Agent skill

Nodetool JS Scripting

by nodetool-ai in nodetool-ai/nodetool

Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.

AGPL-3.0Auto-check passedMedia & Creative

Install Nodetool JS Scripting

skills CLI
$ npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install nodetool-ai/nodetool nodetool-js-scripting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/system-skills/nodetool-js-scripting .claude/skills/nodetool-js-scripting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nodetool-js-scripting
GitHub stars
556
Token cost
~2.7k tokens
SKILL.md length
1,174 words
Files
1
Skills in repo
127
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.

  • Works in 5 steps: Write or read the body. get_js_script… → validate_code / validate_js_script after… → run_code / run_js_script with real… → …
  • Media & Creative work in your project
  • SKILL.md covers The body contract, Capabilities are globals,…, Running an agent from code and Calling nodes from code, plus 5 more sections
  • Calls npm

What it does

Nodetool JS Scripting is an agent skill from nodetool-ai/nodetool. Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Media & Creative. It works with JavaScript. The repository describes itself as: Agent-first Creative Workspace. The licence is AGPL-3.0.

When your agent uses it

  • Media & Creative work in your project

Example prompts

  • “/nodetool-js-scripting”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Write or read the body. get_js_script for a saved script.
  2. validate_code / validate_js_script after every edit. It catches
  3. run_code / run_js_script with real inputs. output values come back
  4. test_code / test_js_script as the regression check. A case supplies
  5. Save. save_js_script validates first and is CAS on update. For a

What it can do on your machine

Read from SKILL.md and the folder at commit 515bd28. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nodetool JS Scripting loads about 2.7k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 1,174 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from nodetool-ai/nodetool at commit 515bd28, republished under its AGPL-3.0 licence (© nodetool-ai). 1,174 words, ~2,674 tokens.

Download SKILL.mdSave it as .claude/skills/nodetool-js-scripting/SKILL.md (or your agent's skills folder).
name
nodetool-js-scripting
description
Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.
featured
true

Write NodeTool sandbox JavaScript

Three places take the same guest JavaScript, with the same globals, the same imports and the same limits.

WhereWhat it isReach it with
Code nodeA body inside a workflow graphvalidate_code, run_code, test_code
JS script documentA named, versioned script with declared ports, secrets, a timeout and saved testslist_js_scripts, get_js_script, save_js_script, edit_js_script, validate_js_script, run_js_script, test_js_script
Native flowGuest code calling nodes as async functions, no graphimport "@nodetool-ai/sandbox-nodetool/flow"

Pick a Code node when the logic belongs to one graph. Pick a script document when the same logic is called from several places, needs its own tests, or needs version history. Pick native flow when the control flow is easier to write than to wire.

The body contract

js
// inputs: { rows: [...], threshold: 10 }
const kept = inputs.rows.filter((r) => r.score > inputs.threshold);
progress(50, `kept ${kept.length}`);
for (const row of kept) await emit("row", row);   // streams as it goes
await output("count", kept.length);               // final, posted at the end
  • Inputs arrive on the inputs object, never as globals of their own name. Values are deep-copied through JSON before entering the guest.
  • Outputs leave through await output(name, value) and await emit(name, value), and nothing else. name must be a declared output handle. A second output on the same handle throws. return is ordinary control flow and its value is ignored. For a script document this is enforced: a body that declares outputs and returns them instead of emitting them is an error, because a script has no legacy return contract. A Code node still accepts the old return/yield contract for one more release, with a deprecation warning.
  • Media inputs arrive as refs. Read one with media.bytes / media.text / media.info, and build one with media.toDocument / toImage / toAudio / toVideo. Pass the whole input object, not its uri, so the ref's own type travels with it. Every media.* call is async.
  • stream is the input side of emit. A body that mentions stream runs once over the whole stream and pulls its own items. A body that never mentions it runs once per incoming item. Nothing is configured: deleting the last stream call flips the node back.
js
for await (const item of stream(name))            // one handle, in order, until EOS
for await (const [handle, item] of stream.any())  // every handle, arrival order
const item = await stream.first(name)             // next value, undefined at EOS
stream.open(name)                                 // could more still arrive?
  • state survives across streaming invocations and resets at each run.
  • progress(percent, message) drives the node's progress bar.

