Claude skill allowed-tools: pre-approve Sume MCP tools

A skill's allowed-tools field pre-approves tools for one turn and does not restrict the rest. How to list Sume's job tools and leave paid ones prompting.

5 min readSume
All posts

In a Claude Code skill, allowed-tools lists tools Claude can use without asking permission during the turn that invokes the skill. It is a pre-approval, not a restriction: every other tool stays callable, and the grant clears when you send your next message. For a skill that makes video with Sume, list the free job-reading tools and leave the paid ones out so they still prompt.

That is from Anthropic's skills page, read 2026-09-29. Which Sume tools are read tools and which are paid comes from Sume's MCP tools and gates. The server is named sume in the examples, so tool names look like mcp__sume__jobs_wait.

How do I write it?

allowed-tools accepts a space- or comma-separated string, or a YAML list. Sume documents jobs_status, jobs_wait and jobs_result as read tools, so a skill can approve exactly those. Save this as .claude/skills/make-clip/SKILL.md:

---
name: make-clip
description: Make a short video clip with Sume and return the finished file.
allowed-tools: mcp__sume__jobs_status mcp__sume__jobs_wait mcp__sume__jobs_result
---
1. Call generate_video with dry_run true and show the cost preview.
2. After the user confirms, call it again with max_spend_usd and an
   idempotency_key.
3. Wait with jobs_wait. If it returns wait_slice_expired, call it again
   with the same job ids. Never resubmit the create.
4. Read the result with jobs_result and give the user the file URL.

Why leave generate_video out?

Anything in allowed-tools runs without a prompt for that turn. Paid Sume tools such as generate_video, generate_image, tts_create and music_create need an idempotency_key, and dry_run and max_spend_usd are optional, so the permission prompt is often the only human checkpoint. Keeping them out means Claude still asks before it spends.

The trade is one prompt per paid call. If you would rather approve a tool for the whole session, Anthropic's page says to add allow rules to your permission settings instead; see Claude Code: allow MCP tools without approving every call.

What does allowed-tools not do?

These are the limits Anthropic's page states for the field.

From Anthropic's skills page, read 2026-09-29.
QuestionAnswer
Does it hide other tools?No; every tool remains callable and your permission settings still govern unlisted tools
How long does the grant last?The turn that invokes the skill; it clears on your next message
Does the skill text persist?Yes; the rendered SKILL.md stays in the conversation, only the grant clears
Does workspace trust gate it?No; a project skill's grant applies even in a -p run in an untrusted folder

How do I remove tools while the skill runs?

Use disallowed-tools in the same frontmatter. Anthropic's page says it removes the listed tools from Claude's available pool while the skill is active, and the restriction clears on your next message. That is the field to use if a skill should never call a tool, and allowed-tools cannot do it.

Is it safe to install a skill from a repo?

Read its frontmatter first. The page warns that a skill can grant itself broad tool access, and that a project skill's allowed-tools applies whenever you or Claude invoke it. A skill that lists mcp__sume__generate_video would spend on your wallet without a prompt. Sume's servers are not involved in that risk; it sits in the skill file.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume