Agent skill

Malloy Publish

by malloydata in malloydata/publisher

Package Malloy models for serving by Malloy Publisher. An agent skill from malloydata/publisher.

MITAuto-check passedDocuments & Office

Install Malloy Publish

skills CLI
$ npx skills add malloydata/publisher --skill malloy-publish -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install malloydata/publisher malloy-publish --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malloy-publish .claude/skills/malloy-publish && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
malloy-publish
GitHub stars
116
Token cost
~3.5k tokens
SKILL.md length
1,918 words
Files
1
Skills in repo
29
Repo updated
First seen
Licence
MIT

At a glance

Package Malloy models for serving by Malloy Publisher. An agent skill from malloydata/publisher.

  • Works in 2 steps: Verify publisher.json → Confirm the package layout
  • User asks to publish
  • SKILL.md covers Publishing in open-source…, Prerequisites, Connections: a flat-file… and Step 1: Verify publisher.json, plus 6 more sections
  • Calls npx

What it does

Malloy Publish is an agent skill from malloydata/publisher. Package Malloy models for serving by Malloy Publisher. Use when user asks to "publish", "package", "deploy", or wants to share models with others.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office. It works with DuckDB. The repository describes itself as: Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere. The licence is MIT.

When your agent uses it

  • User asks to publish
  • Wants to share models with others

Example prompts

  • “publish”
  • “package”
  • “deploy”
  • “/malloy-publish”

Requirements

  • Node.js

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Verify publisher.json
  2. Confirm the package layout

What it can do on your machine

Read from SKILL.md and the folder at commit c43a052. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.malloydata.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Malloy Publish loads about 3.5k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,918 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from malloydata/publisher at commit c43a052, republished under its MIT licence (© malloydata). 1,918 words, ~3,482 tokens.

Download SKILL.mdSave it as .claude/skills/malloy-publish/SKILL.md (or your agent's skills folder).
name
malloy-publish
description
Package Malloy models for serving by Malloy Publisher. Use when user asks to "publish", "package", "deploy", or wants to share models with others.
<!--
Copyright (c) Credible Data Inc.
SPDX-License-Identifier: MIT
-->

Packaging Malloy models for Publisher

CRITICAL: Only package or prepare a release when the user explicitly asks. Making model changes, adding documentation, or building notebooks is NOT a publish request. Never auto-package after completing other tasks.

Publishing in open-source Publisher

Automated publishing is not part of the open-source Malloy Publisher tool surface yet. There is no publish tool to call from this skill. What this skill does is get a package into a publishable shape: a valid publisher.json, a flat layout, and the right files in the package root.

Once the package is in shape, self-hosters publish it through their own host: commit the package to git, then run the host's publish path (for example, the deploy step that points a Publisher server at the package directory or repository). The mechanics of that path depend on how the Publisher instance is deployed, so confirm with the user how their instance is served rather than assuming a hosted control plane.

Prerequisites

  • Malloy model (.malloy) and/or notebook (notebooks/<slug>.malloy) files ready
  • The Publisher MCP tools configured (used by the modeling and analysis skills, not by a publish step)

Connections: a flat-file package needs none

A package backed by data files (CSV/Parquet/XLSX/JSON) needs no connections entry at all in publisher.config.json: every loaded package automatically gets its own DuckDB sandbox connection named duckdb, which is what duckdb.table('data/file.csv') resolves against. That name is reserved: declaring an environment-level connection named duckdb fails the whole environment at init (name an env-level DuckDB connection something like shared_duckdb instead). See docs/connections.md.

Two more facts about how a Publisher server sees the package, both easy to get wrong:

  • A package location is treated as local only when it starts with ./, ../, ~/, or /. A bare name like "spotify" is silently not local; write "./spotify".

  • Local authoring means --watch-env. Without --watch-env <env>, Publisher copies each local package into publisher_data/ at boot and serves the copy; edits to your source directory are never read, however many times you save. Start the server with --watch-env <env> (mounts the package in place and live-reloads), the same command skill:malloy-html-data-apps uses:

    sh
    npx @malloy-publisher/server --server_root . --port 4000 --watch-env <env>

Step 1: Verify publisher.json

Check if publisher.json exists in the package root. If it does, proceed to Step 2.

If it doesn't exist, create one. Suggest a package name based on the model content, write a brief description, and default to version 0.0.1.

json
{
  "name": "package-name",
  "version": "0.0.1",
  "description": "Brief description of the package"
}

Naming conventions:

  • name: lowercase, hyphens allowed (e.g., ecommerce, sales-analytics)
  • version: semver format (e.g., 0.0.1, 1.2.3)
Curating discovery & the query boundary (optional)

A package with no index.malloy and no explores exposes everything: every model is listed and every source is directly queryable.

To curate, add an index.malloy at the package root. Publisher reads it as the package's published surface, so no manifest field is involved:

malloy
// index.malloy
import "order_analysis.malloy"
import "staging.malloy"

export { orders, customers }

What it exports is what agents discover and what may be queried. Everything else still compiles, and other models can import, join and extend it, but a direct query against it is refused with a 404. Where nothing in the model is gated, the 404 says the source is off the surface and how to publish it; where a gate is in play, it reads exactly like a source that does not exist. Reach for this when you have raw/staging/scaffolding sources that exist to build a curated entry point and you don't want agents landing on, or querying, them directly.

Address queries to the surface. Once a package has an index.malloy, .../models/staging.malloy/query is no longer a query entry point, even for a source that file declares itself. Use .../models/index.malloy/query. If you are debugging a refusal rather than authoring, skill:malloy-source-unreachable covers the three ways a source can be out of reach and how to tell them apart.

A surface can be layered. An index.malloy may front a file that fronts another. A source re-exported through a chain of files stays queryable through the surface at any depth, because admission follows the declaration rather than the path taken to it.

Curation hides a landing point, not a column. A published source may join an unpublished one, and a query grouping by a joined field returns that field's values normally. If a column must not be readable, do not join it into something you publish; gate it with #(authorize) instead.

Leaving a source out does not put it out of reach, but there is a condition. export { ... } also decides what an importing file may see, which is Malloy's rule rather than Publisher's. A file that declares no export hands an importer everything it declares, so an unpublished source stays importable and joinable from the file that declares it. A file that does declare one hands over exactly that list: importing a file whose export omits a source and then naming it fails to compile with Reference to undefined object. Put an export on a mid-layer file only when you mean to narrow what its importers can build on, not just what Publisher lists.

About export { … }: the surface filters which files are listed; export { … } (a Malloy statement) filters which sources within a file are exposed, and the two compose. You usually don't write it in a leaf model: a file with no export exposes all of its own top-level sources. It must appear after the definitions it names. See Malloy: Imports & Exports.

Givens reach callers through index.malloy's imports, not its export. A given: is a name like a source. A caller can set it only if index.malloy has it in scope, and you never list givens in export { … }. How you import decides it:

  • import "orders.malloy" (the whole file) brings every given orders.malloy declares. Use this form, then export only the curated sources.
  • import { orders } from "orders.malloy" brings only orders. Its givens stay behind. Name them too: import { orders, REGION } from "orders.malloy".
  • Imports don't chain. If orders.malloy gets its givens from a givens.malloy, import givens.malloy into index.malloy as well, or list the givens in orders.malloy's own export { … }.

A given index.malloy leaves out fails in one of three ways, depending on how it is declared:

the givenwhat happens
has a defaultthe source runs on the default, and a caller who sets the given gets 400 unknown given 'REGION'. Model surfaces [...]. Agents never learn it exists
has no defaulta query on the source answers 400 ... references given MIN_AMT ..., which is not surfaced in this model and has no default, even when the caller sends a value. A query that joins the source in its own text gets 404 Query target is not queryable instead, which reads like curation; compile_model on that query shows the real cause
is read by an #(authorize) or #(access_filter) gatethe package does not load: $GROUPS references a given named GROUPS, which is not declared in this model

To check, fetch index.malloy's model: its givens should list every given a published source reads.

Show full SKILL.md (806 more words)Show less
The older manifest fields

publisher.json has two older keys for this, explores and queryableSources. A new package uses neither: index.malloy does the job.

  • explores (string[]) is deprecated in every form. The files it lists are listed and queryable, and what they export is the surface, wherever they live. The one exception is a tagged dashboard it lists, which reads the surface and adds nothing to it. A package that sets it gets a load-time warning naming the edit that replaces it. A surface spanning several files needs no explores: import them all into one index.malloy and export what you publish.

    malloy
    // index.malloy
    import "order_analysis.malloy"
    import "customer_health.malloy"
    
    export { orders, customers, customer_health }

    "explores": [] is deprecated too. It used to mean "do not curate". To publish everything now, rename or remove index.malloy, and point any file that imports it at the new name first: a broken import fails the whole package. An entry that doesn't resolve to a real .malloy file surfaces in exploresWarnings, and publishing a package that has any is rejected. When explores is set and does not list index.malloy, the index file is ignored, and a warning says so.

