Unreachable Subsystems
calimero-network/core
Finds code that compiles, lints clean and is referenced, but that nothing can actually reach — dead islands whose items reference each other while the outermost edge points at a route, command, or…
Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next.
$ npx skills add malloydata/publisher --skill malloy-source-unreachable -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install malloydata/publisher malloy-source-unreachable --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malloy-source-unreachable .claude/skills/malloy-source-unreachable && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "malloy-source-unreachable" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-source-unreachable into .claude/skills/malloy-source-unreachable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-source-unreachable", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/malloydata/publisher/tree/main/skills/malloy-source-unreachableType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add malloydata/publisher --skill malloy-source-unreachable -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install malloydata/publisher malloy-source-unreachable --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/malloy-source-unreachable .agents/skills/malloy-source-unreachable && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "malloy-source-unreachable" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-source-unreachable into .agents/skills/malloy-source-unreachable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-source-unreachable", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malloydata/publisher --skill malloy-source-unreachable -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install malloydata/publisher malloy-source-unreachable --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/malloy-source-unreachable .cursor/skills/malloy-source-unreachable && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "malloy-source-unreachable" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-source-unreachable into .cursor/skills/malloy-source-unreachable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-source-unreachable", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/malloydata/publisher.git --path skills/malloy-source-unreachable--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add malloydata/publisher --skill malloy-source-unreachable -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install malloydata/publisher malloy-source-unreachable --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/malloy-source-unreachable .gemini/skills/malloy-source-unreachable && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "malloy-source-unreachable" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-source-unreachable into .gemini/skills/malloy-source-unreachable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-source-unreachable", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install malloydata/publisher malloy-source-unreachableInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add malloydata/publisher --skill malloy-source-unreachable -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/malloy-source-unreachable .github/skills/malloy-source-unreachable && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "malloy-source-unreachable" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-source-unreachable into .github/skills/malloy-source-unreachable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-source-unreachable", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malloydata/publisher --skill malloy-source-unreachable -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install malloydata/publisher malloy-source-unreachable --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/malloy-source-unreachable .opencode/skills/malloy-source-unreachable && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "malloy-source-unreachable" agent skill from https://github.com/malloydata/publisher/tree/main/skills/malloy-source-unreachable into .opencode/skills/malloy-source-unreachable/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "malloy-source-unreachable", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
malloy-source-unreachableWork out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next.
Malloy Source Unreachable is an agent skill from malloydata/publisher. Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next. Use when a source you expect is absent from discovery, when executequery answers "No queryable source", when a query that used to work stops working, or when deciding whether a package's curation is hiding something you need.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b9a1a19. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Malloy Source Unreachable loads about 2.2k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,346 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from malloydata/publisher at commit b9a1a19, republished under its MIT licence (© malloydata). 1,346 words, ~2,200 tokens.
.claude/skills/malloy-source-unreachable/SKILL.md (or your agent's skills folder).<!-- Copyright (c) Credible Data Inc. SPDX-License-Identifier: MIT -->
Tool names are written bare here -
get_context,execute_query,get_status,compile_model. The exact prefixed name depends on the host surface; match each against the tools you actually have.
Most packages publish a curated surface, so a source being absent or refused is usually the package working as its author intended, not a fault. Read the refusal before working around it, because the three things that can refuse you need three different responses and they are told apart by the status code.
| what you got | what it means | what to do |
|---|---|---|
| 404 that says "not on this package's published surface" | the name is real and the package does not publish it. It is curation, not a typo | follow the fix the message names (usually: name it in the export { ... } of index.malloy and address the query there), or query what IS published |
| 404, plain "No queryable source", "No queryable model" or "Query target is not queryable" | the name does not exist, or it is hidden in a model that carries an #(authorize) or #(access_filter) gate. In a gated model the two are deliberately indistinguishable, so a refusal cannot be used to probe for hidden names | check the name against get_context, then query something on the surface or ask the package's author to publish it |
| 403, "Access denied" | the source exists and is on the surface, but an #(authorize) gate did not admit you | supply the givens the gate reads, or accept that this caller may not read it |
| 200 with zero rows | you were admitted, and an #(access_filter) narrowed the rows to none of them | this is a real answer. Report it as "no matching rows", never as an error |
A 403 names a source, so it tells you the source exists. A plain 404 tells you nothing at all. That asymmetry is deliberate: a source that is both hidden AND gated answers a plain 404, so you can never use a 403, or the wording of a 404, to discover that a hidden gated name is real.
One 404 is not about the source at all. If a query that joins an exported source in its own text answers Query target is not queryable, check the joined source's givens. A source that reads a given with no default, which index.malloy does not import, is refused that way when joined. Queried directly, the same source answers a 400 that names the cause. Run the joining query through compile_model: the problem then reads "references given NAME ... which is not surfaced in this model". The fix belongs in the model, not the query, so report it to the model's author: index.malloy has to import that given, either by importing its declaring file whole or by naming the given in a selective import.
A query names a model file. When a package curates its surface, only files on that surface are valid entry points, even for a source that file declares itself:
POST .../packages/sales/models/index.malloy/query {"sourceName": "orders"} -> 200
POST .../packages/sales/models/orders.malloy/query {"sourceName": "orders"} -> 404Same source, same package. orders.malloy is off the surface, so it is not an entry point.
Use the model_path that get_context gave you, verbatim. Its source_info.resource_id holds environment, package, model_path and source, and those are exactly execute_query's environmentName, packageName, modelPath and sourceName. On a curated package the model_path is the surface file, not the file that declares the source. Substituting the declaring file because it looks more correct is how this 404 happens.
The query route is not the only one held to the surface. On a curated package, a source or file off it also shows up as a 404 here:
GET .../models/{path} answers 404 for a file off the surface, with the same words as the query route. The file still exists and still compiles; read index.malloy instead. A model that is on the surface lists only the names it publishes, not everything it imports.suggest over a hidden source answers 404. The dashboard itself is still listed. The package load warns once per tile, for example Tile orders_staging -> by_flag on dashboard overview reads orders_staging, which index.malloy doesn't export, so it won't load. Fix: add orders_staging to the export { ... } in index.malloy. It is in the warnings on the package's own response, GET .../packages/{pkg}.The fix is the same in each case: add the source to the export { ... } in index.malloy, or use what is already published.
get_context at allWork down this list. The first three are far more common than the last.
list_packages: a package that failed to load appears with an error, and one serving the model it compiled before a failed reload carries stale: true and the error too. get_status has the full load errors.list_packages and check the environment and package names are the ones you expect. A stale .mcp.json outlives the server that wrote it, and another Publisher may hold that port.search_text) to enumerate rather than rank. If it appears there, the source exists and was a ranking miss.join an unpublished one, and a query grouping by a joined field returns that field's values normally. Hiding a source removes it as a landing point; it does not redact columns a published source pulls in./compile. compile_model is exempt, because compile is the authoring loop. A hidden source can still be compile-checked, and that is intended. The exceptions are a hidden source that is also gated, which answers 404 at compile too, and a document (text with a model-level ## artifact tag): its tiles and cells are held to the surface, so one over a source off it comes back as a query-not-queryable problem rather than compiling.#(authorize) and #(access_filter). A source is not protected by being hidden.If you are writing Malloy rather than just querying, an unpublished source is still usable, with one condition that trips people.
export { ... } decides what an importing file can see, which is Malloy's rule and not Publisher's:
export hands an importer everything it declares, so import the file that declares the source and join it normally;export omits the source and then naming it fails to compile with Reference to undefined object.So an unpublished source is reachable through a file that exports it, or that exports nothing, and not through a file whose export leaves it out. Re-export chains are fine at any depth: a source re-exported through several files stays queryable through the surface, because admission follows the declaration rather than the path taken to it.
Confirm all three, in this order. Each one has been mistaken for "the data is not there".
get_status shows the package loaded and not stale.list_packages names the environment and package you meant.get_context call (a target with no search_text) does not list it.Only then is it genuinely not published, and the answer to the user is that the package does not expose it, not that the data does not exist.
