Convert File
duckdb/duckdb-skills
Convert any data file to another format: CSV, Parquet, JSON, Excel, GeoJSON, and more.
Package Malloy models for serving by Malloy Publisher. An agent skill from malloydata/publisher.
$ npx skills add malloydata/publisher --skill malloy-publish -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install malloydata/publisher malloy-publish --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malloy-publish .claude/skills/malloy-publish && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "malloy-publish" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-publish into .claude/skills/malloy-publish/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-publish", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/malloydata/publisher/tree/main/skills/malloy-publishType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add malloydata/publisher --skill malloy-publish -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install malloydata/publisher malloy-publish --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/malloy-publish .agents/skills/malloy-publish && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "malloy-publish" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-publish into .agents/skills/malloy-publish/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-publish", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malloydata/publisher --skill malloy-publish -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install malloydata/publisher malloy-publish --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/malloy-publish .cursor/skills/malloy-publish && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "malloy-publish" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-publish into .cursor/skills/malloy-publish/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-publish", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/malloydata/publisher.git --path skills/malloy-publish--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add malloydata/publisher --skill malloy-publish -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install malloydata/publisher malloy-publish --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/malloy-publish .gemini/skills/malloy-publish && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "malloy-publish" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-publish into .gemini/skills/malloy-publish/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-publish", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install malloydata/publisher malloy-publishInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add malloydata/publisher --skill malloy-publish -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/malloy-publish .github/skills/malloy-publish && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "malloy-publish" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-publish into .github/skills/malloy-publish/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-publish", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malloydata/publisher --skill malloy-publish -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install malloydata/publisher malloy-publish --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/malloy-publish .opencode/skills/malloy-publish && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "malloy-publish" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-publish into .opencode/skills/malloy-publish/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-publish", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
malloy-publishPackage Malloy models for serving by Malloy Publisher. An agent skill from malloydata/publisher.
Malloy Publish is an agent skill from malloydata/publisher. Package Malloy models for serving by Malloy Publisher. Use when user asks to "publish", "package", "deploy", or wants to share models with others.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Documents & Office. It works with DuckDB. The repository describes itself as: Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere. The licence is MIT.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit c43a052. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.malloydata.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Malloy Publish loads about 3.5k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 1,918 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from malloydata/publisher at commit c43a052, republished under its MIT licence (© malloydata). 1,918 words, ~3,482 tokens.
.claude/skills/malloy-publish/SKILL.md (or your agent's skills folder).<!--
Copyright (c) Credible Data Inc.
SPDX-License-Identifier: MIT
-->
CRITICAL: Only package or prepare a release when the user explicitly asks. Making model changes, adding documentation, or building notebooks is NOT a publish request. Never auto-package after completing other tasks.
Automated publishing is not part of the open-source Malloy Publisher tool surface yet. There is no publish tool to call from this skill. What this skill does is get a package into a publishable shape: a valid publisher.json, a flat layout, and the right files in the package root.
Once the package is in shape, self-hosters publish it through their own host: commit the package to git, then run the host's publish path (for example, the deploy step that points a Publisher server at the package directory or repository). The mechanics of that path depend on how the Publisher instance is deployed, so confirm with the user how their instance is served rather than assuming a hosted control plane.
.malloy) and/or notebook (notebooks/<slug>.malloy) files readyA package backed by data files (CSV/Parquet/XLSX/JSON) needs no connections entry at all in publisher.config.json: every loaded package automatically gets its own DuckDB sandbox connection named duckdb, which is what duckdb.table('data/file.csv') resolves against. That name is reserved: declaring an environment-level connection named duckdb fails the whole environment at init (name an env-level DuckDB connection something like shared_duckdb instead). See docs/connections.md.
Two more facts about how a Publisher server sees the package, both easy to get wrong:
A package location is treated as local only when it starts with ./, ../, ~/, or /. A bare name like "spotify" is silently not local; write "./spotify".
Local authoring means --watch-env. Without --watch-env <env>, Publisher copies each local package into publisher_data/ at boot and serves the copy; edits to your source directory are never read, however many times you save. Start the server with --watch-env <env> (mounts the package in place and live-reloads), the same command skill:malloy-html-data-apps uses:
npx @malloy-publisher/server --server_root . --port 4000 --watch-env <env>Check if publisher.json exists in the package root. If it does, proceed to Step 2.
If it doesn't exist, create one. Suggest a package name based on the model content, write a brief description, and default to version 0.0.1.
{
"name": "package-name",
"version": "0.0.1",
"description": "Brief description of the package"
}Naming conventions:
name: lowercase, hyphens allowed (e.g., ecommerce, sales-analytics)version: semver format (e.g., 0.0.1, 1.2.3)A package with no index.malloy and no explores exposes everything: every model is listed and every source is directly queryable.
To curate, add an index.malloy at the package root. Publisher reads it as the package's published surface, so no manifest field is involved:
// index.malloy
import "order_analysis.malloy"
import "staging.malloy"
export { orders, customers }What it exports is what agents discover and what may be queried. Everything else still compiles, and other models can import, join and extend it, but a direct query against it is refused with a 404. Where nothing in the model is gated, the 404 says the source is off the surface and how to publish it; where a gate is in play, it reads exactly like a source that does not exist. Reach for this when you have raw/staging/scaffolding sources that exist to build a curated entry point and you don't want agents landing on, or querying, them directly.
Address queries to the surface. Once a package has an index.malloy, .../models/staging.malloy/query is no longer a query entry point, even for a source that file declares itself. Use .../models/index.malloy/query. If you are debugging a refusal rather than authoring, skill:malloy-source-unreachable covers the three ways a source can be out of reach and how to tell them apart.
A surface can be layered. An index.malloy may front a file that fronts another. A source re-exported through a chain of files stays queryable through the surface at any depth, because admission follows the declaration rather than the path taken to it.
Curation hides a landing point, not a column. A published source may join an unpublished one, and a query grouping by a joined field returns that field's values normally. If a column must not be readable, do not join it into something you publish; gate it with #(authorize) instead.
Leaving a source out does not put it out of reach, but there is a condition. export { ... } also decides what an importing file may see, which is Malloy's rule rather than Publisher's. A file that declares no export hands an importer everything it declares, so an unpublished source stays importable and joinable from the file that declares it. A file that does declare one hands over exactly that list: importing a file whose export omits a source and then naming it fails to compile with Reference to undefined object. Put an export on a mid-layer file only when you mean to narrow what its importers can build on, not just what Publisher lists.
About export { … }: the surface filters which files are listed; export { … } (a Malloy statement) filters which sources within a file are exposed, and the two compose. You usually don't write it in a leaf model: a file with no export exposes all of its own top-level sources. It must appear after the definitions it names. See Malloy: Imports & Exports.
Givens reach callers through index.malloy's imports, not its export. A given: is a name like a source. A caller can set it only if index.malloy has it in scope, and you never list givens in export { … }. How you import decides it:
import "orders.malloy" (the whole file) brings every given orders.malloy declares. Use this form, then export only the curated sources.import { orders } from "orders.malloy" brings only orders. Its givens stay behind. Name them too: import { orders, REGION } from "orders.malloy".orders.malloy gets its givens from a givens.malloy, import givens.malloy into index.malloy as well, or list the givens in orders.malloy's own export { … }.A given index.malloy leaves out fails in one of three ways, depending on how it is declared:
| the given | what happens |
|---|---|
| has a default | the source runs on the default, and a caller who sets the given gets 400 unknown given 'REGION'. Model surfaces [...]. Agents never learn it exists |
| has no default | a query on the source answers 400 ... references given MIN_AMT ..., which is not surfaced in this model and has no default, even when the caller sends a value. A query that joins the source in its own text gets 404 Query target is not queryable instead, which reads like curation; compile_model on that query shows the real cause |
is read by an #(authorize) or #(access_filter) gate | the package does not load: $GROUPS references a given named GROUPS, which is not declared in this model |
To check, fetch index.malloy's model: its givens should list every given a published source reads.
publisher.json has two older keys for this, explores and queryableSources. A new package uses neither: index.malloy does the job.
explores (string[]) is deprecated in every form. The files it lists are listed and queryable, and what they export is the surface, wherever they live. The one exception is a tagged dashboard it lists, which reads the surface and adds nothing to it. A package that sets it gets a load-time warning naming the edit that replaces it. A surface spanning several files needs no explores: import them all into one index.malloy and export what you publish.
