Getting it into your agent
It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.
git clone --depth 1 https://github.com/tray-tecnologia/tray-api-ai-pluginnpx agentmods add skills/tray-tecnologia/tray-api-ai-plugin/scripts-externosWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/tray-tecnologia/tray-api-ai-plugin/scripts-externos)<a href="https://agentmods.dev/skills/tray-tecnologia/tray-api-ai-plugin/scripts-externos"><img src="https://agentmods.dev/badge/skills/tray-tecnologia/tray-api-ai-plugin/scripts-externos.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00049 | $0.00954 |
| Opus 5 | $0.00024 | $0.00477 |
| Sonnet 5 | $0.00010 | $0.00191 |
| Haiku 4.5 | $0.00005 | $0.00095 |
Grade A, and why
tray-scripts-externos scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 110 lines — stays where its author put it; the contents beside it link to each section on GitHub.
MANDATORY: Tool Call Required Before Answering
Esta chamada é OBRIGATÓRIA, não opcional. Execute-a antes de gerar qualquer código ou payload. Se você está respondendo sem ter chamado a ferramenta abaixo, pare e chame agora.
Buscar documentação atualizada (sempre)
node skills/tray-dev/scripts/search_docs.mjs --topic=scripts-externos "<termo da pergunta>"
<TOPIC_SLUG>: ver tabela emskills/tray-dev/SKILL.md.- Use os trechos retornados como fonte primária; este SKILL.md é resumo.
Nota: este recurso ainda não tem
validate.mjslocal. Você é responsável por revisar campos obrigatórios contra a doc retornada e o resumo abaixo.
Antes de responder
Execute estas verificações antes de gerar qualquer payload ou código:
- Confirme o método HTTP e endpoint correto para a operação solicitada.
- Identifique os campos obrigatórios listados neste documento — não omita nenhum.
- Verifique que
access_tokennão aparece como literal string no código gerado. - Confirme que esta é a skill correta para o recurso (leia
when_not_to_useno frontmatter).
API de Scripts Externos — Tray
Documentação oficial: https://developers.tray.com.br/#apis-de-scripts-externos
Endpoints
| Método | Endpoint | Descrição |
|---|---|---|
| GET | /scripts |
Listagem de scripts externos |
| POST | /scripts |
Cadastrar script externo |
| PUT | /scripts/:id |
Atualizar script |
| DELETE | /scripts/:id |
Excluir script |
Autenticação: ?access_token={token}
Campos
| Campo | Tipo | Descrição |
|---|---|---|
url |
string | URL do script JavaScript |
location |
string | Posição na página: head, body ou footer |
active |
number | 0=inativo, 1=ativo |
Exemplo de Cadastro
{
"Script": {
"url": "https://cdn.exemplo.com/meu-script.js",
"location": "footer",
"active": 1
}
}
Boas Práticas
- Use
footer— para não bloquear o carregamento da página - Scripts leves — evite scripts pesados que impactem a performance
- HTTPS obrigatório — a URL deve usar HTTPS
What ships with it
10 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- examples/script-atualizar.curl.sh 831 B runs code
- examples/script-atualizar.fixture.json 116 B
- examples/script-atualizar.node.mjs 1.2 KB runs code
- examples/script-criar.curl.sh 726 B runs code
- examples/script-criar.fixture.json 116 B
- examples/script-criar.node.mjs 1.1 KB runs code
- examples/script-excluir.curl.sh 856 B runs code
- examples/script-excluir.node.mjs 1.1 KB runs code
- examples/script-listar.curl.sh 536 B runs code
- examples/script-listar.node.mjs 799 B runs code
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 110 lines · 49 tokens per session scan A 0a9c6706792e
tray-scripts-externos is a skill published in the GitHub repository tray-tecnologia/tray-api-ai-plugin (15 stars, last pushed 26d ago), licensed MIT. It adds 49 tokens to every session and 954 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
hostinger-headless
Build, connect, or iterate on a website hosted on Hostinger — provision hosting and a domain, optionally seed an ecommerce store with a real hosted checkout or a WordPress content backend (headless CMS/blog), build the frontend, deploy, and verify. Requires an authenticated Hostinger MCP session (see entry/skill.md).…
shopify-developer
Complete Shopify development reference covering Liquid templating, OS 2.0 themes, GraphQL APIs, Hydrogen, Functions, and performance optimization (API v2026-01). Use when working with .liquid files, building Shopify themes or apps, writing GraphQL queries for Shopify, debugging Liquid errors, creating app extensions…
design-assessment
WHAT - Evidence-based design-unit assessment orchestrated by project-assessment. Evaluates visual hierarchy, UX friction, interaction, a11y, responsiveness, design-system compliance, and distinctiveness with severity/confidence evidence citations. Reuses project-assessment-evidence semantics — no second framework.
review
WCAG 2.2 AA curated accessibility review — distinguishes automatically detectable, browser-assisted, and manual/human-judgment findings with evidence citations and SC mapping. Composes with design-assessment/design-improvement/frontend-design-review.
web-design-guidelines
Review UI code for Web Interface Guidelines compliance. Use when asked to "review my UI", "check accessibility", "audit design", "review UX", or "check my site against best practices".
building-glamorous-tuis
Build terminal UIs with Charmbracelet (Bubble Tea, Lip Gloss, Gum). Use when: Go TUI, shell prompts/spinners, "make CLI prettier", adaptive layouts, async rendering, focus state machines, sparklines, heatmaps, kanban boards, SSH apps.