jsonlogic
Build and Test JsonLogic Business Rules
Business conditions can produce unexpected results when field names, missing values, or library behavior differ. This skill builds JsonLogic rules and guides targeted verification.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "jsonlogic" from https://skillstore.io/skills/valeryia-piatrova-jsonlogic.md and its manifest at https://skillstore.io/api/skills/valeryia-piatrova-jsonlogic/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "jsonlogic". Create a discount eligibility rule for loyalty members who spent more than 100.
Expected outcome:
Eligibility requires loyalty membership and spending above 100. Spending exactly 100 does not qualify. Define missing-field handling before testing.
Using "jsonlogic". Explain why an order rule flags an item priced at 620 when the threshold is 500.
Expected outcome:
The rule checks each item and succeeds when any price exceeds 500. An item priced at 620 qualifies. An empty item list returns false.
Using "jsonlogic". Does passing structural validation prove that my rule works in both JavaScript and Ruby?
Expected outcome:
No. Structural validation checks rule shape only. Execute identical boundary, missing-field, and type cases in both libraries before claiming matching behavior.
Security Audit
High RiskOf 372 static findings, 370 are false positives and two confirm automatic installation of an unpinned Ruby dependency. Additional findings concern artifact publication without consent and unsafe JSON embedding in HTML. No evidence found of credential theft or instructions to override this audit.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
๐ Network access (15)
๐ Filesystem access (17)
โ๏ธ External commands (30)
โก Contains scripts (50)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/valeryia-piatrova-jsonlogic/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/valeryia-piatrova-jsonlogic?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/valeryia-piatrova-jsonlogic?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/valeryia-piatrova-jsonlogic/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/valeryia-piatrova-jsonlogic.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
valeryia-piatrova. (2026). jsonlogic security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/valeryia-piatrova-jsonlogic/audits/1BibTeX citation
@techreport{valeryia-piatrova-valeryia-piatrova-jsonlogic-2026,
author = {valeryia-piatrova},
title = {jsonlogic security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/valeryia-piatrova-jsonlogic/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "jsonlogic security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "valeryia-piatrova"
date-released: "2026-10-01"
url: "https://skillstore.io/skills/valeryia-piatrova-jsonlogic/audits/1"
identifiers:
- type: other
value: "skillstore:valeryia-piatrova-jsonlogic:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Encode Eligibility Conditions
Turn product requirements into explicit rules with documented inputs, outputs, and missing-field behavior.
Debug Application Rules
Reproduce unexpected results, identify coercion or operator issues, and verify corrections against representative data.
Compare Rule Implementations
Test identical inputs across frontend and backend libraries to identify unsupported operators and behavior differences.
Try These Prompts
Explain this JsonLogic rule: [rule]. Describe each operator, required fields, returned values, and missing-field behavior. Do not publish an artifact.
Create a JsonLogic rule for [condition] using [schema or synthetic sample]. Explain assumptions and expected outcomes. Keep all data local.
Debug [rule] with [synthetic input] in [library and version]. Expected: [result]. Add boundary tests and request permission before installing dependencies or publishing.
Compare [rule] in [library A] and [library B] using identical synthetic cases. Cover missing values, coercion, and empty arrays. Separate observed from unverified results.
Best Practices
- Provide a schema or synthetic sample and specify the target library and version.
- Test normal cases, exact boundaries, missing fields, unexpected types, and empty arrays in the actual evaluator.
- Use redacted inputs and explicitly approve dependency installation or artifact publication before either occurs.
Avoid
- Treating structural validation or a playground result as proof of production correctness.
- Assuming all libraries support the same extensions, truthiness rules, and type coercion.
- Providing secrets or production records for automatic artifact publication.
Frequently Asked Questions
What is JsonLogic?
Which AI tools can use this skill?
Which evaluator is used by default?
Can it validate rules without executing them?
Does the playground match every library?
Does using the skill require network access?
Developer Details
Author
valeryia-piatrovaLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Repository
https://github.com/valeryia-piatrova/jsonlogic-skill/tree/19c9ebeb6ae5bf9406d0a39f32a24b60b77738ff/Ref
c7a30fd4df735cc64b379eb7df86db9e58f0193d
Maintenance freshness
10/1/2026
Usage
0 downloads ยท 0 views
File structure
๐ .claude-plugin/
๐ marketplace.json
๐ plugin.json
๐ assets/
๐ demo.gif
๐ jsonlogic-core.js
๐ playground.html
๐ CHANGELOG.md
๐ docs/
๐ installing.md
๐ examples/
๐ basic-rules.json
๐ conditions.json
๐ LICENSE
๐ README.md
๐ references/
๐ jsonlogic.md
๐ libraries.md
๐ operations.md
๐ testing.md
๐ tests/
๐ community/
๐ additional.json
๐ arithmetic/
๐ divide.extra.json
๐ divide.json
๐ minus.extra.json
๐ minus.json
๐ modulo.extra.json
๐ modulo.json
๐ multiply.extra.json
๐ multiply.json
๐ plus.extra.json
๐ plus.json
๐ array/
๐ all.json
๐ filter.json
๐ map.json
๐ merge.json
๐ none.json
๐ reduce.json
๐ some.json
๐ chained.json
๐ coalesce.json
๐ comparison/
๐ greaterThan.json
๐ lessThan.json
๐ lessThanEquals.json
๐ softEquals.json
๐ softNotEquals.json
๐ strictEquals.json
๐ strictNotEquals.json
๐ compatible.json
๐ control/
๐ and.json
๐ doublebang.json
๐ if.json
๐ not.json
๐ or.json
๐ exists.json
๐ index.json
๐ iterators.extra.json
๐ scopes.json
๐ string/
๐ cat.json
๐ in.json
๐ substr.json
๐ throw.json
๐ truthiness.json
๐ try.extra.json
๐ try.json
๐ val-compat.json
๐ val.extra.json
๐ val.json
๐ var.extra.json
๐ core.json
๐ scripts/
๐ jsonlogic.rb
๐ validate_skill.rb
๐ SKILL.md