Agent skill

Manage Risk Policy Audience

by speakeasy-api in speakeasy-api/gram

Inspect and safely change who a risk policy targets in an explicit Speakeasy AI Control Plane project, with confirmed administrator audience changes and clear refusals for unavailable self-exclusion.

AGPL-3.0Auto-check passedAgent Workflows

Install Manage Risk Policy Audience

skills CLI
$ npx skills add speakeasy-api/gram --skill manage-risk-policy-audience -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install speakeasy-api/gram manage-risk-policy-audience --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/speakeasy-api/gram.git skills-src && mkdir -p .claude/skills && cp -r skills-src/server/internal/plugins/platform_mcp_skills/manage-risk-policy-audience .claude/skills/manage-risk-policy-audience && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
manage-risk-policy-audience
GitHub stars
273
Token cost
~1.6k tokens
SKILL.md length
854 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Inspect and safely change who a risk policy targets in an explicit Speakeasy AI Control Plane project, with confirmed administrator audience changes and clear refusals for unavailable self-exclusion.

  • Works in 3 steps: Call list_projects through this client's… → Call list_risk_policies for that project… → Call get_risk_policy for the exact…
  • Tasks that involve MCP servers
  • SKILL.md covers Inspect and confirm the exact…, Remove the authenticated…, Add or remove direct audience… and Replace an audience only when…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Manage Risk Policy Audience is an agent skill from speakeasy-api/gram. Inspect and safely change who a risk policy targets in an explicit Speakeasy AI Control Plane project, with confirmed administrator audience changes and clear refusals for unavailable self-exclusion.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering MCP servers. It works with Model Context Protocol. The repository describes itself as: Securely scale AI usage across your organization. A single stack to Connect, Secure, Observe and Distribute agents, MCPs, and Skills within your company. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve MCP servers

Example prompts

  • “/manage-risk-policy-audience”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Call list_projects through this client's connection. Ask the user to choose the exact project slug. If discovery is incomplete or the…
  2. Call list_risk_policies for that project and ask the user to select the exact policy. Names are not unique: retain the returned policy ID…
  3. Call get_risk_policy for the exact project and policy. Inspect its current audience, compatibility, and opaque version. Keep principal…

What it can do on your machine

Read from SKILL.md and the folder at commit b4c4904. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Manage Risk Policy Audience loads about 1.6k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 854 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from speakeasy-api/gram at commit b4c4904, republished under its AGPL-3.0 licence (© speakeasy-api). 854 words, ~1,612 tokens.

Download SKILL.mdSave it as .claude/skills/manage-risk-policy-audience/SKILL.md (or your agent's skills folder).
name
manage-risk-policy-audience
description
Inspect and safely change who a risk policy targets in an explicit Speakeasy AI Control Plane project, with confirmed administrator audience changes and clear refusals for unavailable self-exclusion.

Manage a risk policy audience

Use the executing client's authenticated Platform MCP connection. Installing this skill grants no authority. Live membership, organization-admin permission, explicit-project authorization, and the risk-mutation rollout remain authoritative. Never request credentials or use another client's identity.

Inspect and confirm the exact target

  1. Call list_projects through this client's connection. Ask the user to choose the exact project slug. If discovery is incomplete or the requested project is unavailable, stop; never substitute Default or another project.
  2. Call list_risk_policies for that project and ask the user to select the exact policy. Names are not unique: retain the returned policy ID rather than guessing from a name. Follow pagination for discovery, or accept an exact user-supplied policy ID and verify it directly.
  3. Call get_risk_policy for the exact project and policy. Inspect its current audience, compatibility, and opaque version. Keep principal URNs, policy IDs, versions, and idempotency keys as internal tool arguments rather than displaying them as user instructions. A policy audience is a set of positive user/role grants, not a list of exceptions or proof of effective membership.

Remove the authenticated requester

For “remove me,” explain that self-removal and effective exclusion are unavailable pending organization-scoped coordination of audience grants. remove_self_from_risk_policy remains discoverable to external organization administrators but always refuses before database transactions or receipt replay. Do not claim that deleting a positive user grant proves the requester is no longer covered.

Stop without writing. Do not bypass this refusal with change_risk_policy_audience, general audience replacement, policy disablement, role or membership changes, a risk exclusion, or reconstruction of Everyone as today's member list. Never infer a human from managed-assistant attribution. A separately requested administrator change to direct positive grants is a different outcome, not a workaround for self-exclusion.

