Agent skill

Extensions

by BuilderIO in BuilderIO/agent-native

Creating, editing, and managing extensions — sandboxed Alpine.js mini-apps that run inside iframes.

No licenceAuto-check passedDatabases

Install Extensions

skills CLI
$ npx skills add BuilderIO/agent-native --skill extensions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BuilderIO/agent-native extensions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BuilderIO/agent-native.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/extensions .claude/skills/extensions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
extensions
GitHub stars
7.1k
Token cost
~6.7k tokens
SKILL.md length
2,991 words
Files
3 (incl. references)
Skills in repo
102
Repo updated
First seen
Licence
None found

At a glance

Creating, editing, and managing extensions — sandboxed Alpine.js mini-apps that run inside iframes.

  • Works in 3 steps: Briefly explain the extension boundary. → Do not stop at "an extension cannot do… → Continue through the normal source-code…
  • Databases work in your project
  • SKILL.md covers References, CRITICAL: What Extensions Are…, When the Request Needs Code… and Data Persistence is Built In, plus 10 more sections
  • Calls pnpm; needs OPENAI_API_KEY and ANTHROPIC_API_KEY

What it does

Extensions is an agent skill from BuilderIO/agent-native. Creating, editing, and managing extensions — sandboxed Alpine.js mini-apps that run inside iframes. Use only when the host app explicitly enables extensions and the user asks for a one-off custom block or mini-app. Distinct from LLM "tools" (function calls) — see note below.

Its SKILL.md is about 6.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/api.md` and `references/examples.md`).

It sits in Databases. The repository describes itself as: A framework for building agentic apps.

When your agent uses it

  • Databases work in your project

Example prompts

  • “/extensions”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Briefly explain the extension boundary.
  2. Do not stop at "an extension cannot do that," and do not silently move the
  3. Continue through the normal source-code customization flow

What it can do on your machine

Read from SKILL.md and the folder at commit e16da0c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY
    • ANTHROPIC_API_KEY
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Extensions loads about 6.7k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 2,991 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~6.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 2,991 words (~6,738 tokens).

“appFetch, dbQuery, dbExec, extensionFetch, extensionData), secrets, Tailwind classes, sharing, navigation, routes, and the full back-compat naming table. Read this when you need the precise signature, scope option, or route for any helper.”

— opening of SKILL.md by BuilderIO
name
extensions
metadata.internal
true

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files (references) in .agents/skills/extensions of BuilderIO/agent-native.

  • SKILL.md
  • references/api.md
  • references/examples.md

Open the folder on GitHubat commit e16da0c

Compare with similar skills

Extensions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Extensions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Extensions this skillBuilderIO/agent-native7.1k—~6.7kAutomated safety check: PassNone
Keeper Stress AnalysisClickHouse/ClickHouse50k—~4.7kAutomated safety check: PassApache-2.0
Perf ComparisonClickHouse/ClickHouse50k—~3.9kAutomated safety check: NotesApache-2.0
Patch Release CheckClickHouse/ClickHouse50k—~4kAutomated safety check: NotesApache-2.0
Evolving The Data ModelTriliumNext/Trilium38k—~2.1kAutomated safety check: PassAGPL-3.0
Hybrid Cloud Outboxesgetsentry/sentry46k—~4.8kAutomated safety check: PassCustom licence

Similar skills

  • Keeper Stress Analysis

    ClickHouse/ClickHouse

    Analyze ClickHouse Keeper stress-test results from play.clickhouse.com / keeperstresstests data warehouse.

    50k GitHub stars~4.7k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Perf Comparison

    ClickHouse/ClickHouse

    Evaluate ClickHouse performance test results from existing CI/dashboard data or local perf.py runs.

    50k GitHub stars~3.9k tokensUpdated yesterday
    DatabasesAuto-check: notes
  • Patch Release Check

    ClickHouse/ClickHouse

    Check whether ClickHouse's supported versions (last 3 majors + latest LTS) have recent stable patch releases, diagnose why the scheduled AutoReleases pipeline failed, and identify which releases…

    50k GitHub stars~4k tokensUpdated yesterday
    DatabasesAuto-check: notes
  • Evolving The Data Model

    TriliumNext/Trilium

    A skill your agent uses when adding a DB migration or a new column/field to a Becca entity in Trilium ("add a migration", "new column on notes/attributes", "ALTER TABLE", "add a field to…

    38k GitHub stars~2.1k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Hybrid Cloud Outboxes

    getsentry/sentry

    Official

    Guide for creating and maintaining outbox-based eventually consistent operations in Sentry.

    46k GitHub stars~4.8k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Adaptive Spin Wait

    microsoft/garnet

    Official

    Selects Garnet spin-wait policies based on the slow-path cost.

    12k GitHub stars~1k tokensUpdated yesterday
    DatabasesAuto-check passed

More from BuilderIO/agent-native

All 102 skills in this repo
  • Actions

    BuilderIO/agent-native

    How to create and run agent actions. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Client Methods

    BuilderIO/agent-native

    Client method surface rules. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Adding A Feature

    BuilderIO/agent-native

    The four-area checklist every new feature must complete. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • Address Feedback

    BuilderIO/agent-native

    Triage feedback from docs, issues, Slack threads, or pasted notes into verified bugs, UX proposals, unclear questions, and skipped noise.

    7.1k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Audit Log

    BuilderIO/agent-native

    Durable, access-scoped, append-only record of who changed what app data, when, and whether it was the agent or a human.

    7.1k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Automations

    BuilderIO/agent-native

    Event-triggered and schedule-triggered automations with natural-language conditions.

    7.1k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Extensions

What does Extensions do?

Creating, editing, and managing extensions — sandboxed Alpine.js mini-apps that run inside iframes. Extensions is an agent skill from BuilderIO/agent-native.js mini-apps that run inside iframes.

When should I use Extensions?

Extensions fits situations like: databases work in your project.

How do I install Extensions in Claude Code?

Run `npx skills add BuilderIO/agent-native --skill extensions -a claude-code`. Or copy the skill folder (.agents/skills/extensions in BuilderIO/agent-native) into .claude/skills/extensions in your project. Claude Code loads it when a task matches its description.

How do I install Extensions in Codex?

Run `npx skills add BuilderIO/agent-native --skill extensions -a codex`. Or copy the skill folder (.agents/skills/extensions in BuilderIO/agent-native) into .agents/skills/extensions in your project. Codex loads it when a task matches its description.

Can I use Extensions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BuilderIO/agent-native --skill extensions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/extensions, .gemini/skills/extensions, .github/skills/extensions and .opencode/skills/extensions in your project.

What does Extensions need to run?

Going by SKILL.md and its folder, Extensions needs the command-line tools its instructions call (pnpm) and credentials named OPENAI_API_KEY, ANTHROPIC_API_KEY and GITHUB_TOKEN.

Does Extensions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Extensions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Extensions use?

No licence was found for Extensions or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Extensions use?

About 6.7k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.2k tokens, read only when the agent opens those files.

What are the alternatives to Extensions?

Skills that share tags, products or a category with Extensions: Keeper Stress Analysis (ClickHouse/ClickHouse, 50k stars), Perf Comparison (ClickHouse/ClickHouse, 50k stars), Patch Release Check (ClickHouse/ClickHouse, 50k stars) and Evolving The Data Model (TriliumNext/Trilium, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Extensions?

BuilderIO (a GitHub organization) maintains it in BuilderIO/agent-native, which has 7,087 GitHub stars. The repository holds 102 skills in this directory. The repository was last updated on October 8, 2026.

Source: BuilderIO/agent-native on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.