Agent skill

Malloy Source Unreachable

by malloydata in malloydata/publisher

Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next.

MITAuto-check passed

Install Malloy Source Unreachable

skills CLI
$ npx skills add malloydata/publisher --skill malloy-source-unreachable -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install malloydata/publisher malloy-source-unreachable --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/malloydata/publisher.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/malloy-source-unreachable .claude/skills/malloy-source-unreachable && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
malloy-source-unreachable
GitHub stars
116
Token cost
~2.2k tokens
SKILL.md length
1,346 words
Files
1
Skills in repo
29
Repo updated
First seen
Licence
MIT

At a glance

Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next.

  • Works in 4 steps: It is off the surface. The package… → The package failed to load, or is… → You are talking to a different server… → …
  • A source you expect is absent from discovery
  • SKILL.md covers The three answers, Addressing the surface, which…, Other places a hidden source… and When the source is not in…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Malloy Source Unreachable is an agent skill from malloydata/publisher. Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next. Use when a source you expect is absent from discovery, when executequery answers "No queryable source", when a query that used to work stops working, or when deciding whether a package's curation is hiding something you need.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere. The licence is MIT.

When your agent uses it

  • A source you expect is absent from discovery
  • Executequery answers No queryable source
  • A query that used to work stops working
  • Deciding whether a packages curation is hiding something you need

Example prompts

  • “No queryable source”
  • “/malloy-source-unreachable”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. It is off the surface. The package publishes a curated set and this source is not in it. Nothing you can do from the query side; it is a…
  2. The package failed to load, or is serving a stale model. Call list_packages: a package that failed to load appears with an error, and one…
  3. You are talking to a different server than you think. Call list_packages and check the environment and package names are the ones you…
  4. Your search phrasing missed it. Retry with a bare target (no search_text) to enumerate rather than rank. If it appears there, the source…

What it can do on your machine

Read from SKILL.md and the folder at commit b9a1a19. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Malloy Source Unreachable loads about 2.2k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 1,346 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from malloydata/publisher at commit b9a1a19, republished under its MIT licence (© malloydata). 1,346 words, ~2,200 tokens.

Download SKILL.mdSave it as .claude/skills/malloy-source-unreachable/SKILL.md (or your agent's skills folder).
name
malloy-source-unreachable
description
Work out why a source is missing from get_context, or why a query against it was refused with a 404 or a 403, and what to do next. Use when a source you expect is absent from discovery, when execute_query answers "No queryable source", when a query that used to work stops working, or when deciding whether a package's curation is hiding something you need.
<!-- Copyright (c) Credible Data Inc. SPDX-License-Identifier: MIT -->

A source you cannot reach

Tool names are written bare here - get_context, execute_query, get_status, compile_model. The exact prefixed name depends on the host surface; match each against the tools you actually have.

Most packages publish a curated surface, so a source being absent or refused is usually the package working as its author intended, not a fault. Read the refusal before working around it, because the three things that can refuse you need three different responses and they are told apart by the status code.

The three answers

what you gotwhat it meanswhat to do
404 that says "not on this package's published surface"the name is real and the package does not publish it. It is curation, not a typofollow the fix the message names (usually: name it in the export { ... } of index.malloy and address the query there), or query what IS published
404, plain "No queryable source", "No queryable model" or "Query target is not queryable"the name does not exist, or it is hidden in a model that carries an #(authorize) or #(access_filter) gate. In a gated model the two are deliberately indistinguishable, so a refusal cannot be used to probe for hidden namescheck the name against get_context, then query something on the surface or ask the package's author to publish it
403, "Access denied"the source exists and is on the surface, but an #(authorize) gate did not admit yousupply the givens the gate reads, or accept that this caller may not read it
200 with zero rowsyou were admitted, and an #(access_filter) narrowed the rows to none of themthis is a real answer. Report it as "no matching rows", never as an error

A 403 names a source, so it tells you the source exists. A plain 404 tells you nothing at all. That asymmetry is deliberate: a source that is both hidden AND gated answers a plain 404, so you can never use a 403, or the wording of a 404, to discover that a hidden gated name is real.

One 404 is not about the source at all. If a query that joins an exported source in its own text answers Query target is not queryable, check the joined source's givens. A source that reads a given with no default, which index.malloy does not import, is refused that way when joined. Queried directly, the same source answers a 400 that names the cause. Run the joining query through compile_model: the problem then reads "references given NAME ... which is not surfaced in this model". The fix belongs in the model, not the query, so report it to the model's author: index.malloy has to import that given, either by importing its declaring file whole or by naming the given in a selective import.

Addressing the surface, which is the most common 404

A query names a model file. When a package curates its surface, only files on that surface are valid entry points, even for a source that file declares itself:

POST .../packages/sales/models/index.malloy/query    {"sourceName": "orders"}   -> 200
POST .../packages/sales/models/orders.malloy/query   {"sourceName": "orders"}   -> 404

Same source, same package. orders.malloy is off the surface, so it is not an entry point.

Use the model_path that get_context gave you, verbatim. Its source_info.resource_id holds environment, package, model_path and source, and those are exactly execute_query's environmentName, packageName, modelPath and sourceName. On a curated package the model_path is the surface file, not the file that declares the source. Substituting the declaring file because it looks more correct is how this 404 happens.

Other places a hidden source answers 404

The query route is not the only one held to the surface. On a curated package, a source or file off it also shows up as a 404 here:

  • Reading a model. GET .../models/{path} answers 404 for a file off the surface, with the same words as the query route. The file still exists and still compiles; read index.malloy instead. A model that is on the surface lists only the names it publishes, not everything it imports.
  • A dashboard tile. A tile, or a filter suggest over a hidden source answers 404. The dashboard itself is still listed. The package load warns once per tile, for example Tile orders_staging -> by_flag on dashboard overview reads orders_staging, which index.malloy doesn't export, so it won't load. Fix: add orders_staging to the export { ... } in index.malloy. It is in the warnings on the package's own response, GET .../packages/{pkg}.
  • A notebook cell. A cell over a hidden source answers 404, even when the notebook imports its file. A source an earlier cell derives from a published one still works.

The fix is the same in each case: add the source to the export { ... } in index.malloy, or use what is already published.

Show full SKILL.md (568 more words)Show less

When the source is not in get_context at all

Work down this list. The first three are far more common than the last.

  1. It is off the surface. The package publishes a curated set and this source is not in it. Nothing you can do from the query side; it is a package edit.
  2. The package failed to load, or is serving a stale model. Call list_packages: a package that failed to load appears with an error, and one serving the model it compiled before a failed reload carries stale: true and the error too. get_status has the full load errors.
  3. You are talking to a different server than you think. Call list_packages and check the environment and package names are the ones you expect. A stale .mcp.json outlives the server that wrote it, and another Publisher may hold that port.
  4. Your search phrasing missed it. Retry with a bare target (no search_text) to enumerate rather than rank. If it appears there, the source exists and was a ranking miss.

What curation does not do

  • It does not hide fields. A published source may join an unpublished one, and a query grouping by a joined field returns that field's values normally. Hiding a source removes it as a landing point; it does not redact columns a published source pulls in.
  • It does not gate /compile. compile_model is exempt, because compile is the authoring loop. A hidden source can still be compile-checked, and that is intended. The exceptions are a hidden source that is also gated, which answers 404 at compile too, and a document (text with a model-level ## artifact tag): its tiles and cells are held to the surface, so one over a source off it comes back as a query-not-queryable problem rather than compiling.
  • It is not access control. Curation answers "what is queryable by name", not "who may query it". Identity is #(authorize) and #(access_filter). A source is not protected by being hidden.

Reaching an unpublished source from your own model

If you are writing Malloy rather than just querying, an unpublished source is still usable, with one condition that trips people.

export { ... } decides what an importing file can see, which is Malloy's rule and not Publisher's:

  • a file that declares no export hands an importer everything it declares, so import the file that declares the source and join it normally;
  • a file that does declare one hands over exactly that list. Importing a file whose export omits the source and then naming it fails to compile with Reference to undefined object.

So an unpublished source is reachable through a file that exports it, or that exports nothing, and not through a file whose export leaves it out. Re-export chains are fine at any depth: a source re-exported through several files stays queryable through the surface, because admission follows the declaration rather than the path taken to it.

Before you report a source as missing

Confirm all three, in this order. Each one has been mistaken for "the data is not there".

  1. get_status shows the package loaded and not stale.
  2. list_packages names the environment and package you meant.
  3. An enumerating get_context call (a target with no search_text) does not list it.

Only then is it genuinely not published, and the answer to the user is that the package does not expose it, not that the data does not exist.

© malloydata, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/malloy-source-unreachable of malloydata/publisher.

Open the folder on GitHubat commit b9a1a19

Compare with similar skills

Malloy Source Unreachable next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Malloy Source Unreachable compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Malloy Source Unreachable this skillmalloydata/publisher116—~2.2kAutomated safety check: PassMIT
Unreachable Subsystemscalimero-network/core171—~1.9kAutomated safety check: PassCustom licence
Debug Openshell ClusterNVIDIA/OpenShell16k—~19kAutomated safety check: NotesApache-2.0
Exp Mock Usage Analysisdotnet/skills5.6k1 repos~1.5kAutomated safety check: PassMIT
Nix Config Debugryan4yin/nix-config2.1k—~1.4kAutomated safety check: PassMIT
Debug Php Wasm Main ModuleWordPress/wordpress-playground2k—~3.1kAutomated safety check: PassGPL-2.0

Similar skills

  • Unreachable Subsystems

    calimero-network/core

    Finds code that compiles, lints clean and is referenced, but that nothing can actually reach — dead islands whose items reference each other while the outermost edge points at a route, command, or…

    171 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Debug Openshell Cluster

    NVIDIA/OpenShell

    Official

    Debug why an OpenShell gateway deployment is unhealthy, unreachable, or unable to create sandboxes.

