wick-custom-connectors

wick-custom-connectors is a skill for Claude Code, Codex from yogasw/wick. It costs 124 tokens per session (1,831 once invoked), scanned A, original, MIT.

A way to define a connection to an external API without writing Go code, rebuilding Wick, or redeploying it. The definition is stored in the database and registered like a built-in connector.

In plain words
What is it for?
Use it to design, validate, create, list, update, disable, delete, or resync custom connectors and their available operations.
Why use it?
It allows Wick to work with an API that has no existing connector while retaining shared credentials, auditing, and access-control handling.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Good fit Use it to design, validate, create, list, update, disable, delete, or resync custom connectors and their available operations.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/yogasw/wick/wick-custom-connectors
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add yogasw/wick --skill wick-custom-connectors
Clone the repo
git clone --depth 1 https://github.com/yogasw/wick

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for wick-custom-connectors

README.md
[![agentmods](https://agentmods.dev/badge/skills/yogasw/wick/wick-custom-connectors/github.svg)](https://agentmods.dev/skills/yogasw/wick/wick-custom-connectors)
Your own site
<a href="https://agentmods.dev/skills/yogasw/wick/wick-custom-connectors"><img src="https://agentmods.dev/badge/skills/yogasw/wick/wick-custom-connectors/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for wick-custom-connectors

Your own site · 80×15
<a href="https://agentmods.dev/skills/yogasw/wick/wick-custom-connectors"><img src="https://agentmods.dev/badge/skills/yogasw/wick/wick-custom-connectors.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 124 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,831 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00124 $0.01831
Opus 5 $0.00062 $0.00915
Sonnet 5 $0.00025 $0.00366
Haiku 4.5 $0.00012 $0.00183

Measured 9d ago against content hash 2dae2c95ccfd, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

wick-custom-connectors scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

internal/agents/skillsync/builtin/wick-custom-connectors/SKILL.md · 151 lines

How it starts

The opening of the file, as written. The whole thing — 151 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Building a custom connector

A custom connector wraps one external API without Go code, a rebuild, or a redeploy. It is a definition stored in the database that wick replays into the same registry as built-in connectors, so afterwards the two are indistinguishable: same tool_id shape, same encrypted fields, same audit trail, same tag-based access control.

Use wick-connectors for CALLING connectors. This skill is about creating one.

You can build it from chat

The custom-connector connector exposes the whole lifecycle as operations, so no one has to open the dashboard. Reach it the usual way — wick_list / wick_search to find its instance, then wick_get for an operation's schema.

Operation Does
def_schema the full draft contract — read this first
def_validate dry-run a draft; persists nothing
def_create create from a manual draft
def_list / def_get what exists, and one definition's current shape
def_update replace a definition wholesale (key is immutable)
def_resync re-fetch an MCP server's tool list
def_set_disabled / def_delete serve zero ops, or remove entirely
mcp_register register an external MCP server as a connector
mcp_set_excluded change which of its tools are exposed
instance_list / instance_create the rows that hold credentials
instance_delete / instance_set_disabled remove or park a row

There is deliberately no cURL-parse operation. Converting a cURL command, a fetch() snippet, or API docs into the draft shape is your job — that is what an LLM is for, and it keeps the surface small.

The workflow is not optional

def_create and mcp_register both state it in their own descriptions, and they mean it:

  1. def_schema — read the contract. Widgets, template syntax, limits, validation rules, categories, a worked example. Do not draft from memory; this skill deliberately does not copy that reference, because a stale copy is worse than a lookup.
  2. Build the draft from whatever the user gave you.
  3. def_validate — same validation def_create runs, plus a key-availability check. Free, persists nothing.
  4. Present the plan and wait. Name, key, icon, description; every config field with its widget and its secret/required flags; every operation with its description, inputs, and request recipe; and the decisions you made for them — single vs multi-instance, which ops you marked destructive, which fields you made secret, the category.
  5. def_create only after they say yes.
  6. instance_create — a definition serves nothing without a row. Config values go in afterwards, via the dashboard or the wickmanager connector's connector_set_config.

Read the full file on GitHub · 151 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 151 lines · 124 tokens per session scan A 2dae2c95ccfd

Subscribe to this mod's changes

wick-custom-connectors is a skill published in the GitHub repository yogasw/wick (5 stars, last pushed yesterday), licensed MIT. It adds 124 tokens to every session and 1,831 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

opencli-sitemap-author

Use when creating or maintaining OpenCLI site sitemaps: agent-facing navigation, page-state, action, workflow, API-reference, pitfall, and fallback knowledge for a website. Use after browser exploration discovers durable site context, when a sitemap is stale, or when promoting local site knowledge into the repo.

jackwener/OpenCLI · 67 tokens

omh-code-review

This is a Hermes-native code-review workflow skill.

rlaope/oh-my-hermes · 46 tokens

android-pentest

A guide for authorized security testing of Android apps, covering APK inspection, runtime testing, traffic capture, code review, and function hooking. An APK is the installable package used by an Android app.

Netw0rkNoob/VulnClaw · 32 tokens

redteam-web-detail-pack

Routing and boundary guidance for authorized general web application security testing. Use as a web testing router when the attack surface should be dispatched to more specific web vulnerability skills.

Netw0rkNoob/VulnClaw · 38 tokens

workflow-builder

Load before calling build-workflow. Default path for all single-workflow work: new one-off workflows, existing-workflow edits, verification repairs, and workflow-local data tables. Write or edit a workspace source file, run workflow-sdk validate via workspaceexecutecommand, then call build-workflow with filePath. When…

n8n-io/n8n · 113 tokens

jikegongyuan-perspective

A writing guide based on GeekPark, a Chinese technology publication and entrepreneur community focused on AI, products, startups, and innovation.

momozi1996/awesome-ai-persona-skills · 154 tokens