Add or remove direct audience grants

For a separately requested incremental administrator change, use change_risk_policy_audience through an external OAuth organization-admin connection. Managed assistants cannot discover or invoke this tool, and their policy reads omit exact audience identities.

  1. Select exact organization user or role principal URNs from trusted administrator selections, not guessed names or emails. Native directory groups are not supported; do not treat a directory group as a role or change directory membership.
  2. Explain the exact additions and removals and obtain explicit confirmation. Removing a direct user grant does not remove role-derived coverage. Removing a role grant changes that role's direct policy grant, not its membership. Never claim the removed user is unaffected by the policy: other roles or broader grants may still cover them.
  3. Refresh get_risk_policy for the exact target immediately before writing. If the audience changed, obtain confirmation again. Call change_risk_policy_audience with the exact project_slug, policy_id, fresh expected_version, stable idempotency_key, confirmed: true, and both add_principals and remove_principals arrays. Each list is bounded to 100 user/role URNs; the resulting targeted audience must contain 1–100 principals. Use an empty array for the unchanged side; at least one array must be nonempty. The tool atomically preserves all audience entries outside the delta and unrelated policy settings.
  4. Stop on Everyone audiences, last-principal removal, unsupported principals, duplicate or overlapping deltas, stale versions, and conflicts with current direct grants. This tool does not create an Everyone-except-one audience or effective exclusion. Never use an audience delta to bypass a self-removal refusal. Do not automatically fall back to replacement, policy disablement, or risk exclusion.
Show full SKILL.md (304 more words)Show less

Replace an audience only when explicitly requested

For a separately requested administrator audience change through an external OAuth connection, use update_risk_policy only for a complete replacement, not an incremental request. Managed-assistant reads omit exact audience identities, and managed assistants cannot replace audiences. Read the exact policy first and obtain explicit confirmation of the complete replacement—not merely one addition or deletion. Omit every unrelated patch field. Use patch.audience with type, principal_urns, and confirm: true, plus the usual project, policy, expected version, and idempotency key.

  • targeted requires a nonempty list of valid organization user or role principal URNs (at most 100 entries). Preserve every principal outside the explicitly confirmed change. Use exact trusted selections; never guess identifiers or use names as identities.
  • everyone requires an empty principal_urns array. This broadens the policy to everyone and needs explicit confirmation of that effect. It is never a fallback for a failed targeted update.
  • Removing a direct user grant does not remove role-derived coverage. There is no negative-grant representation for Everyone-except-one or role exceptions. Do not promise effective exclusion from a raw replacement.

Verify and report

If another grant change prevents the write, report that no change was made and retry only after a fresh policy read and renewed confirmation.

After any write, call get_risk_policy again for the same project and policy. Verify the intended audience and preservation of unrelated policy fields. A receipt replay proves a historical commit, not current state. On a version conflict, read again and obtain renewed confirmation before using a new key; never retry with a different target.

Report only the supported outcome: the committed audience change and whether the fresh read confirms it. Do not claim a permanent exemption, retroactive removal of findings, or immunity from other policies or future audience changes. If verification fails, distinguish the committed result from incomplete current-state verification.

© speakeasy-api, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in server/internal/plugins/platform_mcp_skills/manage-risk-policy-audience of speakeasy-api/gram.

Open the folder on GitHubat commit b4c4904

Compare with similar skills

Manage Risk Policy Audience next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Manage Risk Policy Audience compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Manage Risk Policy Audience this skillspeakeasy-api/gram273—~1.6kAutomated safety check: PassAGPL-3.0
MCP Server Builderanthropics/skills180k63 repos~2.3kAutomated safety check: PassApache-2.0
MCP Server BuildershareAI-lab/learn-claude-code78k4 repos~1.2kAutomated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official38k11 repos~3.1kAutomated safety check: PassApache-2.0
Crush Configurationcharmbracelet/crush29k—~3.7kAutomated safety check: PassCustom licence
Context Mode Output Sandboxmksglu/context-mode26k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 63 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • MCP Server Builder

    shareAI-lab/learn-claude-code

    Walks through building MCP servers in Python or TypeScript that expose tools, resources and prompts to Claude, with templates, registration and testing.

    78k GitHub starsUsed in 4 repos~1.2k tokens
    Agent WorkflowsAuto-check passed
  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    38k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Crush Configuration

    charmbracelet/crush

    Explains how to configure the Crush coding agent with crushrc or crush.json, covering providers, models, LSPs, MCP servers, hooks, permissions and config precedence.