© malloydata, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/malloy-source-unreachable of malloydata/publisher.
Open the folder on GitHubat commit b9a1a19
Malloy Source Unreachable next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Malloy Source Unreachable this skillmalloydata/publisher | 116 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Unreachable Subsystemscalimero-network/core | 171 | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Debug Openshell ClusterNVIDIA/OpenShell | 16k | — | ~19k | Automated safety check: Notes | Apache-2.0 | |
| Exp Mock Usage Analysisdotnet/skills | 5.6k | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Nix Config Debugryan4yin/nix-config | 2.1k | — | ~1.4k | Automated safety check: Pass | MIT | |
| Debug Php Wasm Main ModuleWordPress/wordpress-playground | 2k | — | ~3.1k | Automated safety check: Pass | GPL-2.0 |
calimero-network/core
Finds code that compiles, lints clean and is referenced, but that nothing can actually reach — dead islands whose items reference each other while the outermost edge points at a route, command, or…
NVIDIA/OpenShell
Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.
dotnet/skills
Audits .NET test mock usage by tracing each mock setup through the production code's execution path to find dead, unreachable, redundant, or replaceable mocks.
ryan4yin/nix-config
A skill your agent uses when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.
WordPress/wordpress-playground
Debug PHP.wasm main module crashes including Asyncify errors (unreachable, memory access out of bounds), JSPI errors (SuspendError, trying to suspend JS frames), WASM memory growth bugs, and runtime…
automateyournetwork/netclaw
Catalyst Center troubleshooting workflows - device unreachable investigation, client connectivity issues, interface down analysis, site-wide outage triage, wireless roaming problems, integration…
malloydata/publisher
Score one analytical answer against a verified golden, and score which of the entities the golden depends on retrieval delivered to the answerer.
malloydata/publisher
Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…
malloydata/publisher
Turn a list of questions into an eval set, whatever shape it arrived in: a JSONL a customer sent, a CSV, a spreadsheet export, a markdown doc, an email thread, or a pull from production logs.
malloydata/publisher
Conduct a local Publisher evaluation loop in five steps: scrape/run, eval, diagnose, improve, checkpoint.
malloydata/publisher
Make the smallest safe Malloy model edit that closes a diagnosed model-owned gap, with a probe receipt for every factual claim.
malloydata/publisher
Decide whether ONE answer matches its golden, and say whether you believe the golden.
Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next. Malloy Source Unreachable is an agent skill from malloydata/publisher. Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next.
Malloy Source Unreachable fits situations like: A source you expect is absent from discovery; executequery answers No queryable source; A query that used to work stops working; deciding whether a packages curation is hiding something you need.
Run `npx skills add malloydata/publisher --skill malloy-source-unreachable -a claude-code`. Or copy the skill folder (skills/malloy-source-unreachable in malloydata/publisher) into .claude/skills/malloy-source-unreachable in your project. Claude Code loads it when a task matches its description.
Run `npx skills add malloydata/publisher --skill malloy-source-unreachable -a codex`. Or copy the skill folder (skills/malloy-source-unreachable in malloydata/publisher) into .agents/skills/malloy-source-unreachable in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malloydata/publisher --skill malloy-source-unreachable -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malloy-source-unreachable, .gemini/skills/malloy-source-unreachable, .github/skills/malloy-source-unreachable and .opencode/skills/malloy-source-unreachable in your project.
SKILL.md names no scripts, command-line tools or credentials: Malloy Source Unreachable is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Malloy Source Unreachable is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Malloy Source Unreachable: Unreachable Subsystems (calimero-network/core, 171 stars), Debug Openshell Cluster (NVIDIA/OpenShell, 16k stars), Exp Mock Usage Analysis (dotnet/skills, 5.6k stars) and Nix Config Debug (ryan4yin/nix-config, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
malloydata (a GitHub organization) maintains it in malloydata/publisher, which has 116 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 9, 2026.
Source: malloydata/publisher on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.