// index.malloy
import "order_analysis.malloy"
import "customer_health.malloy"
export { orders, customers, customer_health }"explores": [] is deprecated too. It used to mean "do not curate". To publish everything now, rename or remove index.malloy, and point any file that imports it at the new name first: a broken import fails the whole package. An entry that doesn't resolve to a real .malloy file surfaces in exploresWarnings, and publishing a package that has any is rejected. When explores is set and does not list index.malloy, the index file is ignored, and a warning says so.
queryableSources ("declared" | "all") is deprecated too. "declared" is the default, so setting it does nothing and draws a warning. "all" has one use: hiding an #(authorize)-gated source from listings while authorized callers still query it by name. It keeps the listings index.malloy curates and leaves every source queryable by name. It needs no explores beside it and draws no warning. Leave it out unless you have that case.
Not access control. The surface gates the query surface (the query endpoints, REST and MCP alike), not compile and not raw file retrieval by exact path:
/compileandcompile_modelare deliberately exempt, because compile is the authoring loop and the boundary is discovery curation. It doesn't restrict who may query, only what is queryable by name. Queryable sources are the union of every listed file'sexport {}closure, whichever listed model path a query addresses them through. To gate access by caller-supplied identity/role, use#(authorize)on the source (and#(access_filter)to scope rows), seeskill:malloy-model§ Access Control anddocs/authorize.md. Discovery curation and these gates are independent layers.
The manifest also carries a scope field ("package" | "version", default "package") controlling whether persisted/materialized artifacts are shared across published versions or owned by a single version, and a materialization field configuring that persistence policy (a cron schedule or a freshness window). Both are unrelated to discovery curation; there is no per-source sharing or schedule field, that was retired in favor of the single package-level scope and materialization.
With a valid publisher.json in place, confirm the package is in the flat, publishable shape described below. There is no publish tool to call in open-source v1; hand the package off to the host's publish path (git plus the deploy step for your Publisher instance).
A flat layout at the package root is the simplest default. Subfolders work too: an import path resolves relative to the file that contains it, so import "../storefront.malloy" works from a file under dashboards/. Notebooks live under notebooks/ and dashboards under dashboards/.
<package-name>/
publisher.json
customers.malloy # Base source file
orders.malloy # Base source file
user_order_facts.malloy # Computed source
order_analysis.malloy # Source file (joins base sources)
customer_health.malloy # Source file
notebooks/
monthly_report.malloy # Notebook (optional)Publishable contents:
.malloy files - Semantic model definitions (base sources + joined sources)notebooks/*.malloy files with an ## artifact { kind=notebook … } tag - Notebooks for exploration/documentation, written as a one-column layout of tiles or as older run: cells (see skill:malloy-notebooks). The tag's kind= decides whether a file is a notebook or a dashboard, not its folder. An existing .malloynb is still served; never write a new one.publisher.json when you cut a new release, or if a publish step rejects a version that already exists.publisher.json exists; if not, create it (suggest name from model content, default 0.0.1).notebooks/, dashboards under dashboards/.publisher.json and retry.Can't find source X, or the file is not found): the path is read relative to the importing file, not the package root. Fix the path; do not move files.publisher.json before re-publishing.Step complete. Output: package is in publishable shape (valid publisher.json, imports that resolve), ready for the host's publish path.
© malloydata, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/malloy-publish of malloydata/publisher.
