Agent skill

Formax Permissions Workflow

by yusifeng in yusifeng/formax

A skill your agent uses when implementing or debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules, workspace boundaries, approval prompts, and /permissions overlay…

MITAuto-check passedDevelopment

Install Formax Permissions Workflow

skills CLI
$ npx skills add yusifeng/formax --skill formax-permissions-workflow -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yusifeng/formax formax-permissions-workflow --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yusifeng/formax.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.codex/skills/formax-permissions-workflow .claude/skills/formax-permissions-workflow && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
formax-permissions-workflow
GitHub stars
195
Token cost
~1.3k tokens
SKILL.md length
419 words
Files
1
Skills in repo
21
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when implementing or debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules, workspace boundaries, approval prompts, and /permissions overlay…

  • Works in 4 steps: Policy preflight (ToolCall ->… → Permissions storage + matching (rules &… → Approvals (prompt UI + persistence… → …
  • Debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules
  • SKILL.md covers Goal, Read First, Code Map and High-Signal Patterns, plus 3 more sections
  • Calls bun and npm

What it does

Formax Permissions Workflow is an agent skill from yusifeng/formax. Use when implementing or debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules, workspace boundaries, approval prompts, and /permissions overlay parity with Claude Code).

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: Terminal-first AI assistant for software engineering tasks (inspired by Claude Code v2.0.67). The licence is MIT.

When your agent uses it

  • Debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules
  • Workspace boundaries
  • Approval prompts
  • /permissions overlay parity with Claude Code)

Example prompts

  • “/formax-permissions-workflow”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Policy preflight (ToolCall -> allow/ask/deny decision)
  2. Permissions storage + matching (rules & precedence)
  3. Approvals (prompt UI + persistence side-effects)
  4. /permissions overlay (manage rules + workspace)

What it can do on your machine

Read from SKILL.md and the folder at commit 1b0c3f3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Formax Permissions Workflow loads about 1.3k tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 419 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yusifeng/formax at commit 1b0c3f3, republished under its MIT licence (© yusifeng). 419 words, ~1,273 tokens.

Download SKILL.mdSave it as .claude/skills/formax-permissions-workflow/SKILL.md (or your agent's skills folder).
name
formax-permissions-workflow
description
Use when implementing or debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules, workspace boundaries, approval prompts, and /permissions overlay parity with Claude Code).

Formax permissions / approvals workflow

Goal

Use this skill when changing policy preflight, approval prompts, remember side-effects, or /permissions management.

Read First

  • docs/contracts/permissions-policy-contract.md
  • docs/contracts/interactive-input-contract.md
  • docs/contracts/semantics-contract.md when the change crosses TUI / app-server / Web

These docs are canonical. If stable behavior changes, update them before or with code.

Code Map

1) Policy preflight (ToolCall -> allow/ask/deny decision)
  • packages/core/src/tools/executor/policyPreflight.ts: turns ToolCall into a PolicyAction and decides deny / prompt / allow
  • packages/core/src/tools/executor/policyAction.ts: ToolCall -> PolicyAction mapping
  • packages/core/src/tools/executor/policyExplain.ts: explain / debug text for decisions
  • packages/core/src/tools/modules/bash/policy.ts: Bash risk classification
2) Permissions storage + matching (rules & precedence)
  • packages/core/src/adapters/permissions/permissionsStore.ts: read / write settings and merge precedence
  • packages/core/src/adapters/permissions/permissionKeys.ts: stable keys / paths for settings
  • packages/core/src/adapters/permissions/matcher.ts: matcher semantics
3) Approvals (prompt UI + persistence side-effects)
  • packages/core/src/tools/executor/approvalService.ts: ensureApproved flow and remember writes
  • UI prompts:
    • packages/core/src/components/tool/bashApprovalPrompt.tsx
    • packages/core/src/components/tool/fsReadApprovalPrompt.tsx
    • packages/core/src/components/tool/fsWriteApprovalPrompt.tsx
    • packages/core/src/components/tool/skillApprovalPrompt.tsx
    • packages/core/src/components/tool/editApprovalPrompt.tsx
  • Shared pieces:
    • packages/core/src/components/ui/ApprovalHeader.tsx
    • packages/core/src/components/ui/ConfirmMenu.tsx
4) /permissions overlay (manage rules + workspace)
  • packages/core/src/tui/permissions/PermissionsDialog.tsx: state machine + key handling
  • packages/core/src/tui/permissions/ui.tsx: rendering primitives
  • packages/core/src/features/repl/controller/ui/overlays.ts: overlay open / close and dismissal messages
  • Slash command wiring:
    • packages/core/src/features/commands/registry.ts
    • packages/core/src/screens/repl/createReplCommandRegistry.ts

If app-server or Web input behavior moves, also inspect:

  • packages/core/src/app-server/turn/inputStore.ts
  • packages/core/src/app-server/server.ts
  • packages/web-reference-react/src/store.ts

High-Signal Patterns

  • Pattern A: tool approval prompt (3 options + Esc)
    • Yes
    • Yes, ... (remember / allow in repo or session)
    • Type here to tell Claude what to do differently
    • cancellation remains Esc to cancel, not a bespoke menu item
  • Pattern B: destructive confirm prompt
    • use Yes / No
    • still support Esc to cancel
  • Pattern C: partial emphasis in menu options
    • use ConfirmMenu emphasis support instead of ad-hoc JSX or ANSI
    • selected rows must not leave mismatched emphasis colors behind
Show full SKILL.md (182 more words)Show less

Minimal Workflow

  1. Read the canonical contract(s) above and define the exact behavior delta.
  2. Change the narrowest canonical code path first (policyPreflight, matcher / store, approvalService, or overlay state machine).
  3. Preserve existing UI copy / spacing / colors / keys unless the user explicitly asks for UI changes.
  4. Keep “what the user sees” separate from “what is injected back into model context”.
  5. Run the minimum regression set below, then review via AGENTS.md before commit.

