Skip to content
Module
Module 3 of 5Lesson 4 of 4~14 min

A skill's tools and permissions

A skill that can run commands or edit files without oversight quickly becomes a risk for your data and your repository. This lesson teaches you to decide which tools to allow, remove or keep under approval based on how serious each action is, and to set how the skill is launched and executed.

Lesson objective

By the end of this lesson, you will be able to choose which tools to pre-approve, remove or leave subject to approval for a skill, according to the risk of its actions, and set its invocation and execution mode accordingly.

Topics covered

  • skill permissions
  • allowed-tools
  • skill security
  • Claude Code
  • pre-approved tools

Where it fits

Design and write your skill

How do I write a skill that triggers at the right moment, produces a checkable result and has only the permissions it needs?

Lessons in this module

  1. Write a description that triggers at the right moment
  2. Scope your skill before writing it
  3. Write the SKILL.md and install it
  4. A skill's tools and permissions (this lesson)

What you will learn in the course

This lesson is part of the course Build reliable Claude Skills for your product work

  • Identify a recurring task that justifies a skill rather than a one-off prompt, and explain how the skill is loaded (progressive disclosure).
  • Choose and justify the right mechanism for a given need (skill, CLAUDE.md, subagent, MCP server, hook).
  • Write a name and description that trigger the skill at the right moment, and choose who can invoke it.
  • Design a complete SKILL.md (frontmatter, checkable rules, procedure, output format, reference files) from a scoping brief.
  • Configure a skill's pre-approved and removed tools according to risk, without confusing pre-approval with restriction.
  • Test a skill's triggering and output with evaluation scenarios, iterate, then measure its value over time.
  • Choose, audit and share skills (third-party or internal) while managing the security risks.