phx-permissions
Recommend safe Bash permissions for Elixir mix commands in settings.json.
Install / Use
npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-permissionsInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
AutomationSupported Platforms
Tags
Our assessment of phx-permissions
phx-permissions scores 81/100 on our quality scale, 2467th of 2,869 Automation skills we index.
Its SKILL.md is 4.9 KB long, well organised into 17 sections with 1 code example: a solid amount of guidance for an agent.
It has 560 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 3 days ago, so phx-permissions is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
phx-permissions compared with similar skills
All 4 of these similar skills score higher than phx-permissions; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| phx-permissions (this skill)by oliver-kriska | 81 | 560 | 3d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 91.6k | 20d ago | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.8k | 1d ago | MCP Server |
| rufloby ruvnet | 100 | 73.9k | today | MCP Server |
| algorithmic-artby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
Frequently asked questions
- How do I install phx-permissions?
- Run
npx skills add oliver-kriska/claude-elixir-phoenix --skill phx-permissions. The install tabs above show the steps for each supported agent. - Which AI agents does phx-permissions work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is phx-permissions safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is phx-permissions still maintained?
- The repository was last updated 3 days ago, so phx-permissions is actively maintained.
Skill content
View source on GitHubname: phx-permissions description: Recommend safe Bash permissions for Elixir mix commands in settings.json. Use when permission prompts slow workflow, "fix permissions", "reduce prompts", "auto-allow mix".
Permission Analyzer
Scan recent session transcripts to find Bash commands you keep approving,
cross-reference with current settings.json, and recommend adding the missing ones.
Primary goal: Discover MISSING permissions from actual usage. Secondary goal: Clean up redundant/garbage entries.
Usage
phx-permissions [--days=14] [--dry-run] — Scans session JSONL files, finds uncovered Bash commands, classifies risk, and recommends settings.json changes. Use --dry-run to preview without writing.
Arguments
$ARGUMENTS — --days=N (default: 14), --dry-run (preview only).
Iron Laws
- NEVER auto-allow RED —
rm,sudo,kill,curl|sh,mix ecto.reset,git push --force,chmod 777 - Evidence-based only — Only recommend commands actually approved in sessions
- Show before writing — Present full diff, get explicit confirmation
- Preserve existing — Merge, never overwrite
Risk Classification
| Level | Examples | Action |
|-------|----------|--------|
| GREEN | ls, cat, grep, tail, which, mkdir, cd, mix test/compile/credo/format, git status/log/diff | Auto-recommend |
| YELLOW | git add/commit/push, mix ecto.migrate, mix deps.get, npm install, docker build/run, source, mise exec | Recommend with note |
| RED | rm -rf, sudo, kill, curl|sh,mix ecto.reset/drop,git push --force,git reset --hard | Never recommend |
Workflow
Step 1: Extract Bash Commands from Session JSONL Files
Run the extraction script from references/extraction-script.md.
This scans all project JSONL files from the last N days, checks each Bash command
against current settings.json patterns, and reports uncovered commands with counts.
Run this before any settings cleanup — missing permissions are the primary goal.
Step 2: Classify and Recommend
For each uncovered command from Step 1 output:
- Classify as GREEN / YELLOW / RED per table above
- Generate permission pattern: normalize to
Bash(base_command *)format (use SPACE before*, NOT colon —:*is deprecated)mkdir -p(94x) →Bash(mkdir *)mise exec(39x) →Bash(mise *)tail -5(20x) →Bash(tail *)
- Check for redundancy: skip if a broader existing pattern covers it
- Also scan for garbage in current settings:
Bash(done),Bash(fi),Bash(__NEW_LINE_*), partial heredocs, entries covered by broader patterns - Fix deprecated
:*patterns — replace anyBash(name:*)withBash(name *)(space before*). The:*suffix is deprecated and may not match reliably
Present a combined table:
## Permission Recommendations (last N days)
### ADD — Missing permissions (from session scan)
| Pattern to Add | Times Used | Risk | Example |
|...
### REMOVE — Redundant/garbage entries
| Entry | Reason |
|...
### RED — Require manual approval (not adding)
| Command | Count | Risk |
|...
Step 3: Interactive Triage (unless --dry-run)
Walk through findings interactively using AskUserQuestion. Present items
in batches by risk level, starting with GREEN (safest):
Batch 1 — GREEN items (read-only, tests, safe tools):
Use AskUserQuestion with options:
- "Add all GREEN" — approve entire batch
- "Pick individually" — show each one for yes/no
- "Skip GREEN" — move to YELLOW
Batch 2 — YELLOW items (write ops, need caution):
Always show individually — one AskUserQuestion per item with options:
- "Add" — include in settings
- "Skip" — keep requiring manual approval
- "Customize" — let user edit the pattern before adding
Batch 3 — REMOVE candidates (garbage/redundant):
Use AskUserQuestion with options:
- "Remove all" — clean up entire batch
- "Pick individually" — show each for yes/no
- "Keep all" — skip cleanup
Track approved items in a list. After triage, show final summary of what will be added/removed and ask for confirmation.
Step 4: Apply
Merge approved additions into ~/.claude/settings.json under permissions.allow.
Remove approved garbage entries. Report final counts.
Workflow-artifact permissions (always check)
The plugin's workflow writes to .claude/plans/, .claude/solutions/, and
.claude/reviews/. If these aren't covered, phx-compound and review agents
get write-blocked mid-workflow. Recommend (GREEN):
Write(.claude/plans/**), Write(.claude/solutions/**), Write(.claude/reviews/**).
References
references/risk-classification.md— Full classification rulesreferences/settings-format.md— Permission pattern format
Related
Long mix output flooding context? phx-mix-compression installs rtk filters
that compress mix test/credo/dialyzer/compile output before it reaches the
transcript (5-15% token savings on mix-heavy sessions).
Related Skills
Agent-Reach
91.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
Scrapling
85.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
ruflo
73.9k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
