ToolJet Marketplace Plugin Builder
ToolJet/ToolJet
Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.
A skill your agent uses whenever a Cabloy task crosses the Vona-to-Zova contract boundary: backend DTO, controller, validation, entity, inferred DTO, or OpenAPI changes that should drive SDK…
$ npx skills add cabloy/cabloy --skill cabloy-contract-loop -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cabloy/cabloy cabloy-contract-loop --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cabloy/cabloy.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cabloy-contract-loop .claude/skills/cabloy-contract-loop && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cabloy-contract-loop" agent skill from https://github.com/cabloy/cabloy/tree/main/.agents/skills/cabloy-contract-loop into .claude/skills/cabloy-contract-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cabloy-contract-loop", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cabloy/cabloy/tree/main/.agents/skills/cabloy-contract-loopType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cabloy/cabloy --skill cabloy-contract-loop -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cabloy/cabloy cabloy-contract-loop --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cabloy/cabloy.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/cabloy-contract-loop .agents/skills/cabloy-contract-loop && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cabloy-contract-loop" agent skill from https://github.com/cabloy/cabloy/tree/main/.agents/skills/cabloy-contract-loop into .agents/skills/cabloy-contract-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cabloy-contract-loop", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cabloy/cabloy --skill cabloy-contract-loop -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cabloy/cabloy cabloy-contract-loop --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cabloy/cabloy.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/cabloy-contract-loop .cursor/skills/cabloy-contract-loop && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cabloy-contract-loop" agent skill from https://github.com/cabloy/cabloy/tree/main/.agents/skills/cabloy-contract-loop into .cursor/skills/cabloy-contract-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cabloy-contract-loop", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cabloy/cabloy.git --path .agents/skills/cabloy-contract-loop--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cabloy/cabloy --skill cabloy-contract-loop -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cabloy/cabloy cabloy-contract-loop --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cabloy/cabloy.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/cabloy-contract-loop .gemini/skills/cabloy-contract-loop && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cabloy-contract-loop" agent skill from https://github.com/cabloy/cabloy/tree/main/.agents/skills/cabloy-contract-loop into .gemini/skills/cabloy-contract-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cabloy-contract-loop", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cabloy/cabloy cabloy-contract-loopInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cabloy/cabloy --skill cabloy-contract-loop -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cabloy/cabloy.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/cabloy-contract-loop .github/skills/cabloy-contract-loop && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cabloy-contract-loop" agent skill from https://github.com/cabloy/cabloy/tree/main/.agents/skills/cabloy-contract-loop into .github/skills/cabloy-contract-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cabloy-contract-loop", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cabloy/cabloy --skill cabloy-contract-loop -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cabloy/cabloy cabloy-contract-loop --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cabloy/cabloy.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/cabloy-contract-loop .opencode/skills/cabloy-contract-loop && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cabloy-contract-loop" agent skill from https://github.com/cabloy/cabloy/tree/main/.agents/skills/cabloy-contract-loop into .opencode/skills/cabloy-contract-loop/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cabloy-contract-loop", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cabloy-contract-loopA skill your agent uses whenever a Cabloy task crosses the Vona-to-Zova contract boundary: backend DTO, controller, validation, entity, inferred DTO, or OpenAPI changes that should drive SDK…
Cabloy Contract Loop is an agent skill from cabloy/cabloy. Use this skill whenever a Cabloy task crosses the Vona-to-Zova contract boundary: backend DTO, controller, validation, entity, inferred DTO, or OpenAPI changes that should drive SDK, schema, api, model, or rest-output regeneration, or stale generated frontend consumers that may be out of sync with backend truth. Trigger for requests about stale home-api output, OpenAPI regeneration, whether to regenerate instead of hand-patching types, or how to verify the Cabloy Basic or Cabloy Start contract loop end to end…
Its SKILL.md is about 5.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `evals/evals.json`, `references/contract-loop-map.md` and `references/resource-custom-state-pattern.md`).
It sits in Backend & APIs, covering Project scaffolding and OpenAPI specifications. It works with OpenAPI and npm. The repository describes itself as: Cabloy is a Node.js fullstack framework for AI vibe coding, with AI Spec-Driven Development guiding work from confirmed specs to verifiable delivery. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d1f2e39. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cabloy Contract Loop loads about 5.1k tokens when it runs, and up to ~9.9k if it reads all its reference files. Until then it costs about 170 tokens; SKILL.md has 2,592 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cabloy/cabloy at commit d1f2e39, republished under its MIT licence (© cabloy). 2,592 words, ~5,055 tokens.
