Token导航 LogoToken导航TokenDH.com
开发只读github未标认证来源可访问许可证需确认审计通过

openfgaopenfga 命令行

Agent Skill

openfga 用于记录任务执行中的错误、用户纠正、经验和能力缺口,适合在 Codex、Claude、Cursor、Gemini CLI 中希望让 Agent 持续沉淀问题、修正和最佳实践时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

2,880

周安装

120

GitHub Stars

2

下载量

960
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:openfga(openfga 命令行)
来源仓库:https://github.com/openfga/agent-skills
仓库路径:skills/openfga
安装命令:
npx skills add https://github.com/openfga/agent-skills --skill openfga
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/openfga/agent-skills --skill openfga

简介

openfga 用于记录任务执行中的错误、用户纠正、经验和能力缺口。

  • 适合在 Codex、Claude、Cursor、Gemini CLI 中让 Agent 持续沉淀问题、修正和最佳实践。
  • 通过 npx skills add 命令从指定 GitHub 仓库安装使用。
  • 安装前需确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写操作。
  • openfga 属于开发类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

OpenFGA Best Practices

Use this skill to design and review OpenFGA models end to end: define types and relations, write tuples, derive can_* permissions, choose usersets and inheritance patterns, and validate behavior with .fga.yaml tests and CLI checks.

Quick Start Example

Minimal model:

model
  schema 1.1

type user

type organization
  relations
    define admin: [user]
    define member: [user] or admin

type document
  relations
    define organization: [organization]
    define owner: [user]
    define can_edit: owner or admin from organization
    define can_view: can_edit or member from organization

Example tuples:

organization:acme#admin@user:alice
document:roadmap#organization@organization:acme
document:roadmap#owner@user:bob

Example test targets:

  • check that user:alice can view and edit document:roadmap
  • check that user:bob can edit their own document
  • list_users for document:roadmap#can_view
  • list_objects for documents user:alice can edit

How to Use

When a workflow step points to a rule ID, open the matching file in references/ for detailed guidance and examples.

Note: SDK references (sdk-*.md) are only needed for integration tasks — skip them during pure model authoring and testing.

Rule Index

Core

FileDescription
references/core-types.mdDefine types for entity classes
references/core-relations.mdRelations belong on object types
references/core-tuples.mdRelationship tuples as facts
references/core-separation.mdModel vs data separation
references/core-schema-version.mdSchema version

Relations

FileDescription
references/relation-direct.mdDirect relationships
references/relation-indirect.mdIndirect relationships with X from Y
references/relation-concentric.mdConcentric relationships
references/relation-usersets.mdUsersets for group-based access
references/relation-conditions.mdConditional relationships
references/relation-wildcards.mdWildcards for public access
references/relation-wildcards-as-booleans.mdWildcards for boolean attributes

Design

FileDescription
references/design-permissions.mdDefine permissions with can_ relations
references/design-hierarchy.mdHierarchical structures
references/design-organization.mdOrganization-level access
references/design-create-on-parent.mdCheck create permissions on parent objects
references/design-naming.mdNaming conventions
references/design-modules.mdModularize models (only when asked)

Roles

FileDescription
references/roles-simple.mdSimple static roles
references/roles-static-combo.mdCombining static and custom roles
references/roles-assignments.mdRole assignments for resource-specific roles
references/roles-when-to-use.mdWhen to use each role pattern

Optimization

FileDescription
references/optimize-simplify.mdSimplify models
references/optimize-tuples.mdMinimize tuple count
references/optimize-type-restrictions.mdType restrictions

Testing

FileDescription
references/test-fga-yaml.mdStructure tests in.fga.yaml
references/test-check-assertions.mdCheck assertions
references/test-list-objects.mdList objects tests
references/test-list-users.mdList users tests
references/test-conditions.mdTesting conditions
references/test-cli.mdOpenFGA CLI usage
references/workflow-validate.mdAlways validate models

SDKs (for integration tasks only)

FileDescription
references/sdk-javascript.mdJavaScript/TypeScript SDK
references/sdk-go.mdGo SDK
references/sdk-python.mdPython SDK
references/sdk-java.mdJava SDK
references/sdk-dotnet.md.NET SDK

Recommended Workflow

  1. Model the resource graph. Define types, direct relations, inheritance edges, and can_* permissions. Rules to check first: core-*, relation-*, design-permissions, design-hierarchy.
  2. Add tuples and test intent. Add representative tuples and cover expected behavior with check, list_objects, and list_users tests. Rules to check next: core-tuples, test-fga-yaml, test-check-assertions, test-list-objects, test-list-users.
  3. Review parent-child creation and deletion paths. Verify each parent -> child edge has create permissions on the parent and that no child permission is directly grantable unless intended. Rules to check: design-create-on-parent, relation-direct, design-permissions.
  4. Simplify before removing schema. Before deleting any type or relation, confirm it is not referenced by permissions, tuples, or tests. If a simplification breaks a reference: restore the relation or update the model/tests, then re-run this step. Rules to check: optimize-simplify, optimize-tuples, optimize-type-restrictions.
  5. Validate the model. Run:
fga model validate --file stores/<store>/model.fga

If validation fails: read the reported relation or type errors, fix the model, and re-run validation before continuing.

  1. Run the store tests. Run:
fga model test --tests stores/<store>/store.fga.yaml

If tests fail: update tuples, assertions, or permission definitions, then re-run tests until all checks and list queries pass.

  1. Only then finalize delivery. For touched stores, finish only after validation and tests are green. Final rule to check: workflow-validate.

Full Compiled Document

For the complete guide with all rules expanded: AGENTS.md

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

34.65%
按下载量换算333

Claude

28.94%
按下载量换算278

Cursor

20.69%
按下载量换算199

Gemini CLI

10.17%
按下载量换算98

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills