Agent skill

Create Policies

by ucsandman in ucsandman/DashClaw

Create and test DashClaw guard policies for agent governance

MITAuto-check passedAI & LLM Engineering

Install Create Policies

skills CLI
$ npx skills add ucsandman/DashClaw --skill create-policies -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ucsandman/DashClaw create-policies --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ucsandman/DashClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/dashclaw-agent/create-policies .claude/skills/create-policies && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
create-policies
GitHub stars
310
Token cost
~1.3k tokens
SKILL.md length
186 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

Create and test DashClaw guard policies for agent governance

  • Tasks that involve Building AI agents
  • SKILL.md covers Policy Types, Guard Modes, Defining Policies in YAML and Importing Policies, plus 4 more sections
  • Calls curl; needs DASHCLAW_API_KEY

What it does

Create Policies is an agent skill from ucsandman/DashClaw. Create and test DashClaw guard policies for agent governance

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering Building AI agents. It works with Model Context Protocol. The repository describes itself as: Remote approvals, policy checks, and execution evidence for unattended AI agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Building AI agents

Example prompts

  • “/create-policies”

Requirements

  • A credential in DASHCLAW_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 704824d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DASHCLAW_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Create Policies loads about 1.3k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 186 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ucsandman/DashClaw at commit 704824d, republished under its MIT licence (© ucsandman). 186 words, ~1,335 tokens.

Download SKILL.mdSave it as .claude/skills/create-policies/SKILL.md (or your agent's skills folder).
name
create-policies
description
Create and test DashClaw guard policies for agent governance
license
MIT
metadata.author
ucsandman
metadata.version
1.0.0
metadata.category
configuration

Create Guard Policies

Help developers define, import, and test guard policies that control what agents can and cannot do.

Policy Types

TypePurposeExample
risk_thresholdBlock/warn when risk score exceeds limitBlock actions with risk > 80
action_type_restrictionAllow/deny specific action typesBlock security actions without approval
approval_gateRequire human approval for matching actionsRequire approval for deploys
webhook_checkCall external endpoint for policy decisionCheck Jira ticket status before deploy
semantic_guardrailLLM-based content analysisBlock PII in action metadata

Guard Modes

  • off — No policy enforcement (development only)
  • warn — Log policy violations but allow execution
  • enforce — Block policy violations (production recommended)

Defining Policies in YAML

Risk Threshold Policy
yaml
name: high-risk-blocker
type: risk_threshold
mode: enforce
conditions:
  risk_score_min: 80
  reversible: false
action: block
reason: "Irreversible actions with risk >= 80 require manual execution"
Action Type Restriction
yaml
name: no-unattended-deploys
type: action_type_restriction
mode: enforce
conditions:
  action_types:
    - deploy
    - database
action: require_approval
reason: "Deploy and database actions require human approval"
Approval Gate
yaml
name: production-approval-gate
type: approval_gate
mode: enforce
conditions:
  systems_touched:
    - production
  risk_score_min: 50
action: require_approval
reason: "Production access with risk >= 50 requires approval"
Cost Ceiling
yaml
name: cost-ceiling
type: risk_threshold
mode: enforce
conditions:
  cost_estimate_max: 100.00
action: block
reason: "Actions exceeding $100 estimated cost are blocked"
Content Filter
yaml
name: no-secrets-in-metadata
type: semantic_guardrail
mode: enforce
conditions:
  scan_fields:
    - declared_goal
    - output_summary
  patterns:
    - "password"
    - "api_key"
    - "secret"
action: block
reason: "Sensitive data detected in action metadata"

Importing Policies

Via API
javascript
// POST /api/policies
const response = await fetch(`${baseUrl}/api/policies`, {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'x-api-key': process.env.DASHCLAW_API_KEY
  },
  body: JSON.stringify({
    name: 'high-risk-blocker',
    type: 'risk_threshold',
    mode: 'enforce',
    conditions: { risk_score_min: 80, reversible: false },
    action: 'block',
    reason: 'Irreversible high-risk actions are blocked'
  })
});
Via Legacy SDK Policy Packs
javascript
import { DashClaw } from 'dashclaw/legacy';

const claw = new DashClaw({ baseUrl, apiKey, agentId });