.claude/skills/cabloy-contract-loop/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Use this skill when a backend contract change needs to be reflected in frontend consumers, when frontend-owned metadata or resources need to be reflected back into backend consumers, or when either side appears stale and you need to diagnose where drift actually lives.
Read the public Contract Loop Playbook for the canonical bidirectional model. This skill is the branching orchestration guide.
When the generated .zova-rest artifacts or other generated consumer artifacts already contain the expected new keys or types but Vona still sees stale consumer types, treat that first as a local dependency drift problem rather than a source-editing problem.
This includes the reverse fullstack direction where newly added frontend resources such as custom renderers are later consumed by backend metadata.
In that situation:
npm run deps:vonanpm run build:zova:admin and npm run build:zova:web are representative default wrappers onlybuild:rest:* alone as sufficient, because the SSR bundle and rest output must move togethernpm run deps:vona after the required flavor builds.zova-rest artifacts already contain the expected changes but Vona still sees stale types, delete vona/node_modules and reinstall dependenciesDo not keep debugging source-level contract or renderer changes until the local file-package installation state is known to be healthy.
repo-agent-governance/tools/contract-loop/PostToolUse hook in .claude/settings.jsonPostToolUse hook in .codex/hooks.json; it matches apply_patch / Edit / Write, resolves the project-local bridge without requiring Git, preserves Add/Update/Delete patch operations, and returns model-visible context through the Codex hook contractproject_root_markers to include __CABLOY_BASIC__ and __CABLOY_START__ alongside .git; the repository must not write that user settingpostToolUse for Agent Write context plus afterTabFileEdit for Tab TabWrite side effects in .cursor/hooks.json; the native afterFileEdit route is intentionally absent so one Agent write does not run the gate twice.claude/settings.json, the Claude bridge recognizes Cursor and returns without work, leaving the native Cursor adapter as the single Agent gatepostToolUse injects additional_context into the agent turn; afterTabFileEdit is side-effect only and still runs the shared reverse auto-sync when the edited file matchesapply_patch call and runs at most one high-confidence reverse auto-sync for that patch. Explicit Delete entries use path-only evidence; an unreadable Add or Update target is reported as an inspection failure, never reinterpreted as a deletenpm run build:zova:admin and then npm run deps:vonaCheck the repository root for these marker files:
__CABLOY_BASIC____CABLOY_START__Interpretation:
__CABLOY_BASIC__ present → this is Cabloy Basic__CABLOY_START__ present → this is Cabloy StartThen classify whether the task is really a contract-loop task.
These four modes are shared across Cabloy Basic and Cabloy Start. Edition detection chooses the operational branch, but does not change the core contract-loop model.
Use this skill in four common entry modes.
The user already changed or plans to change backend contract surfaces such as:
The user changed or plans to change frontend-owned resources or metadata that backend-side tooling or metadata will later consume, such as:
ZovaRender.*(...) references depend onThe user reports symptoms on the frontend side such as:
In this mode, first diagnose whether the visible stale behavior comes from skipped regeneration, a wrong source-of-truth edit, or a stale generated consumer.
Use this mode when generated artifacts already contain the expected keys, types, or resources, but installed local file dependencies still behave stale after the normal sync flow.
Use this mode when the request adds a deployable Zova SSR surface that Vona must dispatch separately. This is more than a page or route inside an existing site.
Before proposing implementation, inspect the active repository rather than inferring names from Admin or Web:
package.json wrappers;zova/package.json or its durable source for matching dev:ssr:*, build:ssr:*, and build:rest:* scripts;SITE_ID, mount path, SSR profile, and artifact-copy targets;@SsrSite(...) baseline and the owning site-module asset path;zova-rest-* package.The independent identity tuple—flavor, site ID, public path, bundle path, REST package, Vona site module, and root paired-build wrapper—must be selected together. The root wrapper must build both SSR and REST output before npm run deps:vona; build:rest:* alone is not enough. Default Basic or Start Admin/Web wrappers are validated specimens, not a command template for a differently named site.
Read Independent SSR Site and Flavor Setup for the canonical setup and evidence procedure.
If the task is only backend scaffolding or only frontend scaffolding, the more specialized scaffold skills may be the better primary choice.
Inspect these surfaces before proposing workflow:
package.json that owns the scriptsnpm run zovarepo-docs/fullstack/, repo-docs/backend/, and repo-docs/frontend/For deeper reference material, read:
references/contract-loop-map.mdreferences/verification-checklist.mdreferences/resource-custom-state-pattern.md../../../repo-docs/fullstack/admin-resource-and-web-self-service.mdIn Cabloy, the backend is often the source of truth for the contract. Treat that as the default unless the codebase clearly shows a frontend-owned artifact that the reverse chain should hand back into backend consumers.
Start with the backend side and update the contract deliberately.
Typical backend layers to inspect or change include:
v helpersThe key rule is:
Start with the frontend-owned resource or metadata that backend consumers later depend on.
Typical frontend layers to inspect or change include:
ZovaRender.*(...) references depend onThe key rule is:
Do not assume the visible stale behavior identifies the wrong layer automatically.
Instead:
Only enter this branch after the source layer and generated handoff are already known to be correct.
Before regenerating frontend artifacts, confirm the backend-side contract is actually correct.
That may include:
npm run dev is the normal path and exposes http://localhost:7102/swagger/json?version=V31If the backend contract output is wrong, frontend regeneration will only spread the mistake.
Once the backend contract is correct, decide how the frontend should consume it.
Use this when the frontend consumes generated API contracts.
Typical Zova commands include:
npm run zova :openapi:config ...npm run zova :openapi:generate ...Preflight reminder:
:openapi:generate reads from a local Swagger endpoint, do not assume the generator itself is broken when fetch failsnpm run dev, and confirm http://localhost:7102/swagger/json?version=V31 is reachableWhen the target is a module-local SDK, constrain openapi.config.ts with operations.match unless the module intentionally owns a broad API surface. This prevents unrelated APIs from being generated into the module.
Use the edition-specific Zova REST/type build path when the workflow depends on the built flavor outputs.
Typical examples in Cabloy Basic include:
cd zova && npm run build:rest:cabloyBasicAdmincd zova && npm run build:rest:cabloyBasicWebImportant Cabloy Basic reverse-sync rule:
build:rest:cabloyBasicAdminnpm run build:zova:admin from the repo root instead, then run npm run deps:vonazova/src/**/.metadata/** when it is available; if the effective handoff only appears in .zova-rest, treat the safeguard as conservative reminder/auto-sync assistance rather than strict proofFor Cabloy Start, verify the exact Start-specific flavor names, paths, SSR site baselines, project assets, and source-confirmed root wrappers in the active Start repository. If the work affects an independent SSR site, follow Mode E: build that site’s paired wrapper rather than assuming an Admin/Web command covers it.
When the regenerated contract feeds a form or another metadata-driven UI, decide the ownership path before adding frontend field definitions:
$api for executing an operation;$apiSchema for a named schema facade;$sdk or ModelResource for dynamic schema/resource access;ZForm rendering when the resolved schema already carries the field metadata. A ZForm with schema and no default body slot iterates schema properties automatically; use slotFooter or other structural slots for page-specific actions without replacing the automatic body. A default body slot is an intentional manual/mixed-composition boundary and must render the required fields deliberately.createApiSchemas(...) facade, its requestBody, or an omit/pick/other transformed snapshot across a locale change. Reacquire the current schema through a getter, $computed, or the owning ModelResource; perform page-specific schema transformations inside that reactive derivation and ensure the current facade's SDK query is ready. staleTime: Infinity is cache behavior within a selected runtime, not cross-locale schema validity.ModelResource or a model. A page-specific action may call generated $api directly when it has no shared state or cache ownership; do not add an infrequently used operation to a shared model only for API indirection.deps:vona handoff rather than treating the change as frontend-only.Read the API Schema Guide, Form Guide, A-OpenAPI Under the Hood, and Model Resource Owner Pattern for the ownership and runtime details. Use references/contract-loop-map.md and references/verification-checklist.md for the contract-loop proof steps.
After generation, inspect whether the frontend still needs follow-up in:
Keep frontend follow-up thin:
For one persisted domain with both Admin Resource and Web self-service consumers, choose the state boundary deliberately after backend contract truth and regeneration are established:
rest-resource.model.resource through a thin semantic facade.Share domain persistence and lifecycle logic, not necessarily HTTP projections or frontend state ownership. Read ../../../repo-docs/fullstack/admin-resource-and-web-self-service.md for the complete architecture. Reuse the resource-owned custom state pattern in references/resource-custom-state-pattern.md for the Admin/custom-resource branch.
The collaboration model is shared across Basic and Start, but the operational details may differ.
Especially verify:
Do not silently reuse Basic-specific examples in Start workflows or treat default Admin/Web commands as an independent-site template.
A fullstack contract loop is not done until both sides are checked.
Typical checks may include:
npm run testnpm run tscnpm run buildTypical checks may include:
npm run tsc:zovanpm run build:zovaWhen helpful, structure the response around these points:
Keep the response practical. The value of this skill is to prevent contract drift between Vona and Zova by guiding the user through the right backend-first, regeneration-second, verification-third workflow.
© cabloy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in .agents/skills/cabloy-contract-loop of cabloy/cabloy.
Open the folder on GitHubat commit d1f2e39
Cabloy Contract Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cabloy Contract Loop this skillcabloy/cabloy | 982 | — | ~5.1k | Automated safety check: Pass | MIT | |
| ToolJet Marketplace Plugin BuilderToolJet/ToolJet | 41k | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Release WorkflowGoldziher/spikard | 123 | — | ~909 | Automated safety check: Pass | MIT | |
| Eng Contract Codegen Coshipcompozy/compozy | 2.8k | — | ~664 | Automated safety check: Pass | MIT | |
| API Endpoint Contracttrycompai/comp | 2k | — | ~2.7k | Automated safety check: Pass | AGPL-3.0 | |
| Archestra Dev Backendarchestra-ai/archestra | 4.3k | — | ~1.5k | Automated safety check: Pass | Custom licence |
ToolJet/ToolJet
Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.
Goldziher/spikard
Release/publish the spikard Rust core crate and CLI end-to-end.
compozy/compozy
Contract co-ship for Compozy wire changes. An agent skill from compozy/compozy.
trycompai/comp
The contract every new or modified API endpoint must follow so it is correct for the public OpenAPI spec, the MCP server (npm @trycompai/mcp-server), the ValidationPipe, and the docs.
archestra-ai/archestra
A skill your agent uses when adding or changing Archestra backend routes, models, services, API request/response schemas, endpoint permissions, or OpenAPI/codegen for the generated API client.
EvilFreelancer/openapi-to-cli
Turns an OpenAPI, Swagger or OpenRPC spec into CLI commands the agent can search and call, with no MCP server or code generation.
cabloy/cabloy
A skill your agent uses to create or maintain Cabloy suite specifications under repo-specs, including PRD, SRS, PDP/WBS, acceptance planning, progress, and suite ADRs.
cabloy/cabloy
A skill your agent uses whenever the user wants to plan a new business domain in this Cabloy repo, such as CRM, OA, training, ERP, or a similar long-lived domain.
cabloy/cabloy
This skill must be used only when the user explicitly invokes /cabloy-worktree-environment or explicitly asks to perform the named Cabloy worktree-environment setup.
cabloy/cabloy
This skill should be used when the user needs the Vona backend scaffold/extend path in this Cabloy repo, especially to choose the right npm run vona generator or CRUD command and the required…
cabloy/cabloy
A skill your agent uses whenever the user wants the Zova frontend path in this Cabloy repo: create or extend pages, components, api or model beans, route/query/params work, metadata refresh…
cabloy/cabloy
A skill your agent uses whenever the user wants to update a field on an existing Cabloy backend resource: add a new persisted field, refine validation, add enum-like constraints, attach or change…
Categories
A skill your agent uses whenever a Cabloy task crosses the Vona-to-Zova contract boundary: backend DTO, controller, validation, entity, inferred DTO, or OpenAPI changes that should drive SDK…. Cabloy Contract Loop is an agent skill from cabloy/cabloy. Use this skill whenever a Cabloy task crosses the Vona-to-Zova contract boundary: backend DTO, controller, validation, entity, inferred DTO, or OpenAPI changes that should drive SDK, schema, api, model, or rest-output regeneration, or stale generated frontend consumers that may be out of sync with backend truth.
Cabloy Contract Loop fits situations like: A Cabloy task crosses the Vona-to-Zova contract boundary: backend DTO; openAPI changes that should drive SDK; rest-output regeneration; stale generated frontend consumers that may be out of sync with backend truth.
Run `npx skills add cabloy/cabloy --skill cabloy-contract-loop -a claude-code`. Or copy the skill folder (.agents/skills/cabloy-contract-loop in cabloy/cabloy) into .claude/skills/cabloy-contract-loop in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cabloy/cabloy --skill cabloy-contract-loop -a codex`. Or copy the skill folder (.agents/skills/cabloy-contract-loop in cabloy/cabloy) into .agents/skills/cabloy-contract-loop in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cabloy/cabloy --skill cabloy-contract-loop -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cabloy-contract-loop, .gemini/skills/cabloy-contract-loop, .github/skills/cabloy-contract-loop and .opencode/skills/cabloy-contract-loop in your project.
Going by SKILL.md and its folder, Cabloy Contract Loop needs the command-line tools its instructions call (npm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cabloy Contract Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.1k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Cabloy Contract Loop: ToolJet Marketplace Plugin Builder (ToolJet/ToolJet, 41k stars), Release Workflow (Goldziher/spikard, 123 stars), Eng Contract Codegen Coship (compozy/compozy, 2.8k stars) and API Endpoint Contract (trycompai/comp, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cabloy (a GitHub organization) maintains it in cabloy/cabloy, which has 982 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.
Source: cabloy/cabloy on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.