Skip to content
Masko

Permissions and approvals

Bring agent decisions to the surface.

When an agent stops for permission or a question, Masko makes the request visible and gives you the action the integration can truly support.

Direct response and terminal handoff are always distinguished.

See how it works ↓

No fake buttons

Answer here, or return there.

Some agents expose a response transport. Others keep the decision inside their native terminal or IDE. Masko preserves that boundary.

  1. 01
    Direct response

    Claude Code and supported Grok or Hermes interactions can resolve through Masko.

  2. 02
    Native handoff

    Codex, Cursor, and Kimi keep certain questions and approvals in their own surface.

  3. 03
    Clear command context

    The visible request explains what is asking and what action is proposed.

Needs attentionDirect responseOpen the right session.

How it works

A safer attention flow.

The goal is not to remove the agent security model. It is to make the moment easier to notice and understand.

  1. 01Agent pauses

    A supported hook or bridge exposes the interaction.

  2. 02Mascot asks

    Masko shows the source, request, and available response path.

  3. 03You decide

    Resolve directly or return to the native prompt without hunting for it.

In practice

Capability depends on the connector.

Every agent page publishes its current response behavior and limitation.

Transport-backed

Direct actions are sent only through a response transport owned by the integration.

Native-security aware

Dangerous commands can remain on the agent native security surface.

Version checked

Version-sensitive integrations expose the release used for current compatibility testing.

AI agents

Your mascot keeps watch over your AI agents.

  1. 01Know when an agent needs you.

    See when Claude Code, Claude Cowork, Codex, Cursor, Grok Build, Kimi Code, or Hermes is working, waiting, or done.

  2. 02Keep the work moving.

    Approve a supported command or answer a question through your mascot.

  3. 03Jump to the right session.

    Return to the exact terminal or app without hunting through tabs.

〉_ Bash

Run a build?$npm run build

Builds the app. Nothing else changes.

Questions

The practical bits.

Can Masko approve every agent command?

No. It can answer only when the integration exposes a supported response path.

What happens when direct approval is unavailable?

Masko shows the request and returns you to the agent native terminal or IDE.

Does Masko bypass agent security?

No. Masko routes supported responses and respects native approval boundaries.

Why do capabilities differ by agent?

Each agent exposes different hooks, payloads, and response channels.

Which Macs can run Masko?

Masko Desktop supports macOS 14 or newer.

Masko for Mac

Bring agent decisions to the surface.

Download for Mac

Direct response and terminal handoff are always distinguished.