cognee-permissions

レビュー · 72
Registry に収録

Use when working with cognee's permission system — understanding or changing how users, roles, and tenants get access to datasets, how ACL grants work, where permissions are enforced in add/cognify/search/delete, and how the grant records surface in the memory-provenance view.

Verified installs0
スター30.2K
バージョン1.0.0
品質92/100 · 優秀
信頼72/100 · サンドボックス限定
監査87/100 · 要レビュー

供給アセットの概要

リサーチとナレッジ作業

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

カテゴリを見る

シナリオ

RAG and knowledge

I need my agent to build a RAG workflow over documents and retrieve reliable context.

Agent 適合

Claude Code + CLI + Codex

Codex、Claude Code、Cursor、CLI、またはカスタム Agent に対応します。

インストール

準備完了

npx skills add topoteretes/cognee --skill cognee-permissions

メンテナンス

新しい

本日プッシュ

リスク

要レビュー

Permission surface may require sandboxing

GitHub 品質

30K

92/100 品質 · 80/100 信頼

対象タグ

リサーチRAG and knowledgeagent-skill

レビュー注記

Permission surface may require sandboxing · SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.

Agent 導入スコアカード

信頼、監査、インストール準備状況を一目で確認

公開リポジトリのメタデータ、OpenAgentSkill のレビューシグナル、保守の鮮度、インストール準備状況を組み合わせたスコアです。候補選定の目安であり、人によるレビューの代替ではありません。

品質

優秀
92

採用度と保守性のシグナルが強い高信頼候補です。

信頼

サンドボックス限定
72

信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。

監査

要レビュー
87

インストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。

OpenAgentSkill Trust Score v5

インストール前に人のレビュー

実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。

CodexClaude CodeCursorOpenAgentSkill CLI

スター

GitHub スター 30K

リポジトリ活動

スター 30K、フォーク 3.0K

メンテナンス

本日プッシュ

ライセンス

Apache-2.0

インストール

npx skills add topoteretes/cognee --skill cognee-permissions

インストール安全性

標準パッケージまたはランタイムのインストールパス

権限範囲

filesystem or document access, network or browser access

Agent の成果

Agent の成果データはまだありません

ドキュメント

Usable metadata, review docs

リスク概要

本番前にレビュー

  • SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
  • Quality score needs review
  • Permission surface needs review: filesystem or document access, network or browser access
  • Permission surface: filesystem or document access, network or browser access

インストール準備状況

インストールパスを利用可能

  • インストールパスを利用できます
  • リポジトリの根拠を利用できます
  • ライセンスが明示されています
  • Agent-Proven の成果エビデンスはまだありません

Agent 可読メタデータ

このスキルの機械可読な判断データ。

このブロックまたは埋め込み JSON を使い、Agent がこのスキルをインストールすべきか、代替を選ぶべきか、先に人のレビューを求めるべきかを判断できます。

JSON を開く

適したタスク

  • Database and SQL ワークフロー
  • Claude Code チーム
  • GitHub 採用シグナルを重視するチーム
  • Understand table relationships

適した Agent

CodexClaude CodeCursorOpenAgentSkill CLICLI

インストール判断

コマンド
npx skills add topoteretes/cognee --skill cognee-permissions
ポリシー
レビュー
人によるレビュー
はい

信頼とリスク

信頼
72/100
監査
87/100
リスクレベル
要レビュー

成果ループ

エンドポイント
/api/agent/outcome
イベント ID
resolve
成果
5

インストールコマンド

npx skills add topoteretes/cognee --skill cognee-permissions

使わない場合

  • ベンダー提供の SLA が必要なチーム
  • production agents without a repository review
  • SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
  • OpenAgentSkill の利用フィードバックはまだありません
  • 高リスク権限のヒント: Secrets or environment access

Agent セーフティ v2

55/100 · インストール前にレビュー

実験的レビュー

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

API で解決

ネットワークアクセス

Skill はリモートページ、API、リポジトリ、外部サービスにアクセスする可能性があります。

ファイルシステムアクセス

Skill はプロジェクトファイル、ドキュメント、生成物、ローカルワークスペース状態を読み書きする可能性があります。

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

データベースアクセス

Skill はスキーマを確認し、データベースを照会し、永続ストアを扱う可能性があります。

  • 高リスク権限のヒント: Secrets or environment access
  • Permission surface may require sandboxing

インストール先

Agent ワークフローにこのスキルをインストール

公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install topoteretes-cognee-permissions

Agent 解決プラン

インストール前に Agent に適合性を検証させます。

Resolve API は第一候補、代替、安全ポリシー、監査メモ、インストール先、Agent がそのまま使えるプロンプトを返します。

テキストプランを開く

Agent が確認すべきこと

  • Resolve API でタスク適合と代替を確認。
  • 監査・信頼スコアと安全ポリシーの警告を確認。
  • Codex、Claude Code、Cursor、CLI のインストール先互換性を確認。

プロンプトをコピー

Task: Use cognee-permissions in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20cognee-permissions%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/topoteretes-cognee-permissions/install
Install command: npx skills add topoteretes/cognee --skill cognee-permissions
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 引き継ぎ

別のディレクトリではなく、インストール経路を Agent に渡します。

公開インストールエンドポイントからコマンド、安全チェックリスト、対象プロンプト、正規リンクを取得します。

Install API を開く

Agent プロンプト

Use cognee-permissions for this task. Review https://www.openagentskill.com/api/skills/topoteretes-cognee-permissions/install, then install with: npx skills add topoteretes/cognee --skill cognee-permissions

Registry メタデータ

自動スキル選択用の Agent 可読プロファイル。

Registry API 経由で判断、信頼、監査、ユースケース、インストールのシグナルを提供し、UI をスクレイピングせずに Agent が順位付けできます。

Manifest を開く

Agent 適合

100/100

Database and SQL

プラットフォーム

Claude Code

監査レポート

要レビュー · 87/100

インストール準備、安全メタデータ、保守、採用リスクの機械可読なレビュー。

監査レポートを見る評価レポートを見る

Agent 判断パネル

Database and SQL 向けの第一候補

有力候補として扱い、自分の Agent スタックで README とインストール経路を検証してください。

100
準備状況
採用
段階

スタック内の役割

第一候補

主な適合

Database and SQL

信頼ラベル

本番対応

インストールパス

コマンド準備済み

使う場面

  • Database and SQL ワークフロー
  • Claude Code チーム
  • GitHub 採用シグナルを重視するチーム

根拠

  • GitHub スター 30,192
  • 最近のリポジトリ活動
  • インストールコマンドまたは GitHub リポジトリが利用可能
  • 品質プロファイル 92/100

先にレビュー

  • SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
  • OpenAgentSkill の利用フィードバックはまだありません

実装パス

  1. 1サンドボックスの Agent にインストールし、Database and SQL タスクを一度最初から最後まで実行します。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信頼プロファイル

サンドボックス限定

信頼シグナルが不足または混在する有用な候補です。結果ループがタスク適合を示すまで、隔離されたワークスペースで使用してください。

72
OpenAgentSkill Trust Score

GitHub 採用度

合格

GitHub スター 30K

スター/フォーク活動

合格

スター 30K、フォーク 3.0K; 現在のメタデータでは Issue 活動を利用できません

最近のメンテナンス

合格

本日プッシュ

ライセンスの明確さ

合格

Apache-2.0

良いシグナル

  • AI レビュー承認済み
  • インストールパスを利用できます
  • リポジトリの根拠を利用できます
  • 最近保守されたリポジトリ
  • Large GitHub adoption signal
  • インストールコマンドに明確な高リスクパターンはありません
  • 成果ループは準備済みですが、最初の実行が必要です

インストール前にレビュー

  • SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.
  • Quality score needs review
  • Permission surface needs review: filesystem or document access, network or browser access
  • Permission surface: filesystem or document access, network or browser access
  • 実際の Agent 成果レポートはまだありません
  • 無人インストールの前に人によるレビューが必要です

推奨アクション

実作業で使う前に、サンドボックスでのみ実行し、近い代替と比較してください。

品質プロファイル

優秀 Agent ワークフロー向けの候補

採用度と保守性のシグナルが強い高信頼候補です。

92
GitHub スター
30K
鮮度
今日
インストール準備完了
はい
ライセンス
Apache-2.0
インストール前にレビュー: SKILL.md content appears truncated in the provided excerpt; ensure the full document is present in the repository.