  • queryableSources ("declared" | "all") is deprecated too. "declared" is the default, so setting it does nothing and draws a warning. "all" has one use: hiding an #(authorize)-gated source from listings while authorized callers still query it by name. It keeps the listings index.malloy curates and leaves every source queryable by name. It needs no explores beside it and draws no warning. Leave it out unless you have that case.

Not access control. The surface gates the query surface (the query endpoints, REST and MCP alike), not compile and not raw file retrieval by exact path: /compile and compile_model are deliberately exempt, because compile is the authoring loop and the boundary is discovery curation. It doesn't restrict who may query, only what is queryable by name. Queryable sources are the union of every listed file's export {} closure, whichever listed model path a query addresses them through. To gate access by caller-supplied identity/role, use #(authorize) on the source (and #(access_filter) to scope rows), see skill:malloy-model § Access Control and docs/authorize.md. Discovery curation and these gates are independent layers.

The manifest also carries a scope field ("package" | "version", default "package") controlling whether persisted/materialized artifacts are shared across published versions or owned by a single version, and a materialization field configuring that persistence policy (a cron schedule or a freshness window). Both are unrelated to discovery curation; there is no per-source sharing or schedule field, that was retired in favor of the single package-level scope and materialization.

Step 2: Confirm the package layout

With a valid publisher.json in place, confirm the package is in the flat, publishable shape described below. There is no publish tool to call in open-source v1; hand the package off to the host's publish path (git plus the deploy step for your Publisher instance).

Package Structure

A flat layout at the package root is the simplest default. Subfolders work too: an import path resolves relative to the file that contains it, so import "../storefront.malloy" works from a file under dashboards/. Notebooks live under notebooks/ and dashboards under dashboards/.

<package-name>/
  publisher.json
  customers.malloy              # Base source file
  orders.malloy                 # Base source file
  user_order_facts.malloy       # Computed source
  order_analysis.malloy         # Source file (joins base sources)
  customer_health.malloy        # Source file
  notebooks/
    monthly_report.malloy       # Notebook (optional)

Publishable contents:

  • .malloy files - Semantic model definitions (base sources + joined sources)
  • notebooks/*.malloy files with an ## artifact { kind=notebook … } tag - Notebooks for exploration/documentation, written as a one-column layout of tiles or as older run: cells (see skill:malloy-notebooks). The tag's kind= decides whether a file is a notebook or a dashboard, not its folder. An existing .malloynb is still served; never write a new one.
  • Data files (CSV/Parquet/XLSX) - Embedded data published with package

Version Management

  • Treat each published version as immutable once it is served.
  • "Latest" determines the default version consumers resolve.
  • Keep older versions available so existing consumers keep working.
  • Bump the version in publisher.json when you cut a new release, or if a publish step rejects a version that already exists.

Workflow

  1. Verify publisher.json exists; if not, create it (suggest name from model content, default 0.0.1).
  2. Confirm the package layout: model files in the package root (or imported by relative path from wherever they sit), notebooks under notebooks/, dashboards under dashboards/.
  3. Hand the package to the host's publish path (commit to git, then run the deploy step for your Publisher instance). If a version-already-exists conflict occurs, bump the patch version in publisher.json and retry.
  4. Confirm with the user how their package is served so they can verify it is reachable.

Common Issues

  • An import does not resolve (Can't find source X, or the file is not found): the path is read relative to the importing file, not the package root. Fix the path; do not move files.
  • Version already exists: Bump the patch version in publisher.json before re-publishing.

Done

Step complete. Output: package is in publishable shape (valid publisher.json, imports that resolve), ready for the host's publish path.

© malloydata, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/malloy-publish of malloydata/publisher.

Open the folder on GitHubat commit c43a052

Compare with similar skills

Malloy Publish next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Malloy Publish compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Malloy Publish this skillmalloydata/publisher116—~3.5kAutomated safety check: PassMIT
Convert Fileduckdb/duckdb-skills6031 repos~720Automated safety check: NotesMIT
Gaik ToolkitGAIK-project/gaik-toolkit100—~5.7kAutomated safety check: PassMIT
Data Processingjeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Excel and CSV Data Analysisbytedance/deer-flow84k4 repos~2.2kAutomated safety check: PassMIT
Mathmodel SkillhandsomeZR-netizen/mathmodel-skill292—~2.5kAutomated safety check: PassMIT

Similar skills

  • Convert File

    duckdb/duckdb-skills

    Official

    Convert any data file to another format: CSV, Parquet, JSON, Excel, GeoJSON, and more.