Minimum Regression

  • bun run test -- packages/core/src/tools/executor/policyPreflight.test.ts
  • bun run test -- packages/core/src/tools/executor/approvalService.test.ts
  • bun run test -- packages/core/src/components/tool/bashApprovalPrompt.test.tsx
  • bun run test -- packages/core/src/components/tool/fsReadApprovalPrompt.test.tsx
  • bun run test -- packages/core/src/components/tool/fsWriteApprovalPrompt.test.tsx
  • bun run test -- packages/core/src/components/tool/skillApprovalPrompt.test.tsx
  • bun run test -- packages/core/src/tui/permissions/PermissionsDialog.test.tsx
  • If app-server / Web input behavior changed:
    • bun run test -- packages/core/src/app-server/turn/inputStore.test.ts packages/core/src/app-server/server.test.ts
    • npm --prefix packages/web-reference-react run test -- src/store.test.ts

Guardrails

  • Do not encode permission semantics inside prompt components; contracts live in policy / approval layers.
  • Do not add bespoke key handling or ANSI styling when shared approval components already cover the case.
  • Do not loosen permissions or remember scope just to make parity demos pass.
  • Preserve approval UI copy / spacing / colors / key paths unless the user explicitly asks for UI changes.

© yusifeng, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .codex/skills/formax-permissions-workflow of yusifeng/formax.

Open the folder on GitHubat commit 1b0c3f3

Compare with similar skills

Formax Permissions Workflow next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Formax Permissions Workflow compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Formax Permissions Workflow this skillyusifeng/formax195—~1.3kAutomated safety check: PassMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from yusifeng/formax

All 21 skills in this repo
  • A skill your agent uses when preparing a Formax code handoff: selecting files, generating repomix bundles, and writing a high-quality prompt for WebGPT or another coding agent with clear constraints…

    195 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Formax Skill Capture

    yusifeng/formax

    A skill your agent uses when we want to turn a just-finished Formax workflow (e.g.

    195 GitHub stars~530 tokensUpdated 2 mo ago
    Auto-check passed
  • Analyze Task

    yusifeng/formax

    A skill your agent uses when a Formax repository task is non-trivial and you should analyze goals, non-goals, boundaries, data/type/interface impact, contract impact, test strategy, and whether an…

    195 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • A skill your agent uses when working on Formax code changes and you need a disciplined dev loop: keep a single mainline task, avoid scope drift, run only targeted tests (no coverage), avoid partial…

    195 GitHub stars~686 tokensUpdated 2 mo ago
    Auto-check passed
  • Implement or refactor Formax tool transcript UI using the Tool UI Blocks (C-lite) pattern (ToolUiBlocks renderer + blocks presenters) to avoid touching many tool presenter files; use when adjusting…

    195 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • A skill your agent uses when implementing or modifying behavior that must stay consistent across TUI and Web (mode/input/tool/replay/order).

    195 GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Formax Permissions Workflow

What does Formax Permissions Workflow do?

A skill your agent uses when implementing or debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules, workspace boundaries, approval prompts, and /permissions overlay…. Formax Permissions Workflow is an agent skill from yusifeng/formax. Use when implementing or debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules, workspace boundaries, approval prompts, and /permissions overlay parity with Claude Code).

When should I use Formax Permissions Workflow?

Formax Permissions Workflow fits situations like: debugging Formax permissions/policy/approval behavior and UI (allow/ask/deny rules; workspace boundaries; approval prompts; /permissions overlay parity with Claude Code).

How do I install Formax Permissions Workflow in Claude Code?

Run `npx skills add yusifeng/formax --skill formax-permissions-workflow -a claude-code`. Or copy the skill folder (.codex/skills/formax-permissions-workflow in yusifeng/formax) into .claude/skills/formax-permissions-workflow in your project. Claude Code loads it when a task matches its description.

How do I install Formax Permissions Workflow in Codex?

Run `npx skills add yusifeng/formax --skill formax-permissions-workflow -a codex`. Or copy the skill folder (.codex/skills/formax-permissions-workflow in yusifeng/formax) into .agents/skills/formax-permissions-workflow in your project. Codex loads it when a task matches its description.

Can I use Formax Permissions Workflow in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yusifeng/formax --skill formax-permissions-workflow -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/formax-permissions-workflow, .gemini/skills/formax-permissions-workflow, .github/skills/formax-permissions-workflow and .opencode/skills/formax-permissions-workflow in your project.

What does Formax Permissions Workflow need to run?

Going by SKILL.md and its folder, Formax Permissions Workflow needs the command-line tools its instructions call (bun and npm).

Does Formax Permissions Workflow access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Formax Permissions Workflow safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Formax Permissions Workflow use?

Formax Permissions Workflow is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Formax Permissions Workflow use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Formax Permissions Workflow?

Skills that share tags, products or a category with Formax Permissions Workflow: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Formax Permissions Workflow?

yusifeng (a GitHub user) maintains it in yusifeng/formax, which has 195 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on July 24, 2026.

Source: yusifeng/formax on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.