Open the folder on GitHubat commit c43a052
Malloy Publish next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Malloy Publish this skillmalloydata/publisher | 116 | — | ~3.5k | Automated safety check: Pass | MIT | |
| Convert Fileduckdb/duckdb-skills | 603 | 1 repos | ~720 | Automated safety check: Notes | MIT | |
| Gaik ToolkitGAIK-project/gaik-toolkit | 100 | — | ~5.7k | Automated safety check: Pass | MIT | |
| Data Processingjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Excel and CSV Data Analysisbytedance/deer-flow | 84k | 4 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Mathmodel SkillhandsomeZR-netizen/mathmodel-skill | 292 | — | ~2.5k | Automated safety check: Pass | MIT |
duckdb/duckdb-skills
Convert any data file to another format: CSV, Parquet, JSON, Excel, GeoJSON, and more.
GAIK-project/gaik-toolkit
GAIK toolkit overview and reference. An agent skill from GAIK-project/gaik-toolkit.
jeremylongshore/tons-of-skills-marketplace
A skill your agent uses when working with structured data files (CSV, JSON, YAML, TOML, Parquet) — querying, transforming, filtering, aggregating, or converting between formats
bytedance/deer-flow
Analyzes uploaded Excel and CSV files with SQL through DuckDB, producing schema inspections, statistical summaries and exports to CSV, JSON or Markdown.
handsomeZR-netizen/mathmodel-skill
CUMCM 国赛、MCM/ICM 美赛与电工杯数学建模竞赛的端到端协作工作流。Use when a user explicitly works on one of these modeling contests or asks to run/review a modeling-competition paper from problem selection through modeling…
ItsssssJack/power-design
Generate beautiful, on-brand HTML — presentation decks or full responsive websites — in any brand's design language, combining brand DNA extracted via Firecrawl with codified, research-backed design…
malloydata/publisher
Score one analytical answer against a verified golden, and score which of the entities the golden depends on retrieval delivered to the answerer.
malloydata/publisher
Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…
malloydata/publisher
Turn a list of questions into an eval set, whatever shape it arrived in: a JSONL a customer sent, a CSV, a spreadsheet export, a markdown doc, an email thread, or a pull from production logs.
malloydata/publisher
Conduct a local Publisher evaluation loop in five steps: scrape/run, eval, diagnose, improve, checkpoint.
malloydata/publisher
Make the smallest safe Malloy model edit that closes a diagnosed model-owned gap, with a probe receipt for every factual claim.
malloydata/publisher
Decide whether ONE answer matches its golden, and say whether you believe the golden.
Works with
Categories
Package Malloy models for serving by Malloy Publisher. An agent skill from malloydata/publisher. Malloy Publish is an agent skill from malloydata/publisher. Package Malloy models for serving by Malloy Publisher.
Malloy Publish fits situations like: user asks to publish; wants to share models with others.
Run `npx skills add malloydata/publisher --skill malloy-publish -a claude-code`. Or copy the skill folder (skills/malloy-publish in malloydata/publisher) into .claude/skills/malloy-publish in your project. Claude Code loads it when a task matches its description.
Run `npx skills add malloydata/publisher --skill malloy-publish -a codex`. Or copy the skill folder (skills/malloy-publish in malloydata/publisher) into .agents/skills/malloy-publish in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malloydata/publisher --skill malloy-publish -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malloy-publish, .gemini/skills/malloy-publish, .github/skills/malloy-publish and .opencode/skills/malloy-publish in your project.
Going by SKILL.md and its folder, Malloy Publish needs the command-line tools its instructions call (npx). Our summary lists: Node.js.
SKILL.md names 1 domain. As links in the text: docs.malloydata.dev. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Malloy Publish is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Malloy Publish: Convert File (duckdb/duckdb-skills, 603 stars), Gaik Toolkit (GAIK-project/gaik-toolkit, 100 stars), Data Processing (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Excel and CSV Data Analysis (bytedance/deer-flow, 84k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
malloydata (a GitHub organization) maintains it in malloydata/publisher, which has 116 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 10, 2026.
Source: malloydata/publisher on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.