Agents Connect
aws/agent-toolkit-for-aws
A skill your agent uses when connecting your agent to external APIs, tools, or services via Gateway, or restricting tool access with Cedar policies.
Add or retrofit Tenuo authorization for AI-agent tools and effects.
$ npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tenuo-ai/tenuo tenuo-agent-authorization --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tenuo-ai/tenuo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tenuo-agent-authorization .claude/skills/tenuo-agent-authorization && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "tenuo-agent-authorization" agent skill from https://github.com/tenuo-ai/tenuo/tree/main/skills/tenuo-agent-authorization into .claude/skills/tenuo-agent-authorization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tenuo-agent-authorization", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tenuo-ai/tenuo/tree/main/skills/tenuo-agent-authorizationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tenuo-ai/tenuo tenuo-agent-authorization --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tenuo-ai/tenuo.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/tenuo-agent-authorization .agents/skills/tenuo-agent-authorization && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "tenuo-agent-authorization" agent skill from https://github.com/tenuo-ai/tenuo/tree/main/skills/tenuo-agent-authorization into .agents/skills/tenuo-agent-authorization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tenuo-agent-authorization", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tenuo-ai/tenuo tenuo-agent-authorization --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tenuo-ai/tenuo.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/tenuo-agent-authorization .cursor/skills/tenuo-agent-authorization && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "tenuo-agent-authorization" agent skill from https://github.com/tenuo-ai/tenuo/tree/main/skills/tenuo-agent-authorization into .cursor/skills/tenuo-agent-authorization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tenuo-agent-authorization", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tenuo-ai/tenuo.git --path skills/tenuo-agent-authorization--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tenuo-ai/tenuo tenuo-agent-authorization --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tenuo-ai/tenuo.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/tenuo-agent-authorization .gemini/skills/tenuo-agent-authorization && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "tenuo-agent-authorization" agent skill from https://github.com/tenuo-ai/tenuo/tree/main/skills/tenuo-agent-authorization into .gemini/skills/tenuo-agent-authorization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tenuo-agent-authorization", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tenuo-ai/tenuo tenuo-agent-authorizationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tenuo-ai/tenuo.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/tenuo-agent-authorization .github/skills/tenuo-agent-authorization && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "tenuo-agent-authorization" agent skill from https://github.com/tenuo-ai/tenuo/tree/main/skills/tenuo-agent-authorization into .github/skills/tenuo-agent-authorization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tenuo-agent-authorization", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tenuo-ai/tenuo tenuo-agent-authorization --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tenuo-ai/tenuo.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/tenuo-agent-authorization .opencode/skills/tenuo-agent-authorization && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "tenuo-agent-authorization" agent skill from https://github.com/tenuo-ai/tenuo/tree/main/skills/tenuo-agent-authorization into .opencode/skills/tenuo-agent-authorization/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "tenuo-agent-authorization", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
tenuo-agent-authorizationAdd or retrofit Tenuo authorization for AI-agent tools and effects.
Tenuo Agent Authorization is an agent skill from tenuo-ai/tenuo. Add or retrofit Tenuo authorization for AI-agent tools and effects. Use when implementing Tenuo, protecting an MCP or framework tool, choosing a gateway, sidecar, or embedded enforcement boundary, or testing that an agent cannot exceed delegated authority. Do not use for a review-only audit of an existing warrant.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts and reference files (for example `references/architectural-patterns.md`, `references/common-footguns.md` and `references/framework-integration.md`).
It sits in Backend & APIs, covering Authorization and RBAC and MCP servers. It works with Model Context Protocol. The repository describes itself as: Task-scoped authorization for AI agents. Cryptographic warrants constrain tools and arguments, prevent privilege escalation at every delegation hop, and produce signed evidence… The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c8f2bd0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Tenuo Agent Authorization loads about 2.3k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 85 tokens; SKILL.md has 1,166 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from tenuo-ai/tenuo at commit c8f2bd0, republished under its Apache-2.0 licence (© tenuo-ai). 1,166 words, ~2,256 tokens.
