Help us improve
Share bugs, ideas, or general feedback.
From claude-ecosystem
Guides Claude Code permission configuration, rules (allow/ask/deny), modes, tool-specific patterns (Bash/read/edit/WebFetch), /permissions command, and troubleshooting via docs-management delegation.
npx claudepluginhub melodic-software/claude-code-plugins --plugin claude-ecosystemHow this skill is triggered — by the user, by Claude, or both
Slash command
/claude-ecosystem:permission-managementThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
> **STOP - Before providing ANY response about Claude Code permissions:**
Configures Claude Code permissions: tool rules (allow/deny/ask), modes (plan/dontAsk/bypass), sandboxing. Use for Bash/Edit/WebFetch policies, debugging prompts, org managed settings.
Provides reference for Claude Code permission modes (default, acceptEdits, plan, dontAsk, bypass), allow/deny lists, pattern matching, and tool categories. Use to configure secure tool access and switch modes runtime.
Reviews and manages opencode permission configs: summarizes allowed commands, suggests safe read-only auto-approvals, and edits allow/deny/ask patterns.
Share bugs, ideas, or general feedback.
STOP - Before providing ANY response about Claude Code permissions:
- INVOKE
docs-managementskill- QUERY for the user's specific topic
- BASE all responses EXCLUSIVELY on official documentation loaded
Skipping this step results in outdated or incorrect information.
Before responding, verify:
If ANY checkbox is unchecked, STOP and invoke docs-management first.
Central authority for Claude Code permissions. This skill uses 100% delegation to docs-management - it contains NO duplicated official documentation.
Architecture: Pure delegation with keyword registry. All official documentation is accessed via docs-management skill queries.
Keywords: permissions, allow rules, deny rules, ask rules, permission modes, defaultMode, acceptEdits, bypassPermissions, plan mode, tool permissions, Bash permissions, Read permissions, Edit permissions, WebFetch permissions, MCP permissions, additionalDirectories, /permissions
Use this skill when:
Use these keywords when querying docs-management skill for official documentation:
| Topic | Keywords |
|---|---|
| Overview | "permission system", "tiered permissions", "approval required" |
| Configuration | "configuring permissions", "/permissions command" |
| Rule Types | "allow rules", "ask rules", "deny rules" |
| Precedence | "rule precedence", "deny > ask > allow" |
⚠️ STALENESS WARNING: Do NOT hardcode permission mode names or values. Query docs-management for the authoritative list of permission modes.
| Topic | Query Pattern | What You'll Find |
|---|---|---|
| All Modes | "iam.md permission modes" | Complete list of available modes |
| Mode Behavior | "iam.md defaultMode acceptEdits" | Mode descriptions and effects |
| Mode Configuration | "iam.md configuring permission mode" | How to set modes |
⚠️ STALENESS WARNING: Do NOT hardcode tool names or pattern syntax. Query docs-management for the authoritative list of tools and permission patterns.
| Topic | Query Pattern | What You'll Find |
|---|---|---|
| Bash Rules | "iam.md Bash permissions pattern matching" | Bash permission syntax |
| File Rules | "iam.md Read Edit permissions gitignore" | File permission patterns |
| Path Patterns | "iam.md path pattern types" | Absolute, home, relative patterns |
| WebFetch Rules | "iam.md WebFetch domain permissions" | Domain pattern syntax |
| MCP Rules | "iam.md MCP permissions mcp__server" | MCP tool permission syntax |
⚠️ SECURITY: These topics cover security-sensitive permission behaviors. Query docs-management for the authoritative guidance.
| Topic | Query Pattern | What You'll Find |
|---|---|---|
| Wildcard + Shell Operators | "iam.md wildcard rules shell operators compound commands" | SECURITY FIX (v2.1.7): Wildcard rules matching compound commands |
| Line Continuation Bypass | "iam.md permission bypass line continuation" | SECURITY FIX (v2.1.6): Shell line continuation escape prevention |
| Topic | Keywords |
|---|---|
| Additional Dirs | "additionalDirectories", "--add-dir" |
| Working Directory | "working directories", "file access scope" |
What do you want to do?
| Issue | Keywords for docs-management |
|---|---|
| Permission too restrictive | "allow rules", "auto-approve" |
| Permission too permissive | "deny rules", "prevent usage" |
| Wrong mode active | "permission modes", "defaultMode" |
| MCP tools blocked | "MCP permissions", "mcp__server" |
| Can't access files | "additionalDirectories", "--add-dir" |
v1.1.0 (2026-01-16): Security fixes keyword registry
v1.0.0 (2025-11-30): Initial release (split from security-meta)
Date: 2026-01-16 Model: claude-opus-4-5-20251101