Security Audit Scanner
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
Agent skill
by Impertio-Studio in Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when debugging or preventing errors in Frappe Server Scripts.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-serverscripts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/source/errors/frappe-errors-serverscripts .claude/skills/frappe-errors-serverscripts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "frappe-errors-serverscripts" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-serverscripts into .claude/skills/frappe-errors-serverscripts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-serverscripts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-serverscriptsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-serverscripts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/source/errors/frappe-errors-serverscripts .agents/skills/frappe-errors-serverscripts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "frappe-errors-serverscripts" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-serverscripts into .agents/skills/frappe-errors-serverscripts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-serverscripts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-serverscripts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/source/errors/frappe-errors-serverscripts .cursor/skills/frappe-errors-serverscripts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "frappe-errors-serverscripts" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-serverscripts into .cursor/skills/frappe-errors-serverscripts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-serverscripts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git --path skills/source/errors/frappe-errors-serverscripts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-serverscripts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/source/errors/frappe-errors-serverscripts .gemini/skills/frappe-errors-serverscripts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "frappe-errors-serverscripts" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-serverscripts into .gemini/skills/frappe-errors-serverscripts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-serverscripts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-serverscriptsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/source/errors/frappe-errors-serverscripts .github/skills/frappe-errors-serverscripts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "frappe-errors-serverscripts" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-serverscripts into .github/skills/frappe-errors-serverscripts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-serverscripts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-serverscripts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/source/errors/frappe-errors-serverscripts .opencode/skills/frappe-errors-serverscripts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "frappe-errors-serverscripts" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-serverscripts into .opencode/skills/frappe-errors-serverscripts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-serverscripts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
frappe-errors-serverscriptsA skill your agent uses when debugging or preventing errors in Frappe Server Scripts.
Frappe Errors Serverscripts is an agent skill from Impertio-Studio/Frappe_Claude_Skill_Package. Use when debugging or preventing errors in Frappe Server Scripts. Prevents ImportError (the 1 error), NameError for restricted builtins, sandbox violations, docevents not firing, wrong script type selection, SQL injection, permission denied in scheduled scripts, infinite loops, and API scripts not returning JSON. Covers error message mapping table. Keywords: server script error, ImportError, NameError, sandbox,, ImportError in server script, script not running, sandbox error, restricted function. restricted…
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/anti-patterns.md`, `references/examples.md` and `references/patterns.md`). Compatibility notes: Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16.
It sits in Security, covering Web application vulnerabilities. The repository describes itself as: 60 deterministic Claude AI skills for Frappe Framework & ERPNext v14-v16 development and operations. The licence is MIT.
9 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 36cfa80. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16.
From compatibility in the SKILL.md frontmatter.
Frappe Errors Serverscripts loads about 3k tokens when it runs, and up to ~9.1k if it reads all its reference files. Until then it costs about 152 tokens; SKILL.md has 657 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Impertio-Studio/Frappe_Claude_Skill_Package at commit 36cfa80, republished under its MIT licence (© Impertio-Studio). 657 words, ~2,982 tokens.
.claude/skills/frappe-errors-serverscripts/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Cross-refs: frappe-syntax-serverscripts (syntax), frappe-impl-serverscripts (workflows), frappe-errors-clientscripts (client-side).
Starting from Frappe v15, Server Scripts are disabled by default. You MUST enable them:
# In site_config.json
{ "server_script_enabled": 1 }On Frappe Cloud: Server Scripts are ONLY available on private benches, NOT on shared benches.
ERROR IN SERVER SCRIPT
│
├─► ImportError / NameError
│ ├─► "import json" → BLOCKED. Use frappe.parse_json()
│ ├─► "import datetime" → BLOCKED. Use frappe.utils
│ ├─► "import os/sys/subprocess" → BLOCKED. Security restriction
│ └─► "NameError: name 'dict' is not defined" → Some builtins restricted
│
├─► SyntaxError: not allowed
│ ├─► "try/except" → BLOCKED by RestrictedPython [v14-v15]
│ ├─► "raise ValueError" → BLOCKED. Use frappe.throw()
│ └─► "exec/eval" → BLOCKED. Security restriction
│
├─► Script runs but nothing happens
│ ├─► Wrong Script Type selected → Check Document Event vs API vs Scheduler
│ ├─► Wrong DocType selected → Verify exact DocType name
│ ├─► Wrong Event selected → Before Save ≠ After Save
│ └─► Script disabled → Check "Enabled" checkbox
│
├─► 403 Permission Denied
│ ├─► Scheduler script → Runs as Administrator, check role permissions
│ ├─► API script → Check Allow Guest setting
│ └─► doc_event → User lacks DocType permission
│
├─► Data not saved in Scheduler
│ └─► Missing frappe.db.commit() → REQUIRED in scheduler scripts
│
└─► API script returns empty/wrong response
└─► Not setting frappe.response["message"] → ALWAYS set response| Error Message | Cause | Fix |
|---|---|---|
ImportError: import not allowed | Any import statement in sandbox | Use frappe.utils, frappe.parse_json(), etc. |
NameError: name 'dict' is not defined | Some Python builtins blocked by RestrictedPython | Use frappe._dict() or literal {} |
SyntaxError: try/except not allowed | RestrictedPython blocks exception handling [v14-v15] | Use conditional checks (if/else) instead |
SyntaxError: raise not allowed | RestrictedPython blocks raise | Use frappe.throw() |
Script not executing | Wrong Script Type or Event selected | Verify type matches: Document Event, API, or Scheduler |
doc is not defined | Using doc in API or Scheduler script (no document context) | doc is only available in Document Event scripts |
PermissionError in Scheduler | Scheduler runs as Administrator but script accesses restricted resource | Use ignore_permissions=True where appropriate |
Changes not saved in Scheduler | Missing frappe.db.commit() | ALWAYS call frappe.db.commit() in Scheduler scripts |
API returns empty response | Forgot to set frappe.response["message"] | ALWAYS set frappe.response["message"] = result |
Timeout / killed | Infinite loop or processing too many records | ALWAYS add limit to queries, ALWAYS use batch processing |
ValidationError: qty is required | doc.save() called in Before Save (recursion) | NEVER call doc.save() in Before Save; just set values |
SQL injection via string format | User input in SQL without escaping | ALWAYS use frappe.db.escape() or parameterized queries |
Every beginner hits this. The Server Script sandbox blocks ALL imports except json.
# ❌ BLOCKED — These ALL fail with ImportError
import json # Use frappe.parse_json() / frappe.as_json()
from datetime import datetime # Use frappe.utils.now(), frappe.utils.today()
import re # Not available in sandbox
import os # Security: blocked
import requests # Use frappe.make_get_request(), frappe.make_post_request()
# ✅ CORRECT — Sandbox equivalents
data = frappe.parse_json(doc.json_field) # Instead of json.loads()
today = frappe.utils.today() # Instead of datetime.date.today()
now = frappe.utils.now() # Instead of datetime.now()
diff = frappe.utils.date_diff(date1, date2) # Instead of timedelta
resp = frappe.make_get_request("https://api.com") # Instead of requests.get()
resp = frappe.make_post_request("https://api.com", data=payload)| Category | Available Methods |
|---|---|
| Document | frappe.get_doc(), frappe.new_doc(), frappe.get_last_doc(), frappe.get_cached_doc(), frappe.get_mapped_doc(), frappe.rename_doc(), frappe.delete_doc() |
| Database | frappe.db.get_list(), frappe.db.get_all(), frappe.db.get_value(), frappe.db.get_single_value(), frappe.db.set_value(), frappe.db.exists(), frappe.db.sql(), frappe.db.commit(), frappe.db.rollback(), frappe.db.escape() |
| Query Builder | frappe.qb (full query builder) |
| HTTP | frappe.make_get_request(), frappe.make_post_request(), frappe.make_put_request() |
| Utility | frappe.utils.* (all utility functions), frappe.parse_json(), frappe.as_json() |
| User/Session | frappe.session.user, frappe.get_roles(), frappe.has_permission() |
| Messages | frappe.throw(), frappe.msgprint(), frappe.log_error(), frappe.sendmail() |
| Module | json (the ONLY importable module) |
ALWAYS verify you selected the correct Script Type:
| Script Type | Trigger | Has doc? | Has frappe.form_dict? | Auto-commit? |
|---|---|---|---|---|
| Document Event | DocType lifecycle (Before Save, After Save, etc.) | YES | NO | YES |
| API | HTTP request to /api/method/{method_name} | NO | YES | YES |
| Scheduler Event | Cron schedule | NO | NO | NO — MUST call frappe.db.commit() |
| Permission Query | Every list query on the DocType | NO | NO (has user) | N/A |
# ❌ WRONG — "After Save" cannot prevent save
# Script Type: Document Event, Event: After Save
if not doc.customer:
frappe.throw("Customer is required") # Document already saved!
