Agent skill

Workfront Actions

by adobe in adobe/skills

A skill your agent uses when writing or fixing the server-side code of a Workfront App Builder extension — the Adobe I/O Runtime action the React SPA calls to do work the browser can't.

Apache-2.0Auto-check: notesBackend & APIs

Install Workfront Actions

skills CLI
$ npx skills add adobe/skills --skill workfront-actions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install adobe/skills workfront-actions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/adobe/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/app-builder/skills/appbuilder-workfront/workfront-actions .claude/skills/workfront-actions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
workfront-actions
GitHub stars
195
Token cost
~1.8k tokens
SKILL.md length
812 words
Files
4 (incl. references, assets)
Skills in repo
105
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when writing or fixing the server-side code of a Workfront App Builder extension — the Adobe I/O Runtime action the React SPA calls to do work the browser can't.

  • Works in 3 steps: Receive imsToken plus any apiKey / IDs… → fetch the public REST endpoint with… → Map the result to { data, error }. Never…
  • Tasks that involve Backend development
  • SKILL.md covers Anatomy, Response shape, Auth & inputs and Calling external APIs (the…, plus 3 more sections
  • Runs JavaScript scripts from its folder

What it does

Workfront Actions is an agent skill from adobe/skills. Use when writing or fixing the server-side code of a Workfront App Builder extension — the Adobe I/O Runtime action the React SPA calls to do work the browser can't. Reach for this whenever the user is: structuring or editing action code; deciding what shape an action returns so the frontend can tell success from failure (the {data,error} body); passing the IMS token through and calling an external API from the backend so credentials never reach the browser; calling Workfront's own Public API v21 (search/count…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files and assets (for example `assets/action-boilerplate.js`, `evals/evals.json` and `references/integrations.md`).

It sits in Backend & APIs, covering Backend development. It works with React. The repository describes itself as: Adobe Skills for Agents. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Backend development

Example prompts

  • “/workfront-actions”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Receive imsToken plus any apiKey / IDs as params.
  2. fetch the public REST endpoint with Authorization: Bearer (add x-api-key / x-gw-ims-org-id where required).
  3. Map the result to { data, error }. Never log the token.

What it can do on your machine

Read from SKILL.md and the folder at commit cbc9952. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (JavaScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Workfront Actions loads about 1.8k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 249 tokens; SKILL.md has 812 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~249
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    env is empty once deployed — inputs flow .env → config inputs → params). Also covers CommonJS-only structure, require-ad
  • NoteMentions a .env fileSKILL.md:45
    - **Inputs flow `.env` → action `inputs` (in config) → `params`. Do NOT read `process.env` at runtime.** Under `aio app

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from adobe/skills at commit cbc9952, republished under its Apache-2.0 licence (© adobe). 812 words, ~1,834 tokens.

Download SKILL.mdSave it as .claude/skills/workfront-actions/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
workfront-actions
description
Use when writing or fixing the server-side code of a Workfront App Builder extension — the Adobe I/O Runtime action the React SPA calls to do work the browser can't. Reach for this whenever the user is: structuring or editing action code; deciding what shape an action returns so the frontend can tell success from failure (the {data,error} body); passing the IMS token through and calling an external API from the backend so credentials never reach the browser; calling Workfront's own Public API v21 (search/count, bulk PUT with the updates param, custom DE: field filters); calling Workfront Planning or another Adobe service; or troubleshooting why a deployed action can't read secrets (process.env is empty once deployed — inputs flow .env → config inputs → params). Also covers CommonJS-only structure, require-adobe-auth, and registering actions in app.config.yaml / ext.config.yaml. For generic non-Workfront action templates and SDKs see appbuilder-action-scaffolder.
license
Apache-2.0

Workfront Runtime actions

Actions are the back end — small functions Adobe runs in its cloud on demand ("serverless"; Adobe I/O Runtime, built on OpenWhisk). The front end (SPA, see workfront-ui-extension) calls them via actionWebInvoke; they hold the credentials and call external APIs. The browser must never call Workfront/Adobe APIs directly — that is the action's job, so login tokens never reach the user's browser.

For generic action patterns and templates (webhook receiver, database CRUD, custom event provider, journaling consumer, large-payload redirect, action sequence, Asset Compute worker) and the App Builder SDKs (State/Files/Events/DB), use appbuilder-action-scaffolder. This skill is the Workfront-specific layer: the {data,error} contract, IMS passthrough, and Workfront's own Public API.

Anatomy

actions/<name>/index.js     # exports main(params)
  • CommonJS only — export your function as exports.main. (App Builder supports only CommonJS, not ES Modules.)
  • Register every action in app.config.yaml, or in an extension's ext.config.yaml (which compiles into app.config.yaml), following the OpenWhisk wskdeploy YAML spec.
js
async function main (params) {
  // ...
  return { statusCode: 200, body: { data, error: null } }
}
exports.main = main

Response shape

Always return { data, error } in the body; the UI checks error before using data.

js
return { statusCode: 400, body: { data: null, error: 'missing parameter(s) ...' } }

Auth & inputs

  • require-adobe-auth is a per-action choice, off by default (the platform default) — decide deliberately, don't blanket-enable it. When true, Adobe validates the user's IMS token at the gateway before your code runs.
    • Turn it on when the action itself is the security boundary (privileged work, or nothing downstream authorizes the caller).
    • Leave it off when the downstream API enforces its own authorization — e.g. the action just forwards the user's imsToken to Workfront/Planning, which rejects bad tokens — or unless explicitly asked to enable it.
  • The UI passes imsToken (→ Authorization: Bearer …) and the Workfront instance URL as params; never hardcode them.
  • The IMS org id is in the shared context at auth.imsOrgID (capital ID — not imsOrgId/imsOrg; that casing trap costs hours). The front end reads sharedContext.get('auth').imsOrgID and passes it down; the action uses params.imsOrgId / the x-gw-ims-org-id header. Two traps: (1) reject the strings "undefined"/"null"/empty — an empty front-end value becomes the header string "undefined" (→ 401 "Org Id undefined is not in the list of user org Ids"); (2) with require-adobe-auth: true the gateway validates the org header before your code runs.
  • Inputs flow .env → action inputs (in config) → params. Do NOT read process.env at runtime. Under aio app dev actions run in-process, so process.env may appear to work locally but will be empty once deployed. Wire keys/secrets as inputs and read them from params.

Calling external APIs (the pattern)

For any API — Workfront, Planning, Adobe services:

  1. Receive imsToken plus any apiKey / IDs as params.
  2. fetch the public REST endpoint with Authorization: Bearer <imsToken> (add x-api-key / x-gw-ims-org-id where required).
  3. Map the result to { data, error }. Never log the token.
  • Workfront Planning → verify the Workfront MCP is connected, then fetch the v2 endpoint reference and data from it (details in references/integrations.md); if it isn't connected, stop and tell the user to connect the Workfront MCP before continuing. Other Adobe services → references/integrations.md. Confirm endpoints from the live source rather than guessing.
Show full SKILL.md (332 more words)Show less

Workfront Public API v21.0

Workfront's own REST API — the /attask/api/v21.0 layer. Call it from an action (never from the SPA).

  • wfClient / base URL: {workFrontInstanceUrl}/attask/api/v21.0{path} — a single version constant. workFrontInstanceUrl and imsToken arrive as params (never hardcoded).
  • Search / count objects (projects, tasks, issues) via the documented query params; map the response into { data, error }.
  • Custom DE: fields need {field}_Mod=notblank on search/count, or they are silently omitted from results.
  • Bulk update with PUT /{obj}?updates=[...] (the updates array in the query string) — chunk requests to stay under the ~8 KB URL-length limit; fall back to per-record PUT /{obj}/{ID} when a chunk is still too long.
  • Wrap the calls in a small wfFetch helper; register the action in app.config.yaml; the SPA reaches it via actionWebInvoke only.

Time budget

The action the SPA calls via actionWebInvoke is a web action, so it's bound by Adobe I/O Runtime's 60 s cap on web/blocking actions — raising limits.timeout doesn't lift it (full limits table in appbuilder-action-scaffolder). So don't fetch or process a big dataset in one call: page Workfront search and chunk bulk-PUT work across multiple actionWebInvoke calls (see Workfront Public API v21.0 above), and show partial progress from the UI. A user-facing timeout is a candidate action-timeout, but can equally be a slow CDN/static load, cold start, or downstream API — check aio app logs before concluding.

Add a new action

  1. aio app add action (or hand-create actions/<name>/index.js).
  2. Register it in app.config.yaml / ext.config.yaml with a runtime kind (e.g. runtime: nodejs:20) and its inputs; set require-adobe-auth per the Auth & inputs rule above. runtime is mandatory — deploy fails with Invalid or missing property "runtime" without it (and, when require-adobe-auth is on, the same error fires on the generated __secured_<action> wrapper).
  3. Expose its URL to the SPA (the UI reads injected action URLs — never hardcodes them). See workfront-ui-extension.
  4. Add tests under test/actions/; run aio app test. View logs with aio app logs (command catalog: appbuilder-workfront → references/commands.md).
  5. Deploy with aio app deploy. A ready-to-edit starting point is in assets/action-boilerplate.js.

© adobe, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references, assets) in plugins/app-builder/skills/appbuilder-workfront/workfront-actions of adobe/skills.

