Claims-based authorization for agents and operations. Grant, revoke, and verify permissions for secure multi-agent coordination. Use when: permission management, access control, secure operations, authorization checks. Skip when: open access, no security requirements, single-agent local work.
64
76%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./.agents/skills/claims/SKILL.mdClaims-based authorization for secure agent operations and access control.
| Claim | Description |
|---|---|
read | Read file access |
write | Write file access |
execute | Command execution |
spawn | Agent spawning |
memory | Memory access |
network | Network access |
admin | Administrative operations |
npx claude-flow claims check --agent agent-123 --claim writenpx claude-flow claims grant --agent agent-123 --claim write --scope "/src/**"npx claude-flow claims revoke --agent agent-123 --claim writenpx claude-flow claims list --agent agent-123| Pattern | Description |
|---|---|
* | All resources |
/src/** | All files in src |
/config/*.toml | TOML files in config |
memory:patterns | Patterns namespace |
| Level | Claims |
|---|---|
minimal | read only |
standard | read, write, execute |
elevated | + spawn, memory |
admin | all claims |
Distinct from the authorization claims above: work claims coordinate ownership of a task or resource across agents, and now propagate across a cross-host federation so a claim made on one node is visible to the whole swarm.
| Tool | Purpose |
|---|---|
claims_claim | Take ownership of an issue/resource (with optional TTL). |
claims_release | Give up a claim you hold. |
claims_handoff / claims_accept-handoff | Transfer a claim to another agent. |
claims_steal / claims_mark-stealable | Work-stealing for stalled claims. |
claims_status / claims_list | Inspect current ownership. |
Publish claim events into a federation room (federation_bbs_publish) so ownership converges across
hosts. Message types: ClaimIssued / ClaimReleased / ClaimHandoff / ClaimAck.
Rules: one owner per resourceId; first valid ClaimIssued wins (ties → earliest ts, then smallest
from); ClaimReleased or expired TTL frees it; ClaimHandoff only from the current owner; a
coordinator posts ClaimAck naming the authoritative owner.
Before shared work: claim, sync, and proceed only if you are the acknowledged owner. When a claim
must be both cross-host visible and runtime-enforced, mirror the two — publish the federation claim
message and call claims_claim. See the cross-host-federation skill (ruflo-bbs-federation plugin)
for the transport.
By default every claim event lands in the shared swarm stream, where any relay member reads it. To keep a team's ownership ledger separate — or unreadable by the rest of the relay — publish claim messages into a channel instead:
npx ruflo federation channel --action create --name platform-team --visibility private
npx ruflo federation channel --action grant --channel prv:<hex> --pubkey <teammate 64-hex>
npx ruflo federation channel --action publish --channel prv:<hex> \
--type ClaimIssued --payload '{"resourceId":"repo/foo","ttlSeconds":7200}'
npx ruflo federation channel --action read --channel prv:<hex>Reduction rules are unchanged; only the audience changes. Two caveats before relying on it: a private
channel hides content but not metadata (the relay still sees who published and when), and a claim
nobody outside the channel can read cannot arbitrate against a claim made outside it. If ownership
must be swarm-wide, keep it on the open stream. See the open-federation skill for channel mechanics.
b14c79e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.