Abp Authorization
abpframework/abp
ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.
A skill your agent uses when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific…
$ npx skills add topoteretes/cognee --skill cognee-permissions -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install topoteretes/cognee cognee-permissions --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/topoteretes/cognee.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cognee-permissions .claude/skills/cognee-permissions && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cognee-permissions" agent skill from https://github.com/topoteretes/cognee/tree/main/.agents/skills/cognee-permissions into .claude/skills/cognee-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognee-permissions", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/topoteretes/cognee/tree/main/.agents/skills/cognee-permissionsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add topoteretes/cognee --skill cognee-permissions -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install topoteretes/cognee cognee-permissions --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/topoteretes/cognee.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/cognee-permissions .agents/skills/cognee-permissions && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cognee-permissions" agent skill from https://github.com/topoteretes/cognee/tree/main/.agents/skills/cognee-permissions into .agents/skills/cognee-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognee-permissions", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add topoteretes/cognee --skill cognee-permissions -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install topoteretes/cognee cognee-permissions --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/topoteretes/cognee.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/cognee-permissions .cursor/skills/cognee-permissions && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cognee-permissions" agent skill from https://github.com/topoteretes/cognee/tree/main/.agents/skills/cognee-permissions into .cursor/skills/cognee-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognee-permissions", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/topoteretes/cognee.git --path .agents/skills/cognee-permissions--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add topoteretes/cognee --skill cognee-permissions -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install topoteretes/cognee cognee-permissions --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/topoteretes/cognee.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/cognee-permissions .gemini/skills/cognee-permissions && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cognee-permissions" agent skill from https://github.com/topoteretes/cognee/tree/main/.agents/skills/cognee-permissions into .gemini/skills/cognee-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognee-permissions", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install topoteretes/cognee cognee-permissionsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add topoteretes/cognee --skill cognee-permissions -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/topoteretes/cognee.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/cognee-permissions .github/skills/cognee-permissions && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cognee-permissions" agent skill from https://github.com/topoteretes/cognee/tree/main/.agents/skills/cognee-permissions into .github/skills/cognee-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognee-permissions", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add topoteretes/cognee --skill cognee-permissions -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install topoteretes/cognee cognee-permissions --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/topoteretes/cognee.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/cognee-permissions .opencode/skills/cognee-permissions && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cognee-permissions" agent skill from https://github.com/topoteretes/cognee/tree/main/.agents/skills/cognee-permissions into .opencode/skills/cognee-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cognee-permissions", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cognee-permissionsA skill your agent uses when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific…
Cognee Permissions is an agent skill from topoteretes/cognee. Use when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific user in the SDK or authenticating over HTTP (login, API keys), turning access control on or off, debugging PermissionDeniedError or missing datasets, or understanding where permissions are enforced and how datasets are isolated.
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authorization and RBAC and Multi-tenancy. The repository describes itself as: Cognee is the open-source AI memory platform for agents. Give your AI agents persistent long-term memory with small models for free. The licence is Apache-2.0.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 0ec7a9f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DEFAULT_USER_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cognee Permissions loads about 3.6k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 1,416 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from topoteretes/cognee at commit 0ec7a9f, republished under its Apache-2.0 licence (© topoteretes). 1,416 words, ~3,560 tokens.
.claude/skills/cognee-permissions/SKILL.md (or your agent's skills folder).Every dataset belongs to an owner, and every operation on it is checked
against a grant: a principal (user, role, or tenant) holding a
permission (read, write, delete, share) on a dataset. With access
control on (the default), each user+dataset pair also gets its own graph and
vector databases.
Without user=, SDK calls run as the default user
(default_user@example.com, or DEFAULT_USER_EMAIL). To act as someone
else, create or load them and pass user=:
import cognee
from cognee.modules.users.methods import create_user, get_user
alice = await create_user("alice@example.com", "password")
bob = await create_user("bob@example.com", "password")
res = await cognee.remember("Alice's notes", dataset_name="alice_notes", user=alice)
await cognee.recall("What are the notes about?", user=alice, datasets=["alice_notes"])remember, recall, search, forget, improve and the dataset helpers
all take user=.