ワークフロー適合

このスキルを使うシナリオ

ワークフロー適合

完全なワークフローに追加

代替候補

インストール前に比較

このタスクに適する可能性のある類似スキル。

すべて比較

概要

--- name: cognee-permissions description: Use when working with cognee's permission system — understanding or changing how users, roles, and tenants get access to datasets, how ACL grants work, where permissions are enforced in add/cognify/search/delete, and how the grant records surface in the memory-provenance view. ---

# The cognee permission system

## The master switch

`ENABLE_BACKEND_ACCESS_CONTROL` decides whether any of this runs:

- `true` (default): multi-tenant mode. Every API call requires auth, every dataset operation is permission-checked, and each user+dataset pair gets isolated graph/vector/relational databases (tracked in the `DatasetDatabase` model, supported backends: Kuzu, LanceDB, SQLite, Postgres). - `false`: single-user mode. Permission checks short-circuit to allowed, there is no per-dataset isolation, and **every user's operations resolve to the same shared databases and datasets**. Authentication is a separate knob: `REQUIRE_AUTHENTICATION`. Unset, it inherits this switch (so turning access control off also turns auth off) — but if `REQUIRE_AUTHENTICATION=true` is set, endpoints still demand a login; authenticated users are identified but *not isolated*, all pointing at the same data. The reverse misconfiguration (`REQUIRE_AUTHENTICATION=false` with access control on) is ignored: auth is forced on with a warning, because multi-tenant isolation is meaningless without identity (`get_authenticated_user.py`).

## The core model: principals, permissions, ACL grants

Everything reduces to one relation — **a grant**: *principal* × *permission* × *dataset*, stored as one `ACL` row (`modules/users/models/ACL.py`).

- **Principal** (`Principal.py`) is polymorphic: `User`, `Role`, and `Tenant` all inherit from it. Any of the three can hold a grant, which is how role-wide and tenant-wide access work — one ACL row covers every member. - **Permission** (`Permission.py`) is one of exactly four names, defined in `permissions/permission_types.py`: `read`, `write`, `delete`, `share`. `share` is the meta-permission: it gates granting/revoking access for others. - **Membership** is separate from grants: `UserRole` and `UserTenant` link users into roles/tenants. A user's effective access is the union of their own grants and the grants of every role/tenant they belong to.

## How grants come into existence

1. **Dataset creation** (`modules/data/methods/create_authorized_dataset.py`): the creating user is granted **all four permissions** on the new dataset. If the user has a `parent_user_id` (sub-users/agent identities), the parent is auto-granted all four as well — parents always see their children's datasets. 2. **Explicit sharing** (`permissions/methods/ authorized_give_permission_on_datasets.py`): the caller must hold `share` on the target datasets, then any principal (user, role, or tenant) can be granted any permission. Revocation mirrors this (`authorized_revoke_permission_on_datasets.py`). 3. **Capabilities — tenant-scoped grants of actions, not data** (landing via PR #4302, currently in review): a new `principal_capabilities` table, keyed on `(principal, tenant, capability)`. Where an ACL row grants access to *a dataset*, a capability grants *an action inside a tenant* — the first one being `manage_users`. The catalog of capability names is code (`CAPABILITY_TYPES` in `permission_types.py`), not a database table, "because the code is what gives each name meaning"; only the assignment of a capability to a principal is data. `tenant_id` is stored on every row because a user can belong to multiple tenants: it pins each grant to the user's membership in one specific tenant, so holding a capability in one tenant never carries over to the same user's other tenants. Resolution (`get_effective_capabilities(user, tenant)`) returns the union of what the tenant grants all of its members, what the user's roles in that tenant grant, and what the user was granted personally — there is no deny in the model, resolution is gated on actual tenant membership, and the tenant owner short-circuits as holding every capability. Grant/revoke endpoints ride the permissions router.

