Skip to main content
Back to Skill Library
Agent governance workflow library

Agent tool authority review

Review context quarantine, permission cards, service identities, capability diffs, tool-result influence, browser profiles, and GitHub inputs before changing agent authority.

This is a complete workflow library with 7 individual skills. Download the full library or pick the specific skill folder your team needs first.

Individual skills in this library

Use one skill at a time, or keep the full workflow together.

Some AI tools expect one skill folder per upload. Download the full library when you want the whole workflow, or download an individual skill when you only need one job done.

Skill 1

Agent context quarantine mapper

Use when an agent reads untrusted webpages, emails, documents, retrieval results, logs, issues, comments, or tool output before acting.

Skill 2

Agent permission card writer

Use when an agent, connector, MCP server, browser profile, repository workflow, or automation needs scoped permissions before tool access.

Skill 3

Agent service identity assigner

Use when an agent acts through a human browser session, broad user token, shared credential, or service account.

Skill 4

Agent capability diff reviewer

Use when an updated agent, prompt, Skill, connector, tool, memory path, or retrieval path changes what the workflow can do.

Skill 5

Tool result influence boundary mapper

Use when tool output, API response, browser content, repository text, image output, or retrieval content may steer planning, memory, tool selection, or action.

Skill 6

Browser agent profile isolator

Use when a browser agent needs a profile, cookies, session state, extension access, downloads, or remote debugging access.

Skill 7

GitHub agent input reviewer

Use when an agent reads or acts on GitHub issues, pull requests, comments, workflow files, repo rules, code review text, or generated patches.

Security fit check

Is the public Agent tool authority review library enough, or does this need deeper review?

Use the public library when the workflow is low-risk, the inputs are already sanitized, and a team member can review the output before it reaches a buyer or customer.

Do deeper review when this workflow touches real tools, data sources, role ownership, approval paths, or customer-facing output.

Tool authorityAI OperationsSecurityPlatform Owner

Good deeper-review trigger signals

  • The workflow touches customer, prospect, CRM, proposal, security, pricing, or campaign data.
  • Different teams disagree on the approved source of truth.
  • The AI output could become customer-facing, revenue-impacting, or compliance-sensitive.
  • You need reusable eval checks before asking more people to use the workflow.