agentsclimarketplace

Permission model validator

Skill aborroy/aiup-alfresco/.cursor/skills/permission-model-validator

A Claude Code plugin that packages Alfresco extension development as slash commands, skills, and agents

Install
npx -y skills add aborroy/aiup-alfresco --skill permission-model-validator

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 12 stars12 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Validates custom Alfresco permission model XML for well-formedness, no collision with built-in permission group names, correct permissionSet binding, and that any dynamic authority is registered and implements DynamicAuthority. Trigger automatically after generating or editing a *permissionDefinitions.xml or a *DynamicAuthority.java file.

SKILL.md

2.8 KB, as published. Nobody here has run it

Permission Model Validator

Validate the given custom Alfresco permission model and dynamic authorities against these rules.

XML Structure Validation

  • The file must be well-formed XML with root element <permissions>.
  • Each <permissionSet> must declare a type attribute bound to a custom type or aspect ({prefix}:...), not a redefinition of a core type that removes built-in groups.
  • Each <permissionGroup> and <permission> must declare a name.

Built-in Name Collision

  • FLAG as ERROR any <permissionGroup name="..."> or <permission name="..."> whose name collides with a built-in Alfresco permission group/permission: Read, Write, Delete, AddChildren, ReadProperties, ReadChildren, WriteProperties, Consumer, Contributor, Editor, Collaborator, Coordinator, SiteManager, SiteCollaborator, SiteContributor, SiteConsumer, FullControl, All.
    • Why it breaks: redefining a core group name corrupts the global permission model and can silently alter access across the whole repository.
    • Fix: use a project-scoped PascalCase name; compose on top of a core group with <includePermissionGroup permissionGroup="Read" type="cm:cmobject"/>.

Registration Validation

  • The model must be registered as an extension model, not a replacement: look for a Spring bean with parent="permissionModelBootstrap" and a model property pointing at the permissionDefinitions.xml under alfresco/extension/.
    • WARN if no such registration bean is found in a companion *-context.xml.
  • The registering context must be imported from module-context.xml.

Dynamic Authority Validation

  • If a *DynamicAuthority.java exists:
    • It must implements DynamicAuthority (from org.alfresco.repo.security.permissions).
    • It must implement hasAuthority, getAuthority, and requiredFor.
    • FLAG as ERROR runAsSystem inside hasAuthority (privilege escalation + per-node perf hazard).
    • WARN if hasAuthority does not guard with nodeService.exists().
    • The bean must be registered (id {prefix}.{name}DynamicAuthority) and added to the global dynamicAuthorities list.
  • WARN if a permission/group omits requiresType where it logically applies only to the bound type.

Output

Report all violations with file path, line number, rule violated, and suggested fix. If no violations found, confirm the permission model is valid.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.