// Import a preset pack
await claw.importPolicies({ pack: 'enterprise-strict' });
// Available packs: enterprise-strict, smb-safe, startup-growth, development

Testing Policies

Test a Single Policy
javascript
// POST /api/policies/test
const result = await fetch(`${baseUrl}/api/policies/test`, {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'x-api-key': process.env.DASHCLAW_API_KEY
  },
  body: JSON.stringify({
    action_type: 'deploy',
    risk_score: 85,
    reversible: false,
    systems_touched: ['production']
  })
});

// Response: which policies would trigger and what decisions they'd produce
Test All Policies (Legacy SDK)
javascript
const results = await claw.testPolicies();
// Returns pass/fail for each policy with explanation
Generate Proof Report
javascript
const report = await claw.getProofReport({ format: 'md' });
// Generates compliance-ready report showing all policies and their test results

Common Policy Patterns

Development Environment
yaml
# Permissive — warn only, don't block
- name: dev-risk-warning
  type: risk_threshold
  mode: warn
  conditions: { risk_score_min: 50 }
  action: warn
  reason: "High risk action detected (dev mode — not blocked)"
Production Environment
yaml
# Strict — enforce everything
- name: prod-risk-gate
  type: risk_threshold
  mode: enforce
  conditions: { risk_score_min: 70 }
  action: require_approval

- name: prod-deploy-gate
  type: action_type_restriction
  mode: enforce
  conditions: { action_types: [deploy, database, security] }
  action: require_approval

- name: prod-irreversible-block
  type: risk_threshold
  mode: enforce
  conditions: { risk_score_min: 90, reversible: false }
  action: block

Scoping Policies

Policies can be scoped to specific agents or apply org-wide:

json
{
  "name": "deploy-agent-only",
  "agent_id": "deploy-agent-1",
  "type": "approval_gate",
  "conditions": { "action_types": ["deploy"] },
  "action": "require_approval"
}

If agent_id is omitted, the policy applies to all agents in the org.

Listing Active Policies

bash
# GET /api/policies
curl -H "x-api-key: $DASHCLAW_API_KEY" $DASHCLAW_BASE_URL/api/policies

Response includes all active policies with their type, mode, conditions, and scope.

© ucsandman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/dashclaw-agent/create-policies of ucsandman/DashClaw.

Open the folder on GitHubat commit 704824d

Compare with similar skills

Create Policies next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Create Policies compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Create Policies this skillucsandman/DashClaw310—~1.3kAutomated safety check: PassMIT
Agent Buildern8n-io/n8n207k—~2.5kAutomated safety check: PassCustom licence
Summarizeswarmclawai/swarmclaw688—~531Automated safety check: PassMIT
Agent Squad Python Guide2FastLabs/agent-squad7.8k—~4.7kAutomated safety check: PassApache-2.0
Agent Squad for TypeScript2FastLabs/agent-squad7.8k—~4.3kAutomated safety check: PassApache-2.0
Agent Frameworkjihadkhawaja/Egroo178—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Agent Builder

    n8n-io/n8n

    Official

    Load immediately after an Agent intent. An agent skill from n8n-io/n8n.

    207k GitHub stars~2.5k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Summarize

    swarmclawai/swarmclaw

    Summarize or extract text/transcripts from URLs, podcasts, YouTube videos, and local files using the summarize CLI.

    688 GitHub stars~531 tokensUpdated 3 mo ago
    AI & LLM EngineeringAuto-check passed
  • Agent Squad Python Guide

    2FastLabs/agent-squad

    Map of the agent-squad Python framework for async multi-agent orchestration: which agent, classifier, storage and tool provider to pick, and the pitfalls to avoid.

    7.8k GitHub stars~4.7k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Agent Squad for TypeScript

    2FastLabs/agent-squad

    Guide to building Node.js and TypeScript apps on the agent-squad package: orchestrator, agent types, classifier routing, storage, retrievers and MCP tools.