Capabilities are globals, libraries are imports

Globals need no declaration: console, fetch, workspace, getSecret, nodetool.secrets.*, sleep, crypto, format, image, audio, video, media, canvas, assetToSandbox / sandboxToAsset, progress, emit / output, and the pure helpers toBase64 / fromBase64 / toHex / fromHex / parallelMap. media.* and workspace.* need a ProcessingContext, so they throw in a bare sandbox call with no run behind it.

Everything else is a sandbox package the body imports:

js
import yaml from "@nodetool-ai/sandbox-yaml";

Discover them with list_sandbox_packages and read one's API with get_sandbox_package_docs. Do not guess a specifier: a pack this host does not carry fails validation with "Install <pack>". nodetool packs compile builds one for a dependency that is not shipped.

image.*, audio.* and video.* transforms return a sandbox://media/<id> handle, not bytes. Chain the calls, then <type>.toAsset(handle) before the run ends. A handle does not survive into a later run.

Running an agent from code

Use run_agent when the work needs more than one model call: look something up, act, read the result, correct.

js
import { run_agent } from "@nodetool-ai/sandbox-nodetool/agents";

const answer = await run_agent({
  prompt: "Read storyboard " + inputs.storyboardId + " and list its shot titles.",
  model: inputs.model,                // {provider, id} from a model selector
  tools: ["get_storyboard"],          // capability wire names, nothing else
  output_schema: { type: "object", properties: { titles: { type: "array", items: { type: "string" } } } }
});
await output("titles", answer.result.titles);

Without output_schema, answer.text is the agent's final message. The agent reports its text and tool calls while it runs. A mini app shows them in an Agent Activity widget bound to op:<id>/exec#transcript. generate_text stays the right call for one prompt with no tools.

Calling nodes from code

js
import "@nodetool-ai/sandbox-nodetool/flow";   // mounts the bridge, required
import { concat } from "@nodetool-ai/sandbox-flow/nodetool.text";

const r = await concat({ a: inputs.left, b: inputs.right });
await output("joined", r.output);

await is the edge, a variable is the wire, Promise.all is the fan-out. Both imports are required: the facade does not mount without the capability module. Streaming-output nodes carry .stream(inputs), an async iterable where an early break closes the stream and runs node cleanup. Every call passes the per-call permission gate and bills through the invoking run, bounded by a recursion depth cap of 4 and 16 concurrently open streams per run. Streaming inputs accept arrays only in v1.

A program that must open in the editor, be validated, or run on the server still builds a graph. Use nodetool-workflow-builder for that.

Building a timeline from code

js
import { video } from "@nodetool-ai/sandbox-timeline";

const v = video({ width: 1920, height: 1080, fps: 30 });
const title = v.scene("title", 3, (s) => {
  const t = s.text("Hello", { size: 120, weight: 600, color: "#ffffff" });
  t.enter({ from: { opacity: 0 }, at: 0, dur: 0.5 });
});
v.series([title]);
const saved = await v.save(nodetool.timelines, { name: "Hello" });
await output("timeline_id", saved.timeline_id);

The pack authors a whole motion-graphics cut in seconds, local to each scene, and saves it with one set_timeline_document, instead of one edit_timeline op per clip. Pass the body's nodetool.timelines to v.save: a module cannot see the belt. get_sandbox_package_docs on the specifier returns the full authoring API.

Save the build script itself as a JS script document and it links to the timeline it makes automatically: v.save(nodetool.timelines, {name}) with no timeline_id the first time creates the timeline and links this script to it; every later run of the same script updates that timeline in place instead of making another. Revise with edit_js_script's string-replacement ops (below) rather than resending the whole body.