    29k GitHub stars~3.7k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Context Mode Output Sandbox

    mksglu/context-mode

    Routes large command, file, API and browser output through context-mode tools so only the needed result enters the agent's context, instead of dumping it via Bash.

    26k GitHub stars~4.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed

More from speakeasy-api/gram

All 40 skills in this repo
  • Gram Playwright CLI

    speakeasy-api/gram

    A skill your agent uses when automating the Speakeasy dashboard in a browser, capturing screenshots, inspecting pages.

    273 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Transactional Email

    speakeasy-api/gram

    A skill your agent uses when adding, changing, restyling, reviewing, validating, or previewing a Speakeasy transactional email, in Go or in LMX/MJML — a template<name.go, a TemplateKey constant, a…

    273 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed
  • Admin Shadcn

    speakeasy-api/gram

    A skill your agent uses when adding, changing, or styling UI in client/admin (the Speakeasy admin dashboard) that touches shadcn/ui — a button, dialog, table, sidebar, badge, select, tabs, tooltip…

    273 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • A skill your agent uses when adding, editing, reviewing, testing, or locating a reviewed skill distributed with the Platform MCP plugin; triggers include "Platform MCP skill", "platformmcpskills"…

    273 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Clickhouse

    speakeasy-api/gram

    A skill your agent uses when changing or reviewing Speakeasy ClickHouse schemas, migrations, queries, inserts, access principals, bootstrap SQL, Cloud compatibility, partial migration failures, or…

    273 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Feature Flag

    speakeasy-api/gram

    A skill your agent uses when gating a feature behind a flag, dogfooding or gradually rolling out a change, choosing between productfeatures and PostHog feature flags, adding or checking a product…

    273 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Manage Risk Policy Audience

What does Manage Risk Policy Audience do?

Inspect and safely change who a risk policy targets in an explicit Speakeasy AI Control Plane project, with confirmed administrator audience changes and clear refusals for unavailable self-exclusion. Manage Risk Policy Audience is an agent skill from speakeasy-api/gram. Inspect and safely change who a risk policy targets in an explicit Speakeasy AI Control Plane project, with confirmed administrator audience changes and clear refusals for unavailable self-exclusion.

When should I use Manage Risk Policy Audience?

Manage Risk Policy Audience fits situations like: tasks that involve MCP servers.

How do I install Manage Risk Policy Audience in Claude Code?

Run `npx skills add speakeasy-api/gram --skill manage-risk-policy-audience -a claude-code`. Or copy the skill folder (server/internal/plugins/platform_mcp_skills/manage-risk-policy-audience in speakeasy-api/gram) into .claude/skills/manage-risk-policy-audience in your project. Claude Code loads it when a task matches its description.

How do I install Manage Risk Policy Audience in Codex?

Run `npx skills add speakeasy-api/gram --skill manage-risk-policy-audience -a codex`. Or copy the skill folder (server/internal/plugins/platform_mcp_skills/manage-risk-policy-audience in speakeasy-api/gram) into .agents/skills/manage-risk-policy-audience in your project. Codex loads it when a task matches its description.

Can I use Manage Risk Policy Audience in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add speakeasy-api/gram --skill manage-risk-policy-audience -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/manage-risk-policy-audience, .gemini/skills/manage-risk-policy-audience, .github/skills/manage-risk-policy-audience and .opencode/skills/manage-risk-policy-audience in your project.

What does Manage Risk Policy Audience need to run?

SKILL.md names no scripts, command-line tools or credentials: Manage Risk Policy Audience is instructions for the agent only.

Does Manage Risk Policy Audience access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Manage Risk Policy Audience safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Manage Risk Policy Audience use?

Manage Risk Policy Audience is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Manage Risk Policy Audience use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Manage Risk Policy Audience?

Skills that share tags, products or a category with Manage Risk Policy Audience: MCP Server Builder (anthropics/skills, 180k stars), MCP Server Builder (shareAI-lab/learn-claude-code, 78k stars), MCP Integration for Plugins (anthropics/claude-plugins-official, 38k stars) and Crush Configuration (charmbracelet/crush, 29k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Manage Risk Policy Audience?

speakeasy-api (a GitHub organization) maintains it in speakeasy-api/gram, which has 273 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 10, 2026.

Source: speakeasy-api/gram on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.