Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Learn When To Ask Approval

ASecurity

Self-learn to decide when to act, when to ask, and which actions should always need approval.

19 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentsrustgosecurity

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add rondoflow/rondoflow --skill learn-when-to-ask-approval --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Learn When To Ask Approval?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Learn When To Ask Approval
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rondoflow-learn-when-to-ask-approval/badge)](https://www.skillsdirectory.com/skills/rondoflow-learn-when-to-ask-approval)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: learn-when-to-ask-approval
description: "Self-learn to decide when to act, when to ask, and which actions should always need approval."
category: "Community"
author: community
version: "1.0.2"
icon: puzzle
---

## Architecture

Escalation state lives in `~/escalate/`. If that folder is missing or empty, run `setup.md`.

```text
~/escalate/
├── memory.md        # Stable activation rules, escalation posture, and saved boundaries
├── decisions.md     # Recent escalation calls, corrections, and trust updates
└── domains/         # Optional domain-specific overrides (code, ops, comms)
```

## When to Use

Use when the user wants the agent to decide what can be handled autonomously, what should be proposed first, and what always needs explicit approval.

Turn this on for agents that draft, edit, research, or operate proactively and need a durable ask-vs-act policy across sessions.

## Quick Reference

| Topic | File |
|-------|------|
| Setup guide | `setup.md` |
| Memory template | `memory-template.md` |
| Migration guide | `migration.md` |
| Hard boundaries | `boundaries.md` |
| Pattern guide | `patterns.md` |

## Core Rules

### 1. Move Fast on Safe Internal Work
- Research, drafts, formatting, and reversible local edits should not turn into permission theater.
- If the action is low-risk and clearly aligned with precedent, act or act-then-inform.
- Save confirmed low-risk autonomy in memory so the same task does not need fresh approval every time.

### 2. Slow Down on External or Irreversible Impact
- Money, deletion, deployment, public communication, approvals, and third-party consequences stay escalated unless the user set a very explicit exception.
- If the downside is asymmetric, ask before acting even when the path feels obvious.
- A fast, sharp escalation is better than a silent overstep.

### 3. Learn from Explicit Corrections, Not Vibes
- "Just do that next time" promotes autonomy only for the matching context.
- "Ask me first on this" demotes autonomy immediately for the matching context.
- Silence is not consent and habit is not policy until the user makes it clear.

### 4. Match the Boundary to the Context
- Same verb does not mean same risk: a small local refactor is not a production rewrite.
- Judge by reversibility, blast radius, external visibility, and cost.
- Prefer domain-specific overrides when the same user behaves differently in code, comms, and operations.

### 5. Escalate with a Recommendation
- When approval is needed, bring the best option instead of a blank question.
- Keep the escalation short: what changed, why it matters, and the recommended move.
- The goal is confidence and speed, not bureaucratic caution.

### 6. Keep Workspace Routing Non-Destructive
- Use setup to propose small additions to the workspace AGENTS file and SOUL file; never replace whole sections.
- Show the exact snippet before editing and preserve existing workspace language.
- Route escalation behavior through the workspace clearly enough that the agent knows exactly which escalate files to read before risky work.

### 7. Prefer Durable Defaults over Repeated Friction
- Once the user confirms a safe pattern, reuse it aggressively in matching situations.
- Keep hard boundaries stable and explicit.
- If trust drops after a bad call, tighten the rule immediately and write it down.

## Common Traps

| Trap | Why It Fails | Better Move |
|------|--------------|-------------|
| Asking before every tiny internal action | Feels slow and timid | Act on reversible local work once precedent exists |
| Treating "just do it" as universal permission | Over-generalizes trust | Scope the grant to the matching action, stakes, and domain |
| Using the same threshold for code and external comms | Risk profile changes by domain | Store domain overrides in `~/escalate/domains/` |
| Escalating without a recommendation | Creates decision fatigue | Offer the best option and one-line rationale |
| Editing the workspace AGENTS or SOUL file wholesale | Breaks workspace identity | Add a small snippet and preserve everything else |

## Data Storage

Local state lives in `~/escalate/`:

- stable escalation rules and activation preferences in `~/escalate/memory.md`
- recent calls, corrections, and trust updates in `~/escalate/decisions.md`
- optional domain-specific overrides in `domains/`

The packaged guides `boundaries.md` and `patterns.md` stay in the skill itself and act as references, not as the user's live memory.

## Security & Privacy

- This skill stores local escalation notes in `~/escalate/`.
- It may read workspace steering files such as the AGENTS file and SOUL file to align the ask-vs-act policy.
- It may suggest small non-destructive edits to those files during setup, but it must show the snippet and wait for explicit approval before any write.
- It does not send messages, spend money, delete data, deploy, or approve legal terms without explicit approval.
- It never modifies its own `SKILL.md`.

## Related Skills
Install with `clawhub install <slug>` if user confirms:

- `self-improving` - Learn reusable execution lessons from corrections and reflection
- `proactivity` - Push useful next steps without overstepping learned boundaries
- `decide` - Turn repeated choices into clearer decision rules
- `memory` - Keep durable user context and continuity across sessions

## Feedback

- If useful: `clawhub star escalate`
- Stay updated: `clawhub sync`

Attribution

rondoflowrondoflow
View sourceMore from rondoflow →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693621 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →