Cabloy Contract Loop
cabloy/cabloy
A skill your agent uses whenever a Cabloy task crosses the Vona-to-Zova contract boundary: backend DTO, controller, validation, entity, inferred DTO, or OpenAPI changes that should drive SDK…
Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.
$ npx skills add ToolJet/ToolJet --skill create-plugin -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ToolJet/ToolJet create-plugin --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ToolJet/ToolJet.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/create-plugin .claude/skills/create-plugin && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "create-plugin" agent skill from https://github.com/ToolJet/ToolJet/tree/main/.agents/skills/create-plugin into .claude/skills/create-plugin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-plugin", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ToolJet/ToolJet/tree/main/.agents/skills/create-pluginType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ToolJet/ToolJet --skill create-plugin -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ToolJet/ToolJet create-plugin --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ToolJet/ToolJet.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/create-plugin .agents/skills/create-plugin && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "create-plugin" agent skill from https://github.com/ToolJet/ToolJet/tree/main/.agents/skills/create-plugin into .agents/skills/create-plugin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-plugin", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ToolJet/ToolJet --skill create-plugin -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ToolJet/ToolJet create-plugin --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ToolJet/ToolJet.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/create-plugin .cursor/skills/create-plugin && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "create-plugin" agent skill from https://github.com/ToolJet/ToolJet/tree/main/.agents/skills/create-plugin into .cursor/skills/create-plugin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-plugin", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ToolJet/ToolJet.git --path .agents/skills/create-plugin--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ToolJet/ToolJet --skill create-plugin -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ToolJet/ToolJet create-plugin --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ToolJet/ToolJet.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/create-plugin .gemini/skills/create-plugin && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "create-plugin" agent skill from https://github.com/ToolJet/ToolJet/tree/main/.agents/skills/create-plugin into .gemini/skills/create-plugin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-plugin", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ToolJet/ToolJet create-pluginInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ToolJet/ToolJet --skill create-plugin -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ToolJet/ToolJet.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/create-plugin .github/skills/create-plugin && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "create-plugin" agent skill from https://github.com/ToolJet/ToolJet/tree/main/.agents/skills/create-plugin into .github/skills/create-plugin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-plugin", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ToolJet/ToolJet --skill create-plugin -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ToolJet/ToolJet create-plugin --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ToolJet/ToolJet.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/create-plugin .opencode/skills/create-plugin && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "create-plugin" agent skill from https://github.com/ToolJet/ToolJet/tree/main/.agents/skills/create-plugin into .opencode/skills/create-plugin/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "create-plugin", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
create-pluginTurns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.
The skill turns an API source into a working ToolJet marketplace plugin with three parts: a connection form in manifest.json, a query form in operations.json and a QueryService in index.ts. It starts with an intake of up to seven questions asked one at a time, covering name and id, plugin type (API, database or cloud storage), requirements, the API source, an icon, a design reference and which branch to work on, with stated defaults if you skip them.
Before scaffolding it checks that the plugin id is not already used by a marketplace plugin or a built-in connector kind. The repository's own validator is the final gate, and the agent is told to read marketplace/AGENTS.md for codebase facts rather than relying on the skill. Built-in connectors under plugins/packages are out of scope. JSON templates for different authentication styles and references for backend, frontend and verification come with it.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1786038. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
npmnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
ToolJet Marketplace Plugin Builder loads about 2.1k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 841 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ToolJet/ToolJet at commit 1786038, republished under its AGPL-3.0 licence (© ToolJet). 841 words, ~2,139 tokens.
.claude/skills/create-plugin/SKILL.md (or your agent's skills folder). This skill also uses 21 other files; get the full folder from GitHub.Turn an API source into a working plugin under marketplace/plugins/<id>/: a connection form
(manifest.json), a query form (operations.json), and a QueryService (index.ts). The
repo-owned validator is the gate, not this document. Built-in connectors in plugins/packages/
are out of scope; if asked for one, stop and say so.
Read marketplace/AGENTS.md first. It owns the codebase facts (layout, registry, build, OAuth
widget, customTesting, @spec/ hosting); this skill links to it rather than repeating it.
To validate an existing plugin only, run step 5 and report with the checklist in
references/verify.md section 6; fix nothing unless asked.