.claude/skills/tenuo-agent-authorization/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.Implement the smallest end-to-end integration that enforces approved authority at the component performing the effect. Prompts and instructions coordinate an agent; they are not authorization.
Identify the action-selecting process, the effecting component, every direct or fallback route to the effect, and who issues, holds, and verifies authority.
Tier 1 rejects out-of-policy calls in trusted code, including calls a manipulated prompt induces. Tier 2 keeps those checks and adds signed, holder-bound authority and delegation that can only narrow, which an independent verifier can check. Describe a requested local-policy integration by those checks, as enforcement. Read Integration trust levels. When the agent can skip the guard, identify the effecting component outside the agent's control where enforcement must run. Do not invent a warrant-issuance requirement for a local-policy request.
If an original unguarded application route remains, close it or report the integration as incomplete; a residual-risk disclaimer does not make that route protected. Read Architectural patterns only when the enforcement location is undecided or the task changes deployment topology.
For an MCP integration, run scripts/inspect_mcp_project.py --root ., confirm its findings in source, then read End-to-end MCP integration. Do not add a verifier in isolation: identify how legitimate callers receive holder-bound warrants and send proof with each protected call. If issuance is missing, observation and policy discovery may still be useful, but report that enforcement is incomplete.
For native function, shell, computer-use, or framework tools, run scripts/inspect_native_tools.py --root ., confirm its findings in source, then read Native agent tool integration. Determine whether the framework hook actually runs for every selected tool type; when it does not, enforce in the handler or downstream service that owns the effect.
main only for an unreleased checkout or as an explicit fallback. Never silently mix main examples with a released dependency.Read exactly the applicable language reference:
tenuo and its framework adapters.@tenuo/core or @tenuo/mcp.tenuo crate or a Rust enforcement service.For MCP, also read End-to-end MCP integration. It defines the issuer-to-effect completion gate and reporting levels shared across languages.
For native tools, also read Native agent tool integration. Ordinary application functions count as native tools even without a framework. It covers function-tool dispatch, built-in execution tools, handoffs, and framework hook bypasses.
Read Framework-neutral integration only when no official adapter or verified recipe covers the framework. The linked examples are pinned to the release represented by this skill; use another version's installed API or matching tag rather than adapting them by guesswork.
Delegate only when required. Bind the child to its recipient, use the shortest useful TTL, narrow authority when the work is narrower, and make leaf authority terminal. Equal delegation can be valid when it remains within the parent envelope.
API examples belong in normal SDK example directories where CI exercises them. Do not copy Python, TypeScript, or Rust API snippets into this skill.
Read Common footguns before finalizing. Read Security model and limits when claiming replay resistance, exactly-once effects, revocation, execution evidence, or complete mediation.
Do not finish until:
Instrument a fake effect with an invocation counter or durable test record. Prove one allowed invocation and zero invocations for missing authority, untrusted issuer, wrong holder or PoP, expiry, wrong capability, each important argument boundary, wider child delegation, and the original bypass route. Test replay only when one-use behavior is claimed.
Exercise denials at the receiving boundary, not only in the caller's presentation helper. Check the denial reason: setup errors, missing signer keys, and malformed test fixtures do not prove policy enforcement. For delegation, first prove a valid narrower child works with the correct holder key, then change only the envelope to prove widening is rejected. For compiled APIs, a bypass test must actually attempt the forbidden access and expect compilation failure; a successful test importing only the new API proves nothing about the old route.
Run the narrow tests, then the relevant package suite and type checker. A thrown error is insufficient evidence if the effect may already have happened.
State where verification occurs, what effect it mediates, trusted roots, holder transport, capability and argument envelope, TTL/delegation/replay behavior, tests run, and remaining bypasses or operational dependencies.
Prefer a bounded statement:
Calls reaching this effect boundary execute only after the configured Tenuo verifier accepts the warrant, holder proof, capability, and constrained arguments.
