Gameobject Modify
IvanMurzak/Unity-MCP
Modify GameObject fields and properties in opened Prefab or in a Scene.
Build or modify an in-package HTML data app for a Malloy Publisher package (a public/ directory the package serves): design it, write its Publisher.query code, embed it.
$ npx skills add malloydata/publisher --skill malloy-html-data-apps -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install malloydata/publisher malloy-html-data-apps --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malloy-html-data-apps .claude/skills/malloy-html-data-apps && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "malloy-html-data-apps" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-html-data-apps into .claude/skills/malloy-html-data-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-html-data-apps", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/malloydata/publisher/tree/main/skills/malloy-html-data-appsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add malloydata/publisher --skill malloy-html-data-apps -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install malloydata/publisher malloy-html-data-apps --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/malloy-html-data-apps .agents/skills/malloy-html-data-apps && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "malloy-html-data-apps" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-html-data-apps into .agents/skills/malloy-html-data-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-html-data-apps", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malloydata/publisher --skill malloy-html-data-apps -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install malloydata/publisher malloy-html-data-apps --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/malloy-html-data-apps .cursor/skills/malloy-html-data-apps && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "malloy-html-data-apps" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-html-data-apps into .cursor/skills/malloy-html-data-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-html-data-apps", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/malloydata/publisher.git --path skills/malloy-html-data-apps--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add malloydata/publisher --skill malloy-html-data-apps -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install malloydata/publisher malloy-html-data-apps --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/malloy-html-data-apps .gemini/skills/malloy-html-data-apps && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "malloy-html-data-apps" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-html-data-apps into .gemini/skills/malloy-html-data-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-html-data-apps", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install malloydata/publisher malloy-html-data-appsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add malloydata/publisher --skill malloy-html-data-apps -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/malloy-html-data-apps .github/skills/malloy-html-data-apps && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "malloy-html-data-apps" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-html-data-apps into .github/skills/malloy-html-data-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-html-data-apps", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malloydata/publisher --skill malloy-html-data-apps -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install malloydata/publisher malloy-html-data-apps --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/malloy-html-data-apps .opencode/skills/malloy-html-data-apps && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "malloy-html-data-apps" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-html-data-apps into .opencode/skills/malloy-html-data-apps/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-html-data-apps", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
malloy-html-data-appsBuild or modify an in-package HTML data app for a Malloy Publisher package (a public/ directory the package serves): design it, write its Publisher.query code, embed it.
Malloy HTML Data Apps is an agent skill from malloydata/publisher. Build or modify an in-package HTML data app for a Malloy Publisher package (a public/ directory the package serves): design it, write its Publisher.query code, embed it. Hand-authored, no build step.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files (for example `reference/archetypes.md`, `reference/depth-patterns.md` and `reference/design.md`).
The repository describes itself as: Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere. The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit acc1acd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxpython3nodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Malloy HTML Data Apps loads about 3.5k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 1,832 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from malloydata/publisher at commit acc1acd, republished under its MIT licence (© malloydata). 1,832 words, ~3,522 tokens.
.claude/skills/malloy-html-data-apps/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.<!--
Copyright (c) Credible Data Inc.
SPDX-License-Identifier: MIT
-->
A package becomes a web app by adding a
public/directory. Publisher serves those files and gives the pagePublisher.query(...)to run Malloy against the package's models. No build step, no npm, no framework.
| The user wants | Use |
|---|---|
| A hand-authored HTML/JS dashboard, no toolchain | this skill (an HTML data app) |
| A React app with managed components | the Publisher React SDK (out of scope here) |
| An analyst notebook with charts | a Malloy notebook (notebooks/<slug>.malloy) |
| Point-and-click exploration, no code | the Publisher Explorer |
Pick an HTML data app when the user wants full control of the markup and only plain web files.
my-package/
publisher.json # name, version, description
subscriptions.malloy # the model(s), stays private
subscriptions.parquet # data, stays private
public/ # ONLY this directory is web-served
index.html
app.js
vendor/ # chart library, vendored rather than loaded from a CDN
chart.umd.jsOnly public/ is reachable over the web, at /environments/<env>/packages/<pkg>/<file>. Models, data, and publisher.json are private and reached only through the query API, which still applies the model's filters, access modifiers, and authorize rules. There is no flag to set: a public/ directory is what makes a package an app.