The caller must hold share on the dataset. Share by dataset id:
from uuid import UUID
from cognee.modules.users.permissions.methods import (
authorized_give_permission_on_datasets,
authorized_revoke_permission_on_datasets,
)
await authorized_give_permission_on_datasets(
bob.id, # principal: a user, role, or tenant id
[UUID(res.dataset_id)], # dataset ids (RememberResult.dataset_id is a str)
"read", # "read" | "write" | "delete" | "share"
alice.id, # the owner making the grant
)
await cognee.recall("...", user=bob, dataset_ids=[UUID(res.dataset_id)]) # by id (must be a UUID)Bob must address Alice's dataset by id: dataset names resolve only among the caller's own datasets.
from cognee.modules.users.tenants.methods import add_user_to_tenant, create_tenant, select_tenant
from cognee.modules.users.roles.methods import add_user_to_role, create_role
tenant_id = await create_tenant("Acme", alice.id) # alice owns it
await select_tenant(user_id=alice.id, tenant_id=tenant_id)
role_id = await create_role(role_name="Researcher", owner_id=alice.id)
await add_user_to_tenant(user_id=bob.id, tenant_id=tenant_id, owner_id=alice.id)
await add_user_to_role(user_id=bob.id, role_id=role_id, owner_id=alice.id)
await select_tenant(user_id=bob.id, tenant_id=tenant_id)
alice = await get_user(alice.id) # reload after changing the active tenant
res = await cognee.remember(text, dataset_name="acme_docs", user=alice)
await authorized_give_permission_on_datasets(role_id, [UUID(res.dataset_id)], "read", alice.id)select_tenant; None is the
personal space). Datasets are created in the active tenant.PermissionDeniedError). The principal's tenant is not
checked: a grant to a role on a personal dataset (or one from another
tenant) succeeds, and its members see it only while their active
tenant is the dataset's tenant (personal space for a personal dataset).
To share inside a tenant, create the dataset with that tenant active.select_tenant, then reload the user); a personal dataset is visible
only in personal space.Full walkthrough: examples/demos/permissions/user_permissions_and_access_control_example.py
(also tenant_role_setup_example.py, tenant_role_constraints_example.py).
POST /api/v1/auth/register, then
POST /api/v1/auth/login (form fields username, password). The
response sets an auth cookie and returns {"access_token", "token_type": "bearer"}; send Authorization: Bearer <token>.POST /api/v1/auth/api-keys creates one (GET lists,
DELETE /api-keys/{id} removes); send it as X-Api-Key: <key>.DEFAULT_USER_PASSWORD is set (the server logs a warning at startup)./api/v1/permissions):| Endpoint | What it does |
|---|---|
POST /datasets/{principal_id}?permission_name=read + JSON body [dataset_ids] | Grant (needs share) |
DELETE /datasets/{principal_id} | Revoke |
GET /principals/{principal_id}/datasets?permission_name=read | Datasets a principal holds a permission on |
POST /tenants · POST /tenants/select · GET /tenants/me | Create, switch, list your tenants |
POST /users/{user_id}/tenants · DELETE /tenants/{tenant_id}/users/{user_id} | Add/remove a tenant member |
GET /tenants/{tenant_id}/users | Tenant members |
POST /roles · DELETE /roles/{role_id} · GET /tenants/{tenant_id}/roles | Manage roles |
POST / DELETE /users/{user_id}/roles | Add/remove a role member |
GET /tenants/{tenant_id}/roles/{role_id}/users · GET /tenants/{tenant_id}/roles/users/{user_id} | Role members; a user's roles (404 if not a member) |
ENABLE_BACKEND_ACCESS_CONTROL is the master switch:
true (default): multi-tenant. API calls require auth, every dataset
operation is permission-checked, and each user+dataset gets isolated graph
and vector databases.false: single-user storage. ACL checks still run, but they only gate
which dataset ids may be named: retrieval runs over the shared graph and
vector databases, so other users' content is not filtered out. Every
user reads and writes the same shared databases. Use it only for a
single-user deployment.Authentication follows the switch unless REQUIRE_AUTHENTICATION is set.
REQUIRE_AUTHENTICATION=true with access control off keeps logins but not
isolation; REQUIRE_AUTHENTICATION=false with access control on is ignored
(auth is forced on with a warning).
For production multi-tenant deployments (managed isolation, the production Postgres adapter, and horizontal scaling), contact social@cognee.ai.
