Sponsio Agent Safety Setup
SponsioLabs/Sponsio
Installs, tunes and enforces Sponsio contracts that block unsafe tool calls in LLM agents, covering setup, auditing, observe mode and flipping to enforce.
Guides designing a layered permission pipeline for agent tools that decides which calls are allowed, need confirmation or are denied, with scopes and hooks.
SKILL.md written in Chinese; this summary is our English description.
$ npx skills add simbajigege/book2skills --skill tool-permission-system -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install simbajigege/book2skills tool-permission-system --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/simbajigege/book2skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tool-permission-system .claude/skills/tool-permission-system && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tool-permission-system" agent skill from https://github.com/simbajigege/book2skills/tree/main/skills/tool-permission-system into .claude/skills/tool-permission-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-permission-system", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/simbajigege/book2skills/tree/main/skills/tool-permission-systemType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add simbajigege/book2skills --skill tool-permission-system -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install simbajigege/book2skills tool-permission-system --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simbajigege/book2skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/tool-permission-system .agents/skills/tool-permission-system && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tool-permission-system" agent skill from https://github.com/simbajigege/book2skills/tree/main/skills/tool-permission-system into .agents/skills/tool-permission-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-permission-system", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add simbajigege/book2skills --skill tool-permission-system -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install simbajigege/book2skills tool-permission-system --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simbajigege/book2skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/tool-permission-system .cursor/skills/tool-permission-system && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tool-permission-system" agent skill from https://github.com/simbajigege/book2skills/tree/main/skills/tool-permission-system into .cursor/skills/tool-permission-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-permission-system", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/simbajigege/book2skills.git --path skills/tool-permission-system--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add simbajigege/book2skills --skill tool-permission-system -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install simbajigege/book2skills tool-permission-system --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simbajigege/book2skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/tool-permission-system .gemini/skills/tool-permission-system && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tool-permission-system" agent skill from https://github.com/simbajigege/book2skills/tree/main/skills/tool-permission-system into .gemini/skills/tool-permission-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-permission-system", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install simbajigege/book2skills tool-permission-systemInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add simbajigege/book2skills --skill tool-permission-system -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/simbajigege/book2skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/tool-permission-system .github/skills/tool-permission-system && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tool-permission-system" agent skill from https://github.com/simbajigege/book2skills/tree/main/skills/tool-permission-system into .github/skills/tool-permission-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-permission-system", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add simbajigege/book2skills --skill tool-permission-system -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install simbajigege/book2skills tool-permission-system --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/simbajigege/book2skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/tool-permission-system .opencode/skills/tool-permission-system && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tool-permission-system" agent skill from https://github.com/simbajigege/book2skills/tree/main/skills/tool-permission-system into .opencode/skills/tool-permission-system/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tool-permission-system", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tool-permission-systemGuides designing a layered permission pipeline for agent tools that decides which calls are allowed, need confirmation or are denied, with scopes and hooks.
This skill explains how to build a permission pipeline that runs before every agent tool call and settles on one of three outcomes: allow, ask the user, or deny. Rules come from layers with a fixed priority, from enterprise policy settings that users cannot override down through user, project and session scopes, and each rule names a tool or a tool with content. Deny rules are a hard veto checked first.
Wrapper modes change the outcome after the pipeline: dontAsk turns every ask into a deny for background agents, auto sends asks to an AI classifier, and headless runs permission-request hooks first and denies when none answers. Tools declare safety properties such as read-only, destructive and concurrency-safe with fail-closed defaults, and a tool's own checkPermissions sits between the general deny and allow rules. References include TypeScript files on dangerous patterns, denial tracking and permission types, plus hook and pipeline docs and example settings. Parts of the text are in Chinese.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5ba66c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (TypeScript), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tool Permission System Design loads about 2.1k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 128 tokens; SKILL.md has 256 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from simbajigege/book2skills at commit e5ba66c, republished under its Apache-2.0 licence (© simbajigege). 256 words, ~2,062 tokens.
.claude/skills/tool-permission-system/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.Every time an agent calls a tool, a permission pipeline runs before execution. This pipeline is the single place that decides: auto-allow, ask the user, or deny. The pipeline is layered — different stakeholders (enterprise admin, user, project team, session) can each contribute rules, with higher layers overriding lower ones.
