Writing Denied-Path Matrices
Use when proposed agent tool access needs explicit denied actor, resource, action, target, argument, scope, or data-class cases before capability is granted.
Turn proposed agent tool access into denied-path tests that prove forbidden tools, targets, arguments, prompt-injected requests, policy failures, and side effects fail before real authority is granted.
This is a complete workflow library with 4 individual skills. Download the full library or pick the specific skill folder your team needs first.
Some AI tools expect one skill folder per upload. Download the full library when you want the whole workflow, or download an individual skill when you only need one job done.
Use when proposed agent tool access needs explicit denied actor, resource, action, target, argument, scope, or data-class cases before capability is granted.
Use when denied authorization rows must become deterministic policy, wrapper, sandbox, MCP, gateway, parser, or CI fixtures.
Use when a denied tool call needs evidence that no external or persistent state changed despite retries, partial execution, or misleading error text.
Use when denied-path results must decide whether an agent capability can move from draft or shadow use into broader tool authority.
Use the public library when the workflow is low-risk, the inputs are already sanitized, and a team member can review the output before it reaches a buyer or customer.
Do deeper review when this workflow touches real tools, data sources, role ownership, approval paths, or customer-facing output.