writing-motoko
Write Modern Motoko Backends
Outdated Motoko examples can cause compiler errors and unsuitable backend designs. This skill provides modern language references, modular actor patterns, and mops dependency workflows.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "writing-motoko" from https://skillstore.io/skills/caffeinelabs-writing-motoko.md and its manifest at https://skillstore.io/api/skills/caffeinelabs-writing-motoko/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "writing-motoko". How should I organize a blog canister with mutable users and posts?
Expected outcome:
- Keep entity types in the schema module and domain methods in separate user and post modules.
- Inject only required state into each API mixin, and keep the actor as the composition root.
- Return immutable views. Restrict public lists to published posts and authorize access to drafts.
- Initialize durable state through the configured migration chain before running compiler checks.
Using "writing-motoko". A Nat-keyed map operation reports that the compiler cannot determine compare. What should I check?
Expected outcome:
- Import the core Nat module in the file performing the map operation.
- Map operations resolve their implicit comparator from the imported key-type module.
- Verify the operation signature, then rerun the mops check after fixing the import.
Using "writing-motoko". Which return type should a booking endpoint use for expected caller errors?
Expected outcome:
- Return a typed result with an immutable success view and an error variant.
- Use separate error tags for authorization failures, unknown rooms, and occupied slots.
- Reserve traps for broken invariants and options for normal absence.
Security Audit
High RiskAll 383 static findings are false positives involving Markdown backticks, language identifiers, relative module imports, or the mops documentation link. Three semantic risks affect example applications: unrestricted timer scheduling, unpublished post visibility, and anonymous callers sharing todo ownership. No evidence found of malicious execution, credential exfiltration, or audit-directed prompt injection.
Confirmed security concerns (3)
Risk Factors
⚙️ External commands (50)
📁 Filesystem access (14)
🌐 Network access (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/caffeinelabs-writing-motoko/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/caffeinelabs-writing-motoko?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/caffeinelabs-writing-motoko?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/caffeinelabs-writing-motoko/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/caffeinelabs-writing-motoko.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
caffeinelabs. (2026). writing-motoko security audit report (audit version 1) [Author version 0.2.9]. Skillstore. https://skillstore.io/skills/caffeinelabs-writing-motoko/audits/1BibTeX citation
@techreport{caffeinelabs-caffeinelabs-writing-motoko-2026,
author = {caffeinelabs},
title = {writing-motoko security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/caffeinelabs-writing-motoko/audits/1},
note = {Author version 0.2.9}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "writing-motoko security audit report (audit version 1)"
version: "0.2.9"
type: report
authors:
- name: "caffeinelabs"
date-released: "2026-10-02"
url: "https://skillstore.io/skills/caffeinelabs-writing-motoko/audits/1"
identifiers:
- type: other
value: "skillstore:caffeinelabs-writing-motoko:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Build a First Motoko Service
Use modern syntax and shared API types to organize a small backend into domain modules, mixins, and actor state.
Repair Backend Compile Errors
Compare failing collection calls, imports, and conversions against the supplied signatures and diagnostic guidance.
Align APIs With Client Bindings
Define immutable response views and caller-scoped endpoints before using generated backend bindings in a client application.
Try These Prompts
Explain query versus update functions and shared response types for a simple Motoko todo service. Use this skill's supported toolchain assumptions.
Design a Motoko backend for [domain]. Separate types, domain helpers, API mixins, and actor state. Identify authorization rules and migration prerequisites.
Resolve [compiler diagnostic] in [source excerpt]. Verify relevant core signatures, preserve behavior, and propose focused mops checks without changing platform-managed flags.
Implement [service] using injected state, immutable views, and typed errors. Reject anonymous personal-record access. Bound privileged operations and include negative authorization tests.
Best Practices
- Verify toolchain versions and uncertain core APIs against the supplied references before implementing changes.
- Define backend authorization and visibility policies, then test anonymous, unauthorized, and repeated privileged calls.
- Use mops for dependency changes, iterate with compile checks, and build only after checks pass.
Avoid
- Copying example services into production without reviewing authentication, publication rules, and recurring resource costs.
- Guessing JavaScript-style collection methods or mixing deprecated base APIs with modern core conventions.
- Changing persistent actor state without migration guidance or manually editing dependency lockfiles.
Frequently Asked Questions
Which AI tools can use this skill?
Which Motoko versions does it target?
Does it include core API signatures?
Does it handle canister migrations by itself?
Does reading the skill run commands?
Are the examples ready for production?
Developer Details
Author
caffeinelabsLicense
MIT
Author version
v0.2.9
Skillstore revision
r1
Ref
559e64027386c155cf48ca5094a15146152a9231
Maintenance freshness
10/2/2026
Usage
0 downloads · 0 views
File structure