malloy

malloy is a skill for Claude Code, Codex from malloydata/publisher. It costs 46 tokens per session (1,479 once invoked), scanned A, original, MIT.

An index of Malloy skills, where Malloy is a language for modeling and querying data.

In plain words
What is it for?
It helps start with a Publisher, find available data, build semantic models, and answer analytical questions.
Why use it?
It helps choose the right skill for setup, data discovery, modeling, or analysis instead of guessing which workflow to follow.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/malloydata/publisher/malloy
Any agent
npx skills add malloydata/publisher --skill malloy
Clone the repo
git clone --depth 1 https://github.com/malloydata/publisher

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for malloy

README.md
[![agentmods](https://agentmods.dev/badge/skills/malloydata/publisher/malloy.svg)](https://agentmods.dev/skills/malloydata/publisher/malloy)
Your own site
<a href="https://agentmods.dev/skills/malloydata/publisher/malloy"><img src="https://agentmods.dev/badge/skills/malloydata/publisher/malloy.svg" alt="Measured on agentmods" height="20"></a>
Per session 46 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,479 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00046 $0.01479
Opus 5 $0.00023 $0.00740
Sonnet 5 $0.00009 $0.00296
Haiku 4.5 $0.00005 $0.00148

Measured 2d ago against content hash 8ab7d4ba24d5, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

malloy scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/malloy/SKILL.md · 102 lines

How it starts

The opening of the file, as written. The whole thing — 102 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Malloy Skills Index

First-Time Setup

No .malloy files in workspace? Say "model my data" and the agent will orchestrate the full modeling workflow automatically. Make sure the Malloy Publisher MCP tools are configured first.

Skill Reference

Every skill in this deployment, by what it is for. Start at a driver; it routes to the rest.

This table is a catalogue of what exists, not of what is loaded. A host that installs one group takes that group's skills alone: analysis, modeling, or eval. A row naming a skill from a group you did not install says that the skill exists. It is not an instruction to load it, and it is written as a plain name rather than a skill: reference to say so.

Start here

Skill Use when...
skill:malloy-getting-started First contact with a Publisher: confirming the tools, finding what data exists, running a first grounded query
skill:malloy-modeling Building a semantic model from scratch (the modeling workflow driver)
skill:malloy-analysis Answering a data question or exploring data (the analysis workflow driver)

Modeling phases (driven by skill:malloy-modeling)

Skill Use when...
skill:malloy-discover Silent data discovery: tables, schemas, distributions, prior art
skill:malloy-scope Presenting findings and proposing an analytical focus
skill:malloy-define Proposing the source plan and field definitions
skill:malloy-model Writing base and joined source .malloy files, review, curate (includes normalized schema support)
skill:malloy-document Adding #(doc) tags for discoverability
skill:malloy-lookml-review Prior-art adapter for LookML (field extraction, derived tables, visibility, docs)

Analysis and presentation

Skill Use when...
skill:malloy-model-as-you-go After answering a question, writing down what it assumed: a #(doc)'d field in the model, an extend in the notebook, or a stated assumption plus snippet, depending on what the session can write
skill:malloy-analyze Open-ended exploration with no intent to keep anything: profiling, hypotheses, views
skill:malloy-charts Chart selection and renderer reference for Malloy visualizations
skill:malloy-notebooks Building Malloy notebooks (.malloynb)
skill:malloy-analysis-report Combining validated queries into a notebook report or dashboard
skill:malloy-analysis-pitfalls Checking a query and its results before presenting an answer
malloy-notebook-chat The chat is bound to a notebook or saved report; answer from its cells. Ships in analysis.
skill:malloy-phrase-detection Turning a plain-English question into search targets for the context tool

Read the full file on GitHub · 102 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago Changed · +11 lines 8ab7d4ba24d5
  2. 6d ago First seen · 91 lines · 46 tokens per session scan A 838a3934346d

Subscribe to this mod's changes

malloy is a skill published in the GitHub repository malloydata/publisher (100 stars, last pushed today), licensed MIT. It adds 46 tokens to every session and 1,479 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

debug-local

Debug the Lightdash app using PM2 logs, Maple traces, and browser automation. Use when investigating issues, tracking down bugs, understanding request flow, or correlating frontend actions with backend behavior.

lightdash/lightdash · 42 tokens

frontend-style-guide

Apply the Lightdash frontend style guide and design principles when working on React components or styling frontend code. Use when editing TSX files, building or reviewing UI, fixing styling issues, or when the user mentions Mantine, design, styling, or CSS modules.

lightdash/lightdash · 56 tokens

reusable-visualization

Build ONE reusable chart visualization component that receives its data and its settings from the host application instead of fetching them, and declares the fields and config options the host exposes to viewers. Use this whenever a single chart component is reused across many different queries rather than built for…

lightdash/lightdash · 102 tokens

lightdash-agent-slack-messaging

Use this skill when writing, designing, or generating Slack messages for Lightdash's in-app analytics agent. Triggers when someone asks to create agent update messages, Slack digests, agent notifications, weekly summaries, daily summaries, or any Slack copy for the Lightdash project agent. Also use when asked to vary…

lightdash/lightdash · 114 tokens

upgrade-preflight

Checks whether a self-hosted Lightdash upgrade is safe to run, and reads the tooling's answer without over-reading it. Use when upgrading a self-hosted instance, planning a maintenance window, answering "is this upgrade safe", or recovering a failed, hung, parked or lock-stuck migration — covers lightdash…

lightdash/lightdash · 101 tokens

breakup-pr

Break up a large PR into vertical feature slices delivered incrementally via Graphite stacked PRs. All verticals share a single feature flag so the entire feature ships atomically. Use when: splitting a large PR, breaking up a diff, vertical slicing, incremental delivery, phased rollout, or when a PR is too large to…

lightdash/lightdash · 72 tokens