agy-auto
Configure agy-auto PreToolUse security gate to run Antigravity CLI (agy) unattended with layered policy controls instead of --dangerously-skip-permissions.
Install / Use
npx skills add sickn33/agentic-awesome-skills --skill agy-autoInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of agy-auto
agy-auto scores 98/100 on our quality scale, 21st of 1,002 Security skills we index (top 3%).
Its SKILL.md is 7.2 KB long, well organised into 19 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.
With 46,875 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 7 days ago, so agy-auto is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
agy-auto compared with similar skills
All 4 of these similar skills score higher than agy-auto; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| agy-auto (this skill)by sickn33 | 98 | 46.9k | 7d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 87.5k | 16d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 9d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 9d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 10d ago | SKILL.md |
Frequently asked questions
- How do I install agy-auto?
- Run
npx skills add sickn33/agentic-awesome-skills --skill agy-auto. The install tabs above show the steps for each supported agent. - Which AI agents does agy-auto work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is agy-auto safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is agy-auto still maintained?
- The repository was last updated 7 days ago, so agy-auto is actively maintained.
Skill content
View source on GitHubname: agy-auto description: "Configure agy-auto PreToolUse security gate to run Antigravity CLI (agy) unattended with layered policy controls instead of --dangerously-skip-permissions." category: security risk: critical source: community source_repo: onkarbadve/agy-auto source_type: community date_added: "2026-09-11" author: onkarbadve tags: [antigravity, agy, security, permissions, sandboxing, guardrails, cli] license: "MIT" license_source: "https://github.com/onkarbadve/agy-auto/blob/main/LICENSE" tools: [antigravity]
agy-auto — Antigravity Auto-Permission & Security Gate
Overview
agy-auto is a PreToolUse hook and security harness for Google Antigravity CLI (agy) that enables safe unattended execution without relying on --dangerously-skip-permissions. It passes every pending tool call through a multi-layered policy gate: deterministic hard-deny rules, deterministic fast-allow for workspace-scoped and read-only operations, an LLM classifier fallback (Gemini Flash Lite or local llama.cpp), and single-use scoped token approvals with Zero Ambient Authority.
When to Use This Skill
- Use when running Antigravity CLI (
agy) unattended or in background agent loops and you want automated tool permissions without exposing system files or credentials. - Use when you need granular, auditable controls over shell commands, file modifications, and network egress during
agyworkflows. - Use when setting up a secure pair-programming environment with Antigravity that prevents prompt injection attacks from escaping the workspace.
How It Works
Step 1: Review, Pin, and Install agy-auto
[!IMPORTANT] Because
agy-autoinstalls as an active PreToolUse hook on the permission evaluation path, never clone a mutable branch directly into your live plugin directory. Always clone to a temporary staging folder, pin an immutable release tag or commit SHA, and inspect the codebase before making the hook executable.