The agent orchestrates these. Each query and chart step hands off to a focused skill.
reference/design.md: who opens it, the decision it serves, the archetype, the form each tile takes, and the depth plan. Skipping this is what produces an app that enumerates the model - a KPI row and a chart grid, whatever the domain - instead of one that answers a question. Hand the brief to the user before scaffolding..malloy file directly. Never guess field or view names.reference/runtime.md. Validate each before pasting it into the page, using whatever query tool your environment provides or a running Publisher (see reference/runtime.md). Malloy syntax questions go to skill:malloy-queries.skill:malloy-charts when rendering through <malloy-render>; otherwise it is your own chart library drawing the returned rows. Vendor any chart library into public/ and load it locally, not from a CDN. Two reasons: embedded author JavaScript runs with the viewing user's data authority, and a blocked CDN (agent sandboxes and many corporate networks block them) is easy to miss, because the script never runs and the charts come up empty. The storefront example ships its chart library in public/vendor/ and loads it from public/index.html as ./vendor/chart.umd.js. Copy that, but resolve the path against the page's own directory: a page in a subdirectory (public/reports/index.html) needs ../vendor/chart.umd.js. A wrong relative path 404s and leaves the charts blank, which is the failure you are trying to avoid.reference/embedding.md.The scaffold in step 3 only proves the wiring. It is the start, not the deliverable. What you ship is a production app that meets the recipe below.
A data app you can defend has all of these. Build to this list, not to the scaffold.
reference/design.md step 2 of the inventory). The case that bites is a predicate like != null over a column whose "absent" value is a sentinel string - measured on a real build, that reported 95.6% of police cases cleared where the true figure was 16.6%, and every check in this skill still passed.innerHTML with interpolated values. Build every element with createElement + textContent; do not assign innerHTML (or insertAdjacentHTML, document.write) with any string that contains a model value. Query results render any markup they contain - an XSS vector, and blocked outright under a Trusted-Types CSP. This is a hard build rule, not a lint suggestion: an app that interpolates a model value into innerHTML is not done.reference/runtime.md (pure formatting helpers, a chart layer, your tile/query definitions as data, a thin entry point). One source of truth for each tile's model/source/view, no parallel maps that drift.reference/runtime.md.)nullif; convert units explicitly. (reference/runtime.md.)reference/design.md), carries a real token contract (surfaces, text ramp, semantic colors, a categorical chart palette) that the chart code reads at runtime rather than hardcoding, and puts visible weight on the two or three numbers that lead. A uniform grid of same-size cards, or a tile per view, means the brief was skipped.public/, loaded locally (step 5).reference/lazy-load.md is the recipe: IntersectionObserver (rootMargin ~240px) + a small concurrency cap + reserve each tile's height so lazy tiles don't reflow. Includes the verification trap - on a short/tall-default viewport all tiles intersect at once and you get a false "everything deferred" pass, so test on a deliberately small viewport.You are building for someone who cannot tell a correct dashboard from a broken one. Verification is your job, not theirs.
load plus a content selector, not network idle (publisher.js holds an SSE stream open; see reference/runtime.md). Don't hand-roll this each time - reference/verification-harness.md is a copy-adaptable recipe: a mock sdk/publisher.js returning canned rows keyed by (model, query), a python3 -m http.server webroot, and Playwright assertions (KPIs non-null, no .is-error, no stuck .kit-skeleton, a chart/table present). It also documents the false-"stuck skeleton" trap (assert after the mock's async delay, never on networkidle).node --test can cover it, and run it.publisher.json at the package root:
{ "name": "my-package", "version": "0.0.1", "description": "..." }public/index.html is a NEW file you create (make the public/ directory if it does not exist). Load the runtime root-relative, then query. The examples below assume a subscriptions.malloy model with a subscriptions source; the names are illustrative, so swap in your own model and a view it defines.
Start with the smallest page that proves the wiring, dumping the rows:
<!doctype html>
<title>My dashboard</title>
<pre id="out"></pre>
<script src="/sdk/publisher.js"></script>
<script>
Publisher.query("subscriptions.malloy", "run: subscriptions -> plan_mix").then((rows) => {
document.getElementById("out").textContent = JSON.stringify(rows, null, 2);
});
</script>Then render the rows. This page builds a table from whatever columns the view returns, so it does not depend on the exact field names:
<!doctype html>
<title>Account mix by plan</title>
<table id="t"><thead></thead><tbody></tbody></table>
<script src="/sdk/publisher.js"></script>
<script>
Publisher.query("subscriptions.malloy", "run: subscriptions -> plan_mix").then((rows) => {
const t = document.getElementById("t");
if (!rows.length) { t.textContent = "No rows."; return; }
const cols = Object.keys(rows[0]);
const headRow = t.tHead.insertRow();
for (const c of cols) {
const th = document.createElement("th");
th.textContent = c;
headRow.appendChild(th);
}
for (const r of rows) {
const tr = t.tBodies[0].insertRow();
for (const c of cols) tr.insertCell().textContent = r[c];
}
});
</script>Build row content with textContent, not innerHTML with model values: an innerHTML table renders any markup a value contains. This is the HTML-output side of the don't-trust-interpolated-values rule that reference/runtime.md applies to Malloy query strings.
Two invariants break a page most often:
public/. Publisher serves only public/, so a page written anywhere else (for example /tmp) is never reachable at /environments/<env>/packages/<pkg>/<file>./sdk/publisher.js, not a relative path.A third gotcha: the first argument to Publisher.query is the model FILE path ("subscriptions.malloy"), not the source name.
Authoring happens locally, then you publish. These are two stages.
Run a local Publisher from the directory that holds your publisher.config.json and package folder(s):
npx @malloy-publisher/server --server_root . --port 4000 --watch-env <env>--watch-env is not optional if you are adding public/ to a package that is already loaded. Without it the server COPIES each package into publisher_data/<env>/<pkg>/ at load time and serves static files from that copy, so a public/ directory you create afterwards is never seen: every file in it 404s while the rest of the app serves normally. This is the most expensive mistake in this skill, because it looks like your page is broken rather than like the server is stale,.
If you did not start the server (someone handed you a running one), probe before you build: write a throwaway file into the package's public/, request it, and see whether you get 200 or 404. If it 404s, either restart with --watch-env <env> or mirror your files into the served copy after every edit.
--watch-env <env> (or PUBLISHER_WATCH=<env>) mounts that environment's local-dir packages in place (a symlink, not a copy) and watches them: editing a .malloy recompiles the package, and editing a public/ file live-reloads any open page over an SSE stream. Nothing to wire in the page. The app is served at http://localhost:4000/environments/<env>/packages/<pkg>/index.html.
publisher.config.json (at --server_root) declares the environment, its packages, and its connections:
{
"frozenConfig": false,
"environments": [
{
"name": "<env>",
"packages": [{ "name": "<pkg>", "location": "./<pkg>" }],
"connections": []
}
]
}A local package uses a filesystem location ("./<pkg>", relative to the directory holding publisher.config.json); a remote one uses a GitHub tree URL. If one model in the package fails to compile, the whole package fails to load, so a stray notebook/model error blanks every tile. (Common one: a notebook that imports x.malloy more than once, such as a .malloynb whose cells each import "x.malloy", compiles as one batch, so the repeated import errors Cannot redefine 'x'. Import once, at the top.)
Publishing an app is publishing its package: get the package into publishable shape and hand it to your host's publishing workflow. A deployed package serves its public/ app the same way a local one does, at /environments/<env>/packages/<pkg>/<file>. A deployed environment has no --watch-env live reload, so the loop there is author, publish, then view.
© malloydata, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files in skills/malloy-html-data-apps of malloydata/publisher.
Open the folder on GitHubat commit acc1acd
Malloy HTML Data Apps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Malloy HTML Data Apps this skillmalloydata/publisher | 116 | — | ~3.5k | Automated safety check: Pass | MIT | |
| Gameobject ModifyIvanMurzak/Unity-MCP | 4.4k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Object ModifyIvanMurzak/Unity-MCP | 4.4k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Assets ModifyIvanMurzak/Unity-MCP | 4.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Migrating To Modifier NoderosuH/EasyWatermark | 1.9k | 1 repos | ~5k | Automated safety check: Pass | Apache-2.0 | |
| Gameobject Component ModifyIvanMurzak/Unity-MCP | 4.4k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 |
IvanMurzak/Unity-MCP
Modify GameObject fields and properties in opened Prefab or in a Scene.
IvanMurzak/Unity-MCP
Modify a Unity UnityEngine.Object's serializable fields/properties.
IvanMurzak/Unity-MCP
Modify an asset file in the project. An agent skill from IvanMurzak/Unity-MCP.
rosuH/EasyWatermark
A skill your agent uses to author new custom Jetpack Compose modifiers and migrate legacy ones from Modifier.composed { } to Modifier.Node + ModifierNodeElement<T.
IvanMurzak/Unity-MCP
Modify a specific Component on a GameObject in opened Prefab or in a Scene.
rosuH/EasyWatermark
A skill your agent uses to diagnose and fix Jetpack Compose Modifier ordering bugs — wrong paint region for background, wrong click area for clickable, wrong clipping for clip, wrong measurement for…
malloydata/publisher
Score one analytical answer against a verified golden, and score which of the entities the golden depends on retrieval delivered to the answerer.
malloydata/publisher
Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…
malloydata/publisher
Turn a list of questions into an eval set, whatever shape it arrived in: a JSONL a customer sent, a CSV, a spreadsheet export, a markdown doc, an email thread, or a pull from production logs.
malloydata/publisher
Conduct a local Publisher evaluation loop in five steps: scrape/run, eval, diagnose, improve, checkpoint.
malloydata/publisher
Make the smallest safe Malloy model edit that closes a diagnosed model-owned gap, with a probe receipt for every factual claim.
malloydata/publisher
Decide whether ONE answer matches its golden, and say whether you believe the golden.
Build or modify an in-package HTML data app for a Malloy Publisher package (a public/ directory the package serves): design it, write its Publisher.query code, embed it. Malloy HTML Data Apps is an agent skill from malloydata/publisher.query code, embed it.
Run `npx skills add malloydata/publisher --skill malloy-html-data-apps -a claude-code`. Or copy the skill folder (skills/malloy-html-data-apps in malloydata/publisher) into .claude/skills/malloy-html-data-apps in your project. Claude Code loads it when a task matches its description.
Run `npx skills add malloydata/publisher --skill malloy-html-data-apps -a codex`. Or copy the skill folder (skills/malloy-html-data-apps in malloydata/publisher) into .agents/skills/malloy-html-data-apps in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malloydata/publisher --skill malloy-html-data-apps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malloy-html-data-apps, .gemini/skills/malloy-html-data-apps, .github/skills/malloy-html-data-apps and .opencode/skills/malloy-html-data-apps in your project.
Going by SKILL.md and its folder, Malloy HTML Data Apps needs the command-line tools its instructions call (npx, python3 and node). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Malloy HTML Data Apps is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Malloy HTML Data Apps: Gameobject Modify (IvanMurzak/Unity-MCP, 4.4k stars), Object Modify (IvanMurzak/Unity-MCP, 4.4k stars), Assets Modify (IvanMurzak/Unity-MCP, 4.4k stars) and Migrating To Modifier Node (rosuH/EasyWatermark, 1.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
malloydata (a GitHub organization) maintains it in malloydata/publisher, which has 116 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 7, 2026.
Source: malloydata/publisher on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.