SkillAgentSearch skills...

adobe-policy-guardrails

Analyze and enforce repository, runtime, data, spend, endpoint, and approval guardrails without guessing secret formats or content-policy rules

Install / Use

npx skills add jeremylongshore/tons-of-skills-marketplace --skill adobe-policy-guardrails

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

83/100

Supported Platforms

Universal

Tags

Our assessment of adobe-policy-guardrails

adobe-policy-guardrails scores 83/100 on our quality scale, 1802nd of 3,554 Development & Engineering skills we index.

Its SKILL.md is 4.2 KB long, well organised into 13 sections and no code examples: a solid amount of guidance for an agent.

With 2,785 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
13/20
Description
15/15
Adoption
15/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 5 days ago, so adobe-policy-guardrails is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

adobe-policy-guardrails compared with similar skills

All 4 of these similar skills score higher than adobe-policy-guardrails; compare them before choosing.

SkillScoreStarsUpdatedFormat
adobe-policy-guardrails (this skill)by jeremylongshore832.8k5d agoSKILL.md
ai-job-searchby MadsLorentzen10044.4k1d agoCLAUDE.md
claude-howtoby luongnv8910041.7k3d agoCLAUDE.md
algorithmic-artby anthropics100177.9k7d agoSKILL.md
pptxby anthropics100177.9k7d agoSKILL.md

Frequently asked questions

How do I install adobe-policy-guardrails?
Run npx skills add jeremylongshore/tons-of-skills-marketplace --skill adobe-policy-guardrails. The install tabs above show the steps for each supported agent.
Which AI agents does adobe-policy-guardrails work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is adobe-policy-guardrails safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is adobe-policy-guardrails still maintained?
The repository was last updated 5 days ago, so adobe-policy-guardrails is actively maintained.

name: adobe-policy-guardrails description: >- Analyze and enforce repository, runtime, data, spend, endpoint, and approval guardrails without guessing secret formats or content-policy rules. Use when the task requires adobe policy and execution guardrails. Trigger with "Adobe guardrails", "block unsafe Adobe calls", or "Adobe policy checks". allowed-tools: Read,Glob,Grep,Write,Edit argument-hint: "<repository-or-service> <operations> <policy-owners>" version: 1.8.0 license: MIT author: Jeremy Longshore jeremy@intentsolutions.io tags: [saas, adobe, guardrails] model: inherit effort: high compatibility: "Designed for Claude Code; live Adobe actions require network access, appropriate entitlement and authentication, and explicit approval"

Adobe Policy and Execution Guardrails

Overview

Analyze and enforce repository, runtime, data, spend, endpoint, and approval guardrails without guessing secret formats or content-policy rules. This workflow produces a reviewable artifact and evidence before any live side effect.

Prerequisites

  • Current first-party Adobe documentation for every selected service, API version, auth flow, limit, and lifecycle.
  • Named product, identity, security, data, budget, release, and operations owners appropriate to the scope.
  • Synthetic or approved non-production fixtures with secret and content canaries.

Current Contract

Guardrails derive from current service docs and local policy: approved auth flows, hosts/versions, scopes/profiles, schemas, storage domains, budgets, data classes, and approval boundaries. Secret prefixes and prompt regexes are not authoritative security or content-policy controls. Recheck the dated evidence map before relying on mutable product behavior.

Authentication

Use mature secret scanners plus entropy/context rules and provider revocation procedures. Runtime authorization evaluates credential binding, entitlement, resource, operation, and approval.

Instructions

  1. Inventory all Adobe calls, credentials, endpoints, versions, payload classes, storage URLs, retries, jobs, events, and destructive operations.
  2. Create allowlists for current hosts/versions/services and denylists for JWT, /sensei/cutout, and retired Lightroom Firefly Services.
  3. Validate configuration/request/response schemas and redact tokens, signed URLs, prompts, and customer content.
  4. Enforce data-purpose, owner, budget, concurrency, idempotency, and approval tokens before side effects.
  5. Route Adobe policy outcomes to a human-readable denial path; never silently rewrite prompts or broaden scopes.
  6. Test bypasses, stale docs, false positives, emergency disablement, exception expiry, and audit receipts.

Tool Discipline

Use Read, Glob, and Grep to inspect current documentation, configuration, code, fixtures, and evidence. Use Write and Edit only for approved repository artifacts. Skill invocation alone does not authorize network access, credentials, Adobe content, consent, uploads, generation, spend, deployment, registration changes, replay, cancellation, or deletion.

Approval Boundaries

Security/product/data/budget owners approve policy and exceptions. Generation, upload, deploy, webhook change, cancellation, replay, and deletion remain independently approved actions.

Error Handling

  • Do not claim Adobe secrets always have a specific prefix.
  • Do not claim local regexes predict Firefly policy decisions.
  • Fail closed when endpoint/version or approval evidence is unknown.

Output

Return policy sources, allow/deny rules, enforcement points, test corpus, exceptions, receipts, drift monitor, and owners. Mark assumptions, observed environment behavior, owners, evidence dates, and unresolved gaps explicitly.

Examples

  • Block /sensei/cutout before network execution.
  • Detect a signed URL in a log fixture and fail the gate.

Validation

Exercise and record expected and observed results for:

  • obsolete route
  • unknown host
  • secret leak
  • policy outcome
  • budget ceiling
  • expired exception

Resources

  • Current first-party evidence map — recheck dated Adobe sources before execution.
  • Treat observed tenant or product behavior as environment-specific evidence, never a universal Adobe guarantee.

Related Skills

View on GitHub
GitHub Stars2.8k
CategoryDevelopment
Updated5d ago
Forks404

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions