Dotlottie Web
LottieFiles/dotlottie-web
Implement Lottie animations using dotLottie runtimes (@lottiefiles/dotlottie-web and @lottiefiles/dotlottie-react).
Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.
$ npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install nodetool-ai/nodetool nodetool-js-scripting --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/system-skills/nodetool-js-scripting .claude/skills/nodetool-js-scripting && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nodetool-js-scripting" agent skill from https://github.com/nodetool-ai/nodetool/tree/main/packages/system-skills/nodetool-js-scripting into .claude/skills/nodetool-js-scripting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nodetool-js-scripting", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/nodetool-ai/nodetool/tree/main/packages/system-skills/nodetool-js-scriptingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install nodetool-ai/nodetool nodetool-js-scripting --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/system-skills/nodetool-js-scripting .agents/skills/nodetool-js-scripting && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nodetool-js-scripting" agent skill from https://github.com/nodetool-ai/nodetool/tree/main/packages/system-skills/nodetool-js-scripting into .agents/skills/nodetool-js-scripting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nodetool-js-scripting", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install nodetool-ai/nodetool nodetool-js-scripting --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/system-skills/nodetool-js-scripting .cursor/skills/nodetool-js-scripting && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nodetool-js-scripting" agent skill from https://github.com/nodetool-ai/nodetool/tree/main/packages/system-skills/nodetool-js-scripting into .cursor/skills/nodetool-js-scripting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nodetool-js-scripting", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/nodetool-ai/nodetool.git --path packages/system-skills/nodetool-js-scripting--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install nodetool-ai/nodetool nodetool-js-scripting --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/system-skills/nodetool-js-scripting .gemini/skills/nodetool-js-scripting && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nodetool-js-scripting" agent skill from https://github.com/nodetool-ai/nodetool/tree/main/packages/system-skills/nodetool-js-scripting into .gemini/skills/nodetool-js-scripting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nodetool-js-scripting", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install nodetool-ai/nodetool nodetool-js-scriptingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/system-skills/nodetool-js-scripting .github/skills/nodetool-js-scripting && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nodetool-js-scripting" agent skill from https://github.com/nodetool-ai/nodetool/tree/main/packages/system-skills/nodetool-js-scripting into .github/skills/nodetool-js-scripting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nodetool-js-scripting", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install nodetool-ai/nodetool nodetool-js-scripting --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/nodetool-ai/nodetool.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/system-skills/nodetool-js-scripting .opencode/skills/nodetool-js-scripting && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nodetool-js-scripting" agent skill from https://github.com/nodetool-ai/nodetool/tree/main/packages/system-skills/nodetool-js-scripting into .opencode/skills/nodetool-js-scripting/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nodetool-js-scripting", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nodetool-js-scriptingWrite JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.
Nodetool JS Scripting is an agent skill from nodetool-ai/nodetool. Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Media & Creative. It works with JavaScript. The repository describes itself as: Agent-first Creative Workspace. The licence is AGPL-3.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 515bd28. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nodetool JS Scripting loads about 2.7k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 1,174 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from nodetool-ai/nodetool at commit 515bd28, republished under its AGPL-3.0 licence (© nodetool-ai). 1,174 words, ~2,674 tokens.
.claude/skills/nodetool-js-scripting/SKILL.md (or your agent's skills folder).Three places take the same guest JavaScript, with the same globals, the same imports and the same limits.
| Where | What it is | Reach it with |
|---|---|---|
| Code node | A body inside a workflow graph | validate_code, run_code, test_code |
| JS script document | A named, versioned script with declared ports, secrets, a timeout and saved tests | list_js_scripts, get_js_script, save_js_script, edit_js_script, validate_js_script, run_js_script, test_js_script |
| Native flow | Guest code calling nodes as async functions, no graph | import "@nodetool-ai/sandbox-nodetool/flow" |
Pick a Code node when the logic belongs to one graph. Pick a script document when the same logic is called from several places, needs its own tests, or needs version history. Pick native flow when the control flow is easier to write than to wire.