## Where permissions are enforced

The single chokepoint for dataset resolution is `get_authorized_existing_datasets(datasets, permission, user)` — every entrypoint resolves names/IDs through it with the permission it needs:

| Operation | Required permission | Enforcement path | |---|---|---| | `add` / `cognify` / `remember` | `write` | dataset resolution before the pipeline runs | | `search` / `recall` / visualize | `read` | dataset resolution; retrieval is restricted to documents of readable datasets | | `delete` / prune of a dataset | `delete` | `datasets.py` resolves with `"delete"` | | grant/revoke for others | `share` | `authorized_give/revoke_permission_on_datasets` |

Two behaviors worth knowing:

- **Denied reads return empty results, not 403.** A search against a dataset you cannot read yields `[]` — deliberate, to avoid leaking which datasets exist. When debugging "search returns nothing", check grants before checking the graph.

## Roles, tenants, and who may manage them

- **User management** (listing tenant users, assigning/removing roles, adding/removing users) is allowed for the **tenant owner** always, and today for members of roles named in `USER_MANAGEMENT_ALLOWED_ROLE_NAMES` (currently `{"admin"}`, `permissions/permission_types.py`). That name-matching is a known footgun — any customer group that happens to be called "admin" gets user management — and PR #4302 replaces it: the check becomes "does the requester hold the `manage_users` capability in this tenant" (owner always passes), with the role-name match kept only as a deprecated fallback so tenants upgrading from the old check don't lose user management until their `admin` role is granted the capability. - **Role visibility**: members of a role can see the role itself and their co-members; anyone with user-management permission sees all (`tenants/methods/get_users_in_role.py`). Lookups are tenant-scoped — a role id from another tenant cannot be used to read that tenant's members.