PermissionDeniedError (HTTP 403).DatasetNotFoundError, even if it is shared with you. On writes
(remember/add/cognify) it silently creates a new dataset of your own
with that name. Use the id.[].share on a dataset in the granter's active tenant;
otherwise PermissionDeniedError. The principal's tenant is not checked,
so a grant can succeed yet be visible to its members only in the
dataset's tenant (see above).select_tenant (get_user(id)): an old User
object still carries the previous active tenant."notes" datasets are unrelated.OSError naming it
(multi_user_support_possible() in cognee/context_global_variables.py),
never a silent fall back to shared databases. Switch backends or set
ENABLE_BACKEND_ACCESS_CONTROL=false. The support matrix is in CLAUDE.md
("Multi-Tenant Access Control").manage_users is a tenant-scoped
capability in principal_capabilities, granted to a tenant (every member),
a role (its members) or a user (that person, in that tenant) and resolved
as their union (get_effective_capabilities); the tenant owner holds every
capability. Every check goes through
has_grant_permission(requester, tenant, capability);
has_user_management_permission is that check for manage_users. Creating
roles, assigning them and adding users to a tenant need manage_users, not
ownership. Assigning a role has one more rule (require_role_capabilities):
the requester must hold every capability the role carries, and a role named
admin counts as carrying all of them.POST/DELETE /permissions/capabilities/{principal_id}) and are gated by
capabilities of their own: granting needs grant_capabilities, revoking
needs revoke_capabilities, and neither comes with manage_users. A
granter can only pass on capabilities they hold themselves
(get_unheld_capabilities). Each row records who made the grant in
granted_by; both endpoints take capability repeated to grant or revoke
several at once, all or nothing. For a user principal the grant lands in
the tenant_id given, or the caller's current tenant, and the user must
already be a member of it (CapabilityGrantToNonMemberError, 403, says
so); a role or tenant principal always uses its own tenant. A missing principal or tenant answers
like a refusal (403), so the endpoints do not reveal which ids exist.
Removing a user from a tenant drops their personal capabilities there, and
deleting a role drops the role's.admin role name. Members of a role named
admin (LEGACY_ALL_CAPABILITY_ROLE_NAMES) pass every capability check
until the role is granted the capabilities it needs; the fallback sits in
has_grant_permission, so it also passes the grant and revoke checks.A grant is one ACL row: principal × permission × dataset
(cognee/modules/users/models/ACL.py).
Principal.py) is polymorphic: User, Role, and Tenant
all inherit from it, so one ACL row can cover every member of a role or
tenant.permissions/permission_types.py):
read, write, delete, share. share gates granting and revoking.UserRole, UserTenant) is separate from grants. A
user's access is the union of their own grants and those of their roles
and tenants.Grants come from:
cognee/modules/data/methods/create_authorized_dataset.py):
the creator gets all four permissions. If the creator has a
parent_user_id (a sub-user or agent identity,
create_user(..., parent_user_id=...)), the parent gets all four too.authorized_give_permission_on_datasets /
authorized_revoke_permission_on_datasets).Most entry points resolve datasets through
get_authorized_existing_datasets(datasets, permission, user)
(cognee/modules/data/methods/); all of them end in
get_specific_user_permission_datasets / get_all_user_permission_datasets
(cognee/modules/users/permissions/methods/):
| Operation | Permission |
|---|---|
remember / add / cognify / improve | write |
recall / search / visualize | read |
forget / delete / empty a dataset | delete |
| grant / revoke | share |
With access control on, each user+dataset pair has its own graph and vector
databases, recorded in the DatasetDatabase model (names, providers,
handlers, connection info, migration revision). The relational database
(users, ACLs, the registry) is always shared. The handler is chosen from the
configured providers; the registry is
cognee/infrastructure/databases/dataset_database_handler/supported_dataset_database_handlers.py.
The *_shared handlers (pgvector_shared, postgres_graph_shared) give
each dataset its own Postgres schema inside cognee's main database instead
of a separate database, so no CREATE DATABASE privilege is needed. Select
them with VECTOR_DATASET_DATABASE_HANDLER / GRAPH_DATASET_DATABASE_HANDLER.
cognee/api/v1/visualize/memory_provenance.py renders ACL grants as edges
from principal to dataset (reads, writes, can_delete, can_share),
served by the schema router (visualize_memory_provenance HTML,
get_memory_provenance_payload JSON).
cognee/modules/users/models/ (ACL, Principal, Permission,
Role, Tenant, UserRole, UserTenant, DatasetDatabase,
UserApiKey, PrincipalCapability)cognee/modules/users/methods/,
cognee/modules/users/tenants/methods/, cognee/modules/users/roles/methods/cognee/modules/users/permissions/methods/cognee/modules/users/authentication/,
cognee/api/v1/users/routers/, cognee/api/v1/api_keys/routers/cognee/api/v1/permissions/routers/get_permissions_router.pyget_authorized_existing_datasets with the right permission before doing
any work; never read a dataset by id without that check.DatasetDatabaseHandlerInterface and register
it in the handler registry (or at runtime with
use_dataset_database_handler()), otherwise multi-tenant mode refuses to
start with it.CAPABILITY_TYPES in
permission_types.py and gate the operation with
has_grant_permission(requester_id, tenant_id, <name>); the owner holds it
immediately, everyone else once it is granted. Dataset permissions
(read/write/delete/share) stay in the ACL and are rejected by
validate_capability.cognee/tests/unit/users/, cognee/tests/unit/modules/users/, and
the examples above.© topoteretes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/cognee-permissions of topoteretes/cognee.
