Create Override (Grade A) logo

Create Override (Grade A)Security-tested data-ai skill for Claude AI. Grade A. Create a governed session override for a policy that would otherwise deny — mandatory justification, server-clamped TTL, blocked for critical-risk

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

Create a governed session override for a policy that would otherwise deny mandatory justification, server-clamped TTL, blocked for critical-risk policies. Use this skill when a user has been blocked by a non-critical policy and wants to bypass it for the rest of their session with a documented justification. Before calling this skill, the user MUST provide: - policy_id: the ID of the policy to override (typically surfaced by explain-decision) - policy_type: "static" (system / dynamic registry policy) or "dynamic" - override_reason: free-text justification (1-500 chars). This is mandatory and recorded in the audit trail. Optional: tool_signature: restrict the override to a specific tool name (recommended; narrower scope) - ttl_seconds: requested duration. Server clamps to [60, 86400]; default 3600 (1h). Call the create_override MCP tool.

Key features

  • Governed session override creation
  • Mandatory justification for overrides
  • Server-clamped TTL for override duration
  • Restriction to specific tool names for narrower scope
  • Audit trail recording of justifications

Pricing

Model
Free
Category
Skills
Rating
No reviews yet

Use cases

Bypassing a Non-Critical Policy Block

A user is blocked by a non-critical policy and wants to bypass it for the rest of their session with a documented justification.

Creating a Temporary Override for a Specific Tool

A user needs to temporarily override a policy for a specific tool, providing a justification and a requested duration.

Pros & Cons

Pros

  • Allows users to bypass non-critical policy blocks with a justified override
  • Mandatory justification ensures accountability
  • Server-clamped TTL prevents overly long or short overrides
  • Blocked for critical-risk policies to maintain high security standards

Cons

  • Requires a valid justification for the override
  • Overrides are not allowed for critical-risk policies
  • TTL is clamped to a specific range (60 to 86400 seconds)

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

What gets checked?

AxonFlow ships with 80+ built‑in system policies that apply to Claude Code automatically. No configuration is required—new policies added to the platform are immediately enforced in every session. | Category | Coverage | |---|---| | Dangerous commands | Reverse shells (nc -e, bash -i, /dev/tcp/), rm -rf /, dd if=, curl \| bash, credential file access (cat ~/.ssh/, cat ~/.aws/), path traversal | | SQL injection | 30+ patterns including UNION injection, stacked queries, auth bypass, encoding tricks | | PII detection | SSN, credit card, Aadhaar, PAN, email, phone, NRIC/FIN (Singapore), and more — with redaction | | Secrets exposure | API keys, connection strings, hardcoded credentials, code secrets | | SSRF | Cloud metadata endpoint (169.254.169.254) and internal‑network blocking | | Prompt injection | Instruction override, jailbreak attempts, role hijacking | | Claude Code‑specific | .claude/settings.json write protection, .claude/hooks/.json modification warnings (enabled via AXONFLOWINTEGRATIONS=claude-code) | Custom policies can be added via POST /api/v1/dynamic-policies or through the Customer Portal.

Asked by Devin Walker · Jan 30, 2026

How does it work?

Governed tools include Bash, Write, Edit, NotebookEdit, and all MCP server tools (mcp). Read‑only tools (Read, Glob, Grep) are not governed by default because they don’t modify state or send data externally. Failure behavior: - AxonFlow unreachable (network) → fail‑open, tool execution continues - AxonFlow auth/config error → fail‑closed, tool call denied until config is fixed - PostToolUse failures → never block (audit and PII scan are best‑effort).

Asked by Ximenez Alvarado · Nov 30, 2025

Why you'd add this?

Claude Code is Anthropic's official CLI — a fast, agentic coding assistant that edits files, runs shell commands, and calls MCP servers. It's excellent at developer productivity. It was never designed to be the layer where your security and compliance team lives. The gaps start surfacing the moment Claude Code moves from one developer's laptop to a team or production setting: | Production requirement | Claude Code alone | With this plugin | |---|---|---| | Policy enforcement before tool execution | Hooks available, no governance logic | 80+ built-in policies evaluated on every governed tool call | | Dangerous command blocking (rm -rf /, reverse shells, curl \| bash) | Not addressed | Blocked before execution with decision context | | PII / secrets detection in tool outputs | Developer responsibility | Auto-scan; Claude is instructed to use redacted version | | SQL-injection detection on MCP queries | MCP server's problem | 30+ patterns evaluated on every MCP tool call | | Compliance-grade audit trail | Session logs, not compliance-formatted | Every governed call recorded with policies, decision, duration | | Decision explainability after a block | Generic hook failure message | decisionid surfaced in deny reason; explaindecision MCP tool returns the full record | | Self-service, time-bounded exceptions | Not available | createoverride with mandatory justification, fully audited | | Cloud metadata / SSRF / path traversal blocking | Not addressed | Built in** | You get all of t

Asked by Jarrah Whitlock · Nov 25, 2025

Ask a question

Skills alternatives

Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)

(0)
Free
D
Docs Writer (Grade A)Skills

Security-tested devops skill for Claude AI. Grade A. **WORKFLOW SKILL** — Maintains repository documentation accuracy and freshness across the docs site, agent files, and changelog. WHEN: "update docs

(0)
Free