Agent skill

Validate Selector

by simstudioai in simstudioai/sim

Audit a Sim dynamic selector across its declaration, browser-safe manifest, server attachment, provider primitive, and selectors.execute security boundary.

Apache-2.0Auto-check passed

Install Validate Selector

skills CLI
$ npx skills add simstudioai/sim --skill validate-selector -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install simstudioai/sim validate-selector --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/simstudioai/sim.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/validate-selector .claude/skills/validate-selector && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validate-selector
GitHub stars
30k
Token cost
~1.2k tokens
SKILL.md length
560 words
Files
2
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit a Sim dynamic selector across its declaration, browser-safe manifest, server attachment, provider primitive, and selectors.execute security boundary.

  • Works in 7 steps: Session authentication before request… → Canonical workflow/workspace loading and… → Manifest capability and exact-context… → …
  • Reviewing selector correctness
  • SKILL.md covers Gather the path, Validate the declaration and…, Validate the server boundary and Validate provider reuse and…, plus 1 more section
  • Calls bun and git

What it does

Validate Selector is an agent skill from simstudioai/sim. Audit a Sim dynamic selector across its declaration, browser-safe manifest, server attachment, provider primitive, and selectors.execute security boundary. Use when reviewing selector correctness, secret handling, scope authorization, or dead selector-only routes.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

The repository describes itself as: Sim is the collaborative workspace to build, deploy, and monitor AI agents and workflows. Used by 100,000+ builders. The licence is Apache-2.0.

When your agent uses it

  • Reviewing selector correctness
  • Secret handling
  • Scope authorization
  • Dead selector-only routes

Example prompts

  • “/validate-selector”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Session authentication before request parsing.
  2. Canonical workflow/workspace loading and read authorization.
  3. Manifest capability and exact-context allowlisting.
  4. Exact environment-reference resolution on the server.
  5. Credential use, workspace, and trusted provider/service binding.
  6. Destination-policy enforcement before provider network access.
  7. Provider/internal execution followed by explicit option projection and sanitization.

What it can do on your machine

Read from SKILL.md and the folder at commit 546d4e7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validate Selector loads about 1.2k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 560 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from simstudioai/sim at commit 546d4e7, republished under its Apache-2.0 licence (© simstudioai). 560 words, ~1,243 tokens.

Download SKILL.mdSave it as .claude/skills/validate-selector/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
validate-selector
description
Audit a Sim dynamic selector across its declaration, browser-safe manifest, server attachment, provider primitive, and selectors.execute security boundary. Use when reviewing selector correctness, secret handling, scope authorization, or dead selector-only routes.
argument-hint
<selector-key-or-service>

Validate Selector

Validate the complete path, not only the provider adapter.

Gather the path

Read:

  • Every block, trigger, and connector field using the selector key.
  • apps/sim/lib/selectors/manifest.ts and types.ts.
  • apps/sim/lib/selectors/context.ts.
  • The matching server attachment and any shared provider listing primitive.
  • apps/sim/lib/selectors/server/registry.ts.
  • The shared application executor, route contract, client transport, and focused tests when the finding concerns shared behavior.

Search literal API paths as well as TypeScript imports before deciding whether an old provider route or contract is unused.

Validate the declaration and manifest

  • The key has exactly one classification and one attachment (local keys use the local registry).
  • Allowed context is minimal and readiness matches the provider request.
  • List, pagination, search, detail, unknown-detail, scope, and stale-time metadata match actual UX.
  • dependsOn names the required source fields; canonical pairs contribute only their active member.
  • Action/trigger and connector surfaces build the same canonical context.
  • Exact {{KEY}} references remain unresolved in the browser; runtime references are omitted, while embedded interpolation is forwarded unresolved and rejected by the server executor.
  • Query keys contain no context value, reference, credential ID, secret, or hash of one.

Validate the server boundary

For provider and internal selectors, confirm the shared executor owns this order:

  1. Session authentication before request parsing.
  2. Canonical workflow/workspace loading and read authorization.
  3. Manifest capability and exact-context allowlisting.
  4. Exact environment-reference resolution on the server.
  5. Credential use, workspace, and trusted provider/service binding.
  6. Destination-policy enforcement before provider network access.
  7. Provider/internal execution followed by explicit option projection and sanitization.

The attachment must not duplicate these shared checks. It must not accept a browser-provided module, provider, service, operation kind, origin, or scope list.

Review its destination classification:

  • fixed origins are code-defined.
  • credential-bound origins are derived from or checked against the authorized credential.
  • user-controlled destinations have an explicit policy for hidden use-only authentication and network safety.

Missing and inaccessible references, and missing, unauthorized, or provider-mismatched credentials, must not become existence oracles. Hidden/server-only resolved plaintext, credentials, authentication material, and raw upstream errors must not enter responses, query/cache/rate keys, selector result caches, logs, audit metadata, redirects, or error messages. Browser-known literals and viewable personal/shared values are not automatically protected plaintext, but the executor must still never deliberately or wholesale echo selector context. Only intentionally projected, normalized { id, label, meta? } options and bounded cursors may cross the boundary.

Selector code adds no context, token, or result cache beyond the single accepted exception described in the add-selector skill ("Wire the UI declaration").

Show full SKILL.md (157 more words)Show less

Validate provider reuse and browser boundaries

  • The attachment calls a server-only provider primitive, not a route handler or internal HTTP URL.
  • A surviving provider route has a proven non-selector caller and delegates to the same primitive.
  • There is no client provider selector module, selector-specific token request, or browser request to a provider-specific selector route.
  • Internal selectors delegate to existing authorized use cases rather than querying protected data in the route or adapter.