    603 GitHub starsUsed in 1 repo~720 tokens
    Documents & OfficeAuto-check: notes
  • Gaik Toolkit

    GAIK-project/gaik-toolkit

    GAIK toolkit overview and reference. An agent skill from GAIK-project/gaik-toolkit.

    100 GitHub stars~5.7k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Data Processing

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses when working with structured data files (CSV, JSON, YAML, TOML, Parquet) — querying, transforming, filtering, aggregating, or converting between formats

    2.8k GitHub stars~1.3k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Excel and CSV Data Analysis

    bytedance/deer-flow

    Analyzes uploaded Excel and CSV files with SQL through DuckDB, producing schema inspections, statistical summaries and exports to CSV, JSON or Markdown.

    84k GitHub starsUsed in 4 repos~2.2k tokens
    Data & AnalyticsAuto-check passed
  • Mathmodel Skill

    handsomeZR-netizen/mathmodel-skill

    CUMCM 国赛、MCM/ICM 美赛与电工杯数学建模竞赛的端到端协作工作流。Use when a user explicitly works on one of these modeling contests or asks to run/review a modeling-competition paper from problem selection through modeling…

    292 GitHub stars~2.5k tokensUpdated 14 days ago
    Documents & OfficeAuto-check passed
  • Power Design

    ItsssssJack/power-design

    Generate beautiful, on-brand HTML — presentation decks or full responsive websites — in any brand's design language, combining brand DNA extracted via Firecrawl with codified, research-backed design…

    722 GitHub stars~2.8k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check passed

More from malloydata/publisher

All 29 skills in this repo
  • Eval Answer

    malloydata/publisher

    Score one analytical answer against a verified golden, and score which of the entities the golden depends on retrieval delivered to the answerer.

    116 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Fix Scan Finding

    malloydata/publisher

    Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

    116 GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • Eval Import

    malloydata/publisher

    Turn a list of questions into an eval set, whatever shape it arrived in: a JSONL a customer sent, a CSV, a spreadsheet export, a markdown doc, an email thread, or a pull from production logs.

    116 GitHub stars~5.9k tokensUpdated today
    Auto-check passed
  • Eval Loop

    malloydata/publisher

    Conduct a local Publisher evaluation loop in five steps: scrape/run, eval, diagnose, improve, checkpoint.

    116 GitHub stars~7.8k tokensUpdated today
    Auto-check passed
  • Eval Improve

    malloydata/publisher

    Make the smallest safe Malloy model edit that closes a diagnosed model-owned gap, with a probe receipt for every factual claim.

    116 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Eval Judge

    malloydata/publisher

    Decide whether ONE answer matches its golden, and say whether you believe the golden.

    116 GitHub stars~3.4k tokensUpdated today
    Auto-check passed

Works with

Questions about Malloy Publish

What does Malloy Publish do?

Package Malloy models for serving by Malloy Publisher. An agent skill from malloydata/publisher. Malloy Publish is an agent skill from malloydata/publisher. Package Malloy models for serving by Malloy Publisher.

When should I use Malloy Publish?

Malloy Publish fits situations like: user asks to publish; wants to share models with others.

How do I install Malloy Publish in Claude Code?

Run `npx skills add malloydata/publisher --skill malloy-publish -a claude-code`. Or copy the skill folder (skills/malloy-publish in malloydata/publisher) into .claude/skills/malloy-publish in your project. Claude Code loads it when a task matches its description.

How do I install Malloy Publish in Codex?

Run `npx skills add malloydata/publisher --skill malloy-publish -a codex`. Or copy the skill folder (skills/malloy-publish in malloydata/publisher) into .agents/skills/malloy-publish in your project. Codex loads it when a task matches its description.

Can I use Malloy Publish in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malloydata/publisher --skill malloy-publish -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malloy-publish, .gemini/skills/malloy-publish, .github/skills/malloy-publish and .opencode/skills/malloy-publish in your project.

What does Malloy Publish need to run?

Going by SKILL.md and its folder, Malloy Publish needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Malloy Publish access the network?

SKILL.md names 1 domain. As links in the text: docs.malloydata.dev. This is read from the text; nothing was executed.

Is Malloy Publish safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Malloy Publish use?

Malloy Publish is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Malloy Publish use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Malloy Publish?

Skills that share tags, products or a category with Malloy Publish: Convert File (duckdb/duckdb-skills, 603 stars), Gaik Toolkit (GAIK-project/gaik-toolkit, 100 stars), Data Processing (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Excel and CSV Data Analysis (bytedance/deer-flow, 84k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Malloy Publish?

malloydata (a GitHub organization) maintains it in malloydata/publisher, which has 116 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 10, 2026.

Source: malloydata/publisher on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.