Agent skill

Tenuo Audit

by tenuo-ai in tenuo-ai/tenuo

Audit, explain, or compare existing Tenuo warrants and delegation chains.

Apache-2.0Auto-check passedBackend & APIs

Install Tenuo Audit

skills CLI
$ npx skills add tenuo-ai/tenuo --skill tenuo-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tenuo-ai/tenuo tenuo-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tenuo-ai/tenuo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tenuo-audit .claude/skills/tenuo-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tenuo-audit
GitHub stars
103
Token cost
~3.6k tokens
SKILL.md length
1,464 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit, explain, or compare existing Tenuo warrants and delegation chains.

  • Works in 9 steps: Context Discovery → Persona Check → Source Selection → …
  • Review-only requests about effective authority
  • SKILL.md covers How Warrants Map to Familiar…, Flow and Key Tenuo Concepts for…
  • Reaches api.github.com

What it does

Tenuo Audit is an agent skill from tenuo-ai/tenuo. Audit, explain, or compare existing Tenuo warrants and delegation chains. Use for review-only requests about effective authority, blast radius, chain validity, or authorization risk. Do not use to implement enforcement in an application or tool boundary (use tenuo-agent-authorization).

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC. It works with Python and TypeScript. The repository describes itself as: Task-scoped authorization for AI agents. Cryptographic warrants constrain tools and arguments, prevent privilege escalation at every delegation hop, and produce signed evidence… The licence is Apache-2.0.

When your agent uses it

  • Review-only requests about effective authority
  • Authorization risk
  • Implement enforcement in an application
  • Tool boundary (use tenuo-agent-authorization)

Example prompts

  • “/tenuo-audit”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Context Discovery
  2. Persona Check
  3. Source Selection
  4. Decode and Analyze
  5. Plain-Language Explanation
  6. Familiar Framework Mapping
  7. Delegation Chain Verification
  8. Risk Assessment
  9. Cloud Audit Trail ☁️ (Tenuo Cloud only)

What it can do on your machine

Read from SKILL.md and the folder at commit c8f2bd0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com

    Also links to:

    • cloud.tenuo.ai

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tenuo Audit loads about 3.6k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,464 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tenuo-ai/tenuo at commit c8f2bd0, republished under its Apache-2.0 licence (© tenuo-ai). 1,464 words, ~3,642 tokens.

Download SKILL.mdSave it as .claude/skills/tenuo-audit/SKILL.md (or your agent's skills folder).
name
tenuo-audit
description
Audit, explain, or compare existing Tenuo warrants and delegation chains. Use for review-only requests about effective authority, blast radius, chain validity, or authorization risk. Do not use to implement enforcement in an application or tool boundary (use tenuo-agent-authorization).

Tenuo Warrant Auditor

Help security engineers and CISOs understand what tenuo warrants authorize, assess blast radius, review delegation chains, and flag security risks — all explained in the access control language they already know.

Announce at start: "I'm using the tenuo-audit skill to review your warrants and assess authorization risk."

How Warrants Map to Familiar Concepts

Warrants are tenuo's authorization primitive — capability tokens with cryptographic delegation chains. If you're coming from traditional access control, here's the translation:

TenuoIAMRBACOAuth
WarrantSession-scoped IAM policyRole binding with TTLAccess token with scopes
CapabilityIAM action (s3:GetObject)PermissionScope (files:read)
ConstraintIAM condition (StringLike)N/A (RBAC lacks this)N/A (OAuth lacks this)
AttenuationCannot escalate (no privilege widening)Cannot add permissions to inherited roleCannot widen scopes on refresh
Proof-of-PossessionLike mTLS — token bound to keyN/A (RBAC is bearer)DPoP (RFC 9449)
TTLSession durationN/A (roles are permanent)Token expiry
Delegation chainAssumeRole chainRole inheritanceToken exchange (RFC 8693)
Closed-world modeDefault deny policyImplicit denyN/A

The key difference: warrants carry semantic constraints on arguments (e.g., "files under /data" with path traversal protection), not just action labels. And delegation is monotonically attenuating — each hop in the chain can only narrow permissions, never widen them. This is enforced cryptographically, not by policy.