## The grant records in memory provenance (the new grant view)

`api/v1/visualize/memory_provenance.py` surfaces the ACL grants as first-class graph data. Each grant becomes an `AclGrantRecord`:

```python {"principal_id": ..., "principal_kind": "user" | "role" | "tenant", "permission": ...} ```

and is rendered into the provenance graph as an edge from the principal node to the dataset, with the permission mapped to a relation name (`_ACL_EDGE_RELATIONS`):

| permission | provenance edge | |---|---| | read | `reads` | | write | `writes` | | delete | `can_delete` | | share | `can_share` |

Grants are rendered (never dropped) even when the principal is unknown, because "an ACL row exists because someone granted it". The view is exposed through the schema router (`get_schema_router.py`): `visualize_memory_provenance` (HTML) and `get_memory_provenance_payload` (JSON) — this is where you *see* the permission state of a memory rather than query it.

## HTTP API surface (`api/v1/permissions/routers/get_permissions_router.py`)

| Endpoint | What it does | |---|---| | `POST /permissions/datasets/{principal_id}` | grant a permission on datasets to a principal (requires `share`) | | `DELETE /permissions/datasets/{principal_id}` | revoke a permission | | `POST /permissions/roles` · `DELETE /permissions/roles/{role_id}` | create/delete a role | | `POST/DELETE /permissions/users/{user_id}/roles` | add/remove a user to/from a role | | `POST /permissions/users/{user_id}/tenants` | add a user to a tenant | | `GET /permissions/tenants/{tenant_id}/roles/{role_id}/users` | members of a role (self-visible to members) | | `GET /permissions/tenants/{tenant_id}/roles/users/{user_id}` | a user's roles | | `GET /permissions/tenants/{tenant_id}/users` | users in a tenant | | `GET /permissions/tenants/me` | the caller's tenants |

## Key files map

- Models: `cognee/modules/users/models/` — `ACL`, `Principal`, `Permission`, `Role`, `Tenant`, `UserRole`, `UserTenant`, `DatasetDatabase` (and `PrincipalCapability` once #4302 lands) - Methods: `cognee/modules/users/permissions/methods/` — grant/revoke, checks, dataset resolution, document filtering - Enforcement chokepoint: `cognee/modules/data/methods/` (`get_authorized_existing_datasets`, `create_authorized_dataset`) - Grant provenance view: `cognee/api/v1/visualize/memory_provenance.py` - HTTP API: `cognee/api/v1/permissions/routers/get_permissions_router.py`

技術詳細

バージョン
1.0.0
ライセンス
Apache-2.0
最終更新
2026年8月23日
公開日
2026年8月23日

判断の要約

第一候補

100
準備完了
採用
段階

GitHub スター 30,192

監査

インストールレビュー

インストールと採用のレビュー

87
要レビュー
セキュリティ
78/100
メンテナンス
100/100
インストール
92/100
完全な監査を開く評価レポートを見る

Agent 実証エビデンス

Agent 実証エビデンス

Resolve、レビュー、インストール、限定実行後の成果レポート。

0
実証済み
Needs first agent run自動インストール: 先にレビュー最新: 不明
成功率
直近の失敗
成果
0
出力品質
失敗
0
非該当
0
インストール数
0
リスクによりブロック
0
設定が必要
0
本番
0

Agent の実行結果はまだありません。最初の実行では /api/agent/outcome を通じて成功、設定要件、リスクによるブロック、失敗、非該当を報告できます。

インストール

Agent ワークフローに追加

無料・オープンソース. 本番 Agent にインストールする前にレポートを確認してください。

成長ループ

共有キット

X

cognee-permissions 用のシナリオベース草案です。X へ手動投稿できます。

キュレーターノート
cognee-permissions: Use when working with cognee's permission system — understanding or changing how users, roles...

30.2K stars

https://www.openagentskill.com/skills/topoteretes-cognee-permissions?ref=x
X 下書きを開く
任意:インストールコマンド付きの返信
Listing + install path for cognee-permissions:
https://www.openagentskill.com/skills/topoteretes-cognee-permissions?ref=x

Install: npx skills add topoteretes/cognee --skill cognee-permissions
返信の下書きを開く

掲載元

Registry により登録

申請可能

この掲載は公開ソースから登録されており、メンテナー申請が承認されるまで公式として表示されません。

作成者
topoteretes
インデックス作成者
OpenAgentSkill コミュニティインデックス

帰属は公開リポジトリまたは作成者プロフィールにリンクされています。作成者は掲載を申請して所有権シグナルを更新できます。

このスキルを申請

所有者の申請

このスキル掲載を申請

この Registry により登録 掲載は topoteretes に帰属していますが、まだ公式として表示されていません。申請すると、確認済み所有者シグナルが追加され、今後の公開、インストール、監査更新の信頼性が高まります。

クリエイター被リンクキット

README にエビデンスバッジを追加

開発者がリポジトリを評価する場所で、正規掲載、現在の信頼・監査シグナル、実際の Agent-Proven エビデンスを表示します。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/topoteretes-cognee-permissions?metric=listed&label=Listed)](https://www.openagentskill.com/skills/topoteretes-cognee-permissions)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/topoteretes-cognee-permissions?metric=trust&label=Trust)](https://www.openagentskill.com/skills/topoteretes-cognee-permissions)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/topoteretes-cognee-permissions?metric=audit&label=Audit)](https://www.openagentskill.com/skills/topoteretes-cognee-permissions/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/topoteretes-cognee-permissions?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/topoteretes-cognee-permissions)

作者

T

topoteretes

@topoteretes

プラットフォーム適合

健全性シグナル

GitHub スター
30.2K
品質スコア
55/100
最終 GitHub プッシュ
2026年8月23日
フレームワークのヒント
不明
OpenAgentSkill 閲覧数
0
インストールコピー数
0
外部クリック
0

コミュニティシグナル

このスキルが Agent ワークフローに役立つかを共有してください。集約されたフィードバックがランキングを改善します。

信頼と安全性

サンドボックス限定

72
  • GitHub 採用度GitHub スター 30K合格
  • スター/フォーク活動スター 30K、フォーク 3.0K; 現在のメタデータでは Issue 活動を利用できません合格
  • 最近のメンテナンス本日プッシュ合格
  • ライセンスの明確さApache-2.0合格
  • README/SKILL.md の完全性公開メタデータにはより十分な README/SKILL.md の文脈が必要です情報
  • 依存関係/ランタイムのリスクnetwork or browser surface, database surface情報