consensus-permission-escalation-guard
/install consensus-permission-escalation-guard
consensus-permission-escalation-guard
consensus-permission-escalation-guard is the final safety gate before privilege elevation is applied.
What this skill does
- validates escalation requests against a strict input schema (reject unknown fields)
- evaluates hard-block and rewrite policy flags for IAM risk patterns
- runs persona-weighted voting (or aggregates external votes)
- returns one of:
ALLOW | BLOCK | REQUIRE_REWRITE - writes decision artifacts for replay/audit
Decision policy shape
Hard-block examples:
- wildcard permissions (
*,: *, broad owner/admin jumps) - missing ticket reference when required
- break-glass escalation without incident reference
- separation-of-duties conflicts (e.g., create + approve authority)
Rewrite examples:
- weak or non-actionable justification
- temporary duration exceeds policy limit
- production escalation requires explicit human confirmation gate
Runtime and safety model
- runtime binaries:
node,tsx - network behavior: none in deterministic guard logic
- environment config read by this package:
CONSENSUS_STATE_FILE,CONSENSUS_STATE_ROOT - filesystem writes: consensus board/state artifacts under configured state path
Invoke contract
invoke(input, opts?) -> Promise\x3COutputJson | ErrorJson>
Modes:
mode="persona"(default): uses local deterministic persona defaults for internal votingmode="external_agent": consumeexternal_votes[], then aggregate and enforce policy deterministically
Install
npm i consensus-permission-escalation-guard
Quick start
node --import tsx run.js --input ./examples/input.json
Tests
npm test
Test coverage includes schema rejection, hard-block paths, rewrite paths, allow paths, idempotent retries, and external-agent aggregation behavior.
Note: this skill depends on consensus-guard-core for aggregation/state helpers; review that package alongside this one for full runtime auditability.
See also: SECURITY-ASSURANCE.md for threat model, runtime boundaries, and deployment hardening guidance.
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install consensus-permission-escalation-guard - 安装完成后,直接呼叫该 Skill 的名称或使用
/consensus-permission-escalation-guard触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
consensus-permission-escalation-guard 是什么?
Pre-execution governance for IAM and permission escalation changes. Use when an agent or workflow proposes granting, expanding, or assuming higher privileges... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 539 次。
如何安装 consensus-permission-escalation-guard?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install consensus-permission-escalation-guard」即可一键安装,无需额外配置。
consensus-permission-escalation-guard 是免费的吗?
是的,consensus-permission-escalation-guard 完全免费(开源免费),可自由下载、安装和使用。
consensus-permission-escalation-guard 支持哪些平台?
consensus-permission-escalation-guard 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 consensus-permission-escalation-guard?
由 Kai Cianflone(@kaicianflone)开发并维护,当前版本 v0.1.13。