    16k GitHub stars~19k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Audits .NET test mock usage by tracing each mock setup through the production code's execution path to find dead, unreachable, redundant, or replaceable mocks.

    5.6k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Nix Config Debug

    ryan4yin/nix-config

    A skill your agent uses when something in this repo is broken, such as an eval or build error, a failed activation, a crashed service, or an unreachable host or MicroVM guest.

    2.1k GitHub stars~1.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Debug Php Wasm Main Module

    WordPress/wordpress-playground

    Debug PHP.wasm main module crashes including Asyncify errors (unreachable, memory access out of bounds), JSPI errors (SuspendError, trying to suspend JS frames), WASM memory growth bugs, and runtime…

    2k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Catc Troubleshoot

    automateyournetwork/netclaw

    Catalyst Center troubleshooting workflows - device unreachable investigation, client connectivity issues, interface down analysis, site-wide outage triage, wireless roaming problems, integration…

    676 GitHub stars~7.1k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed

More from malloydata/publisher

All 29 skills in this repo
  • Eval Answer

    malloydata/publisher

    Score one analytical answer against a verified golden, and score which of the entities the golden depends on retrieval delivered to the answerer.

    116 GitHub stars~4.3k tokensUpdated today
    Auto-check passed
  • Fix Scan Finding

    malloydata/publisher

    Fix a CRITICAL Trivy finding that is failing CI in this repo (a vulnerability, misconfiguration, or secret from security-scan.yml or image-scan.yml), or add, review, or retire an entry in…

    116 GitHub stars~5.1k tokensUpdated today
    Auto-check passed
  • Eval Import

    malloydata/publisher

    Turn a list of questions into an eval set, whatever shape it arrived in: a JSONL a customer sent, a CSV, a spreadsheet export, a markdown doc, an email thread, or a pull from production logs.

    116 GitHub stars~5.9k tokensUpdated today
    Auto-check passed
  • Eval Loop

    malloydata/publisher

    Conduct a local Publisher evaluation loop in five steps: scrape/run, eval, diagnose, improve, checkpoint.

    116 GitHub stars~7.8k tokensUpdated today
    Auto-check passed
  • Eval Improve

    malloydata/publisher

    Make the smallest safe Malloy model edit that closes a diagnosed model-owned gap, with a probe receipt for every factual claim.

    116 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Eval Judge

    malloydata/publisher

    Decide whether ONE answer matches its golden, and say whether you believe the golden.

    116 GitHub stars~3.4k tokensUpdated today
    Auto-check passed

Questions about Malloy Source Unreachable

What does Malloy Source Unreachable do?

Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next. Malloy Source Unreachable is an agent skill from malloydata/publisher. Work out why a source is missing from getcontext, or why a query against it was refused with a 404 or a 403, and what to do next.

When should I use Malloy Source Unreachable?

Malloy Source Unreachable fits situations like: A source you expect is absent from discovery; executequery answers No queryable source; A query that used to work stops working; deciding whether a packages curation is hiding something you need.

How do I install Malloy Source Unreachable in Claude Code?

Run `npx skills add malloydata/publisher --skill malloy-source-unreachable -a claude-code`. Or copy the skill folder (skills/malloy-source-unreachable in malloydata/publisher) into .claude/skills/malloy-source-unreachable in your project. Claude Code loads it when a task matches its description.

How do I install Malloy Source Unreachable in Codex?

Run `npx skills add malloydata/publisher --skill malloy-source-unreachable -a codex`. Or copy the skill folder (skills/malloy-source-unreachable in malloydata/publisher) into .agents/skills/malloy-source-unreachable in your project. Codex loads it when a task matches its description.

Can I use Malloy Source Unreachable in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malloydata/publisher --skill malloy-source-unreachable -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/malloy-source-unreachable, .gemini/skills/malloy-source-unreachable, .github/skills/malloy-source-unreachable and .opencode/skills/malloy-source-unreachable in your project.

What does Malloy Source Unreachable need to run?

SKILL.md names no scripts, command-line tools or credentials: Malloy Source Unreachable is instructions for the agent only.

Does Malloy Source Unreachable access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Malloy Source Unreachable safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Malloy Source Unreachable use?

Malloy Source Unreachable is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Malloy Source Unreachable use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Malloy Source Unreachable?

Skills that share tags, products or a category with Malloy Source Unreachable: Unreachable Subsystems (calimero-network/core, 171 stars), Debug Openshell Cluster (NVIDIA/OpenShell, 16k stars), Exp Mock Usage Analysis (dotnet/skills, 5.6k stars) and Nix Config Debug (ryan4yin/nix-config, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Malloy Source Unreachable?

malloydata (a GitHub organization) maintains it in malloydata/publisher, which has 116 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 9, 2026.

Source: malloydata/publisher on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.