
Create Override (Grade A)Security-tested data-ai skill for Claude AI. Grade A. Create a governed session override for a policy that would otherwise deny — mandatory justification, server-clamped TTL, blocked for critical-risk
Overview
Key features
- Governed session override creation
- Mandatory justification for overrides
- Server-clamped TTL for override duration
- Restriction to specific tool names for narrower scope
- Audit trail recording of justifications
Pricing
- Model
- Free
- Category
- Skills
- Rating
- No reviews yet
Use cases
Bypassing a Non-Critical Policy Block
A user is blocked by a non-critical policy and wants to bypass it for the rest of their session with a documented justification.
Creating a Temporary Override for a Specific Tool
A user needs to temporarily override a policy for a specific tool, providing a justification and a requested duration.
Pros & Cons
Pros
- Allows users to bypass non-critical policy blocks with a justified override
- Mandatory justification ensures accountability
- Server-clamped TTL prevents overly long or short overrides
- Blocked for critical-risk policies to maintain high security standards
Cons
- Requires a valid justification for the override
- Overrides are not allowed for critical-risk policies
- TTL is clamped to a specific range (60 to 86400 seconds)
Reviews
Sign in to leave a review.
No reviews yet. Be the first!
Q&A
What gets checked?
AxonFlow ships with 80+ built‑in system policies that apply to Claude Code automatically. No configuration is required—new policies added to the platform are immediately enforced in every session. | Category | Coverage | |---|---| | Dangerous commands | Reverse shells (nc -e, bash -i, /dev/tcp/), rm -rf /, dd if=, curl \| bash, credential file access (cat ~/.ssh/, cat ~/.aws/), path traversal | | SQL injection | 30+ patterns including UNION injection, stacked queries, auth bypass, encoding tricks | | PII detection | SSN, credit card, Aadhaar, PAN, email, phone, NRIC/FIN (Singapore), and more — with redaction | | Secrets exposure | API keys, connection strings, hardcoded credentials, code secrets | | SSRF | Cloud metadata endpoint (169.254.169.254) and internal‑network blocking | | Prompt injection | Instruction override, jailbreak attempts, role hijacking | | Claude Code‑specific | .claude/settings.json write protection, .claude/hooks/.json modification warnings (enabled via AXONFLOWINTEGRATIONS=claude-code) | Custom policies can be added via POST /api/v1/dynamic-policies or through the Customer Portal.
Asked by Devin Walker · Jan 30, 2026
How does it work?
Governed tools include Bash, Write, Edit, NotebookEdit, and all MCP server tools (mcp). Read‑only tools (Read, Glob, Grep) are not governed by default because they don’t modify state or send data externally. Failure behavior: - AxonFlow unreachable (network) → fail‑open, tool execution continues - AxonFlow auth/config error → fail‑closed, tool call denied until config is fixed - PostToolUse failures → never block (audit and PII scan are best‑effort).
Asked by Ximenez Alvarado · Nov 30, 2025
Why you'd add this?
Claude Code is Anthropic's official CLI — a fast, agentic coding assistant that edits files, runs shell commands, and calls MCP servers. It's excellent at developer productivity. It was never designed to be the layer where your security and compliance team lives. The gaps start surfacing the moment Claude Code moves from one developer's laptop to a team or production setting: | Production requirement | Claude Code alone | With this plugin | |---|---|---| | Policy enforcement before tool execution | Hooks available, no governance logic | 80+ built-in policies evaluated on every governed tool call | | Dangerous command blocking (rm -rf /, reverse shells, curl \| bash) | Not addressed | Blocked before execution with decision context | | PII / secrets detection in tool outputs | Developer responsibility | Auto-scan; Claude is instructed to use redacted version | | SQL-injection detection on MCP queries | MCP server's problem | 30+ patterns evaluated on every MCP tool call | | Compliance-grade audit trail | Session logs, not compliance-formatted | Every governed call recorded with policies, decision, duration | | Decision explainability after a block | Generic hook failure message | decisionid surfaced in deny reason; explaindecision MCP tool returns the full record | | Self-service, time-bounded exceptions | Not available | createoverride with mandatory justification, fully audited | | Cloud metadata / SSRF / path traversal blocking | Not addressed | Built in** | You get all of t
Asked by Jarrah Whitlock · Nov 25, 2025
Ask a question
Skills alternatives

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)
Security-tested devops skill for Claude AI. Grade A. **WORKFLOW SKILL** — Maintains repository documentation accuracy and freshness across the docs site, agent files, and changelog. WHEN: "update docs
Trending now

Accurate Homework Help with Full Explanations

Document intelligence API that parses, splits, OCRs, and extracts structured data from complex PDFs, slides, and spreadsheets.

Open multimodal 12B model handling interleaved images and text with a 128K context window.

Sponsored answers, paid per click.
