本文へ移動
cccskills
無料GitHub で公開

action-validator

Pre-action boundary checking — validates agent tool calls against declared capabilities and task contracts

インストール方法を見る

含まれるファイル(1)

  • SKILL.md5.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Action Validator Skill

Purpose

Advisory pre-action validation layer that checks agent tool calls against declared capabilities, file access scope (R002), and task contracts before execution. Inspired by AutoHarness (Google DeepMind) — enforcing action-space legality at agent boundaries.

This skill does NOT block actions (R021 advisory-first model). It emits warnings when agents attempt operations outside their declared scope.

Validation Checks

CheckWhatAgainst
Tool scopeTool being calledAgent's tools frontmatter list
File scopeFile path in Write/EditR002 file access rules
Domain scopeTarget file extensionAgent's domain frontmatter
Task contractOperation typeTask description constraints

Advisory Format

--- [Action Validator] Scope warning ---
  Agent: {agent-name}
  Tool: {tool-name}
  Target: {file-path}
  Issue: {description}
  Declared scope: {agent's declared tools/domain}
  💡 Suggestion: {recommended action}
---

Integration Points

SystemHow
PreToolUse hooksOptional hook to check tool calls (advisory only)
pipeline-guardsComplements pipeline stage gates
adversarial-reviewProvides action-space-legality criterion
R002 (Permissions)Validates against declared file access rules
R010 (Orchestrator)Orchestrator validates subagent scope claims

Policy Cache Pattern

For high-repetition agents (e.g., mgr-gitnerd commit workflows), capture validated decision paths as reusable policies:

policy_cache:
  agent: mgr-gitnerd
  action: git-commit
  validated_steps:
    - tool: Bash
      pattern: "git add *"
      verdict: allow
      hints: { safety: normal, parallel: false, approval: auto }
    - tool: Bash
      pattern: "git commit *"
      verdict: allow
      hints: { safety: normal, parallel: false, approval: auto }
    - tool: Bash
      pattern: "git push *"
      verdict: warn_confirm
      hints: { safety: low, parallel: false, approval: needs_approval }

Policy caching reduces redundant LLM calls for well-understood workflows. Policies are advisory — the orchestrator may override.

Capability Hints (Opus 4.7+)

When agents target Opus 4.7 (opus47 model alias), tool capability hints improve batched tool-call planning. Declare per-tool metadata in policy cache entries:

FieldValuesEffect
safetynormal, lowlow triggers confirmation advisory
paralleltrue, falsetrue allows concurrent scheduling
approvalauto, needs_approvalMaps to R002 permission tier

Example: Enhanced Policy Cache with Capability Hints

policy_cache:
  agent: mgr-gitnerd
  action: git-commit
  validated_steps:
    - tool: Bash
      pattern: "git add *"
      verdict: allow
      hints: { safety: normal, parallel: false, approval: auto }
    - tool: Bash
      pattern: "git push *"
      verdict: warn_confirm
      hints: { safety: low, parallel: false, approval: needs_approval }
    - tool: Read
      pattern: "*"
      verdict: allow
      hints: { safety: normal, parallel: true, approval: auto }

Hints are advisory — they inform model scheduling but do not enforce. Inspired by ouroboros PR #353 capability graph pattern.

Code Harness Integration (AutoHarness)

When a synthesized harness exists for an agent (.claude/outputs/harnesses/{agent-name}-*.yaml), action-validator can use it for enhanced validation:

Tool: Writing artifacts under .claude/outputs/

CC sensitive-path check inspects tool target paths and triggers permission prompts on .claude/ regardless of bypassPermissions and allow rules (refs: #960, #961, #978, #981, #1016).

To write action-validator results under .claude/outputs/sessions/:

  1. Write the artifact body to /tmp/action-validator-$(date +%H%M%S).md first (Write tool target = /tmp, no sensitive-path trigger)
  2. Use a /tmp/*.sh Bash script to move/copy the file under .claude/outputs/sessions/$(date +%Y-%m-%d)/ (Bash target = /tmp, script-internal cp to .claude/ is not audited)
  3. Read-only Bash on .claude/outputs/ (e.g., cat, head, wc) is allowed for verification

Reference: feedback_sensitive_path_tmp_bypass.md, R006 sensitive-path handling, #1016, #1045.

ModeSourceBehavior
Advisory (default)Prompt-based checksEmit warnings only
Code-verifiedharness-synthesizer outputRun harness validation code, emit advisory results
Hard-enforce (opt-in)harness-synthesizer --hard-enforceBlock invalid actions (requires explicit opt-in, see R021)

To generate a harness for an agent: /harness-synthesizer --agent {name} --mode verifier

Code harness validation is additive — it supplements prompt-based checks, not replaces them.

Scope

This skill is an advisory layer, not a hard enforcement mechanism:

  • Does: Emit warnings, log scope violations, suggest corrections
  • Does NOT: Block tool execution, modify agent behavior, override R021
  • Future: May integrate with PreToolUse hooks for automated checking (see R021 promotion criteria)

Related Guide

  • guides/harness-engineering/ — 하네스 엔지니어링 통합 가이드 (Behavior Control Layer 관점에서 action-validator 위치)

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Auto-detect project context and optimize harness — deactivate unused agents/skills, suggest missing experts, generate project profile

日本語の概要は準備中です。原文の説明を表示しています。

baekenough/second-brain152026年10月8日 更新

Adversarial code review using attacker mindset — trust boundary, attack surface, business logic, and defense evaluation

日本語の概要は準備中です。原文の説明を表示しています。

baekenough/second-brain152026年10月8日 更新

Apache Airflow best practices for DAG authoring, testing, and production deployment

日本語の概要は準備中です。原文の説明を表示しています。

baekenough/second-brain152026年10月8日 更新

Alembic migration patterns for naming conventions, safety checks, expand-contract, env.py configuration, and CI integration

日本語の概要は準備中です。原文の説明を表示しています。

baekenough/second-brain152026年10月8日 更新

Pre-routing ambiguity analysis — scores request clarity and asks clarifying questions when needed (inspired by ouroboros)

日本語の概要は準備中です。原文の説明を表示しています。

baekenough/second-brain152026年10月8日 更新

AWS patterns from Well-Architected Framework

日本語の概要は準備中です。原文の説明を表示しています。

baekenough/second-brain152026年10月8日 更新

baekenough のスキルをすべて見る

このスキルの問題を報告する