Do not claim that Tenuo proves human intent, covers every application action, or proves that an authorized downstream effect completed.
Before reporting any integration, read Integration trust levels and name its evidenced label: incomplete integration, observation only, development loop, or production boundary. Test-only minting does not establish an application issuance path. Report an in-process guardrail separately when it can be bypassed by the agent process.
© tenuo-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 13 other files (scripts, references) in skills/tenuo-agent-authorization of tenuo-ai/tenuo.
Open the folder on GitHubat commit c8f2bd0
Tenuo Agent Authorization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Tenuo Agent Authorization this skilltenuo-ai/tenuo | 103 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Agents Connectaws/agent-toolkit-for-aws | 2.8k | — | ~7.4k | Automated safety check: Notes | Apache-2.0 | |
| Notion MCP Skillholon-run/uxc | 116 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Flexport Enterprise Rbacjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Page Deliverinfometa/workbuddyskills | 348 | — | ~3.9k | Automated safety check: Pass | None | |
| Fastmcp Serverdavila7/claude-code-templates | 33k | — | ~1.9k | Automated safety check: Pass | MIT |
aws/agent-toolkit-for-aws
A skill your agent uses when connecting your agent to external APIs, tools, or services via Gateway, or restricting tool access with Cedar policies.
holon-run/uxc
Operate Notion workspace content through Notion MCP using the UXC CLI, including search, fetch, users/teams lookup, page/database creation and updates, and comments.
jeremylongshore/tons-of-skills-marketplace
Map Flexport endpoint-scoped OAuth credentials and MCP role permissions to approved workloads.
infometa/workbuddyskills
A skill your agent uses for page-deliver application code generation, page creation, publishing, deployment, going live, MCP enablement, or runtime access/control of deployed HRClaw applications.
davila7/claude-code-templates
Complete guide for building MCP servers with FastMCP 3.0 - tools, resources, authentication, providers, middleware, and deployment.
butterbase-ai/butterbase-skills
A skill your agent uses when designing, deploying, or debugging a Butterbase Agent (declarative LLM/tool graph), registering an MCP server for tool use, or wiring access controls and rate limits.
tenuo-ai/tenuo
Create or delegate Tenuo warrants from natural-language authority requirements.
tenuo-ai/tenuo
Audit, explain, or compare existing Tenuo warrants and delegation chains.
tenuo-ai/tenuo
Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority.
Works with
Add or retrofit Tenuo authorization for AI-agent tools and effects. Tenuo Agent Authorization is an agent skill from tenuo-ai/tenuo. Add or retrofit Tenuo authorization for AI-agent tools and effects.
Tenuo Agent Authorization fits situations like: implementing Tenuo; protecting an MCP; choosing a gateway; embedded enforcement boundary.
Run `npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a claude-code`. Or copy the skill folder (skills/tenuo-agent-authorization in tenuo-ai/tenuo) into .claude/skills/tenuo-agent-authorization in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a codex`. Or copy the skill folder (skills/tenuo-agent-authorization in tenuo-ai/tenuo) into .agents/skills/tenuo-agent-authorization in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tenuo-ai/tenuo --skill tenuo-agent-authorization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tenuo-agent-authorization, .gemini/skills/tenuo-agent-authorization, .github/skills/tenuo-agent-authorization and .opencode/skills/tenuo-agent-authorization in your project.
Going by SKILL.md and its folder, Tenuo Agent Authorization needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Tenuo Agent Authorization is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Tenuo Agent Authorization: Agents Connect (aws/agent-toolkit-for-aws, 2.8k stars), Notion MCP Skill (holon-run/uxc, 116 stars), Flexport Enterprise Rbac (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Page Deliver (infometa/workbuddyskills, 348 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tenuo-ai (a GitHub organization) maintains it in tenuo-ai/tenuo, which has 103 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.
Source: tenuo-ai/tenuo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.