GPR-008 · medium risk
Allow a reviewed skill
Allow a specific skill identifier after its source and behavior have been reviewed.
Decision
allow
Matcher
tool = trusted-skill
Reviewed
2026-08-09
Safe test cases
matching synthetic case
tool = trusted-skill → allow
different benign synthetic case
tool = benign-trusted-skill → unmatched
Limitations
- Publisher trust and skill content can change; re-review on version or hash change.
Review before applying
This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.
Recipe SHA-256: 6c65212f9f720b8e293e523156f9dc8a43f9a9c8be8d5f94583e853ffd940a18
When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.