// inputs: { rows: [...], threshold: 10 }
const kept = inputs.rows.filter((r) => r.score > inputs.threshold);
progress(50, `kept ${kept.length}`);
for (const row of kept) await emit("row", row); // streams as it goes
await output("count", kept.length); // final, posted at the endinputs object, never as globals of their own name.
Values are deep-copied through JSON before entering the guest.await output(name, value) and await emit(name, value), and nothing else. name must be a declared output handle. A second
output on the same handle throws. return is ordinary control flow and its
value is ignored. For a script document this is enforced: a body that declares
outputs and returns them instead of emitting them is an error, because a
script has no legacy return contract. A Code node still accepts the old
return/yield contract for one more release, with a deprecation warning.media.bytes / media.text /
media.info, and build one with media.toDocument / toImage / toAudio /
toVideo. Pass the whole input object, not its uri, so the ref's own type
travels with it. Every media.* call is async.stream is the input side of emit. A body that mentions stream runs
once over the whole stream and pulls its own items. A body that never
mentions it runs once per incoming item. Nothing is configured: deleting the
last stream call flips the node back.for await (const item of stream(name)) // one handle, in order, until EOS
for await (const [handle, item] of stream.any()) // every handle, arrival order
const item = await stream.first(name) // next value, undefined at EOS
stream.open(name) // could more still arrive?state survives across streaming invocations and resets at each run.progress(percent, message) drives the node's progress bar.Globals need no declaration: console, fetch, workspace, getSecret,
nodetool.secrets.*, sleep, crypto, format, image, audio, video,
media, canvas, assetToSandbox / sandboxToAsset, progress, emit /
output, and the pure helpers toBase64 / fromBase64 / toHex / fromHex /
parallelMap. media.* and workspace.* need a ProcessingContext, so they
throw in a bare sandbox call with no run behind it.
Everything else is a sandbox package the body imports:
import yaml from "@nodetool-ai/sandbox-yaml";Discover them with list_sandbox_packages and read one's API with
get_sandbox_package_docs. Do not guess a specifier: a pack this host does not
carry fails validation with "Install <pack>". nodetool packs compile builds one for a dependency that is not shipped.
image.*, audio.* and video.* transforms return a sandbox://media/<id>
handle, not bytes. Chain the calls, then <type>.toAsset(handle) before the run
ends. A handle does not survive into a later run.
Use run_agent when the work needs more than one model call: look something
up, act, read the result, correct.
import { run_agent } from "@nodetool-ai/sandbox-nodetool/agents";
const answer = await run_agent({
prompt: "Read storyboard " + inputs.storyboardId + " and list its shot titles.",
model: inputs.model, // {provider, id} from a model selector
tools: ["get_storyboard"], // capability wire names, nothing else
output_schema: { type: "object", properties: { titles: { type: "array", items: { type: "string" } } } }
});
await output("titles", answer.result.titles);Without output_schema, answer.text is the agent's final message. The agent
reports its text and tool calls while it runs. A mini app shows them in an
Agent Activity widget bound to op:<id>/exec#transcript. generate_text stays
the right call for one prompt with no tools.
import "@nodetool-ai/sandbox-nodetool/flow"; // mounts the bridge, required
import { concat } from "@nodetool-ai/sandbox-flow/nodetool.text";
const r = await concat({ a: inputs.left, b: inputs.right });
await output("joined", r.output);await is the edge, a variable is the wire, Promise.all is the fan-out. Both
imports are required: the facade does not mount without the capability module.
Streaming-output nodes carry .stream(inputs), an async iterable where an early
break closes the stream and runs node cleanup. Every call passes the per-call
permission gate and bills through the invoking run, bounded by a recursion depth
cap of 4 and 16 concurrently open streams per run. Streaming inputs accept
arrays only in v1.
A program that must open in the editor, be validated, or run on the server still
builds a graph. Use nodetool-workflow-builder
for that.
import { video } from "@nodetool-ai/sandbox-timeline";
const v = video({ width: 1920, height: 1080, fps: 30 });
const title = v.scene("title", 3, (s) => {
const t = s.text("Hello", { size: 120, weight: 600, color: "#ffffff" });
t.enter({ from: { opacity: 0 }, at: 0, dur: 0.5 });
});
v.series([title]);
const saved = await v.save(nodetool.timelines, { name: "Hello" });
await output("timeline_id", saved.timeline_id);The pack authors a whole motion-graphics cut in seconds, local to each scene,
and saves it with one set_timeline_document, instead of one edit_timeline
op per clip. Pass the body's nodetool.timelines to v.save: a module cannot
see the belt. get_sandbox_package_docs on the specifier returns the full
authoring API.
Save the build script itself as a JS script document and it links to the
timeline it makes automatically: v.save(nodetool.timelines, {name}) with no
timeline_id the first time creates the timeline and links this script to
it; every later run of the same script updates that timeline in place
instead of making another. Revise with edit_js_script's string-replacement
ops (below) rather than resending the whole body.
get_js_script for a saved script.validate_code / validate_js_script after every edit. It catches
syntax, imports against the installed catalog, undefined names, undeclared
inputs.* reads, outputs no emit/output call reaches, duplicate or
non-identifier port names, and tests naming ports the script does not
declare. It is far cheaper than running.run_code / run_js_script with real inputs. output values come back
as outputs, emit values as streamed, an ordered list of {name, value}.
Stage a streamed input with input_streams, keyed by handle.test_code / test_js_script as the regression check. A case supplies
inputs (or input_streams) and optionally expect — final values per
handle, compared structurally, with unnamed outputs ignored, and
expected_streamed, the full ordered emit list. A case with neither passes
when the body runs without error.save_js_script validates first and is CAS on update. For a
small revision, edit_js_script(js_script_id, ops) is cheaper: each op is
{old, new}, and old must match exactly once in the current code — like
a code editor's find/replace, refused by name on zero or on an ambiguous
match. It validates the result the same way save_js_script does.Script documents get the same version family as the other documents:
list_js_script_versions, get_js_script_version, create_js_script_version,
restore_js_script_version, delete_js_script_version.
Read a credential with nodetool.secrets.get(name) — never inline one, and
never write one into a body or a test case. A script's declared secrets are
intersected with whatever allowance the invoking context carries. There is no
set_secret: request_secret asks the user's own client for one and the value
never enters the guest, the transcript, or the model's context. A headless run
carries no secret prompt, so the call is refused by name rather than quietly
writing something nobody approved.
Script composition is bounded like sub-agents: depth cap 4 with a script id chain, so a cycle fails the call naming it. Execution time defaults to 30s and every limit is overridable per invocation and clamped to a ceiling.
These are the nodetool CLI. From a NodeTool checkout the same commands run
as npm run dev:nodetool -- <command>.
nodetool jsscript validate <id|file.json> --json
nodetool jsscript run <id|file.json> --inputs '{"numbers":[1,2,3]}'
nodetool jsscript run <id|file.json> --input-streams '{"numbers":[1,2,3]}'
nodetool jsscript test <id|file.json> --json
nodetool jsscript versions list|show|create|restore|delete <id>A path that exists on disk wins over an id, and a file target needs no database.
jsscript test exits non-zero on any failure and is the keyless selfcheck the
harness gate runs.
In a NodeTool checkout, these repository sources go further:
docs/javascript-sandbox.md — the guest surface, marshaling, limits,
concurrency and the security model.docs/js-script-document-design.md — document shape, storage, invocation
from agents, Code nodes and mini apps.docs/harnesses.md § nodetool jsscriptpackages/sandbox-packs/README.md© nodetool-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in packages/system-skills/nodetool-js-scripting of nodetool-ai/nodetool.
Open the folder on GitHubat commit 515bd28
Nodetool JS Scripting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nodetool JS Scripting this skillnodetool-ai/nodetool | 556 | — | ~2.7k | Automated safety check: Pass | AGPL-3.0 | |
| Dotlottie WebLottieFiles/dotlottie-web | 892 | — | ~3.5k | Automated safety check: Pass | MIT | |
| Speech To Texttadaspetra/loop | 296 | 3 repos | ~2k | Automated safety check: Pass | MIT | |
| HTML DesignNimaChu/html-design | 101 | — | ~2.7k | Automated safety check: Pass | None | |
| Explainroovincentsch/explainroo | 489 | — | ~439 | Automated safety check: Pass | MIT | |
| OneWorks 3D Avatar Designeroneworks-ai/avatar | 250 | — | ~1.7k | Automated safety check: Pass | MIT |
LottieFiles/dotlottie-web
Implement Lottie animations using dotLottie runtimes (@lottiefiles/dotlottie-web and @lottiefiles/dotlottie-react).
tadaspetra/loop
Transcribe audio to text using ElevenLabs Scribe v2. An agent skill from tadaspetra/loop.
NimaChu/html-design
Create, redesign, repair, validate, preview, and package lightweight standalone HTML deliverables.
vincentsch/explainroo
Make an explainer video (MP4) with a voice-over using explainroo.
oneworks-ai/avatar
Creates, refines and exports editable OneWorks 3D geometric avatars for mascots, bots or agents, keeping one shared scene state across preview, share link and export.
deepgram/deepgram-js-sdk
A skill your agent uses when writing or reviewing JavaScript/TypeScript in this repo that calls Deepgram audio analytics overlays on /v1/listen - summarize, topics, intents, sentiment, diarize…
nodetool-ai/nodetool
Cut a NodeTool timeline to music and shape its pacing — detect the beat grid, place cuts on phrases, pick a cut type, build speed ramps with time remap, and give the piece an arc.
nodetool-ai/nodetool
Add and animate a consistent text layer on an existing NodeTool timeline.
nodetool-ai/nodetool
Choose and animate colour on a NodeTool timeline, including shape and text gradients, colour grades, 3D LUTs, and dither.
nodetool-ai/nodetool
Write a shootable, precisely timed commercial beat sheet and store it as a NodeTool storyboard, with a consistent entity roster behind every shot.
nodetool-ai/nodetool
Direct ElevenLabs speech, dialogue, sound effects and music — the bracketed audio tags v3 acts on and why the voice decides whether a tag lands, stability as the delivery dial, punctuation instead…
nodetool-ai/nodetool
Stage the frame on a NodeTool timeline — grids, focal placement, safe areas per aspect ratio, depth layers and parallax, camera moves, and where elements enter and leave.
Works with
Categories
Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code. Nodetool JS Scripting is an agent skill from nodetool-ai/nodetool. Write JavaScript that runs in NodeTool's QuickJS sandbox: Code node bodies, saved JS script documents, sandbox package imports, and calling nodes from code.
Nodetool JS Scripting fits situations like: media & Creative work in your project.
Run `npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a claude-code`. Or copy the skill folder (packages/system-skills/nodetool-js-scripting in nodetool-ai/nodetool) into .claude/skills/nodetool-js-scripting in your project. Claude Code loads it when a task matches its description.
Run `npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a codex`. Or copy the skill folder (packages/system-skills/nodetool-js-scripting in nodetool-ai/nodetool) into .agents/skills/nodetool-js-scripting in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add nodetool-ai/nodetool --skill nodetool-js-scripting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nodetool-js-scripting, .gemini/skills/nodetool-js-scripting, .github/skills/nodetool-js-scripting and .opencode/skills/nodetool-js-scripting in your project.
Going by SKILL.md and its folder, Nodetool JS Scripting needs the command-line tools its instructions call (npm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nodetool JS Scripting is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nodetool JS Scripting: Dotlottie Web (LottieFiles/dotlottie-web, 892 stars), Speech To Text (tadaspetra/loop, 296 stars), HTML Design (NimaChu/html-design, 101 stars) and Explainroo (vincentsch/explainroo, 489 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
nodetool-ai (a GitHub organization) maintains it in nodetool-ai/nodetool, which has 556 GitHub stars. The repository holds 127 skills in this directory. The repository was last updated on October 8, 2026.
Source: nodetool-ai/nodetool on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.