Ask one question at a time. Skip any the user already answered. If the user says to use defaults,
state them: type api, no PRD, no icon, no design reference, current branch, version 1.0.0, V1,
and a tags category (step 3).
| # | Question | Notes |
|---|---|---|
| 1 | Display name and plugin id? | id: lowercase, [a-z][a-z0-9_-]*, e.g. "Stripe" / stripe |
| 2 | Plugin type? | api, database, or cloud-storage (the scaffold's --type) |
| 3 | PRD or requirements? | Issue URL, inline text, file path, or none |
| 4 | API source? | OpenAPI file or URL, Postman collection, npm package, docs URL, or a description |
| 5 | Icon? | SVG URL or path, or none (keep the scaffolded placeholder) |
| 6 | Design reference? | Figma link, screenshot, or none |
| 7 | Where to work? | Current branch or a new branch/worktree. Default: current branch |
Right after question 1, check the id is free, including built-in connector kinds:
grep -n '"id": "<id>"' server/src/assets/marketplace/plugins.json; ls marketplace/plugins/<id>
grep -l '"kind": "<id>"' plugins/packages/*/lib/manifest.jsonA built-in match (e.g. googlesheets) means pick another id; the validator rejects it. A
marketplace match: stop and ask whether to update that plugin instead. Updating skips step 3 and
edits the existing files. Never add a second registry entry for the same id: the validator fails
on duplicates (the CLI would abort with "Plugin id already exists").
Produce plugin-spec.json, the contract both generators work from. Route by source:
| Source | Reference |
|---|---|
OpenAPI spec (.json, .yaml, URL) | references/intake-openapi.md |
| Postman collection | references/intake-postman.md, then references/intake-openapi.md |
| npm package, DB driver, docs URL, description | references/intake-docs.md |
Write plugin-spec.json outside the repo (or delete it before committing). It is an
intermediate artifact and is never committed. Without subagents, it may stay in the conversation
instead of a file. Nothing validates it; the step 5 checks do.
User gate. Show the auth type, the operation list, operationsMode, and the schema version
(V1 unless the form needs cascading V2 widgets). Proceed only on a yes.
Render the repo's plugin templates directly, with no prompts. This is what tooljet plugin create
runs internally (the human path is in marketplace/AGENTS.md). Once per checkout, run
npm install at the repo root first (it provides hygen; takes a few minutes).
cd marketplace
../node_modules/.bin/hygen plugin new --name <id> --type <type> --display_name "<Display Name>" --plugins_path .It writes plugins/<id>/ (lib/{index.ts,types.ts,manifest.json,operations.json,icon.svg},
__tests__/index.js, package.json, tsconfig.json, README.md, .gitignore) and nothing
else. It upper-cases the first letter of the display name (libSQL becomes LibSQL); step 4
overwrites the manifest and operations from templates. In README.md, fix the heading and
replace the docs link (a placeholder page that does not exist) with a one-line description. Then:
Register the plugin: append an entry to server/src/assets/marketplace/plugins.json (the
file has no trailing newline; keep it that way). From the repo root, fill in and run (it inserts one entry before the closing ] in the file's own format):
node -e 'const fs=require("fs"),f="server/src/assets/marketplace/plugins.json",s=fs.readFileSync(f,"utf8").trimEnd();
const e={name:"<Display Name>",description:"<one line>",version:"1.0.0",id:"<id>",author:"Tooljet",timestamp:new Date().toUTCString(),repo:"",tags:["<Category>"]};
fs.writeFileSync(f,s.slice(0,-1).trimEnd()+",\n"+JSON.stringify(e,null,2).replace(/\[\s+("[^"]*")\s+\]/,"[$1]").replace(/^/gm," ")+"\n]")'tags is free-form: reuse an existing one when it fits, else one short Title Case category
(Database, Weather). To list them:
node -p '[...new Set(require("./server/src/assets/marketplace/plugins.json").flatMap((p) => p.tags || []))]'
Link the workspace: npm i in marketplace/ (updates package-lock.json).
If the id contains -, rename the generated class in lib/index.ts to a valid identifier.
Icon: save the provided SVG as lib/icon.svg, otherwise keep the placeholder.
Identity rule: marketplace/AGENTS.md (plugins.json id = source.kind = directory name).
Two independent jobs, both fed plugin-spec.json, the PRD, the API source, and the plugin
directory:
lib/index.ts and lib/types.ts: references/backend.md.lib/manifest.json, lib/operations.json, openapi-specs/: references/frontend.md.If your harness supports subagents, run them in parallel, one each, and pass the reference path
in the prompt. Otherwise do backend then frontend in this session. Both need
references/manifest-and-operations.md for widget and auth patterns. Install what index.ts
imports (npm i <pkg> --workspace=@tooljet-marketplace/<id>) before step 5.
Follow references/verify.md: build, npm run validate:plugin -- <id>, lint, spec coverage,
then an optional UI check. On failure, hand the exact error back to the job that owns the file and fix
only that. Stop after 3 fix rounds and report what still fails.
