permission-manager
Manage opencode permissions: review always-allow lists, suggest safe read-only commands, configure permission patterns
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
What I do
- Review and summarize currently always-allowed commands
- Suggest safe read-only commands for auto-approval
- Add or remove commands from the allow list in opencode.json
- Configure skill-level permissions (allow/deny/ask) with wildcard patterns
- Audit permission configs for security and usability
When to Use
Use this when optimizing opencode's permission settings, reviewing allowed commands, or configuring skill access controls.
Workflow Steps
- Read current config: Load
~/.config/opencode/opencode.jsonor project-levelopencode.json - Summarize permissions: Identify currently allowed commands and skill permissions
- Suggest additions: Propose safe read-only commands for auto-allow (see recommended list below)
- Apply changes: Edit the config to add/remove permission entries
- Validate: Ensure JSON is valid after changes
Complements opencode's built-in allow/deny/ask permissions by auditing current config and recommending adjustments through conversation.
Key Rules
- Never allow commands that modify files, commit, push, or change system state
- Prefer exact command entries such as
git status --short,git diff --stat, andls -la - Avoid trailing wildcards such as
git status*unless the expanded command family has been manually reviewed as read-only - Confirm with user before modifying permission config
- Distinguish between bash command permissions and skill permissions
- Keep config organized: group related commands together
Limitations
- This skill is scoped to opencode permission configuration and should not modify other agent hosts' permission stores.
- Treat all write-capable command permissions as high-risk; review them manually even when a pattern looks narrow.
How to trigger me
Use the Task tool with the permission-manager subagent type:
/permissions
Or in natural language, ask opencode to "manage opencode permissions" or "review allowed commands".
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
同名技能的其他版本
有 3 个不同仓库或目录里都有叫 permission-manager 的技能。它们内容并不相同,别混用:
- sickn33/agentic-awesome-skills — Manage opencode permissions: review always-allow lists, suggest safe read-only commands, c
- sickn33/agentic-awesome-skills — Manage opencode permissions: review always-allow lists, suggest safe read-only commands, c