# ✅ CORRECT — Use "Before Save" or "Before Validate"
# Script Type: Document Event, Event: Before Save
if not doc.customer:
frappe.throw("Customer is required") # Prevents save# ❌ BLOCKED in sandbox
try:
customer = frappe.get_doc("Customer", doc.customer)
except Exception:
frappe.throw("Customer not found")
# ✅ CORRECT — Check first, then access
if not frappe.db.exists("Customer", doc.customer):
frappe.throw(f"Customer '{doc.customer}' not found")
customer = frappe.get_doc("Customer", doc.customer)# ❌ BLOCKED
if amount < 0:
raise ValueError("Amount cannot be negative")
# ✅ CORRECT
if amount < 0:
frappe.throw("Amount cannot be negative")| Exception | HTTP Code | Use When |
|---|---|---|
frappe.ValidationError | 417 | Input validation failure |
frappe.PermissionError | 403 | Access denied |
frappe.DoesNotExistError | 404 | Record not found |
frappe.AuthenticationError | 401 | Not logged in |
| (default, no exc) | 417 | General validation error |
# API Script — Correct exception types
if not customer:
frappe.throw("Customer param required", exc=frappe.ValidationError) # 417
if not frappe.db.exists("Customer", customer):
frappe.throw("Customer not found", exc=frappe.DoesNotExistError) # 404
if not frappe.has_permission("Customer", "read", customer):
frappe.throw("Access denied", exc=frappe.PermissionError) # 403# ❌ WRONG — No limit, no commit, no error logging
invoices = frappe.get_all("Sales Invoice", filters={"status": "Unpaid"})
for inv in invoices:
frappe.db.set_value("Sales Invoice", inv.name, "reminder_sent", 1)
# ✅ CORRECT — Limit, batch commit, error logging
BATCH_SIZE = 50
invoices = frappe.get_all(
"Sales Invoice",
filters={"status": "Unpaid", "docstatus": 1},
fields=["name", "customer"],
limit=500 # ALWAYS limit
)
errors = []
for i in range(0, len(invoices), BATCH_SIZE):
batch = invoices[i:i + BATCH_SIZE]
for inv in batch:
if not frappe.db.exists("Customer", inv.customer):
errors.append(f"{inv.name}: Customer not found")
continue
frappe.db.set_value("Sales Invoice", inv.name, "reminder_sent", 1)
frappe.db.commit() # REQUIRED
if errors:
frappe.log_error("\n".join(errors), "Reminder Errors")
frappe.db.commit()# ❌ VULNERABLE — String interpolation with user input
territory = frappe.form_dict.get("territory")
conditions = f"`tabCustomer`.territory = '{territory}'" # SQL INJECTION!
# ✅ SAFE — Use frappe.db.escape()
territory = frappe.form_dict.get("territory")
conditions = f"`tabCustomer`.territory = {frappe.db.escape(territory)}"
# ✅ SAFEST — Use parameterized query or Query Builder
results = frappe.db.get_all("Customer", filters={"territory": territory})frappe.utils.* instead of Python imports — Only json module is importablefrappe.throw() instead of raise — raise is blocked by sandboxtry/except — Exception handling is blocked [v14-v15]frappe.db.commit() in Scheduler scripts — Changes are NOT auto-committedlimit to ALL queries in Scheduler scripts — Prevent memory exhaustionfrappe.response["message"] in API scripts — Otherwise response is emptyfrappe.db.escape() for user input in SQL — Prevent SQL injectionfrappe.log_error() — No user to see errorsimport statements (except json) — Blocked by RestrictedPythontry/except or raise — Blocked by sandbox [v14-v15]doc.save() in Before Save — Causes infinite recursionlimitdoc exists in API/Scheduler scripts — Only available in Document Eventsfrappe.db.commit() in Scheduler — All changes will be lost| File | Contents |
|---|---|
references/examples.md | Real error scenarios with diagnosis |
references/anti-patterns.md | Common sandbox mistakes with fixes |
references/patterns.md | Defensive error handling patterns by script type |
© Impertio-Studio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/source/errors/frappe-errors-serverscripts of Impertio-Studio/Frappe_Claude_Skill_Package.