    7.8k GitHub stars~4.3k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Agent Framework

    jihadkhawaja/Egroo

    Build, extend, and debug AI agents in Egroo using the Microsoft Agent Framework (C .NET).

    178 GitHub stars~1.9k tokensUpdated 6 mo ago
    AI & LLM EngineeringAuto-check passed
  • Openma

    openma-ai/open-managed-agents

    Use the openma platform to build, deploy, and manage AI agents.

    316 GitHub stars~854 tokensUpdated today
    AI & LLM EngineeringAuto-check passed

More from ucsandman/DashClaw

All 13 skills in this repo
  • Dashclaw Governance

    ucsandman/DashClaw

    Governance behavior for AI agents governed by DashClaw. An agent skill from ucsandman/DashClaw.

    310 GitHub stars~2.7k tokensUpdated 3 days ago
    Auto-check passed
  • Dashclaw Ship

    ucsandman/DashClaw

    The single command that gets a DashClaw change ON MAIN AND LIVE — it resolves everything blocking production, never defers, and never hands back a checklist.

    310 GitHub stars~7.2k tokensUpdated 3 days ago
    Auto-check passed
  • Repro

    ucsandman/DashClaw

    Turn a bug symptom into a structured, reproducible bug report — summary, environment, exact repro steps, actual vs expected, and evidence (logs, error text, failing route/test) — and then optionally…

    310 GitHub stars~1.5k tokensUpdated 3 days ago
    Auto-check passed
  • Muse Governance

    ucsandman/DashClaw

    Governance behavior for Muse agents governed by DashClaw. An agent skill from ucsandman/DashClaw.

    310 GitHub stars~1.7k tokensUpdated 3 days ago
    Auto-check passed
  • Build Dashclaw

    ucsandman/DashClaw

    Contribute to the DashClaw codebase — architecture, scaffolding, tests, CI

    310 GitHub stars~1.3k tokensUpdated 3 days ago
    Auto-check passed
  • Compliance Drift Evals

    ucsandman/DashClaw

    Set up compliance exports, drift detection, evaluations, scoring, and learning analytics

    310 GitHub stars~1.8k tokensUpdated 3 days ago
    Auto-check passed

Questions about Create Policies

What does Create Policies do?

Create and test DashClaw guard policies for agent governance. Create Policies is an agent skill from ucsandman/DashClaw.

When should I use Create Policies?

Create Policies fits situations like: tasks that involve Building AI agents.

How do I install Create Policies in Claude Code?

Run `npx skills add ucsandman/DashClaw --skill create-policies -a claude-code`. Or copy the skill folder (.claude/skills/dashclaw-agent/create-policies in ucsandman/DashClaw) into .claude/skills/create-policies in your project. Claude Code loads it when a task matches its description.

How do I install Create Policies in Codex?

Run `npx skills add ucsandman/DashClaw --skill create-policies -a codex`. Or copy the skill folder (.claude/skills/dashclaw-agent/create-policies in ucsandman/DashClaw) into .agents/skills/create-policies in your project. Codex loads it when a task matches its description.

Can I use Create Policies in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ucsandman/DashClaw --skill create-policies -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-policies, .gemini/skills/create-policies, .github/skills/create-policies and .opencode/skills/create-policies in your project.

What does Create Policies need to run?

Going by SKILL.md and its folder, Create Policies needs the command-line tools its instructions call (curl) and credentials named DASHCLAW_API_KEY. Our summary lists: A credential in DASHCLAW_API_KEY.

Does Create Policies access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Create Policies safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Create Policies use?

Create Policies is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Create Policies use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Create Policies?

Skills that share tags, products or a category with Create Policies: Agent Builder (n8n-io/n8n, 207k stars), Summarize (swarmclawai/swarmclaw, 688 stars), Agent Squad Python Guide (2FastLabs/agent-squad, 7.8k stars) and Agent Squad for TypeScript (2FastLabs/agent-squad, 7.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Create Policies?

ucsandman (a GitHub user) maintains it in ucsandman/DashClaw, which has 310 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: ucsandman/DashClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.