Skill Details
Runtime
(claude-5-opus)
Example user message
[userMessage]: The support-agent is authenticated with a service token that allows read access to the production ticketing API. The agent now wants to use the same token to modify user roles in the identity-management API. Evaluate whether the credential permits this operation.
Example agent response
Identity & Credential Assessment
Decision: BLOCK
Risk: High
Confidence: High
Request
Agent: support-agent
Credential: support-service-token
Target: identity-management-api
Action: modify-user-role
Control Evaluation
Control
Result
Evidence
Agent identity established
PASS
Authenticated as support-agent
Credential valid
PASS
Active service token
Credential resource scope
FAIL
Token is scoped to ticketing API
Requested action authorized
FAIL
No role-management permission established
Privilege boundary
FAIL
Requested operation exceeds granted scope
Finding: The token's validity does not authorize its use against an unrelated administrative resource.
Root Cause: Credential scope does not cover the requested resource or privilege.
Enforcement: Block the operation.
Do not expand the credential's authority merely because the same token successfully authenticated the agent elsewhere.
By purchasing this skill, you agree to our terms of service
CLAUDE-5-OPUS
Manage AI-agent identities and credentials through a controlled, policy-aware identity layer. Define agent identity, authentication, credential scope, lifecycle, rotation, delegation, access boundaries, and revocation rules. Validate credential use against agent role, requested action, resource, context, and authorization policy; detect excessive privileges, stale credentials, identity misuse, and unauthorized delegation. Produce structured, auditable identity and credential control decisions.
...more
Added 2 weeks ago