Open the folder on GitHubat commit 36cfa80
Frappe Errors Serverscripts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Frappe Errors Serverscripts this skillImpertio-Studio/Frappe_Claude_Skill_Package | 187 | — | ~3k | Automated safety check: Pass | MIT | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| Performing Security Code Reviewjeremylongshore/tons-of-skills-marketplace | 2.8k | 2 repos | ~1.3k | Automated safety check: Notes | MIT | |
| Code Review Securitynicepkg/auto-company | 192 | 1 repos | ~3.9k | Automated safety check: Pass | MIT | |
| TS Reviewliuyanghejerry/Clausura | 204 | — | ~166 | Automated safety check: Pass | MIT | |
| Mobile Code ReviewOWASP/secure-agent-playbook | 187 | — | ~622 | Automated safety check: Pass | CC-BY-4.0 |
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
jeremylongshore/tons-of-skills-marketplace
Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
nicepkg/auto-company
Security-focused code review checklist and automated scanning patterns.
liuyanghejerry/Clausura
TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura.
OWASP/secure-agent-playbook
Security-focused review of native Android and iOS mobile app source code against OWASP MASVS v2.1.0.
jabrena/plinth
A skill your agent uses when you need to write or review programmatic JDBC with Spring — including JdbcClient (Spring Framework 7+) as the default API, JdbcTemplate only where batch/streaming APIs…
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when receiving vague or unclear ERPNext/Frappe development requests that need interpretation.
Impertio-Studio/Frappe_Claude_Skill_Package
Deploy HTML/CSS websites to ERPNext/Frappe (v15/v16) as Web Pages via the REST API.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when implementing hooks.py configurations in a Frappe custom app.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building API endpoints with @frappe.whitelist() in Frappe.
Categories
A skill your agent uses when debugging or preventing errors in Frappe Server Scripts. Frappe Errors Serverscripts is an agent skill from Impertio-Studio/Frappe_Claude_Skill_Package. Use when debugging or preventing errors in Frappe Server Scripts.
Frappe Errors Serverscripts fits situations like: preventing errors in Frappe Server Scripts; tasks that involve Web application vulnerabilities.
Run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a claude-code`. Or copy the skill folder (skills/source/errors/frappe-errors-serverscripts in Impertio-Studio/Frappe_Claude_Skill_Package) into .claude/skills/frappe-errors-serverscripts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a codex`. Or copy the skill folder (skills/source/errors/frappe-errors-serverscripts in Impertio-Studio/Frappe_Claude_Skill_Package) into .agents/skills/frappe-errors-serverscripts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-serverscripts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/frappe-errors-serverscripts, .gemini/skills/frappe-errors-serverscripts, .github/skills/frappe-errors-serverscripts and .opencode/skills/frappe-errors-serverscripts in your project.
SKILL.md names no scripts, command-line tools or credentials: Frappe Errors Serverscripts is instructions for the agent only. Our summary lists: Python 3. Compatibility (from SKILL.md): Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16..
SKILL.md names 1 domain. In commands or code: api.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Frappe Errors Serverscripts is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Frappe Errors Serverscripts: Security Audit Scanner (ruvnet/ruflo, 74k stars), Performing Security Code Review (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Code Review Security (nicepkg/auto-company, 192 stars) and TS Review (liuyanghejerry/Clausura, 204 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Impertio-Studio (a GitHub organization) maintains it in Impertio-Studio/Frappe_Claude_Skill_Package, which has 187 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on September 17, 2026.
Source: Impertio-Studio/Frappe_Claude_Skill_Package on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.