Report:
operationsMode.Commit and open PRs with the repo's commit and create-pr skills. Commit plugins.json,
marketplace/plugins/<id>/ and marketplace/package-lock.json; do not commit dist/ or
plugin-spec.json.
| Mistake | Fix |
|---|---|
@spec/ reference with no file in openapi-specs/ | File name without extension must equal the @spec/<id>/<name> suffix |
| Hand-written operations for an OpenAPI source | Use react-component-api-endpoint with @spec/ |
| Retrying a Postman share URL that returns HTML | Ask the user to export the collection file |
| Adding jest tests as a gate | Plugin tests are not wired up; verify with build + validator |
© ToolJet, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 21 other files (scripts, references, assets) in .agents/skills/create-plugin of ToolJet/ToolJet.
Open the folder on GitHubat commit 1786038
ToolJet Marketplace Plugin Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| ToolJet Marketplace Plugin Builder this skillToolJet/ToolJet | 41k | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Cabloy Contract Loopcabloy/cabloy | 982 | — | ~5.1k | Automated safety check: Pass | MIT | |
| OpenAPI CLI CallerEvilFreelancer/openapi-to-cli | 265 | — | ~879 | Automated safety check: Pass | MIT | |
| Release WorkflowGoldziher/spikard | 123 | — | ~909 | Automated safety check: Pass | MIT | |
| Eng Contract Codegen Coshipcompozy/compozy | 2.8k | — | ~664 | Automated safety check: Pass | MIT | |
| Use Yaakmountain-loop/yaak | 19k | — | ~1.9k | Automated safety check: Pass | MIT |
cabloy/cabloy
A skill your agent uses whenever a Cabloy task crosses the Vona-to-Zova contract boundary: backend DTO, controller, validation, entity, inferred DTO, or OpenAPI changes that should drive SDK…
EvilFreelancer/openapi-to-cli
Turns an OpenAPI, Swagger or OpenRPC spec into CLI commands the agent can search and call, with no MCP server or code generation.
Goldziher/spikard
Release/publish the spikard Rust core crate and CLI end-to-end.
compozy/compozy
Contract co-ship for Compozy wire changes. An agent skill from compozy/compozy.
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
jasonjgardner/blockbench-mcp-plugin
Zod schema validation best practices for type safety, parsing, and error handling.
ToolJet/ToolJet
Commits changes across ToolJet's root repo and its server/ee and frontend/ee submodules, writing messages from the diffs and updating submodule pointers in order.
ToolJet/ToolJet
Opens a pull request for the current ToolJet branch, pushing the root repo and the ee submodules, creating submodule PRs first and then the main PR with a generated description.
ToolJet/ToolJet
Reviews a ToolJet pull request of any size and writes a findings report for you to read first, scaling the process to the diff and posting to GitHub only on request.
ToolJet/ToolJet
Cuts a ToolJet release branch, bumps the version and moves feature PRs onto it, or adds more PRs to a release that already exists.
ToolJet/ToolJet
Merges a source branch into the current branch across ToolJet's root repo and its server/ee and frontend/ee submodules, handling conflicts and submodule order.
ToolJet/ToolJet
Decides where a new agent skill belongs in the ToolJet repo, public root or private ee submodule, then wires the symlinks so it loads in Claude Code, Cursor and Codex.
Categories
Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator. ts. It starts with an intake of up to seven questions asked one at a time, covering name and id, plugin type (API, database or cloud storage), requirements, the API source, an icon, a design reference and which branch to work on, with stated defaults if you skip them.
ToolJet Marketplace Plugin Builder fits situations like: adding a new data source or API connector to ToolJet's marketplace; generating a plugin from an OpenAPI file or Postman collection; validating an existing marketplace plugin.
Run `npx skills add ToolJet/ToolJet --skill create-plugin -a claude-code`. Or copy the skill folder (.agents/skills/create-plugin in ToolJet/ToolJet) into .claude/skills/create-plugin in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ToolJet/ToolJet --skill create-plugin -a codex`. Or copy the skill folder (.agents/skills/create-plugin in ToolJet/ToolJet) into .agents/skills/create-plugin in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ToolJet/ToolJet --skill create-plugin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-plugin, .gemini/skills/create-plugin, .github/skills/create-plugin and .opencode/skills/create-plugin in your project.
Going by SKILL.md and its folder, ToolJet Marketplace Plugin Builder needs the command-line tools its instructions call (npm and node). Our summary lists: A checkout of the ToolJet repository.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
ToolJet Marketplace Plugin Builder is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with ToolJet Marketplace Plugin Builder: Cabloy Contract Loop (cabloy/cabloy, 982 stars), OpenAPI CLI Caller (EvilFreelancer/openapi-to-cli, 265 stars), Release Workflow (Goldziher/spikard, 123 stars) and Eng Contract Codegen Coship (compozy/compozy, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ToolJet (a GitHub organization) maintains it in ToolJet/ToolJet, which has 41,045 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.
Source: ToolJet/ToolJet on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.