audit-permission-grants
Purpose
Audit whether a repo's permission grants actually take effect. Answers a question the sibling
audit skill does not: "Are our allow-rules and allowed-tools grants portable across
machines and durable when the session enters auto mode — and is the operative rule in a place that can
work?"
The principle, the three anti-patterns, and the correct pattern (with official-doc citations) live in the marketplace's permission-rule-hygiene convention, published at https://raw.githubusercontent.com/melodic-software/claude-code-plugins/main/docs/conventions/permission-rule-hygiene/README.md. The mechanical check definitions (P1/P2/P3, severities, detector invocation) are in reference/criteria.md, which carries every recommendation this skill needs at run time — the convention is the doctrine's owner, not a runtime dependency.