAgent Workflows

Install Kode Permissions Debugging

skills CLI
$ npx skills add shareAI-lab/Kode-CLI --skill permissions-debug -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install shareAI-lab/Kode-CLI permissions-debug --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/shareAI-lab/Kode-CLI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/builtin-skills/skills/permissions-debug .claude/skills/permissions-debug && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
permissions-debug
GitHub stars
5.2k
Token cost
~498 tokens
SKILL.md length
220 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
Apache-2.0

At a glance

Troubleshoots Kode permission prompts and denials, including allowlists, command-level tool limits, dontAsk mode and subagent inheritance, without loosening permissions.

  • Works in 3 steps: Confirm what is blocked → Inspect approved tools / project allowlist → Check per-command constraints
  • A tool is unexpectedly blocked in Kode
  • SKILL.md covers Non-negotiables, Fast triage (what to check…, Verification loop (keep it… and Forensics (when “it should…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The skill sets three ground rules: never escalate permissions automatically, make minimal and reversible permission changes and check them straight away, and in `dontAsk` contexts treat a would-be prompt as a denial instead of working around it. Triage starts by confirming exactly which tool was blocked and with what message, and for a subagent, whether the parent context was more restricted.

Next it inspects the approved tools list through the `/approved-tools list` command and removes only stale entries that matter, then checks per-command limits such as a command's `allowed-tools` frontmatter. A verification loop re-runs the blocked action to see whether a prompt appears interactively or the tool is allowed or denied deterministically in headless mode. When something should have worked, the agent reads session messages and errors under `~/.kode/` and cross-checks background task output files.

When your agent uses it

  • A tool is unexpectedly blocked in Kode
  • The same permission prompt keeps reappearing after you approve it
  • A subagent is denied something the main agent is allowed to do

Example prompts

  • “Kode keeps asking me to approve the same bash command, find out why the approval does not stick.”
  • “My subagent cannot run Grep although the main agent can, check how permissions are inherited.”
  • “A tool call was denied in dontAsk mode, show me what was attempted and which rule blocked it.”

Requirements

  • Kode CLI
  • Pre-approved tools (allowed-tools): SlashCommand, Read, Grep

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Confirm what is blocked
  2. Inspect approved tools / project allowlist
  3. Check per-command constraints

What it can do on your machine

Read from SKILL.md and the folder at commit c7f6fcc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • SlashCommand
    • Read
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kode Permissions Debugging loads about 498 tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 220 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~498

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from shareAI-lab/Kode-CLI at commit c7f6fcc, republished under its Apache-2.0 licence (© shareAI-lab). 220 words, ~498 tokens.

Download SKILL.mdSave it as .claude/skills/permissions-debug/SKILL.md (or your agent's skills folder).
name
permissions-debug
description
Troubleshoot Kode permission prompts/denials (tool allowlists, commandAllowedTools, dontAsk fail-closed, subagent inheritance). Use when tools are unexpectedly blocked, permission prompts repeat, or behavior differs between main agent and subagents.
allowed-tools
SlashCommand, Read, Grep

Permissions Debug (Kode-first, fail-closed)

Non-negotiables

  • Do not auto-escalate permissions. If an action would normally require user approval, keep it interactive and explain why.
  • Prefer minimal, reversible permission changes and verify immediately.
  • In dontAsk contexts, treat “would prompt” as deny (fail-closed). Do not try to bypass.

Fast triage (what to check first)

  1. Confirm what is blocked

    • Look for the exact tool name and the rejection message.
    • If the failure is from a subagent, confirm whether the parent context was more restricted.
  2. Inspect approved tools / project allowlist

    • Use SlashCommand to run /approved-tools list and confirm whether the tool (or its rule category) is present.
    • If the list is unexpectedly long or contains stale entries, remove only the minimum needed with /approved-tools remove <tool>.
  3. Check per-command constraints

    • Some flows apply commandAllowedTools constraints (slash command / skill execution contexts). Confirm the command’s allowed-tools frontmatter and whether it should be restrictive.

Verification loop (keep it tight)

  • Re-run the exact action that was blocked and confirm:
    • whether the prompt appears (interactive modes), or
    • whether the tool is allowed/denied deterministically (headless / dontAsk).

Forensics (when “it should have worked”)

  • Inspect the latest session artifacts under ~/.kode/ (messages + errors) to confirm what tool call was attempted and why it was denied.
  • If a background shell was involved, cross-check task output files in ~/.kode/**/tasks/ for the corresponding bashId.

© shareAI-lab, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/builtin-skills/skills/permissions-debug of shareAI-lab/Kode-CLI.

Open the folder on GitHubat commit c7f6fcc

Compare with similar skills

Kode Permissions Debugging next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kode Permissions Debugging compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kode Permissions Debugging this skillshareAI-lab/Kode-CLI5.2k—~498Automated safety check: PassApache-2.0
Cline Pilotsickn33/agentic-awesome-skills47k1 repos~4.6kAutomated safety check: PassMIT
Gemini CLI DelegationCherryHQ/cherry-studio52k1 repos~334Automated safety check: PassAGPL-3.0
GitHub Copilot CLI DelegationCherryHQ/cherry-studio52k1 repos~365Automated safety check: PassAGPL-3.0
MiniMax Code DelegationCherryHQ/cherry-studio52k1 repos~357Automated safety check: PassAGPL-3.0
OpenCode DelegationCherryHQ/cherry-studio52k1 repos~343Automated safety check: PassAGPL-3.0

Similar skills

  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Agent WorkflowsAuto-check passed
  • Gemini CLI Delegation

    CherryHQ/cherry-studio

    Runs Gemini CLI once in headless JSON mode for repository analysis or coding work, keeping its approvals read-only unless you ask for changes.

    52k GitHub starsUsed in 1 repo~334 tokens
    Agent WorkflowsAuto-check passed
  • GitHub Copilot CLI Delegation

    CherryHQ/cherry-studio

    Runs GitHub Copilot CLI non-interactively on a repository task and reads its JSONL output, denying tools by default so nothing changes unless you ask.

    52k GitHub starsUsed in 1 repo~365 tokens
    Agent WorkflowsAuto-check passed
  • MiniMax Code Delegation

    CherryHQ/cherry-studio

    Sends a bounded task to MiniMax Code with mcode exec, passing the smart permission mode for analysis and never the full one.

    52k GitHub starsUsed in 1 repo~357 tokens
    Agent WorkflowsAuto-check passed
  • OpenCode Delegation

    CherryHQ/cherry-studio

    Runs OpenCode once with opencode run and reads its JSON event stream, leaving its default denial of permission prompts in place for analysis.

    52k GitHub starsUsed in 1 repo~343 tokens
    Agent WorkflowsAuto-check passed
  • Qoder CLI Delegation

    CherryHQ/cherry-studio

    Runs the Qoder CN CLI statelessly with JSON output and accepts the result only when the is_error field says the task succeeded.

    52k GitHub starsUsed in 1 repo~369 tokens
    Agent WorkflowsAuto-check passed

More from shareAI-lab/Kode-CLI

All 8 skills in this repo
  • Skill Creator

    shareAI-lab/Kode-CLI

    Guides writing a new agent skill or improving an existing one, covering how to keep it concise, how much freedom to give the agent and how to lay out bundled resources.

    5.2k GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed
  • Skill Judge

    shareAI-lab/Kode-CLI

    Evaluates the design quality of an agent skill against official specifications and patterns from existing examples, scoring it and suggesting improvements.

    5.2k GitHub starsUsed in 4 repos~7.5k tokens
    Auto-check passed
  • Vibe Coding Partner

    shareAI-lab/Kode-CLI

    Gives an agent a set of working rules for any development task: understand first, surface decisions, verify results, and load deeper reference files per scenario.

    5.2k GitHub stars~5.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Doc Co-Authoring Workflow

    shareAI-lab/Kode-CLI

    Guides a three-stage workflow for turning partial context into a clear PRD, RFC or design doc: capture context, draft section by section, then test with a fresh reader.

    5.2k GitHub stars~977 tokensUpdated 1 mo ago
    Auto-check passed
  • Kode Capabilities Manager

    shareAI-lab/Kode-CLI

    Lets the Kode agent manage its own features, such as LSP, statusline, output styles and plugins, by running its slash commands for you instead of listing install steps.

    5.2k GitHub stars~760 tokensUpdated 1 mo ago
    Auto-check passed
  • Kode LSP Maintenance

    shareAI-lab/Kode-CLI

    Diagnoses why Kode's LSP tool returns nothing and fixes it through plugin .lsp.json files and slash commands, then verifies with a real LSP call.

    5.2k GitHub stars~573 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Kode Permissions Debugging

What does Kode Permissions Debugging do?

Troubleshoots Kode permission prompts and denials, including allowlists, command-level tool limits, dontAsk mode and subagent inheritance, without loosening permissions. The skill sets three ground rules: never escalate permissions automatically, make minimal and reversible permission changes and check them straight away, and in `dontAsk` contexts treat a would-be prompt as a denial instead of working around it. Triage starts by confirming exactly which tool was blocked and with what message, and for a subagent, whether the parent context was more restricted.

When should I use Kode Permissions Debugging?

Kode Permissions Debugging fits situations like: A tool is unexpectedly blocked in Kode; the same permission prompt keeps reappearing after you approve it; A subagent is denied something the main agent is allowed to do.

How do I install Kode Permissions Debugging in Claude Code?

Run `npx skills add shareAI-lab/Kode-CLI --skill permissions-debug -a claude-code`. Or copy the skill folder (packages/builtin-skills/skills/permissions-debug in shareAI-lab/Kode-CLI) into .claude/skills/permissions-debug in your project. Claude Code loads it when a task matches its description.

How do I install Kode Permissions Debugging in Codex?

Run `npx skills add shareAI-lab/Kode-CLI --skill permissions-debug -a codex`. Or copy the skill folder (packages/builtin-skills/skills/permissions-debug in shareAI-lab/Kode-CLI) into .agents/skills/permissions-debug in your project. Codex loads it when a task matches its description.

Can I use Kode Permissions Debugging in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add shareAI-lab/Kode-CLI --skill permissions-debug -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/permissions-debug, .gemini/skills/permissions-debug, .github/skills/permissions-debug and .opencode/skills/permissions-debug in your project.

What does Kode Permissions Debugging need to run?

SKILL.md names no scripts, command-line tools or credentials: Kode Permissions Debugging is instructions for the agent only. Our summary lists: Kode CLI. Its frontmatter pre-approves these tools: SlashCommand, Read, Grep.

Does Kode Permissions Debugging access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kode Permissions Debugging safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kode Permissions Debugging use?

Kode Permissions Debugging is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kode Permissions Debugging use?

About 498 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kode Permissions Debugging?

Skills that share tags, products or a category with Kode Permissions Debugging: Cline Pilot (sickn33/agentic-awesome-skills, 47k stars), Gemini CLI Delegation (CherryHQ/cherry-studio, 52k stars), GitHub Copilot CLI Delegation (CherryHQ/cherry-studio, 52k stars) and MiniMax Code Delegation (CherryHQ/cherry-studio, 52k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kode Permissions Debugging?

shareAI-lab (a GitHub organization) maintains it in shareAI-lab/Kode-CLI, which has 5,232 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on August 27, 2026.

Source: shareAI-lab/Kode-CLI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.