Some checks failed
Deploy (Gitea) / deploy (push) Failing after 11s
- Secret Exposure Gate + Privacy Filter (Bouncer) - Shell actuator safety harness (timeout, blocked patterns) - REPL-first enforcement (lisp validation gate, system-prompt-augment) - Engineering Standards lifecycle (two-track Org-first + REPL-first) - Literate Programming discipline (one function per block, reflect-back) - AGENTS.md: thin routing layer, skills are authoritative - SKILLS_DIR removed, ~/notes fallback eliminated - opencortex.sh: multi-distro (Debian+Fedora), configure, install service, backup, restore, help - infrastructure/opencortex.service (systemd user unit) - Docker: updated to debian:trixie, fixed build context - GitHub CI: lint + test workflows fixed, trigger on tags only - Gitea CI: deploy workflow paths fixed - README: one-line curl install, badges - USER_MANUAL: Deployment section (bare metal, Docker, backup) - .gitignore: skills/*.lisp and tests/*.lisp as generated artifacts - Prose/block refactor across all 35 org files - Test suite Tier 1: 43/45 pass (env-dependent failures isolated)
39 lines
1.2 KiB
Org Mode
39 lines
1.2 KiB
Org Mode
#+TITLE: SKILL: Tool Permissions (org-skill-tool-permissions.org)
|
|
#+AUTHOR: Agent
|
|
#+FILETAGS: :skill:security:permissions:
|
|
#+PROPERTY: header-args:lisp :tangle org-skill-tool-permissions.lisp
|
|
|
|
* Overview
|
|
The *Tool Permissions* skill manages the authorization levels for different cognitive tools.
|
|
|
|
* Implementation
|
|
|
|
** Permission store (tool level)
|
|
Hash table mapping tool names to their permission level.
|
|
#+begin_src lisp
|
|
(defvar *tool-permissions* (make-hash-table :test 'equal))
|
|
#+end_src
|
|
|
|
** Set permission
|
|
Sets the permission level for a specific cognitive tool.
|
|
#+begin_src lisp
|
|
(defun set-tool-permission (tool-name level)
|
|
"Sets the permission level for a tool."
|
|
(setf (gethash (string-downcase (string tool-name)) *tool-permissions*) level))
|
|
#+end_src
|
|
|
|
** Get permission
|
|
Retrieves the current permission level for a tool. Defaults to ~:ask~ if unset.
|
|
#+begin_src lisp
|
|
(defun get-tool-permission (tool-name)
|
|
"Retrieves the permission level for a tool. Defaults to :ask."
|
|
(gethash (string-downcase (string tool-name)) *tool-permissions* :ask))
|
|
#+end_src
|
|
|
|
** Skill Registration
|
|
#+begin_src lisp
|
|
(defskill :skill-tool-permissions
|
|
:priority 600
|
|
:trigger (lambda (ctx) (declare (ignore ctx)) nil))
|
|
#+end_src
|