extension-oql
Expose Canister Data Through OQL
Structured canister data is difficult for intelligence agents to query safely. This skill adds OQL entities, schema discovery, query execution, relationships, and per-entity authorization.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "extension-oql" from https://skillstore.io/skills/caffeinelabs-extension-oql.md and its manifest at https://skillstore.io/api/skills/caffeinelabs-extension-oql/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "extension-oql". Expose a products map while keeping access limited to controllers.
Expected outcome:
- Added a product entity with its identifier as the primary key.
- Kept controller-only authorization and added an empty-state schema sample.
- Registered schema discovery and query execution through the Expose mixin.
Using "extension-oql". Make private notes queryable by each note owner.
Expected outcome:
- Tagged the owner principal as the row owner.
- Applied user-scoped authorization so each caller receives only owned notes.
- Kept ownership available during joins to prevent cross-user traversal.
Using "extension-oql". Connect products and vendors through a supplies collection.
Expected outcome:
- Created a manual supply entity from map entries.
- Promoted product and vendor identifiers into queryable fields.
- Linked both identifiers to their target entities for relationship traversal.
Security Audit
SafeAll 115 static findings are false positives caused by Markdown code formatting, Motoko examples, a fixed Mops setup command, the `keys()` method, and sample records. SKILL.md contains no shell backtick execution, key-file access, system reconnaissance, prompt injection, or data-exfiltration intent. It documents explicit per-entity authorization and warns developers to choose access levels carefully.
Risk Factors
โ๏ธ External commands (50)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/caffeinelabs-extension-oql/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/caffeinelabs-extension-oql?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/caffeinelabs-extension-oql?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/caffeinelabs-extension-oql/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/caffeinelabs-extension-oql.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
caffeinelabs. (2026). extension-oql security audit report (audit version 1) [Author version 0.4.0]. Skillstore. https://skillstore.io/skills/caffeinelabs-extension-oql/audits/1BibTeX citation
@techreport{caffeinelabs-caffeinelabs-extension-oql-2026,
author = {caffeinelabs},
title = {extension-oql security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/caffeinelabs-extension-oql/audits/1},
note = {Author version 0.4.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "extension-oql security audit report (audit version 1)"
version: "0.4.0"
type: report
authors:
- name: "caffeinelabs"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/caffeinelabs-extension-oql/audits/1"
identifiers:
- type: other
value: "skillstore:caffeinelabs-extension-oql:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Add Canister Analytics
Expose product, customer, or project collections for natural-language questions and aggregate analysis.
Protect User-Scoped Queries
Apply owner fields and scoped authorization so signed-in users receive only permitted rows.
Model Complex Relationships
Create edges, junction entities, flattened records, and computed payloads for richer queries.
Try These Prompts
Inspect my Motoko canister and expose the products collection through caffeineai-oql. Keep controller-only authorization and summarize each change.
Expose my notes collection. Use its owner principal for row-level access, and prevent users from reading another user's rows.
Expose products, vendors, and supplies as related OQL entities. Define stable primary keys and edges that support dotted-path queries.
Review all persistent collections. Propose authorized entities, manual projections, conversion modules, hidden fields, samples, and synthetic junctions before implementing them.
Best Practices
- Keep controller-only authorization until the intended audience for every entity is explicit.
- Expose only fields and collections required for supported questions.
- Verify primary keys, owner fields, edges, and empty-collection samples before deployment.
Avoid
- Do not mark private or user-owned data as public.
- Do not enable scoped access without a valid owner field or subject-aware iterator.
- Do not rely on populated collections for schema discovery when data can be empty.
Frequently Asked Questions
What does this skill add?
Which collection types are supported?
How is access controlled?
Does it expose every collection automatically?
What versions are required?
How are non-primitive fields handled?
Developer Details
Author
caffeinelabsLicense
MIT
Author version
v0.4.0
Skillstore revision
r1
Ref
f32f934280aa94e399d875d7cf7b2ed16d1b82a3
Maintenance freshness
7/23/2026
Usage
0 downloads ยท 0 views
File structure
๐ SKILL.md