Agent Permission Delegation
Reduce child-agent authority to the intersection of parent authority, task needs, organization policy, and currently approved effects.
10 CANONICAL SKILLS · V0.1.0
Least-privilege delegation, exact approvals, budgets, context recovery, loop detection, and independent evaluation.
Run from a full toolkit checkout. This prints a file manifest, not an installer.
node tools/bundle.mjs resolve agent-runtimeReduce child-agent authority to the intersection of parent authority, task needs, organization policy, and currently approved effects.
Place approvals at consequential effect boundaries and bind them to exact scope, inputs, identity, expiry, and execution policy.
Reserve and reconcile agent, token, tool, and effect budgets without converting missing usage into free execution or silently switching billing paths.
Detect repeated no-progress tool calls, equivalent patches, and unchanged failures using bounded evidence windows and explicit stop/escalation criteria.
Evaluate whether delegation improves accepted task outcomes using matched inputs, independent checks, repeated sessions, and explicit handoff/integration scoring.
Allocate task context by relevance and authority while preserving accepted constraints, high-value code, unresolved failures, and recoverable references.
Preserve task state across compaction or handoff with source-backed decisions, unresolved failures, current artifacts, and explicit freshness checks.
Enforce tenant-scoped operations across transports, jobs, data, and caches using trusted identity and independent cross-tenant denial tests.
Design thin MCP adapters with bounded schemas, trusted application identity, shared authorization, and explicit effects rather than treating instructions as permissions.
Select relevant project-owned checks for an observed change and produce an evidence-based verification report that distinguishes passed, failed, skipped, blocked, and not-run checks.
Pick the skill needed for the current task. A private adapter supplies project-specific roots, command IDs, accepted contracts, and policy. It should pin and verify the public revision before exposing guidance to an internal agent.
Skill effectiveness remains experimental. Package validation and content hashes do not establish host compatibility, artifact authenticity, or permission to execute.
Read the private-adapter boundary ↗