Borrowing it
Nothing to install: this file belongs to vgtitov/bsl-ai-toolkit. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/vgtitov/bsl-ai-toolkit/main/.claude/skills/1c-metadata/SKILL.mdgit clone --depth 1 https://github.com/vgtitov/bsl-ai-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vgtitov/bsl-ai-toolkit/1c-metadata)<a href="https://agentmods.dev/skills/vgtitov/bsl-ai-toolkit/1c-metadata"><img src="https://agentmods.dev/badge/skills/vgtitov/bsl-ai-toolkit/1c-metadata/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/vgtitov/bsl-ai-toolkit/1c-metadata"><img src="https://agentmods.dev/badge/skills/vgtitov/bsl-ai-toolkit/1c-metadata.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium analysis-evasion · line 1 Suspicious Unicode normalization or mixed-script contentFix: Review the flagged content for security risks. Ensure no credentials, secrets, or sensitive data are exposed.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00192 | $0.02371 |
| Opus 5 | $0.00096 | $0.01185 |
| Sonnet 5 | $0.00038 | $0.00474 |
| Haiku 4.5 | $0.00019 | $0.00237 |
Grade A, and why
1c-metadata scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 108 lines — stays where its author put it; the contents beside it link to each section on GitHub.
1c-metadata — структурные правки метаданных 1С
Локализация (сначала, если есть)
Если в скилле есть каталог references/local/ — прочитай его ПЕРЕД работой: version-stack.md
(версии платформы/библиотек, режим совместимости, префиксы ТВОЕЙ компании) и остальные карты.
При противоречии локальное побеждает generic. Контракт — docs/SKILL_LOCALIZATION.md toolkit.
Ядро: onec_metadata/ (Python, lxml). CLI: bin/1c-meta. Каталог покрытия:
onec_metadata/catalog.py — операции вне каталога делает человек в IDE.
Железные правила
- Только тест-база. Загрузка изменений — исключительно в тестовую ИБ
(напр.
localhost\<testbase>). В прод — человек, после приёмки. - Round-trip обязателен. После загрузки: повторная выгрузка → diff
с эталоном == строго целевые файлы (
apply.dumpload.roundtrip_verify). Без чистого round-trip правка не считается выполненной. - Минимальный дифф. Формат-слой (
formats/configurator.py) даёт byte-perfect round-trip (BOM/CRLF/табы); операции меняют только целевые узлы. Никогда не переформатируй XML вручную/другими инструментами. - BSL после правки кода — если задет
*.bsl, прогони BSL Language Server. - Смок-валидатор СКД (ENFORCED, офлайн) — после любой правки схемы компоновки:
1c-meta scd validate <Schema.xml>(exit 1 = поломка: пропал набор, поле без dataPath, дубль поля, битая связь наборов, невалидный XML). До загрузки в 1С. - Класс поля СКД перед добавлением в группировку. Поле выводится в выбранных полях группировки, только
если оно: поле группировки | реквизит поля группировки (
dataPathчерез точку —Номенклатура.Артикул) | ресурс (totalField). Иначе —Поле ... не может быть использовано в группировке .... Для обычного (неагрегатного) атрибута правильный класс — реквизит, не ресурс: в структуре «Таблица» ресурсы уходят в ячейки на пересечении строк и колонок, а не в колонку строки. Перед правкой посмотреть, как объявлены уже работающие неагрегатные поля этой же группировки, и повторить их класс. ПроверитьРасположениеРеквизитов(умолчание «Вместе с владельцем» → колонки склеиваются с владельцем; для отдельных колонок нужноОтдельно). Подробно —references/skd-fields-in-groupings.md. - Объект расширения в типовом интерфейсе — через
ПодключаемыеОтчетыИОбработки.СведенияОВнешнейОбработке()работает ТОЛЬКО для внешних файлов.erf/.epfв справочникеДополнительныеОтчетыИОбработки(БСП поднимает их изХранилищеОбработкичерезВнешниеОтчеты.Создать). Для отчёта/обработки ВНУТРИ расширения она не вызывается никогда. Штатный путь: заимствовать подсистемуПодключаемыеОтчетыИОбработки, включить в её состав свой объект, в модуле менеджера определитьПриОпределенииНастроек+ парную процедуру (ДобавитьКомандыПечати/ДобавитьКомандыОтчетов/НастроитьВариантыОтчета/ДобавитьКомандыЗаполнения/ДобавитьКомандыСозданияНаОсновании). Подробно, включая рецепт печатной формы с макетом Word —references/bsp-extension-attachable-objects.md. - Scope-guard «не тронул незатронутое» (ENFORCED, офлайн) — property-level
diff
onec_metadata/apply/scope_guard.assert_in_scope(before, after, scope)БЕЗ тест-базы блокирует дрейф свойств у объектов, которые правка менять не должна была (дополняет файловыйroundtrip_verifyдо уровня свойств).
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago Changed · +7 lines 9a9109e40793
- 10d ago First seen · 101 lines · 192 tokens per session scan A d427f31c9e00
1c-metadata is a skill published in the GitHub repository vgtitov/bsl-ai-toolkit (21 stars, last pushed 2d ago), licensed MIT. It adds 192 tokens to every session and 2,371 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
bsp
A guide for developing and reviewing business software in 1C with its Standard Subsystems Library, a collection of shared building blocks for common tasks.
docx-from-sample
A document-building tool that creates a new DOCX file using an existing DOCX as its formatting template. DOCX is the file format used by Microsoft Word.
1c-bsp-registration
A helper for 1C external reports and processors that adds the function needed to register them in the Standard Subsystems Library (БСП). БСП is a set of reusable features for 1C configurations.
claude-md-bootstrap
A project setup tool that creates or updates a CLAUDE.md file, which gives an AI coding agent project-specific instructions and background at the start of each session.
1c-cfe-patch-method
A tool for creating method interceptors in a 1C configuration extension. 1C is business software, and an interceptor can run code before, after, or instead of an inherited method.
1c-mxl-info
A structure reader for 1C spreadsheet-layout files. It summarizes named regions, parameters, and column sets instead of showing the full XML.