permission-manager
Manage opencode permissions: review always-allow lists, suggest safe read-only commands, configure permission patterns
Install
npx skills add https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/permission-manager
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install sickn33-agentic-awesome-skills@llmmart
git clone https://github.com/sickn33/agentic-awesome-skills.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole sickn33/agentic-awesome-skills collection as a plugin from our marketplace. Git is the plain clone.
README
permission-manager
Manage opencode permissions: review always-allow lists, suggest safe read-only commands, configure permission patterns.
What it does
- Reviews and summarizes currently always-allowed commands
- Suggests safe read-only commands for auto-approval
- Adds or removes commands from the allow list in opencode.json
- Configures skill-level permissions (allow/deny/ask) with wildcard patterns
- Audits permission configs for security and usability
When to use
Use this when optimizing opencode's permission settings, reviewing allowed commands, or configuring skill access controls.
Key capabilities
- Config review: Loads
~/.config/opencode/opencode.jsonor project-level config - Permission summary: Identifies currently allowed commands and skill permissions
- Safe commands: Suggests reviewed read-only commands such as
git status --short,git log --oneline,rg,grep, andcat; broad trailing wildcards need manual review. - Change application: Edits config to add/remove permission entries, validates JSON
Skill manifest
What I do
- Review and summarize currently always-allowed commands
- Suggest safe read-only commands for auto-approval
- Add or remove commands from the allow list in opencode.json
- Configure skill-level permissions (allow/deny/ask) with wildcard patterns
- Audit permission configs for security and usability
When to Use
Use this when optimizing opencode's permission settings, reviewing allowed commands, or configuring skill access controls.
Workflow Steps
- Read current config: Load
~/.config/opencode/opencode.jsonor project-levelopencode.json - Summarize permissions: Identify currently allowed commands and skill permissions
- Suggest additions: Propose safe read-only commands for auto-allow (see recommended list below)
- Apply changes: Edit the config to add/remove permission entries
- Validate: Ensure JSON is valid after changes
Complements opencode's built-in allow/deny/ask permissions by auditing current config and recommending adjustments through conversation.
Key Rules
- Never allow commands that modify files, commit, push, or change system state
- Prefer exact command entries such as
git status --short,git diff --stat, andls -la - Avoid trailing wildcards such as
git status*unless the expanded command family has been manually reviewed as read-only - Confirm with user before modifying permission config
- Distinguish between bash command permissions and skill permissions
- Keep config organized: group related commands together
Limitations
- This skill is scoped to opencode permission configuration and should not modify other agent hosts' permission stores.
- Treat all write-capable command permissions as high-risk; review them manually even when a pattern looks narrow.
How to trigger me
Use the Task tool with the permission-manager subagent type:
/permissions
Or in natural language, ask opencode to "manage opencode permissions" or "review allowed commands".
Files (agentic-awesome-skills)
-
README.md 1 KB
# permission-manager Manage opencode permissions: review always-allow lists, suggest safe read-only commands, configure permission patterns. ## What it does - Reviews and summarizes currently always-allowed commands - Suggests safe read-only commands for auto-approval - Adds or removes commands from the allow list in opencode.json - Configures skill-level permissions (allow/deny/ask) with wildcard patterns - Audits permission configs for security and usability ## When to use Use this when optimizing opencode's permission settings, reviewing allowed commands, or configuring skill access controls. ## Key capabilities - **Config review**: Loads `~/.config/opencode/opencode.json` or project-level config - **Permission summary**: Identifies currently allowed commands and skill permissions - **Safe commands**: Suggests reviewed read-only commands such as `git status --short`, `git log --oneline`, `rg`, `grep`, and `cat`; broad trailing wildcards need manual review. - **Change application**: Edits config to add/remove permission entries, validates JSON -
SKILL.md 2.3 KB
--- name: permission-manager version: 1.0.0 description: "Manage opencode permissions: review always-allow lists, suggest safe read-only commands, configure permission patterns" risk: critical source: community source_type: community source_repo: mskadu/opencode-agent-skills license: MIT license_source: "https://github.com/mskadu/opencode-agent-skills/blob/main/LICENSE" date_added: "2026-06-05" --- ## What I do - Review and summarize currently always-allowed commands - Suggest safe read-only commands for auto-approval - Add or remove commands from the allow list in opencode.json - Configure skill-level permissions (allow/deny/ask) with wildcard patterns - Audit permission configs for security and usability ## When to Use Use this when optimizing opencode's permission settings, reviewing allowed commands, or configuring skill access controls. ## Workflow Steps 1. **Read current config**: Load `~/.config/opencode/opencode.json` or project-level `opencode.json` 2. **Summarize permissions**: Identify currently allowed commands and skill permissions 3. **Suggest additions**: Propose safe read-only commands for auto-allow (see recommended list below) 4. **Apply changes**: Edit the config to add/remove permission entries 5. **Validate**: Ensure JSON is valid after changes Complements opencode's built-in allow/deny/ask permissions by auditing current config and recommending adjustments through conversation. ## Key Rules - Never allow commands that modify files, commit, push, or change system state - Prefer exact command entries such as `git status --short`, `git diff --stat`, and `ls -la` - Avoid trailing wildcards such as `git status*` unless the expanded command family has been manually reviewed as read-only - Confirm with user before modifying permission config - Distinguish between bash command permissions and skill permissions - Keep config organized: group related commands together ## Limitations - This skill is scoped to opencode permission configuration and should not modify other agent hosts' permission stores. - Treat all write-capable command permissions as high-risk; review them manually even when a pattern looks narrow. ## How to trigger me Use the Task tool with the `permission-manager` subagent type: ``` /permissions ``` Or in natural language, ask opencode to "manage opencode permissions" or "review allowed commands".
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.