Agent skill

Tenuo Agent Authorization

by tenuo-ai in tenuo-ai/tenuo

Add or retrofit Tenuo authorization for AI-agent tools and effects.

Apache-2.0Auto-check passedBackend & APIs

Install Tenuo Agent Authorization

skills CLI
$ npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tenuo-ai/tenuo tenuo-agent-authorization --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tenuo-ai/tenuo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tenuo-agent-authorization .claude/skills/tenuo-agent-authorization && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tenuo-agent-authorization
GitHub stars
103
Token cost
~2.3k tokens
SKILL.md length
1,166 words
Files
14 (incl. scripts, references)
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add or retrofit Tenuo authorization for AI-agent tools and effects.

  • Works in 5 steps: Read manifests and lockfiles to… → Inspect that installed package's README,… → If those artifacts are insufficient,… → …
  • Implementing Tenuo
  • SKILL.md covers Locate the boundary, Resolve the actual API, Implement one vertical slice and Pass the completion gate, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Tenuo Agent Authorization is an agent skill from tenuo-ai/tenuo. Add or retrofit Tenuo authorization for AI-agent tools and effects. Use when implementing Tenuo, protecting an MCP or framework tool, choosing a gateway, sidecar, or embedded enforcement boundary, or testing that an agent cannot exceed delegated authority. Do not use for a review-only audit of an existing warrant.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts and reference files (for example `references/architectural-patterns.md`, `references/common-footguns.md` and `references/framework-integration.md`).

It sits in Backend & APIs, covering Authorization and RBAC and MCP servers. It works with Model Context Protocol. The repository describes itself as: Task-scoped authorization for AI agents. Cryptographic warrants constrain tools and arguments, prevent privilege escalation at every delegation hop, and produce signed evidence… The licence is Apache-2.0.

When your agent uses it

  • Implementing Tenuo
  • Protecting an MCP
  • Choosing a gateway
  • Embedded enforcement boundary

Example prompts

  • “/tenuo-agent-authorization”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read manifests and lockfiles to determine the resolved Tenuo version.
  2. Inspect that installed package's README, declarations, importable source, and packaged examples. Not every package ships examples.
  3. If those artifacts are insufficient, inspect an immutable repository release tag whose package manifest matches the resolved version.
  4. Use main only for an unreleased checkout or as an explicit fallback. Never silently mix main examples with a released dependency.
  5. Find existing wrappers, authority transport, trust-root configuration, identity, secrets, logs, and effect handlers before editing.

What it can do on your machine

Read from SKILL.md and the folder at commit c8f2bd0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tenuo Agent Authorization loads about 2.3k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 1,166 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from tenuo-ai/tenuo at commit c8f2bd0, republished under its Apache-2.0 licence (© tenuo-ai). 1,166 words, ~2,256 tokens.

Download SKILL.mdSave it as .claude/skills/tenuo-agent-authorization/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
tenuo-agent-authorization
description
Add or retrofit Tenuo authorization for AI-agent tools and effects. Use when implementing Tenuo, protecting an MCP or framework tool, choosing a gateway, sidecar, or embedded enforcement boundary, or testing that an agent cannot exceed delegated authority. Do not use for a review-only audit of an existing warrant.

Tenuo Agent Authorization

Implement the smallest end-to-end integration that enforces approved authority at the component performing the effect. Prompts and instructions coordinate an agent; they are not authorization.

Locate the boundary

Identify the action-selecting process, the effecting component, every direct or fallback route to the effect, and who issues, holds, and verifies authority.

  • An in-process guardrail limits calls reaching a wrapper. It is not an independent boundary when the agent process can bypass it or reach the resource directly.
  • Effect-boundary enforcement verifies in a server, gateway, sidecar, worker, or tool host outside the agent's authority before performing the effect.

Tier 1 rejects out-of-policy calls in trusted code, including calls a manipulated prompt induces. Tier 2 keeps those checks and adds signed, holder-bound authority and delegation that can only narrow, which an independent verifier can check. Describe a requested local-policy integration by those checks, as enforcement. Read Integration trust levels. When the agent can skip the guard, identify the effecting component outside the agent's control where enforcement must run. Do not invent a warrant-issuance requirement for a local-policy request.

If an original unguarded application route remains, close it or report the integration as incomplete; a residual-risk disclaimer does not make that route protected. Read Architectural patterns only when the enforcement location is undecided or the task changes deployment topology.

For an MCP integration, run scripts/inspect_mcp_project.py --root ., confirm its findings in source, then read End-to-end MCP integration. Do not add a verifier in isolation: identify how legitimate callers receive holder-bound warrants and send proof with each protected call. If issuance is missing, observation and policy discovery may still be useful, but report that enforcement is incomplete.

For native function, shell, computer-use, or framework tools, run scripts/inspect_native_tools.py --root ., confirm its findings in source, then read Native agent tool integration. Determine whether the framework hook actually runs for every selected tool type; when it does not, enforce in the handler or downstream service that owns the effect.

Resolve the actual API

  1. Read manifests and lockfiles to determine the resolved Tenuo version.
  2. Inspect that installed package's README, declarations, importable source, and packaged examples. Not every package ships examples.
  3. If those artifacts are insufficient, inspect an immutable repository release tag whose package manifest matches the resolved version.
  4. Use main only for an unreleased checkout or as an explicit fallback. Never silently mix main examples with a released dependency.
  5. Find existing wrappers, authority transport, trust-root configuration, identity, secrets, logs, and effect handlers before editing.

Read exactly the applicable language reference:

For MCP, also read End-to-end MCP integration. It defines the issuer-to-effect completion gate and reporting levels shared across languages.

For native tools, also read Native agent tool integration. Ordinary application functions count as native tools even without a framework. It covers function-tool dispatch, built-in execution tools, handoffs, and framework hook bypasses.

Read Framework-neutral integration only when no official adapter or verified recipe covers the framework. The linked examples are pinned to the release represented by this skill; use another version's installed API or matching tag rather than adapting them by guesswork.

Implement one vertical slice

  1. Name a capability for the effect and constrain every argument that materially changes it.
  2. Issue short-lived authority to the holder's public key. The holder creates proof; the verifier-facing API accepts a presentation or public transport data, never a private signing key.
  3. Configure trusted roots, verification time, and local policy ceilings independently of request data. A test clock belongs in private test code or trusted verifier construction, not a caller-selectable execution argument.
  4. Verify immediately before the effect and execute with the returned or identically normalized verified arguments. Reject values that cannot be represented losslessly in both authorization and effect types; unchecked numeric casts can authorize a different value than the one executed.
  5. Fail closed for missing, malformed, expired, untrusted, wrong-holder, wrong-capability, or constraint-violating authority.
  6. Make the effect client private to or owned by the enforcement component, or guard every effecting method.

Delegate only when required. Bind the child to its recipient, use the shortest useful TTL, narrow authority when the work is narrower, and make leaf authority terminal. Equal delegation can be valid when it remains within the parent envelope.

API examples belong in normal SDK example directories where CI exercises them. Do not copy Python, TypeScript, or Rust API snippets into this skill.

Show full SKILL.md (419 more words)Show less

Pass the completion gate

Read Common footguns before finalizing. Read Security model and limits when claiming replay resistance, exactly-once effects, revocation, execution evidence, or complete mediation.

Do not finish until:

  • a test attempts the original direct route at its original module/import and method, not just a top-level re-export, and proves it is inaccessible or produces zero effects; removing an export or adding an underscore is not sufficient if the callable still works;
  • the verifier does not receive or use a holder or issuer private key to manufacture caller proof;
  • verification covers the final material arguments and the effect uses the verified values;
  • missing and invalid authority fail before the effect;
  • development, observation, shadow, optional-warrant, and unknown-argument modes are disabled or reported as weaker modes;
  • replay, idempotency, revocation, approvals, receipts, and execution evidence are not conflated with authorization.

Prove behavior

Instrument a fake effect with an invocation counter or durable test record. Prove one allowed invocation and zero invocations for missing authority, untrusted issuer, wrong holder or PoP, expiry, wrong capability, each important argument boundary, wider child delegation, and the original bypass route. Test replay only when one-use behavior is claimed.

Exercise denials at the receiving boundary, not only in the caller's presentation helper. Check the denial reason: setup errors, missing signer keys, and malformed test fixtures do not prove policy enforcement. For delegation, first prove a valid narrower child works with the correct holder key, then change only the envelope to prove widening is rejected. For compiled APIs, a bypass test must actually attempt the forbidden access and expect compilation failure; a successful test importing only the new API proves nothing about the old route.

Run the narrow tests, then the relevant package suite and type checker. A thrown error is insufficient evidence if the effect may already have happened.

Report the guarantee

State where verification occurs, what effect it mediates, trusted roots, holder transport, capability and argument envelope, TTL/delegation/replay behavior, tests run, and remaining bypasses or operational dependencies.

Prefer a bounded statement:

Calls reaching this effect boundary execute only after the configured Tenuo verifier accepts the warrant, holder proof, capability, and constrained arguments.

Do not claim that Tenuo proves human intent, covers every application action, or proves that an authorized downstream effect completed.

Before reporting any integration, read Integration trust levels and name its evidenced label: incomplete integration, observation only, development loop, or production boundary. Test-only minting does not establish an application issuance path. Report an in-process guardrail separately when it can be bypassed by the agent process.

© tenuo-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (scripts, references) in skills/tenuo-agent-authorization of tenuo-ai/tenuo.

  • SKILL.md
  • references/architectural-patterns.md
  • references/common-footguns.md
  • references/framework-integration.md
  • references/mcp.md
  • references/native-tools.md
  • references/python.md
  • references/rust.md
  • references/security-model.md
  • references/trust-levels.md
  • references/typescript.md
  • release.json
  • scripts/inspect_mcp_project.py
  • scripts/inspect_native_tools.py

Open the folder on GitHubat commit c8f2bd0

Compare with similar skills

Tenuo Agent Authorization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tenuo Agent Authorization compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tenuo Agent Authorization this skilltenuo-ai/tenuo103—~2.3kAutomated safety check: PassApache-2.0
Agents Connectaws/agent-toolkit-for-aws2.8k—~7.4kAutomated safety check: NotesApache-2.0
Notion MCP Skillholon-run/uxc116—~1.2kAutomated safety check: PassMIT
Flexport Enterprise Rbacjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Page Deliverinfometa/workbuddyskills348—~3.9kAutomated safety check: PassNone
Fastmcp Serverdavila7/claude-code-templates33k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Agents Connect

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when connecting your agent to external APIs, tools, or services via Gateway, or restricting tool access with Cedar policies.

    2.8k GitHub stars~7.4k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Notion MCP Skill

    holon-run/uxc

    Operate Notion workspace content through Notion MCP using the UXC CLI, including search, fetch, users/teams lookup, page/database creation and updates, and comments.

    116 GitHub stars~1.2k tokensUpdated 25 days ago
    Backend & APIsAuto-check passed
  • Flexport Enterprise Rbac

    jeremylongshore/tons-of-skills-marketplace

    Map Flexport endpoint-scoped OAuth credentials and MCP role permissions to approved workloads.

    2.8k GitHub stars~1.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Page Deliver

    infometa/workbuddyskills

    A skill your agent uses for page-deliver application code generation, page creation, publishing, deployment, going live, MCP enablement, or runtime access/control of deployed HRClaw applications.

    348 GitHub stars~3.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Fastmcp Server

    davila7/claude-code-templates

    Complete guide for building MCP servers with FastMCP 3.0 - tools, resources, authentication, providers, middleware, and deployment.

    33k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Agents

    butterbase-ai/butterbase-skills

    A skill your agent uses when designing, deploying, or debugging a Butterbase Agent (declarative LLM/tool graph), registering an MCP server for tool use, or wiring access controls and rate limits.

    534 GitHub stars~1.8k tokensUpdated 4 days ago
    Agent WorkflowsAuto-check passed

More from tenuo-ai/tenuo

  • Tenuo Warrant

    tenuo-ai/tenuo

    Create or delegate Tenuo warrants from natural-language authority requirements.

    103 GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Tenuo Audit

    tenuo-ai/tenuo

    Audit, explain, or compare existing Tenuo warrants and delegation chains.

    103 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Tenuo Denial Triage

    tenuo-ai/tenuo

    Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority.

    103 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Tenuo Agent Authorization

What does Tenuo Agent Authorization do?

Add or retrofit Tenuo authorization for AI-agent tools and effects. Tenuo Agent Authorization is an agent skill from tenuo-ai/tenuo. Add or retrofit Tenuo authorization for AI-agent tools and effects.

When should I use Tenuo Agent Authorization?

Tenuo Agent Authorization fits situations like: implementing Tenuo; protecting an MCP; choosing a gateway; embedded enforcement boundary.

How do I install Tenuo Agent Authorization in Claude Code?

Run `npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a claude-code`. Or copy the skill folder (skills/tenuo-agent-authorization in tenuo-ai/tenuo) into .claude/skills/tenuo-agent-authorization in your project. Claude Code loads it when a task matches its description.

How do I install Tenuo Agent Authorization in Codex?

Run `npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a codex`. Or copy the skill folder (skills/tenuo-agent-authorization in tenuo-ai/tenuo) into .agents/skills/tenuo-agent-authorization in your project. Codex loads it when a task matches its description.

Can I use Tenuo Agent Authorization in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tenuo-agent-authorization, .gemini/skills/tenuo-agent-authorization, .github/skills/tenuo-agent-authorization and .opencode/skills/tenuo-agent-authorization in your project.

What does Tenuo Agent Authorization need to run?

Going by SKILL.md and its folder, Tenuo Agent Authorization needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Tenuo Agent Authorization access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Tenuo Agent Authorization safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Tenuo Agent Authorization use?

Tenuo Agent Authorization is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tenuo Agent Authorization use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Tenuo Agent Authorization?

Skills that share tags, products or a category with Tenuo Agent Authorization: Agents Connect (aws/agent-toolkit-for-aws, 2.8k stars), Notion MCP Skill (holon-run/uxc, 116 stars), Flexport Enterprise Rbac (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Page Deliver (infometa/workbuddyskills, 348 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tenuo Agent Authorization?

tenuo-ai (a GitHub organization) maintains it in tenuo-ai/tenuo, which has 103 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: tenuo-ai/tenuo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.