Tool call request
↓
[硬否决] Deny rules → immediate deny
↓
[强制确认] Ask rules → force prompt (even in bypass mode)
↓
[工具自身] Tool's checkPermissions() → tool-specific logic
↓
[安全绕过免疫] Safety checks (.git/, .claude/, shell configs) → prompt, immune to bypass
↓
[模式快速通过] Bypass / acceptEdits mode → immediate allow
↓
[白名单] Allow rules → immediate allow
↓
[默认] passthrough → prompt user (ask)外层包装(作用于整条流水线之后):
dontAsk 模式:把所有 ask 转为 deny(用于无交互的后台 agent)auto 模式:把所有 ask 转给 AI 分类器判断,而不是打断用户headless 模式:先跑 PermissionRequest hooks,hooks 没回应就自动 denytype PermissionBehavior = 'allow' | 'deny' | 'ask'
type PermissionDecision =
| { behavior: 'allow'; updatedInput?: unknown; decisionReason?: DecisionReason }
| { behavior: 'ask'; message: string; suggestions?: PermissionUpdate[] }
| { behavior: 'deny'; message: string; decisionReason: DecisionReason }规则来源按优先级从高到低排列:
policySettings ← 企业管理员,用户不可覆盖
userSettings ← 用户全局 (~/.agent/settings.json)
projectSettings ← 项目级 (.agent/settings.json,可提交 git)
localSettings ← 本地私有 (.agent/settings.local.json)
cliArg ← 启动参数
command ← 运行时命令
session ← 当次会话临时每条规则的格式:ToolName 或 ToolName(content)。
async function hasPermission(tool, input, context): Promise<PermissionDecision> {
// Step 1: deny rules (优先级最高,含企业强制)
const denyRule = findMatchingRule(context.denyRules, tool, input)
if (denyRule) return { behavior: 'deny', message: '...', decisionReason: { type: 'rule', rule: denyRule } }
// Step 2: ask rules (强制弹框,绕过模式也无法跳过)
const askRule = findMatchingRule(context.askRules, tool, input)
if (askRule) return { behavior: 'ask', message: '...' }
// Step 3: 工具自身的 checkPermissions()
const toolResult = await tool.checkPermissions(input, context)
if (toolResult.behavior === 'deny') return toolResult
if (toolResult.behavior === 'ask' && toolResult.decisionReason?.type === 'rule') return toolResult // ask rule 免疫 bypass
if (toolResult.behavior === 'ask' && toolResult.decisionReason?.type === 'safetyCheck') return toolResult // 安全检查免疫 bypass
// Step 4: bypass 模式快速通过
if (context.mode === 'bypassPermissions') return { behavior: 'allow', updatedInput: input }
// Step 5: allow rules 白名单
const allowRule = findMatchingRule(context.allowRules, tool, input)
if (allowRule) return { behavior: 'allow', updatedInput: input }
// Step 6: 默认转 ask
return { behavior: 'ask', message: `Agent requested to use ${tool.name}` }
}工具与权限系统的接合点是工具接口上的一组安全属性。关键设计:所有属性都遵循失败关闭(fail-closed)——开发者不声明时,系统按"最保守"假设处理,必须主动声明"我是安全的"才放宽。
// 工厂函数用 TOOL_DEFAULTS 填充未声明的属性
const TOOL_DEFAULTS = {
isEnabled: () => true,
isConcurrencySafe: () => false, // 默认不并发(怕数据竞争)
isReadOnly: () => false, // 默认假设会写入
isDestructive: () => false, // 默认假设不可逆操作要谨慎
checkPermissions: (input) => ({ behavior: 'allow', updatedInput: input }), // 默认交给中央权限系统
}
function buildTool(def) { return { ...TOOL_DEFAULTS, ...def } }| 属性 | 返回 | 谁来问 / 影响什么 |
|---|---|---|
isReadOnly(input) | boolean | 权限系统:只读操作可绕过部分限制 |
isDestructive(input) | boolean | 权限系统:不可逆操作需更严格确认 |
isConcurrencySafe(input) | boolean | Agent Loop:能否与其他工具并发执行(默认 false → 串行) |
