mcpbeat Sign in

Ca Override Agent Skill

Sanctioned, logged bypass of a gate or hard rule — one audit line, then proceed.

908 tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
138
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/arbiterForge/codeArbiter --skill ca-override

The instruction itself

5 sections, as written by the author

$ca-override — logged bypass

The sanctioned escape hatch. Bypass is permitted only with an audit log entry. Overrides are always

logged, always visible, never silent. Single identity, single confirm.

Flow

  • Validate $ARGUMENTS — the reason names the gate being bypassed and a justification. Reject a

vague reason ("just skip it") and ask for a specific one.

  • Detect the operator identity from git config user.email only. If it is unset, ask the user once

to state their identity for the log. (No platform ladder, no second confirmation.)

  • Append one line to <project-root>/.codearbiter/overrides.log:
   [ISO-8601 timestamp] | BY: <email> | GATE: <gate bypassed> | REASON: <reason>

The log is append-only — never edited or deleted, committed as a permanent audit artifact.

  • Proceed with the overridden action. Note in the response that the override is logged.

Security ceiling — heavier path for security-critical stops

A routine gate (lint, a style rule, a non-security review finding) takes the single-confirm path above.

But a security-critical stop is NOT bypassable by a single confirm. The following require the

heavier path below, never the one-line flow:

  • a security CRITICAL finding;
  • the crypto/secret commit gate (hook H-09b / H-10b — staged crypto/TLS or secret without a gate pass);
  • an irreversible operation (data loss, a destructive migration, anything unrollbackable).

Heavier path (all required, in order):

  • Surface the specific finding verbatim — name the exact primitive/secret/operation and the

concrete risk. A generic "security override" is rejected.

  • Explicit per-finding acknowledgement — the user must acknowledge *that specific finding* in

their own words (a bare "yes"/"go ahead"/"I trust you" is declined — this mirrors decision-variance).

Detect identity from git config user.email; if unset, ask once.

  • Heavier log entry — append a line tagged SECURITY-OVERRIDE that records the specific finding,

not just the gate name:

   [ISO-8601] | BY: <email> | SECURITY-OVERRIDE | FINDING: <specific finding> | REASON: <reason>
  • Only then record the bypass. For the crypto/secret commit gate, that means running

python3 "${CLAUDE_PLUGIN_ROOT}/hooks/security-pass.py" || python "${CLAUDE_PLUGIN_ROOT}/hooks/security-pass.py",

which writes <project-root>/.codearbiter/.markers/security-gate-passed bound to the

sensitive lines it approves, so hook H-09b/H-10b allows the commit — recorded only after

steps 1–3, never to skip the gate proper.

Under $ca-sprint, a security-critical override is a hard-gate STOP: it surfaces to the user and is

never auto-decided, even in autonomous mode (SPRINT.md hard gates).

Hard gate

MUST write the log line before proceeding — it is not optional. MUST capture an operator identity —

"codeArbiter" or "automated" are not valid. MUST include a justification. The override is scoped to

the immediate action only; it creates no standing exception. MUST NOT edit or delete an existing

overrides.log entry. MUST route a security-critical / crypto-secret / irreversible stop through the

Security ceiling path — never the single-confirm flow — and MUST NOT auto-decide such an override

under $ca-sprint.

When NOT to use

  • Routine work that passes all gates — never needed.
  • Reconciling two conflicting sources → $ca-conflict.

Other skills for the same job

different authors, same section of the catalogue
Protocolsio Integration
by christophacham
×4

Integration with protocols.io API for managing scientific protocols. This skill should be used when working with protocols.io to search, create, update, or publish protocols; manage protocol steps and materials; handle discussions and comments; organize workspaces; upload and manage files; or integrate protocols.io functionality into workflows. Applicable for protocol discovery, collaborative protocol development, experiment tracking, lab protocol management, and scientific documentation.

16k tokens
Tailored Resume Generator
by frostant
×4

Analyzes job descriptions and generates tailored resumes that highlight relevant experience, skills, and achievements to maximize interview chances

3k tokens
Excalidraw Diagram Generator
by github
vendor ×3

Generate Excalidraw diagrams from natural language descriptions. Use when asked to "create a diagram", "make a flowchart", "visualize a process", "draw a system architecture", "create a mind map", or "generate an Excalidraw file". Supports flowcharts, relationship diagrams, mind maps, and system architecture diagrams. Outputs .excalidraw JSON files that can be opened directly in Excalidraw.

36k tokens scripts
Expo Dev Client
by openai
vendor ×3

Build and distribute Expo development clients locally or via TestFlight

961 tokens
Executing Plans
by ZhanlinCui
×3

Use when you have a written implementation plan to execute in a separate session with review checkpoints

542 tokens
Anndata
by christophacham
×3

Data structure for annotated matrices in single-cell analysis. Use when working with .h5ad files or integrating with the scverse ecosystem. This is the data format skill—for analysis workflows use scanpy; for probabilistic models use scvi-tools; for population-scale queries use cellxgene-census.

16k tokens
Benchling Integration
by christophacham
×3

Benchling R&D platform integration. Access registry (DNA, proteins), inventory, ELN entries, workflows via API, build Benchling Apps, query Data Warehouse, for lab data management automation.

14k tokens
Biopython
by christophacham
×3

Comprehensive molecular biology toolkit. Use for sequence manipulation, file parsing (FASTA/GenBank/PDB), phylogenetics, and programmatic NCBI/PubMed access (Bio.Entrez). Best for batch processing, custom bioinformatics pipelines, BLAST automation. For quick lookups use gget; for multi-service integration use bioservices.

24k tokens

How to use it

Copy the folder

Take arbiterforge/ca-override from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.