Explain Decision (Grade A) logo

Explain Decision (Grade A)Security-tested data-ai skill for Claude AI. Grade A. Fetch the full reasoning behind an AxonFlow policy decision — matched policies, risk level, override availability, recent hit count

(0)
Daniel NikulshynReviewed by Daniel Nikulshyn·Updated July 2026

Overview

Explain Decision is a security-tested data-ai skill for Claude AI that provides the full reasoning behind an AxonFlow policy decision. It is used to answer questions like 'why was that blocked?' or 'what policy fired?' by fetching details such as matched policies, risk level, override availability, and recent hit count. The skill requires the decision_id from a previous policy-check response and returns a summary including the policy that fired, risk level, override availability, and suggestions for requesting an override.

Key features

  • Fetches matched policies with policy_id and policy_name
  • Includes risk level (critical, high, medium, low)
  • Indicates override availability
  • Provides recent hit count in a 24h window

Pricing

Model
Free
Category
Skills
Rating
No reviews yet

Use cases

Troubleshooting Policy Decisions

Used when a user needs to understand why a certain action was blocked or allowed by the AxonFlow policy.

Requesting Overrides

Used to determine if an override is available for a policy decision and to facilitate requesting one.

Pros & Cons

Pros

  • Provides detailed explanations for policy decisions
  • Helps in understanding and addressing security concerns
  • Suggests override options when available

Cons

  • Requires specific decision_id to function
  • Limited to explaining existing policy decisions

Reviews

Sign in to leave a review.

No reviews yet. Be the first!

Q&A

What gets checked

AxonFlow ships with 80+ built-in system policies that apply to Claude Code automatically. No configuration required — new policies added to the platform are immediately enforced in every session. | Category | Coverage | |---|---| | Dangerous commands | Reverse shells (nc -e, bash -i, /dev/tcp/), rm -rf /, dd if=, curl \| bash, credential file access (cat ~/.ssh/, cat ~/.aws/), path traversal | | SQL injection | 30+ patterns including UNION injection, stacked queries, auth bypass, encoding tricks | | PII detection | SSN, credit card, Aadhaar, PAN, email, phone, NRIC/FIN (Singapore), and more — with redaction | | Secrets exposure | API keys, connection strings, hardcoded credentials, code secrets | | SSRF | Cloud metadata endpoint (169.254.169.254) and internal-network blocking | | Prompt injection | Instruction override, jailbreak attempts, role hijacking | | Claude Code-specific | .claude/settings.json write protection, .claude/hooks/.json modification warnings (enabled via AXONFLOWINTEGRATIONS=claude-code) | Custom policies are easy — POST /api/v1/dynamic-policies or the Customer Portal. See Policy Enforcement. ---

Asked by Lena Fischer · Mar 31, 2026

How it works

Governed tools: Bash, Write, Edit, NotebookEdit, and all MCP server tools (mcp). Read-only tools (Read, Glob, Grep) are not governed by default — they don't modify state or send data externally. Fail behavior:** AxonFlow unreachable (network) → fail-open, tool execution continues AxonFlow auth/config error → fail-closed, tool call denied until config is fixed PostToolUse failures → never block (audit and PII scan are best-effort) ---

Asked by Adaeze Uche · Mar 22, 2026

Why you'd add this

Claude Code is Anthropic's official CLI — a fast, agentic coding assistant that edits files, runs shell commands, and calls MCP servers. It's excellent at developer productivity. It was never designed to be the layer where your security and compliance team lives. The gaps start surfacing the moment Claude Code moves from one developer's laptop to a team or production setting: | Production requirement | Claude Code alone | With this plugin | |---|---|---| | Policy enforcement before tool execution | Hooks available, no governance logic | 80+ built-in policies evaluated on every governed tool call | | Dangerous command blocking (rm -rf /, reverse shells, curl \| bash) | Not addressed | Blocked before execution with decision context | | PII / secrets detection in tool outputs | Developer responsibility | Auto-scan; Claude is instructed to use redacted version | | SQL-injection detection on MCP queries | MCP server's problem | 30+ patterns evaluated on every MCP tool call | | Compliance-grade audit trail | Session logs, not compliance-formatted | Every governed call recorded with policies, decision, duration | | Decision explainability after a block | Generic hook failure message | decisionid surfaced in deny reason; explaindecision MCP tool returns the full record | | Self-service, time-bounded exceptions | Not available | createoverride with mandatory justification, fully audited | | Cloud metadata / SSRF / path traversal blocking | Not addressed | Built in** | You get all of t

Asked by Hana Kobayashi · Jan 29, 2026

Ask a question

Skills alternatives

Using Git Worktrees (Grade A) logo
Using Git Worktrees (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

(0)
Free
Ga4 Bigquery Schema (Grade A) logo
Ga4 Bigquery Schema (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

(0)
Free
Meta Capi (Grade A) logo
Meta Capi (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

(0)
Free
Callees (Grade A) logo
Callees (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

(0)
Free
Test Module Name (Grade A) logo
Test Module Name (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

(0)
Free
Board Of Directors (Grade A) logo
Board Of Directors (Grade A)Skills

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

(0)
Free
Advpl Mvc Avancado (Grade A) logo
Advpl Mvc Avancado (Grade A)Skills

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)

(0)
Free
D
Docs Writer (Grade A)Skills

Security-tested devops skill for Claude AI. Grade A. **WORKFLOW SKILL** — Maintains repository documentation accuracy and freshness across the docs site, agent files, and changelog. WHEN: "update docs

(0)
Free