insights-rbac: Skill for Cursor

.cursor/skills/ephemeral-rbac/SKILL.md

ephemeral-rbac-diagnose is a skill for Cursor from project-kessel/insights-rbac. It costs 65 tokens per session (2,317 once invoked), scanned A, original, AGPL-3.0.

A troubleshooting guide for access-control data in temporary OpenShift environments. It focuses on relationships, users, permissions, and replication between Postgres and Kessel/SpiceDB.

In plain words
What is it for?
Use it to investigate missing SpiceDB records, empty principals, incorrect permissions, or mismatches between Postgres and Kessel while debugging temporary environments such as crc-eph.
Why use it?
It helps find why access data is missing, empty, or different between systems in an ephemeral environment.

Skill for Cursor

Written for Cursor: installed under .cursor/.

This is project-kessel/insights-rbac's own configuration. It tells Cursor how to work on insights-rbac itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything insights-rbac configures →

Reuse

Borrowing it

Nothing to install: this file belongs to project-kessel/insights-rbac. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/project-kessel/insights-rbac/master/.cursor/skills/ephemeral-rbac/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/project-kessel/insights-rbac

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ephemeral-rbac-diagnose

README.md
[![agentmods](https://agentmods.dev/badge/skills/project-kessel/insights-rbac/ephemeral-rbac/github.svg)](https://agentmods.dev/skills/project-kessel/insights-rbac/ephemeral-rbac)
Your own site
<a href="https://agentmods.dev/skills/project-kessel/insights-rbac/ephemeral-rbac"><img src="https://agentmods.dev/badge/skills/project-kessel/insights-rbac/ephemeral-rbac/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for ephemeral-rbac-diagnose

Your own site · 80×15
<a href="https://agentmods.dev/skills/project-kessel/insights-rbac/ephemeral-rbac"><img src="https://agentmods.dev/badge/skills/project-kessel/insights-rbac/ephemeral-rbac.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 65 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,317 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00065 $0.02317
Opus 5 $0.00032 $0.01158
Sonnet 5 $0.00013 $0.00463
Haiku 4.5 $0.00006 $0.00232

Measured 3d ago against content hash b595bf8bbad0, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

ephemeral-rbac-diagnose scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/diagnose-platform-role-children.sh), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.cursor/skills/ephemeral-rbac/SKILL.md · 221 lines

The source is not reproduced here

Licensed AGPL-3.0

The repository is licensed AGPL-3.0, which this catalogue does not treat as permission to reproduce the file. Read it at the source.

Read it on GitHub

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago Changed b595bf8bbad0
  2. 11d ago First seen · 221 lines · 65 tokens per session scan A ff1922908153

Subscribe to this mod's changes

ephemeral-rbac-diagnose is a skill published in the GitHub repository project-kessel/insights-rbac (11 stars, last pushed today), licensed AGPL-3.0. It adds 65 tokens to every session and 2,317 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

oh-my-posh

Install, configure, or troubleshoot Oh My Posh/ohmyposh: shell init, themes, segments, Nerd Font icons, and prompt setup on PowerShell, zsh, bash, or fish.

JanDeDobbeleer/oh-my-posh · 47 tokens

code-changes

Orchestration workflow for any task that ends in code changes: issue analysis, pull request review, feature implementation, bug fixes, refactors, or fleshing out an idea. MUST be invoked at the start of such a task, before reading or writing any code. Defines how to analyze first, gate on user approval, plan, pick the…

JanDeDobbeleer/oh-my-posh · 88 tokens

mma-investigator

Expert system for investigating MMA (Multi-Metric Allocator) behavior on CockroachDB clusters. Helps oncall engineers diagnose load imbalances, understand rebalancing decisions, and identify why MMA did or didn't act.

cockroachdb/cockroach · 47 tokens

sap-background-jobs

Investigate SAP background jobs, including failed or aborted jobs, job status, job steps, job logs, runtime dumps, TBTCO, TBTCP, and TBTCJOBLOG0-9.

marcellourbani/vscode_abap_remote_fs · 46 tokens

abap-performance-ecc

ABAP performance best practices for ECC / traditional database systems (Oracle, DB2,MSSQL, MaxDB). Use when writing or reviewing ABAP code on NON-HANA systems.IMPORTANT: First use the SAP system info tool to check the system type — if the system is S/4HANA or runs on HANA DB, load the abap-performance-hana skill…

marcellourbani/vscode_abap_remote_fs · 0 tokens

zdx-investigate-multi-app-outage

Diagnose a multi-application outage scoped to one location by correlating ZDX alerts, affected devices, and shared cloud-path hops. Identifies the devices affected at a specific office, compares the per-application network path across multiple SaaS apps to surface the common network bottleneck, and produces an…

zscaler/zscaler-mcp-server · 155 tokens