Open the folder on GitHubat commit 0ec7a9f
Cognee Permissions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cognee Permissions this skilltopoteretes/cognee | 32k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Abp Authorizationabpframework/abp | 14k | — | ~1.3k | Automated safety check: Pass | LGPL-3.0 | |
| Django Access Reviewgetsentry/skills | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Supercheck Security Authsupercheck-io/supercheck | 215 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | |
| Backend AI Guidelablup/backend.ai-webui | 133 | 1 repos | ~1.8k | Automated safety check: Pass | LGPL-3.0 | |
| Arandu Shared Modules Guidearandu-io/arandu | 281 | — | ~1.8k | Automated safety check: Pass | MIT |
abpframework/abp
ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.
getsentry/skills
Django access control and IDOR security review. An agent skill from getsentry/skills.
supercheck-io/supercheck
Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…
lablup/backend.ai-webui
Expert guide for Backend.AI distributed computing platform. An agent skill from lablup/backend.ai-webui.
arandu-io/arandu
Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.
growupanand/ConvoForm
Clerk Organizations for B2B and multi-tenant apps - org switching, roles and permissions, verified domains, and enterprise SSO.
topoteretes/cognee
Drives cognee from the terminal with remember, recall, forget and improve memory commands, dataset and config management and database migrations.
topoteretes/cognee
Guide to using and contributing cognee community packages: database adapters, data-source connectors, custom tasks and retrievers, and Keywords AI observability.
topoteretes/cognee
Defines the shape of cognee's knowledge graph with graph_model: DataPoint node classes, identity and index fields, typed edges and fixes for duplicated nodes.
topoteretes/cognee
Shows how to write custom cognee tasks, chain them into pipelines, store custom DataPoints and run enrichment over the existing graph.
topoteretes/cognee
Runs the Cognee AI memory platform in Docker, from a one-file prebuilt image to a full compose stack with UI, MCP server, Postgres and Neo4j.
topoteretes/cognee
Removes data from cognee memory with forget(), finding the right dataset and document first and choosing between one document, a dataset or only the graph and vector memory.
Categories
A skill your agent uses when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific…. Cognee Permissions is an agent skill from topoteretes/cognee. Use when working with cognee's users, permissions, and multi-tenancy — creating users, tenants and roles, sharing datasets (read/write/delete/share grants), acting as a specific user in the SDK or authenticating over HTTP (login, API keys), turning access control on or off, debugging PermissionDeniedError or missing datasets, or understanding where permissions are enforced and how datasets are isolated.
Cognee Permissions fits situations like: working with cognees users; multi-tenancy — creating users; tenants and roles; sharing datasets (read/write/delete/share grants).
Run `npx skills add topoteretes/cognee --skill cognee-permissions -a claude-code`. Or copy the skill folder (.agents/skills/cognee-permissions in topoteretes/cognee) into .claude/skills/cognee-permissions in your project. Claude Code loads it when a task matches its description.
Run `npx skills add topoteretes/cognee --skill cognee-permissions -a codex`. Or copy the skill folder (.agents/skills/cognee-permissions in topoteretes/cognee) into .agents/skills/cognee-permissions in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add topoteretes/cognee --skill cognee-permissions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cognee-permissions, .gemini/skills/cognee-permissions, .github/skills/cognee-permissions and .opencode/skills/cognee-permissions in your project.
Going by SKILL.md and its folder, Cognee Permissions needs credentials named DEFAULT_USER_PASSWORD. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cognee Permissions is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cognee Permissions: Abp Authorization (abpframework/abp, 14k stars), Django Access Review (getsentry/skills, 1k stars), Supercheck Security Auth (supercheck-io/supercheck, 215 stars) and Backend AI Guide (lablup/backend.ai-webui, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
topoteretes (a GitHub organization) maintains it in topoteretes/cognee, which has 31,919 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.
Source: topoteretes/cognee on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.