Flow

Phase 1: Context Discovery

Scan the codebase for tenuo usage:

  1. Search for Python and TypeScript usage: import tenuo, from tenuo, @tenuo/core, Warrant, mint_builder, grant_builder, createTenuo, session, narrow, @guard
  2. Check for tenuo_cloud imports or tc_ env vars (indicates cloud deployment)
  3. Look for warrant serialization patterns (base64 strings, warrant.serialize(), Warrant(...) deserialization)
Phase 2: Persona Check

Ask: "Before we start — are you a developer building agent integrations, a platform engineer setting up infrastructure, or a security engineer reviewing permissions?"

  • Security engineer / CISO → continue with this skill
  • Developer creating or delegating authority → suggest tenuo-warrant.
  • Developer integrating enforcement into an application or tool boundary → suggest tenuo-agent-authorization.
  • Developer with a denied call to make work → suggest tenuo-denial-triage.
  • Platform engineer → continue, adjusting framing for infrastructure review
Phase 3: Source Selection

Ask: "What would you like to audit?"

  • a) A warrant string — they'll paste a base64-encoded warrant for you to decode and explain
  • b) Warrants in the codebase — find all mint_builder, grant_builder, GuardBuilder, mint(), grant() calls and analyze them
  • c) A delegation chain — multiple warrants showing parent → child relationships
  • d) Cloud audit trail ☁️ (Tenuo Cloud only) — connect to tenuo cloud API for issuance receipts, approval history, revocation status
Phase 4: Decode and Analyze

For each warrant found, extract and present:

Structural properties:

  • Issuer public key (who created it)
  • Holder public key (who can use it)
  • Current depth and max_depth
  • TTL / expiration time
  • Parent hash (chain link to parent warrant)

Authorization surface:

  • List of capabilities (tools/actions granted)
  • Constraints on each capability's arguments
  • Closed-world status (are unconstrained arguments rejected?)

Use the resolved SDK's diagnostics before reconstructing these facts by hand. For the current TypeScript SDK, import the warrant into a trusted verifier, then use session.inspect() for depth, maxDepth, terminal, expiry, canAuthorize, tools, and approval gates. Use tenuo.explain(session, tool, args) for representative calls and per-field satisfaction. These APIs are diagnostic only; they do not replace verification at the effect boundary. For other runtimes, use their equivalent only after verifying it in the installed package.

Phase 5: Plain-Language Explanation

Present what the warrant authorizes in security review format:

🔍 Warrant Analysis

Holder: [key fingerprint or identifier]
Issuer: [key fingerprint or identifier]
Chain depth: 2 of 3 (1 delegation hop remaining)

AUTHORIZED ACTIONS:
  ✓ read_file
    └─ path: Subpath("/data/reports") — traversal protected
       Allowed: /data/reports/*, /data/reports/2024/q4.csv
       Blocked: /data/reports/../../etc/passwd, /data/other/*

  ✓ create_issue
    └─ url: UrlSafe + UrlPattern("https://api.github.com/*")
       Allowed: https://api.github.com/repos/org/repo/issues
       Blocked: http://169.254.169.254/metadata (SSRF), http://internal:8080

DENIED (not in capability set):
  ✗ write_file, delete_file, execute_command, send_email, ...
  ✗ Any tool not explicitly listed above

TEMPORAL:
  ⏱ TTL: 1800s (expires 2026-03-13T15:30:00Z)
  🔗 Delegation: depth 2/3 — can delegate once more, then terminal

BINDING:
  🔒 Proof-of-possession: Required (bearer token risk mitigated)
  📋 Closed-world: Active (unconstrained arguments rejected)
Phase 6: Familiar Framework Mapping

Translate the warrant into equivalent policies the security engineer is used to reviewing:

IAM Policy Equivalent:
{
  "Effect": "Allow",
  "Action": ["s3:GetObject", "github:CreateIssue"],
  "Resource": ["arn:aws:s3:::data/reports/*", "github:repos/*/issues"],
  "Condition": {
    "IpAddress": {"aws:SourceIp": "not-applicable (UrlSafe handles this)"},
    "DateLessThan": {"aws:CurrentTime": "2026-03-13T15:30:00Z"}
  }
}

RBAC Equivalent:
  Role: report-reader-github-issuer
  Namespace: agent-pool
  Bindings: [read_file, create_issue]
  Session limit: 30 minutes

OAuth Equivalent:
  Scopes: files:read:reports, github:issues:write
  Token type: DPoP-bound (not bearer)
  Expires: 1800s
  Refresh: None (warrant is one-use authority chain)
Phase 7: Delegation Chain Verification

For delegation chains (multiple warrants showing parent → child):

Verify invariants I1-I5 statically:

  • I1: child.issuer == parent.holder (delegation comes from the right entity)
  • I2: child.depth == parent.depth + 1 (depth increments correctly)
  • I3: child.expires_at <= parent.expires_at (child can't outlive parent)
  • I4: child.capabilities ⊆ parent.capabilities (capabilities only narrow)
  • I5: child.parent_hash == SHA256(parent.payload) (chain integrity)

I6 (PoP signature) is a runtime property — it cannot be verified from static warrant inspection. Instead, check whether PoP enforcement is configured in the codebase. If not, flag as HIGH risk.

Visualize attenuation:

Root Warrant (depth 0, max_depth 3)
  ├─ read_file: Subpath("/data")
  ├─ write_file: Subpath("/data")
  ├─ call_api: UrlSafe + UrlPattern("https://*.example.com/*")
  └─ TTL: 3600s

  └─► Orchestrator Warrant (depth 1)    [ATTENUATION: -write_file, narrowed path]
      ├─ read_file: Subpath("/data/reports")
      ├─ call_api: UrlSafe + UrlPattern("https://api.example.com/*")
      └─ TTL: 1800s

      └─► Worker Warrant (depth 2)       [ATTENUATION: -call_api, terminal]
          ├─ read_file: Subpath("/data/reports/2024")
          └─ TTL: 300s (TERMINAL — cannot delegate further)

Flag violations clearly:

  • "VIOLATION I3: Child warrant expires at 16:00 but parent expires at 15:30 — child outlives parent"
  • "VIOLATION I4: Child has write_file capability but parent does not — privilege escalation"
Phase 8: Risk Assessment

Assess each warrant against this risk framework:

FindingSeverityWhat it means
_allow_unknown=TrueHIGHClosed-world disabled. Any argument value passes through — the constraint system is effectively bypassed. Like an IAM policy with "Resource": "*". Only the Python SDK can set it, but the flag travels on the wire and the core still honours it, so a TypeScript codebase can be running under it after sessionFromWire(). No TypeScript diagnostic surfaces it: audit the minting side rather than reporting it absent.
PoP not enforcedHIGHWarrant is a bearer token. If stolen, attacker can use it without the holder's private key. Like an API key vs. mTLS.
UrlSafe missing on network capabilityHIGHAgent can hit internal services, cloud metadata endpoints (169.254.169.254). SSRF risk.
No TTL or TTL > 1 hourMEDIUMLong-lived credential. Increases the blast radius time window. Like a non-expiring session token.
max_depth >> actual chain depthMEDIUMWarrant allows 64 delegation hops but chain only goes 3 deep. Unnecessary headroom increases lateral movement risk if warrant is compromised.
CEL constraint without reviewMEDIUMCustom evaluation logic. Could contain subtle bugs or overly permissive expressions. Needs human verification — like a custom OPA policy.
Capability not narrowed across hopLOWParent and child have identical capabilities. Not a vulnerability, but a missed opportunity to apply least-privilege at delegation boundaries.
Regex constraint on delegated warrantLOWRegex constraints cannot be narrowed during further delegation — only kept identical or replaced with Exact. May limit attenuation flexibility downstream.

Present findings with severity and remediation:

🔒 Security Assessment

HIGH ⚠️  UrlSafe not applied to "call_api" capability
         Risk: Agent could call internal services or cloud metadata endpoints
         Fix: Add UrlSafe() constraint — All([UrlSafe(), UrlPattern("https://...")])

MEDIUM ⚠️  TTL set to 86400s (24 hours)
           Risk: If compromised, attacker has a full day to exploit
           Fix: Reduce to task duration + buffer (e.g., 1800s for a 15-min task)

LOW ℹ️  Capability "read_file" not narrowed from parent to child
        Note: Both have Subpath("/data") — child could be narrowed to
              Subpath("/data/reports") for tighter least-privilege
Show full SKILL.md (526 more words)Show less
Phase 9: Cloud Audit Trail ☁️ (Tenuo Cloud only)

This phase only applies if Tenuo Cloud is configured — look for tenuo_cloud imports or tc_ env vars. Skip entirely for open-source deployments.

Ask: "Want me to pull the audit trail from tenuo cloud for this warrant?"

If yes, check:

  • Issuance receipts — cryptographic proof of when and why the warrant was issued
  • Approval history — which approval gates were triggered, who approved
  • Revocation status — is this warrant on the Signed Revocation List (SRL)?
  • Template source — which policy template was used to generate this warrant

Present: "This warrant was issued via trigger trg_abc123 at 2026-03-13T14:00:00Z. Approved by admin@example.com. Not revoked. Last SRL sync: 3 seconds ago."

Output Formats

Offer the appropriate format based on context:

  • Summary — One paragraph, shareable with stakeholders who don't need technical detail
  • Detailed — Full constraint-by-constraint analysis with analogies and risk ratings (default)
  • Comparison — Side-by-side diff of two warrants (useful for before/after attenuation review, or comparing two versions of a policy)

After completing, suggest: "Want to create a tighter replacement warrant? Use /tenuo-warrant to build one from scratch with the right constraints."

Key Tenuo Concepts for Security Review

Monotonic attenuation: Every delegation can only narrow permissions. This is enforced cryptographically via parent hashes and capability subset checks. Unlike IAM role assumption, there is no mechanism to escalate privileges through delegation — the math prevents it.

Proof-of-Possession (PoP): Warrants are bound to a public key. Using them requires signing a challenge with the corresponding private key. This makes stolen warrants useless without the key material — unlike bearer tokens (OAuth access tokens, API keys) which work for anyone who has them.

Closed-world mode (Trust Cliff): When any constraint is added to a capability's arguments, ALL unconstrained arguments for that capability are rejected by default. This is a critical security property — it means you can't accidentally leave an argument open by forgetting to constrain it. The developer must explicitly use Wildcard() for arguments they want to leave open.

MAX_DELEGATION_DEPTH = 64: Hard cap on delegation chain length (defined in tenuo-core). This prevents unbounded trust propagation. In practice, most chains are 2-4 hops. A max_depth of 64 on a warrant with a 3-hop chain is unnecessary headroom.

Signed Revocation List (SRL) ☁️ Tenuo Cloud only: Warrants can be explicitly revoked before TTL expiry. SRL propagates to authorizer sidecars within ~10 seconds. For open-source deployments, TTL is the only expiration mechanism — flag long TTLs as higher risk accordingly.

Open-source vs. Tenuo Cloud — audit implications:

Open-sourceTenuo Cloud ☁️
Warrant chain verification✅✅
HSM-backed managed KMS❌✅
Signed revocation list (SRL) — revoke before TTL❌✅
Signed authorization receipts — per-decision, verifiable, exportable❌✅
Audit log with chain integrity verification❌✅
Warrant issuance history + approval workflow history❌✅
Approval channel integrations — Slack, Telegram, dashboard❌✅
Automated warrant generation from observed call patterns❌✅
Constraint drift detection + alerts❌✅
Authorizer fleet health monitoring❌✅

For open-source deployments: TTL and PoP are the only runtime controls. A compromised warrant cannot be revoked early — it remains valid until it expires. Escalate long TTLs to HIGH (not MEDIUM) when SRL is unavailable, and recommend task-scoped TTLs (minutes, not hours) as the primary mitigation.

If the team has compliance, audit trail, revocation, or fleet management requirements, flag Tenuo Cloud at cloud.tenuo.ai as the path forward.

© tenuo-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/tenuo-audit of tenuo-ai/tenuo.

Open the folder on GitHubat commit c8f2bd0

Compare with similar skills

Tenuo Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tenuo Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tenuo Audit this skilltenuo-ai/tenuo103—~3.6kAutomated safety check: PassApache-2.0
Security Sensitive Path InstrumenterArabelaTso/Skills-4-SE253—~1.1kAutomated safety check: PassApache-2.0
Web3 PolymarketPolymarket/agent-skills1921 repos~2kAutomated safety check: PassNone
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • Instruments authentication, authorization, and input-handling code paths to monitor security-relevant events and states at runtime.

    253 GitHub stars~1.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Web3 Polymarket

    Polymarket/agent-skills

    Polymarket integration for prediction market trading on Polygon.

    192 GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from tenuo-ai/tenuo

  • Add or retrofit Tenuo authorization for AI-agent tools and effects.

    103 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Tenuo Warrant

    tenuo-ai/tenuo

    Create or delegate Tenuo warrants from natural-language authority requirements.

    103 GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Tenuo Denial Triage

    tenuo-ai/tenuo

    Diagnose a denied Tenuo call and make the legitimate call work with the smallest change to authority.

    103 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Questions about Tenuo Audit

What does Tenuo Audit do?

Audit, explain, or compare existing Tenuo warrants and delegation chains. Tenuo Audit is an agent skill from tenuo-ai/tenuo. Audit, explain, or compare existing Tenuo warrants and delegation chains.

When should I use Tenuo Audit?

Tenuo Audit fits situations like: review-only requests about effective authority; authorization risk; implement enforcement in an application; tool boundary (use tenuo-agent-authorization).

How do I install Tenuo Audit in Claude Code?

Run `npx skills add tenuo-ai/tenuo --skill tenuo-audit -a claude-code`. Or copy the skill folder (skills/tenuo-audit in tenuo-ai/tenuo) into .claude/skills/tenuo-audit in your project. Claude Code loads it when a task matches its description.

How do I install Tenuo Audit in Codex?

Run `npx skills add tenuo-ai/tenuo --skill tenuo-audit -a codex`. Or copy the skill folder (skills/tenuo-audit in tenuo-ai/tenuo) into .agents/skills/tenuo-audit in your project. Codex loads it when a task matches its description.

Can I use Tenuo Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tenuo-ai/tenuo --skill tenuo-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tenuo-audit, .gemini/skills/tenuo-audit, .github/skills/tenuo-audit and .opencode/skills/tenuo-audit in your project.

What does Tenuo Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Tenuo Audit is instructions for the agent only. Our summary lists: Python 3.

Does Tenuo Audit access the network?

SKILL.md names 2 domains. In commands or code: api.github.com; the agent is likely to contact it when it follows the instructions. As links in the text: cloud.tenuo.ai. This is read from the text; nothing was executed.

Is Tenuo Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tenuo Audit use?

Tenuo Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tenuo Audit use?

About 3.6k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tenuo Audit?

Skills that share tags, products or a category with Tenuo Audit: Security Sensitive Path Instrumenter (ArabelaTso/Skills-4-SE, 253 stars), Web3 Polymarket (Polymarket/agent-skills, 192 stars), Django Access Review (getsentry/skills, 1k stars) and Payload (payloadcms/payload, 45k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tenuo Audit?

tenuo-ai (a GitHub organization) maintains it in tenuo-ai/tenuo, which has 103 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 10, 2026.

Source: tenuo-ai/tenuo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.