  • SKILL.md
  • assets/action-boilerplate.js
  • evals/evals.json
  • references/integrations.md

Open the folder on GitHubat commit cbc9952

Compare with similar skills

Workfront Actions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Workfront Actions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Workfront Actions this skilladobe/skills195—~1.8kAutomated safety check: NotesApache-2.0
Frontmcp Auth UIagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0
Laravel Inertia React Structurefreekmurze/dotfiles1k—~1kAutomated safety check: PassNone
Twenty Syncable Entity Cache and Transformtwentyhq/twenty58k—~2.4kAutomated safety check: PassCustom licence
Livewire Developmentcoollabsio/coolify63k—~964Automated safety check: PassMIT
Livewire Developmentyungifez/skuul4091 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Frontmcp Auth UI

    agentfront/frontmcp

    A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frontend structure conventions for Laravel Inertia React applications based on Spatie's production practices.

    1k GitHub stars~1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Walks through step 2 of adding a syncable entity to the Twenty server: a cache service for flat entity maps and utilities that transform entities and DTOs into universal flat entities.

    58k GitHub stars~2.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Livewire Development

    coollabsio/coolify

    A skill your agent uses for any task or question involving Livewire.

    63k GitHub stars~964 tokensUpdated today
    Backend & APIsAuto-check passed
  • Livewire Development

    yungifez/skuul

    A skill your agent uses for any task or question involving Livewire.

    409 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Wayfinder Development

    slimani-dev/muraqib

    A skill your agent uses for Laravel Wayfinder which auto-generates typed functions for Laravel controllers and routes.

    128 GitHub starsUsed in 1 repo~622 tokens
    Backend & APIsAuto-check passed

More from adobe/skills

All 105 skills in this repo
  • Scaffolds, implements, deploys and debugs Adobe Runtime actions in App Builder projects, with templates for webhooks, events, database CRUD, sequences and Asset Compute workers.

    195 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Launches Chrome with an unpacked extension over CDP, opens its sidepanel, popup or options page, and hands over to cdp-connect for clicks, typing and screenshots.

    195 GitHub stars~952 tokensUpdated today
    Auto-check passed
  • Extracts icons, metadata, text, forms, videos and social links from any web page with playwright-cli, with SVG icon classification and cleanup.

    195 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Page Langs

    adobe/skills

    Detect all languages used on a webpage — both declared (html@lang, hreflang alternate links, nested lang= attributes, meta content-language) and actually present in the body text (Google CLD3 via…

    195 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Page Prep

    adobe/skills

    Prepare any webpage for clean interaction by detecting and removing disruptive overlays (cookie banners, GDPR consent, modals, popups, newsletter signups, paywalls, login walls).

    195 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Page Reduce

    adobe/skills

    Reduce a webpage to a structural skeleton with semantic tokens.

    195 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Questions about Workfront Actions

What does Workfront Actions do?

A skill your agent uses when writing or fixing the server-side code of a Workfront App Builder extension — the Adobe I/O Runtime action the React SPA calls to do work the browser can't. Workfront Actions is an agent skill from adobe/skills. Use when writing or fixing the server-side code of a Workfront App Builder extension — the Adobe I/O Runtime action the React SPA calls to do work the browser can't.

When should I use Workfront Actions?

Workfront Actions fits situations like: tasks that involve Backend development.

How do I install Workfront Actions in Claude Code?

Run `npx skills add adobe/skills --skill workfront-actions -a claude-code`. Or copy the skill folder (plugins/app-builder/skills/appbuilder-workfront/workfront-actions in adobe/skills) into .claude/skills/workfront-actions in your project. Claude Code loads it when a task matches its description.

How do I install Workfront Actions in Codex?

Run `npx skills add adobe/skills --skill workfront-actions -a codex`. Or copy the skill folder (plugins/app-builder/skills/appbuilder-workfront/workfront-actions in adobe/skills) into .agents/skills/workfront-actions in your project. Codex loads it when a task matches its description.

Can I use Workfront Actions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add adobe/skills --skill workfront-actions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workfront-actions, .gemini/skills/workfront-actions, .github/skills/workfront-actions and .opencode/skills/workfront-actions in your project.

What does Workfront Actions need to run?

Going by SKILL.md and its folder, Workfront Actions needs JavaScript for the scripts in its folder. Our summary lists: Node.js.

Does Workfront Actions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Workfront Actions safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Workfront Actions use?

Workfront Actions is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Workfront Actions use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 745 tokens, read only when the agent opens those files.

What are the alternatives to Workfront Actions?

Skills that share tags, products or a category with Workfront Actions: Frontmcp Auth UI (agentfront/frontmcp, 146 stars), Laravel Inertia React Structure (freekmurze/dotfiles, 1k stars), Twenty Syncable Entity Cache and Transform (twentyhq/twenty, 58k stars) and Livewire Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Workfront Actions?

adobe (a GitHub organization) maintains it in adobe/skills, which has 195 GitHub stars. The repository holds 105 skills in this directory. The repository was last updated on October 6, 2026.

Source: adobe/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.