Option A: Native Antigravity Plugin (Recommended)
# 1. Clone into a temporary review directory and checkout an immutable release tag
git clone https://github.com/onkarbadve/agy-auto.git /tmp/agy-auto-review
cd /tmp/agy-auto-review
git checkout v0.2.0-alpha
# 2. Inspect hook.sh and engine/ files before deployment
less hook.sh
python3 -m unittest -v tests/test_engine.py
# 3. Once reviewed and verified, copy to the Antigravity plugin directory and set permissions
mkdir -p ~/.gemini/config/plugins/agy-auto
cp -r . ~/.gemini/config/plugins/agy-auto/
chmod +x ~/.gemini/config/plugins/agy-auto/hook.sh
Ensure toolPermission: "always-proceed" is configured in ~/.gemini/antigravity-cli/settings.json so hooks can gate tool calls:
{
"toolPermission": "always-proceed"
}
Option B: Global Hook via Installer
# 1. Clone to an isolated location and pin release
git clone https://github.com/onkarbadve/agy-auto.git ~/.local/share/agy-auto
cd ~/.local/share/agy-auto
git checkout v0.2.0-alpha
# 2. Review and run the installer
chmod +x hook.sh
./install.sh # registers hook in hooks.json, sets always-proceed, runs smoke tests
Step 2: Policy Evaluation Layers
agy-auto evaluates each tool invocation through sequential layers (first match wins):
- Hard Deny: Immediately blocks recursive deletes outside workspace, credential reads (
~/.ssh,.env, cloud tokens), git history rewrites (push --force,rebase), package publishing, system file writes (/etc, shell rc), and gate tampering. - Fast Allow: Immediately permits parsed read-only commands (
cat,grep,git status) and workspace-confined writes without invoking an LLM. - Classifier: Ambiguous or grey-area commands fall through to an LLM classifier (Google Gemini 3.5 Flash Lite free tier, or a local
llama.cpp/ Ollama endpoint) that reviews the pending call against conversation context and fail-closes on timeout. - Scoped Action Approval: If a command is denied or needs human judgment, the engine issues a single-use 6-character action token bound strictly to
(tool, normalized_cmd, cwd). You approve it by replying> agy-approve <token>in chat. Conversational phrases like "yes" or "proceed" are ignored to prevent ambient authority leakage.
Examples
Example 1: Approving a Blocked Command
When an unclassified command is blocked, agy-auto outputs a token:
tool call denied by pre-tool hook: [agy-auto/classifier] needs human approval: pip install requests. Reply '> agy-approve a1b2c3' in chat to proceed.
To authorize this specific command for a single run, reply directly in the chat:
> agy-approve a1b2c3
Example 2: Configuring a Local Model Backend
To run agy-auto completely offline using llama.cpp or Ollama instead of cloud APIs, edit ~/.gemini/config/agy-auto/policy.toml:
[classifier]
endpoint = "http://127.0.0.1:8080/v1/chat/completions"
model = "qwen2.5-coder:7b"
timeout_s = 20
Example 3: Running Headless Invocations
When invoking agy in headless mode (-p), always pass --add-dir so agy-auto recognizes the workspace boundaries:
agy --add-dir . -p "Run test suite and fix failing cases"
Best Practices
- ✅ Always keep
toolPermission: "always-proceed"enabled so the pre-tool hook can intercept and gate every tool call. - ✅ Add custom repetitive dev tools (e.g. specialized compilers, formatters) to
[fast_allow]in~/.gemini/config/agy-auto/policy.tomlfor instant sub-millisecond execution. - ✅ Pass
--add-dir <path>when running headless commands (agy -p) to prevent false-positive path denials. - ❌ Do not use
--dangerously-skip-permissions;agy-autoprovides safe autonomous execution without removing safety guardrails. - ❌ Do not attempt conversational approval words ("approve", "proceed", "yes"); approvals strictly require the ephemeral action token.
Common Pitfalls
- Problem: Commands fail with
path is outside the workspacewhen runningagy -p. Solution: Headlessagydoes not infer workspace roots automatically. Pass--add-dir .(e.g.agy --add-dir . -p "..."). - Problem: Classifier fails closed with
policy classifier unavailable (The read operation timed out). Solution: Increasetimeout_sin~/.gemini/config/agy-auto/policy.toml(especially when running local LLMs on integrated graphics), or verify yourGEMINI_API_KEY. - Problem: Changes to
policy.tomlorhook.share blocked by[agy-auto/hard_deny]. Solution:agy-autoenforces self-protection against agents tampering with the security gate. Edit policy files directly from your own shell.
Limitations
agy-autoonly intercepts actions performed via tool calls (e.g.run_command,write_to_file); it cannot restrict internal LLM network reasoning or Antigravity's own internal context-gathering file reads.- Requires
toolPermission: "always-proceed"in Antigravity settings to ensure the PreToolUse hook intercepts all tool invocations. - Shell parsing is conservative: complex pipelines with computed variable expansions that cannot be statically resolved will fall through to the LLM classifier or require manual token approval.
Additional Resources
Related Skills
Agent-Reach
87.5kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
