This skill should be used for Claude Code permission rules, modes, settings, MCP permission syntax, and hooks boundaries. Do not use it as the authorization contract for Claude Platform memory, bash, text-editor, computer-use, server tools, or Messages API handlers.
Author, audit, and explain Claude Code permission policies for settings files, CLI overrides, skills, subagents, and hook-adjacent workflows. Use this skill for permission rules, permission modes, MCP wildcards, parameter matching, and safe automation boundaries. [DOC]
Do not apply Claude Code permissions.*, modes, or Bash(...) rule syntax to Claude Platform tools. Platform client-tool authorization belongs inside the application handler governed by claude-api-client-tools; server-tool request policy belongs to claude-api-server-tools. [CONFIG]
Treat current Claude Code documentation as the source of truth for runtime behavior. If the local Claude Code version or documentation date is unknown, include coverage_gap: active Claude Code version not verified. [DOC][INFERENCIA]
Supporting files:
references/rule-syntax.md - Detailed Tool and Tool(specifier) syntax, wildcards, parameter matching, and tool-specific caveats. [CONFIG]references/modes-and-safety.md - Mode selection guidance for default, acceptEdits, plan, auto, dontAsk, and bypassPermissions. [CONFIG]references/hooks-boundary.md - How hooks interact with permission rules and why permissions remain the enforcement layer. [CONFIG]assets/policy-review-checklist.md - Portable checklist for reviewing a policy draft before applying it. [CONFIG]settings.json, /permissions export, CLI flags, subagent frontmatter, or hook output.coverage_gap items.permissions.allow to let matching tool calls proceed without manual approval. [DOC]permissions.ask to force confirmation for matching tool calls. [DOC]permissions.deny to block matching tool calls and protect sensitive files, commands, domains, tools, or MCP surfaces. [DOC]Bash(aws *) blocks a narrower allow such as Bash(aws s3 ls). [DOC]Tool to match all uses of a tool.Tool(specifier) for fine-grained control.Bash(*) as equivalent to Bash. As a deny rule, both forms remove the tool from model context. [DOC]mcp__* only for deny or ask rules that intentionally target every MCP tool. Allow rules may use MCP globs only after a literal server prefix, such as mcp__github__get_*. [DOC]Tool(param:value) only for deny and ask rules against direct, top-level scalar tool input parameters. [DOC]Agent(model:opus) and Agent(isolation:worktree).* in parameter values to match any character sequence; omitted parameters never match.command, file tool file_path, Grep/Glob path, NotebookEdit notebook_path, and WebFetch url. Use the tool's canonical specifier syntax instead. [DOC]Use default for normal interactive work. Use acceptEdits only when file edits and common filesystem commands inside the working directory are low risk. Use plan for read-only exploration before implementation. Use dontAsk for constrained automation where explicit allow rules pre-approve all permitted actions. [DOC]
Use auto only with reviewed environment context and explicit deny/ask boundaries. Auto mode runs a classifier after the permission system; deny and explicit ask rules still run first. Shared project settings cannot grant themselves auto mode, and auto mode configuration is not read from shared project settings. [DOC]
Use bypassPermissions only in isolated containers, VMs, or disposable worktrees. It skips permission prompts, including protected project directories, while explicit ask rules and root/home deletion circuit breakers still prompt. Prefer disabling bypass in managed settings when organizational policy requires it. [DOC]
Identify the active source: ~/.claude/settings.json, .claude/settings.json, .claude/settings.local.json, managed settings, command-line flags, subagent frontmatter, skill frontmatter, hook output, or SDK settings. State which layer owns the proposed change. [DOC]
Classify each requested rule as allow, ask, or deny. Default to deny for irreversible, secret-bearing, exfiltration-prone, or production-impacting actions. Default to ask for legitimate but high-impact operations. Default to allow only for narrow, repeatable, low-risk actions. [INFERENCIA]
Prefer exact commands, project-root paths, explicit domains, named subagents, and literal MCP server prefixes. Avoid broad allows such as Bash, WebFetch, Edit, mcp__server__*, or mcp__* unless the scope is intentionally trusted and compensating controls are documented. [DOC][INFERENCIA]
Build an overlap table with columns: Candidate call, deny match, ask match, allow match, effective result, reason. Flag impossible allowlist exceptions caused by broad deny rules. [INFERENCIA]
Choose the least permissive mode that satisfies the workflow. Pair auto and bypassPermissions with explicit deny/ask guardrails, environment isolation, or managed disable settings. Explain why default, plan, or dontAsk is insufficient before recommending a more permissive mode. [INFERENCIA]
Use permission rules for durable policy enforcement. Use hooks for automation, supplemental checks, permission suggestions, logging, or runtime workflow control. Do not present a hook allow decision as overriding a matching deny or ask rule. [DOC]
Apply assets/policy-review-checklist.md. Include JSON parse status when reviewing settings. Include coverage_gap for unknown Claude Code version, unavailable managed settings, unavailable active /permissions view, or unverified MCP server names.
Tool or Tool(specifier) syntax.mcp__* from allowed server-scoped globs.auto and bypassPermissions recommendations include safety conditions./tool-permission-policyauthor Claude Code permissions for this repoaudit these permissions.allow and permissions.deny rulesexplain whether this hook can bypass a deny rulereview this bypassPermissions setupallowed-tools NO restringe en skills (usa disallowed-tools); herramientas UI-dependientes no aplican en subagentes. [EXPLICIT]Capas del packet, cargables bajo demanda (disciplina ICM: una capa por vez, nunca todas juntas): references/ guías de profundidad (cargar UNA por etapa) · knowledge/ cuerpo de conocimiento · prompts/ prompts listos · examples/ salida de ejemplo · agents/ subagentes del packet · templates/ plantilla de output · assets/ recursos estáticos.
e8f986b
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.