Show full SKILL.md (417 more words)Show less

The loop

  1. Write or read the body. get_js_script for a saved script.
  2. validate_code / validate_js_script after every edit. It catches syntax, imports against the installed catalog, undefined names, undeclared inputs.* reads, outputs no emit/output call reaches, duplicate or non-identifier port names, and tests naming ports the script does not declare. It is far cheaper than running.
  3. run_code / run_js_script with real inputs. output values come back as outputs, emit values as streamed, an ordered list of {name, value}. Stage a streamed input with input_streams, keyed by handle.
  4. test_code / test_js_script as the regression check. A case supplies inputs (or input_streams) and optionally expect — final values per handle, compared structurally, with unnamed outputs ignored, and expected_streamed, the full ordered emit list. A case with neither passes when the body runs without error.
  5. Save. save_js_script validates first and is CAS on update. For a small revision, edit_js_script(js_script_id, ops) is cheaper: each op is {old, new}, and old must match exactly once in the current code — like a code editor's find/replace, refused by name on zero or on an ambiguous match. It validates the result the same way save_js_script does.

Script documents get the same version family as the other documents: list_js_script_versions, get_js_script_version, create_js_script_version, restore_js_script_version, delete_js_script_version.

Secrets and limits

Read a credential with nodetool.secrets.get(name) — never inline one, and never write one into a body or a test case. A script's declared secrets are intersected with whatever allowance the invoking context carries. There is no set_secret: request_secret asks the user's own client for one and the value never enters the guest, the transcript, or the model's context. A headless run carries no secret prompt, so the call is refused by name rather than quietly writing something nobody approved.

Script composition is bounded like sub-agents: depth cap 4 with a script id chain, so a cycle fails the call naming it. Execution time defaults to 30s and every limit is overridable per invocation and clamped to a ceiling.

Verify from a shell

These are the nodetool CLI. From a NodeTool checkout the same commands run as npm run dev:nodetool -- <command>.

bash
nodetool jsscript validate <id|file.json> --json
nodetool jsscript run <id|file.json> --inputs '{"numbers":[1,2,3]}'
nodetool jsscript run <id|file.json> --input-streams '{"numbers":[1,2,3]}'
nodetool jsscript test <id|file.json> --json
nodetool jsscript versions list|show|create|restore|delete <id>

A path that exists on disk wins over an id, and a file target needs no database. jsscript test exits non-zero on any failure and is the keyless selfcheck the harness gate runs.

Reference

In a NodeTool checkout, these repository sources go further:

  • docs/javascript-sandbox.md — the guest surface, marshaling, limits, concurrency and the security model.
  • docs/js-script-document-design.md — document shape, storage, invocation from agents, Code nodes and mini apps.
  • docs/harnesses.md § nodetool jsscript
  • packages/sandbox-packs/README.md

© nodetool-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in packages/system-skills/nodetool-js-scripting of nodetool-ai/nodetool.

Open the folder on GitHubat commit 515bd28

Compare with similar skills

Nodetool JS Scripting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nodetool JS Scripting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nodetool JS Scripting this skillnodetool-ai/nodetool556—~2.7kAutomated safety check: PassAGPL-3.0
Dotlottie WebLottieFiles/dotlottie-web892—~3.5kAutomated safety check: PassMIT
Speech To Texttadaspetra/loop2963 repos~2kAutomated safety check: PassMIT
HTML DesignNimaChu/html-design101—~2.7kAutomated safety check: PassNone
Explainroovincentsch/explainroo489—~439Automated safety check: PassMIT
OneWorks 3D Avatar Designeroneworks-ai/avatar250—~1.7kAutomated safety check: PassMIT

Similar skills

  • Dotlottie Web

    LottieFiles/dotlottie-web

    Implement Lottie animations using dotLottie runtimes (@lottiefiles/dotlottie-web and @lottiefiles/dotlottie-react).

    892 GitHub stars~3.5k tokensUpdated yesterday
    Media & CreativeAuto-check passed
  • Speech To Text

    tadaspetra/loop

    Transcribe audio to text using ElevenLabs Scribe v2. An agent skill from tadaspetra/loop.

    296 GitHub starsUsed in 3 repos~2k tokens
    Media & CreativeAuto-check passed
  • HTML Design

    NimaChu/html-design

    Create, redesign, repair, validate, preview, and package lightweight standalone HTML deliverables.

    101 GitHub stars~2.7k tokensUpdated 1 mo ago
    Media & CreativeAuto-check passed
  • Explainroo

    vincentsch/explainroo

    Make an explainer video (MP4) with a voice-over using explainroo.

    489 GitHub stars~439 tokensUpdated 4 days ago
    Media & CreativeAuto-check passed
  • OneWorks 3D Avatar Designer

    oneworks-ai/avatar

    Creates, refines and exports editable OneWorks 3D geometric avatars for mascots, bots or agents, keeping one shared scene state across preview, share link and export.

    250 GitHub stars~1.7k tokensUpdated 1 mo ago
    Media & CreativeAuto-check passed
  • Deepgram JS Audio Intelligence

    deepgram/deepgram-js-sdk

    A skill your agent uses when writing or reviewing JavaScript/TypeScript in this repo that calls Deepgram audio analytics overlays on /v1/listen - summarize, topics, intents, sentiment, diarize…

    276 GitHub stars~1.5k tokensUpdated yesterday
    Media & CreativeAuto-check passed

More from nodetool-ai/nodetool

All 127 skills in this repo
  • Beat Sync Editing

    nodetool-ai/nodetool

    Cut a NodeTool timeline to music and shape its pacing — detect the beat grid, place cuts on phrases, pick a cut type, build speed ramps with time remap, and give the piece an arc.

    556 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Caption Titles

    nodetool-ai/nodetool

    Add and animate a consistent text layer on an existing NodeTool timeline.

    556 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Color Motion

    nodetool-ai/nodetool

    Choose and animate colour on a NodeTool timeline, including shape and text gradients, colour grades, 3D LUTs, and dither.

    556 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Commercial Beat Sheet

    nodetool-ai/nodetool

    Write a shootable, precisely timed commercial beat sheet and store it as a NodeTool storyboard, with a consistent entity roster behind every shot.

    556 GitHub stars~4.6k tokensUpdated today
    Auto-check passed
  • Elevenlabs Audio Prompting

    nodetool-ai/nodetool

    Direct ElevenLabs speech, dialogue, sound effects and music — the bracketed audio tags v3 acts on and why the voice decides whether a tag lands, stability as the delivery dial, punctuation instead…

    556 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Frame Composition

    nodetool-ai/nodetool

    Stage the frame on a NodeTool timeline — grids, focal placement, safe areas per aspect ratio, depth layers and parallax, camera moves, and where elements enter and leave.

    556 GitHub stars~3.5k tokensUpdated today
    Auto-check passed

Works with

Questions about Nodetool JS Scripting

What does Nodetool JS Scripting do?

Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code. Nodetool JS Scripting is an agent skill from nodetool-ai/nodetool. Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.

When should I use Nodetool JS Scripting?

Nodetool JS Scripting fits situations like: media & Creative work in your project.

How do I install Nodetool JS Scripting in Claude Code?

Run `npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a claude-code`. Or copy the skill folder (packages/system-skills/nodetool-js-scripting in nodetool-ai/nodetool) into .claude/skills/nodetool-js-scripting in your project. Claude Code loads it when a task matches its description.

How do I install Nodetool JS Scripting in Codex?

Run `npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a codex`. Or copy the skill folder (packages/system-skills/nodetool-js-scripting in nodetool-ai/nodetool) into .agents/skills/nodetool-js-scripting in your project. Codex loads it when a task matches its description.

Can I use Nodetool JS Scripting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nodetool-js-scripting, .gemini/skills/nodetool-js-scripting, .github/skills/nodetool-js-scripting and .opencode/skills/nodetool-js-scripting in your project.

What does Nodetool JS Scripting need to run?

Going by SKILL.md and its folder, Nodetool JS Scripting needs the command-line tools its instructions call (npm).

Does Nodetool JS Scripting access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Nodetool JS Scripting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nodetool JS Scripting use?

Nodetool JS Scripting is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nodetool JS Scripting use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nodetool JS Scripting?

Skills that share tags, products or a category with Nodetool JS Scripting: Dotlottie Web (LottieFiles/dotlottie-web, 892 stars), Speech To Text (tadaspetra/loop, 296 stars), HTML Design (NimaChu/html-design, 101 stars) and Explainroo (vincentsch/explainroo, 489 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nodetool JS Scripting?

nodetool-ai (a GitHub organization) maintains it in nodetool-ai/nodetool, which has 556 GitHub stars. The repository holds 127 skills in this directory. The repository was last updated on October 8, 2026.

Source: nodetool-ai/nodetool on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.