Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/ccdawn/vibelution/tool-authorization-entrypointsgit clone --depth 1 https://github.com/CCDawn/VibelutionWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00788 |
| Opus 5 | $0.00000 | $0.00394 |
| Sonnet 5 | $0.00000 | $0.00158 |
| Haiku 4.5 | $0.00000 | $0.00079 |
Grade A, and why
tool-authorization-entrypoints scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent Tool Authorization Entry Points
This inventory is the Milestone 0 baseline for the unified authorization design. It records where tools become visible to a model and where calls reach executable implementations. It does not change runtime behavior.
Policy baselines
| Agent class | Current policy source | Migration requirement |
|---|---|---|
| Default session Agent | private session default policy | Preserve the complete current coding tool assignment |
| Explicit zero-tool Agent | private policy with allowedTools=[] |
Preserve zero tools as an explicit valid policy |
| Research fixed role | agent_role_tool_profile_service |
Materialize the role profile as ordinary ToolPolicy v2 |
| Team operation role | agent_role_tool_profile_service |
Materialize bounded context/writeback policy |
| Self-evolution executor | executable session policy | Materialize explicit policy without broadening |
| Supervised/observer role | system no-tool role | Materialize explicit zero-tool policy |
| Legacy wide private policy | Agent Directory private policy | Preserve and label for operator review |
| Missing/corrupt policy | unresolved state | Deny all and require repair |
The machine-readable baseline is tests/fixtures/tool_authorization/agent_policy_baselines.json.
Model visibility entry points
| Entry | Run kinds | Current authority | Target authority |
|---|---|---|---|
SelfEvolvingAgent._init_llm |
session, room, team, research, evolution | current-Agent filter | AuthorizationDecision.visibleTools |
SelfEvolvingAgent._get_llm_for_current_mode |
all Agent modes | mode and Agent filters | AuthorizationDecision.visibleTools |
run_existing_agent_single_turn |
direct session, chat room | Agent-bound surface | host TurnToolGrant plus decision |
| Responses wire projection | all LLM turns, replay, parallel | bound semantic tools | protocol projection of the same decision |
| Chat Completions wire projection | all LLM turns, replay, parallel | bound semantic tools | protocol projection of the same decision |
| Subagent runtime binding | delegated work | parent runtime plus child filter | parent grant intersect child policy |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 74 lines · 0 tokens per session scan A 902ce1cf832d
tool-authorization-entrypoints is an agent published in the GitHub repository CCDawn/Vibelution (21 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 788 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
medical-learning-safety-reviewer
审校医学学习草稿的来源、教育边界、患者隐私和输出风险;只返回审校意见,不处理外部动作或状态写入。.
guideline-learning-designer
将主助手已核验的指南材料组织成安全、可继续展开的学习地图、流程关系、学习诊断或复习路径;不处理真实患者决策。.
ingest-confluence
Ingest one Confluence page into an AKB vault as a five-section LLM-wiki summary document, fetched live via the Atlassian MCP server.
ingest-doc
Ingest one document (local file or web URL) into an AKB vault as a five-section LLM-wiki summary page, optionally preserving the original bytes in the raw file layer.
ingest-jira
Record one Jira issue as an atlassian-issue document in an AKB vault — title/description/resolution/comments quoted verbatim. Fetched live via the Atlassian MCP server; always upsert.
ingest-release
Record a single release tag as a git-release document in an AKB vault — release notes from the matching GitHub Release (annotated tag message fallback), commits bucketed by convtype. Requires range commits pre-ingested.