permission-gate-inherits-operator-allow-list
v1.1.0Audit what a service actually auto-runs when it reuses a permission gate built for an interactive terminal. The gate reads a human's editor settings, so an agent or bot driven by other people's input inherits that human's personal allow-list -- measured on one deployment: 123 Bash() patterns, including gh pr merge, gh api and codex exec, auto-running with no approval card. Use when a command you expected to need approval ran without one, when a verdict says "matches user allow pattern", when wiring such a gate into a service, or when a suite's verdicts change with whose machine runs it. Covers locating the discovery paths, measuring and proving the surface with the gate's own verdicts, cutting the inheritance off upstream rather than around it, and asserting at boot that it stayed cut.
By voitta-aiLicense: MIT3 GitHub starsUpdated 2 hours ago
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 0 skill or MCP entries
- Source updated
- Sep 28, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install permission-gate-inherits-operator-allow-list for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install permission-gate-inherits-operator-allow-list@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/voitta-ai/skillzClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/permission-gate-inherits-operator-allow-list/.
Plugin files
└── .claude-plugin/plugin.json
Plugin manifests1
{
"name": "permission-gate-inherits-operator-allow-list",
"description": "Audit what a service actually auto-runs when it reuses a permission gate built for an interactive terminal. The gate reads a human's editor settings, so an agent or bot driven by other people's input inherits that human's personal allow-list -- measured on one deployment: 123 Bash() patterns, including gh pr merge, gh api and codex exec, auto-running with no approval card. Use when a command you expected to need approval ran without one, when a verdict says \"matches user allow pattern\", when wiring such a gate into a service, or when a suite's verdicts change with whose machine runs it. Covers locating the discovery paths, measuring and proving the surface with the gate's own verdicts, cutting the inheritance off upstream rather than around it, and asserting at boot that it stayed cut.",
"version": "1.1.0",
"author": {
"name": "voitta-ai"
},
"homepage": "https://github.com/voitta-ai/skillz",
"repository": "https://github.com/voitta-ai/skillz",
"license": "MIT",
"skills": "./skills/"
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[permission-gate-inherits-operator-allow-list on Agent Plugins Marketplace](https://pluginsmp.com/plugins/permission-gate-inherits-operator-allow-list)