vals-56f63e — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited vals-56f63e (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Installs the Val Town MCP server and Skills for Claude Code, Codex, and Cursor.
Skills are markdown files with platform guidance for building on Val Town. Used by Val Town's own tools (Townie, the MCP server) and by AI coding agents. Skills include HTTP vals, crons, SQLite, email, OAuth, frontend, and API integrations.
Installing the plugin makes platform skills available to your agent and registers the hosted Val Town MCP server (https://api.val.town/v3/mcp). On first use of an MCP tool, the agent runs the OAuth flow in your browser.
Install the Val Town plugin by running:
claude plugin install valtown@claude-plugins-official#### codex CLI
First, run:
codex plugin marketplace add val-town/pluginsThen fire up codex and run:
/pluginsSearch for Val Town, hit install, and it'll take you through the OAuth path.
#### Codex desktop app
https://github.com/val-town/plugins and select "Add marketplace"In Cursor, run:
/add-plugin valtownOr in Cursor Settings, copy-paste https://github.com/val-town/plugins in the search box and select "Add to Cursor."
Skills live in plugin/skills/<name>/SKILL.md with YAML frontmatter:
---
name: http-endpoints
description: Use when building an HTTP val — a web endpoint, API route, webhook...
triggers: [http, endpoint, webhook, api, request, response]
---
# HTTP Endpoints
...guide body...name (required) — must match the directory name; lowercase, hyphens, ≤64 chars.description (required) — written as "Use when…"; this is how Claude decidesto load the skill. ≤1024 chars.
triggers (optional) — keyword hints that boost searchSkills ranking;ignored by Claude Code's native loader.
Keep content audience-neutral: only platform knowledge true for every consumer. No product-flow or chat-only advice.
Then build:
npm install
npm run build # generate src/generated/skills.ts, then tsc
npm test # build + smoke testsnpm run generate validates every skill against both our schema and Claude Code's frontmatter constraints — a skill that wouldn't load in Claude Code fails the build.
This package is the source of truth for skill content. The Val Town app and MCP server consume it as a dependency rather than holding their own copy. See docs/SKILLS_PLUGIN.md in the main repo for the full design.
This repository uses Changesets for publishing. See their documentation for more information.
npx @changesets/cliand fill out the interactive prompts to describe the changes. This will generate a new changeset in the .changesets directory.
release.yml GitHub actionto create a new release PR.
#### Claude Code
The official Claude plugin marketplace pulls from .plugins/marketplace.json.
#### Codex
Codex reads the native marketplace at .agents/plugins/marketplace.json (and falls back to the Claude .claude-plugin/marketplace.json for compatibility).
#### Cursor
Cursor reads .cursor-plugin/marketplace.json and the per-plugin plugin/.cursor-plugin/plugin.json.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.