tool-authorization-entrypoints

An inventory of the places where an AI coding agent is shown available tools and where its requests reach executable code. It documents the starting point for a unified permission design without changing how the system runs.

In plain words
What is it for?
Use it to review agent tool access, plan permission migrations, and check how different agent roles should be handled. It is a reference document, not a runtime feature.
Why use it?
It makes scattered tool permissions and call paths visible before they are combined. This helps preserve intended access, including agents that should have no tools, and exposes missing or damaged policies for repair.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/ccdawn/vibelution/tool-authorization-entrypoints
Clone the repo
git clone --depth 1 https://github.com/CCDawn/Vibelution
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 788 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00788
Opus 5 $0.00000 $0.00394
Sonnet 5 $0.00000 $0.00158
Haiku 4.5 $0.00000 $0.00079

Measured 2d ago against content hash 902ce1cf832d, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

tool-authorization-entrypoints scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/agents/tool-authorization-entrypoints.md · 74 lines

How it starts

The opening of the file, as written. The whole thing — 74 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Agent Tool Authorization Entry Points

This inventory is the Milestone 0 baseline for the unified authorization design. It records where tools become visible to a model and where calls reach executable implementations. It does not change runtime behavior.

Policy baselines

Agent class Current policy source Migration requirement
Default session Agent private session default policy Preserve the complete current coding tool assignment
Explicit zero-tool Agent private policy with allowedTools=[] Preserve zero tools as an explicit valid policy
Research fixed role agent_role_tool_profile_service Materialize the role profile as ordinary ToolPolicy v2
Team operation role agent_role_tool_profile_service Materialize bounded context/writeback policy
Self-evolution executor executable session policy Materialize explicit policy without broadening
Supervised/observer role system no-tool role Materialize explicit zero-tool policy
Legacy wide private policy Agent Directory private policy Preserve and label for operator review
Missing/corrupt policy unresolved state Deny all and require repair

The machine-readable baseline is tests/fixtures/tool_authorization/agent_policy_baselines.json.

Model visibility entry points

Entry Run kinds Current authority Target authority
SelfEvolvingAgent._init_llm session, room, team, research, evolution current-Agent filter AuthorizationDecision.visibleTools
SelfEvolvingAgent._get_llm_for_current_mode all Agent modes mode and Agent filters AuthorizationDecision.visibleTools
run_existing_agent_single_turn direct session, chat room Agent-bound surface host TurnToolGrant plus decision
Responses wire projection all LLM turns, replay, parallel bound semantic tools protocol projection of the same decision
Chat Completions wire projection all LLM turns, replay, parallel bound semantic tools protocol projection of the same decision
Subagent runtime binding delegated work parent runtime plus child filter parent grant intersect child policy

Read the full file on GitHub · 74 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 74 lines · 0 tokens per session scan A 902ce1cf832d

Subscribe to this mod's changes

tool-authorization-entrypoints is an agent published in the GitHub repository CCDawn/Vibelution (21 stars, last pushed 4d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 788 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.