checkPermissions(input, ctx) | PermissionResult | 权限系统:工具专属权限逻辑(流水线 1c) |
validateInput(input, ctx) | ValidationResult | Agent Loop:执行前的输入合法性校验 |
checkPermissions 在流水线里的位置是"夹心结构":通用 deny/ask 规则在它之前(且 bypass 也拦不住),通用 allow 白名单在它之后。所以工具自检既挡不住企业 deny,也不必重复实现通用 allow——只管工具特有的逻辑:
class MyTool implements Tool {
isReadOnly = () => false
isConcurrencySafe = () => false
async checkPermissions(input, context): Promise<PermissionResult> {
// 检查工具特定规则(如 Bash 检查具体命令前缀)
const allowRules = getRuleContentsForTool(context, this, 'allow')
if (allowRules.has(getCommandPrefix(input.command))) {
return { behavior: 'allow' }
}
// 检查危险路径(命中后 type:'safetyCheck' → bypass 也拦不住,见下方说明)
if (isDangerousPath(input.path)) {
return {
behavior: 'ask',
message: '...',
decisionReason: { type: 'safetyCheck', reason: '...', classifierApprovable: false }
}
}
return { behavior: 'passthrough', message: '...' } // 没意见 → 交给外层
}
}危险路径黑名单(safetyCheck)是一份硬编码的敏感文件/目录清单,即使 bypass / acceptEdits / 配了 allow 规则也强制弹框,防两类攻击:① 代码执行(.git/ hooks、.bashrc/.zshrc 等 shell 启动脚本、.vscode/.idea 任务配置);② AI 改自己的护栏(.claude/、.mcp.json、.claude.json —— agent 不能通过"正常编辑文件"给自己提权)。完整清单见 references/dangerous-patterns.ts。
Hook 让用户/企业在工具生命周期各节点插入自定义逻辑:
// 配置格式(settings.json)
{
"hooks": {
"PreToolUse": [{
"matcher": "MyTool", // 可选,工具名过滤
"hooks": [{
"type": "command", // command | prompt | agent | http
"command": "check-safety.sh $TOOL_INPUT"
}]
}],
"PostToolUse": [{
"matcher": "FileEdit",
"hooks": [{ "type": "command", "command": "prettier --write $FILE_PATH" }]
}]
}
}Hook 执行结果影响权限决策:
{"action": "allow"} → 覆盖决策当使用 AI 分类器自动判断权限时,需要 circuit breaker 防止分类器过于严格:
// 连续拒绝 3 次或累计拒绝 20 次 → 回退到人工确认
const DENIAL_LIMITS = { maxConsecutive: 3, maxTotal: 20 }
function shouldFallback(state: DenialTrackingState): boolean {
return (
state.consecutiveDenials >= DENIAL_LIMITS.maxConsecutive ||
state.totalDenials >= DENIAL_LIMITS.maxTotal
)
}设计时必须明确的三个问题:
decisionReason.type === 'safetyCheck' 标记shouldAvoidPermissionPrompts = true + 跑 hooks + 自动 deny// 最简实现:三层规则 + 工具自检
type Rule = { toolName: string; content?: string; behavior: 'allow' | 'deny' | 'ask' }
type PermissionContext = {
mode: 'default' | 'bypassPermissions' | 'acceptEdits'
allowRules: Rule[]
denyRules: Rule[]
askRules: Rule[]
}
async function checkPermission(toolName: string, input: unknown, ctx: PermissionContext) {
if (ctx.denyRules.some(r => matches(r, toolName, input))) return 'deny'
if (ctx.askRules.some(r => matches(r, toolName, input))) return 'ask'
if (ctx.mode === 'bypassPermissions') return 'allow'
if (ctx.allowRules.some(r => matches(r, toolName, input))) return 'allow'
return 'ask' // default: prompt
}This skill owns:
isReadOnly / isDestructive / isConcurrencySafe / checkPermissions + fail-closed 默认值)This skill does not own:
references/permission-types.tsreferences/permission-pipeline.mdreferences/denial-tracking.tsreferences/hook-system.mdreferences/settings-examples.json© simbajigege, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 10 other files (references) in skills/tool-permission-system of simbajigege/book2skills.
Open the folder on GitHubat commit e5ba66c
Tool Permission System Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tool Permission System Design this skillsimbajigege/book2skills | 183 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Sponsio Agent Safety SetupSponsioLabs/Sponsio | 454 | — | ~12k | Automated safety check: Pass | Apache-2.0 | |
| Trigger.dev Agent Patternspapermark/papermark | 9.2k | — | ~2k | Automated safety check: Pass | Custom licence | |
| Add Example AgentGetBindu/Bindu | 10k | — | ~1.1k | Automated safety check: Notes | Custom licence | |
| Failproof AI SDK IntegrationFailproofAI/failproofai | 5.3k | — | ~6k | Automated safety check: Pass | Custom licence | |
| Agent Squad for TypeScript2FastLabs/agent-squad | 7.8k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 |
SponsioLabs/Sponsio
Installs, tunes and enforces Sponsio contracts that block unsafe tool calls in LLM agents, covering setup, auditing, observe mode and flipping to enforce.
papermark/papermark
Patterns for building LLM agents on Trigger.dev tasks: prompt chaining, routing, parallel workers, orchestrator-workers, evaluator loops and human approval gates.
GetBindu/Bindu
Add a new self-contained example agent under examples/. An agent skill from GetBindu/Bindu.
FailproofAI/failproofai
Helps instrument a custom Python or TypeScript agent to record events for Failproof AI, verify what gets written, and run an evaluator worker that scores the runs.
2FastLabs/agent-squad
Guide to building Node.js and TypeScript apps on the agent-squad package: orchestrator, agent types, classifier routing, storage, retrievers and MCP tools.
millionco/cli-to-js
A skill your agent uses when wrapping CLI binaries in JavaScript, automating shell workflows in TypeScript, composing multiple CLIs into scripts, or building agent tool-use.
simbajigege/book2skills
Reorganizes an overgrown MEMORY.md into a short pointer index plus separate topic files, and fixes or deletes outdated memories instead of archiving them.
simbajigege/book2skills
A developer guide to adding compact memory to an agent: when to trigger compaction, how to fork a compactor sub-agent, what the summary holds, and how to restore it.
simbajigege/book2skills
Turns text, screenshots, or existing diagrams into minimal, accessible line-art SVGs for teaching material, with an optional Mermaid relationship spec.
simbajigege/book2skills
Helps define agent tools with a fail-closed pattern: one class holding name, schema, security flags and a validate, permission and call execution chain.
simbajigege/book2skills
Implements a production-style agent loop in your own AI product, with tool calling, tool results fed back, exit conditions and budget guards.
simbajigege/book2skills
Analyzes Chinese public company financial statements (balance sheet, income statement, cash flow) to assess asset quality, profit authenticity, cash flow health, solvency, and overall investment…
Works with
Categories
Guides designing a layered permission pipeline for agent tools that decides which calls are allowed, need confirmation or are denied, with scopes and hooks. This skill explains how to build a permission pipeline that runs before every agent tool call and settles on one of three outcomes: allow, ask the user, or deny. Rules come from layers with a fixed priority, from enterprise policy settings that users cannot override down through user, project and session scopes, and each rule names a tool or a tool with content.
Tool Permission System Design fits situations like: building an agent that must auto-allow, confirm or deny tool calls; designing allow and deny rules across enterprise, user and project scopes; adding hooks that can approve or block tool calls; defining fail-closed safety flags on tools.
Run `npx skills add simbajigege/book2skills --skill tool-permission-system -a claude-code`. Or copy the skill folder (skills/tool-permission-system in simbajigege/book2skills) into .claude/skills/tool-permission-system in your project. Claude Code loads it when a task matches its description.
Run `npx skills add simbajigege/book2skills --skill tool-permission-system -a codex`. Or copy the skill folder (skills/tool-permission-system in simbajigege/book2skills) into .agents/skills/tool-permission-system in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add simbajigege/book2skills --skill tool-permission-system -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tool-permission-system, .gemini/skills/tool-permission-system, .github/skills/tool-permission-system and .opencode/skills/tool-permission-system in your project.
Going by SKILL.md and its folder, Tool Permission System Design needs TypeScript for the scripts in its folder.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Tool Permission System Design is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Tool Permission System Design: Sponsio Agent Safety Setup (SponsioLabs/Sponsio, 454 stars), Trigger.dev Agent Patterns (papermark/papermark, 9.2k stars), Add Example Agent (GetBindu/Bindu, 10k stars) and Failproof AI SDK Integration (FailproofAI/failproofai, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
simbajigege (a GitHub user) maintains it in simbajigege/book2skills, which has 183 GitHub stars. The repository holds 37 skills in this directory. The repository was last updated on August 26, 2026.
Source: simbajigege/book2skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.