Tests and report

Use existing Vitest/route/React Query patterns. Preserve valuable provider tests, but do not demand a per-selector authorization matrix. Shared executor tests should cover ordering, references, credential binding, sanitization, and safe errors; adapter tests should cover only special provider behavior.

Report critical, warning, and suggestion findings. Treat browser secret resolution, missing scope or credential authorization, unsafe destination binding, provider payload passthrough, and plaintext egress as critical.

Run the smallest relevant focused suites plus:

bash
bun run --cwd apps/sim type-check
bun run check:api-validation:strict
bun run check:fork-dependent-coverage
bun run check:client-boundary
git diff --check

State which live-provider checks remain pending when disposable credentials are unavailable.

© simstudioai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/validate-selector of simstudioai/sim.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 546d4e7

Compare with similar skills

Validate Selector next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validate Selector compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validate Selector this skillsimstudioai/sim30k—~1.2kAutomated safety check: PassApache-2.0
Has Selectorthedaviddias/Front-End-Checklist74k—~547Automated safety check: PassMIT
Dynamic Workflow Modeaffaan-m/ECC275k1 repos~1.3kAutomated safety check: PassMIT
Molecular DynamicsK-Dense-AI/scientific-agent-skills48k1 repos~4.7kAutomated safety check: PassMIT
Dynamic WorkflowNousResearch/hermes-agent252k—~2.8kAutomated safety check: PassMIT
Declarative Agentsgithub/awesome-copilot40k1 repos~1.2kAutomated safety check: PassMIT

Similar skills

  • Has Selector

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing stylesheets or components that use JavaScript to toggle classes on parent elements based on child state, form input values, or content presence — :has() may…

    74k GitHub stars~547 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Design task-local harnesses, eval gates, and reusable skill extraction for Claude dynamic workflow mode and other adaptive agent harnesses.

    275k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Molecular Dynamics

    K-Dense-AI/scientific-agent-skills

    Runs and analyzes molecular dynamics simulations with OpenMM and MDAnalysis.

    48k GitHub starsUsed in 1 repo~4.7k tokens
    Research & ScienceAuto-check passed
  • Dynamic Workflow

    NousResearch/hermes-agent

    Plan-in-code fan-outs, adversarial verification, waves. An agent skill from NousResearch/hermes-agent.

    252k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Declarative Agents

    github/awesome-copilot

    Official

    Complete development kit for Microsoft 365 Copilot declarative agents with three comprehensive workflows (basic, advanced, validation), TypeSpec support, and Microsoft 365 Agents Toolkit integration

    40k GitHub starsUsed in 1 repo~1.2k tokens
    Documents & OfficeAuto-check passed
  • MCP Create Declarative Agent

    github/awesome-copilot

    Official

    Skill converted from mcp-create-declarative-agent.prompt.md. An agent skill from github/awesome-copilot.

    40k GitHub starsUsed in 2 repos~2k tokens
    Agent WorkflowsAuto-check: notes

More from simstudioai/sim

All 40 skills in this repo
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Add Column Type

    simstudioai/sim

    Add a new table column type to Sim — registry entry, icon, storage shape, coercion, and the behavioral hooks the grid and API read.

    30k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Add Enrichment

    simstudioai/sim

    Add a code-defined table enrichment (registry entry) under apps/sim/enrichments/ backed by an ordered provider cascade, ensuring every provider tool it calls has hosted-key support.

    30k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Add Managed CLI

    simstudioai/sim

    Add or upgrade a curated, immutable managed CLI for Sim Function sandboxes, including client-safe catalog metadata, a pinned server-only installation recipe, checksum and executable verification…

    30k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Add Selector

    simstudioai/sim

    Add or update a Sim dynamic selector using the shared manifest, server attachment, and selectors.execute path.

    30k GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Questions about Validate Selector

What does Validate Selector do?

Audit a Sim dynamic selector across its declaration, browser-safe manifest, server attachment, provider primitive, and selectors.execute security boundary. Validate Selector is an agent skill from simstudioai/sim.execute security boundary.

When should I use Validate Selector?

Validate Selector fits situations like: reviewing selector correctness; secret handling; scope authorization; dead selector-only routes.

How do I install Validate Selector in Claude Code?

Run `npx skills add simstudioai/sim --skill validate-selector -a claude-code`. Or copy the skill folder (.agents/skills/validate-selector in simstudioai/sim) into .claude/skills/validate-selector in your project. Claude Code loads it when a task matches its description.

How do I install Validate Selector in Codex?

Run `npx skills add simstudioai/sim --skill validate-selector -a codex`. Or copy the skill folder (.agents/skills/validate-selector in simstudioai/sim) into .agents/skills/validate-selector in your project. Codex loads it when a task matches its description.

Can I use Validate Selector in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add simstudioai/sim --skill validate-selector -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validate-selector, .gemini/skills/validate-selector, .github/skills/validate-selector and .opencode/skills/validate-selector in your project.

What does Validate Selector need to run?

Going by SKILL.md and its folder, Validate Selector needs the command-line tools its instructions call (bun and git).

Does Validate Selector access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Validate Selector safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Validate Selector use?

Validate Selector is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validate Selector use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validate Selector?

Skills that share tags, products or a category with Validate Selector: Has Selector (thedaviddias/Front-End-Checklist, 74k stars), Dynamic Workflow Mode (affaan-m/ECC, 275k stars), Molecular Dynamics (K-Dense-AI/scientific-agent-skills, 48k stars) and Dynamic Workflow (NousResearch/hermes-agent, 252k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validate Selector?

simstudioai (a GitHub organization) maintains it in simstudioai/sim, which has 29,792 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 8, 2026.

Source: simstudioai/sim on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.