Skills Directory

Reusable, audited skills for BoxLang & the Ortus ecosystem.

Showing 258 skills

Use this skill when adding CSRF protection to ColdBox/BoxLang applications with the cbcsrf module. Covers token generation, form helpers, AJAX/meta-tag patterns, manual handler validation, route exemptions, SPA integration, token rotation, and configuration best practices for preventing cross-site request forgery.

Use this skill when securing ColdBox/BoxLang applications with cbsecurity. Covers firewall rule configuration, annotation-based security on handlers/actions, JWT authentication, role and permission checks, route middleware (Authenticated, Authorized, JwtAuth, BasicAuth, Throttle, ApiKey, AllowedIPs, DenyIPs, EnsureHttps, VerifyCsrf, Honeypot, Signed), signed URLs, security context helpers, custom validators, interceptor events, and production hardening patterns.

Use this skill when selecting or configuring TestBox reporters: Agent, ANTJunit, Console, Doc, Dot, JSON, JUnit, Min, MinText, Simple, Text, XML, Streaming; the TestBox 7.2 HTML reporters (Simple, Min, Dot, Doc) with light/dark themes, keyboard shortcuts, status filters and Ask AI (aiAssist, aiProviders, aiContextLines, aiStackFrames, aiPrompt, urlParams); editor links; setting reporter options (hideSkipped); how reporters show spec attachments (attach(), browser screenshots/traces/videos) and retry attempts; or creating a custom reporter by implementing the IReporter interface.

Use this skill when implementing CSRF (Cross-Site Request Forgery) protection in ColdBox forms, using cbcsrf to generate and validate tokens, adding csrf() tokens to HTML forms, validating tokens in POST/PUT/DELETE handlers, configuring the cbcsrf module, or excluding API routes from CSRF verification.

Use this skill when monitoring or debugging bx-orm activity in BoxLang: listening to ORM queries, flushes and exceptions with the onORMQuery, onORMFlush and onORMException interception points, capturing slow SQL, bound parameters, and reading Hibernate statistics with ORMService.getStatistics.

Use this skill when configuring bx-orm in BoxLang: Application.bx ormSettings, enabling the ORM, datasource setup, dbcreate options, dialect selection, entity paths, event handling, session management settings, and secondary cache configuration.

Use this skill when writing integration tests for ColdBox that use real dependencies (database, WireBox, ColdBox context), testing full request/response cycles with execute(), setting up and tearing down test databases, testing services with real data, or using BaseTestCase for end-to-end handler tests with actual WireBox injections.

Use this skill when configuring ColdBox routes, setting up RESTful resource routes, creating route groups, implementing URL pattern matching with constraints, defining named routes, answering a route inline with a toResponse() closure, attaching route-scoped middleware with .middleware()/middlewareGroup()/registerMiddleware()/.withoutMiddleware(), sharing route metadata through a group() meta option, declaring route-level cache rules with Router.withCache(), streaming a route with Router.toSSE(), exposing BoxLang AI surfaces with the toAi(), toMCP() and toAiGateway() route terminators, or working with Router.cfc in a ColdBox application.

Use this skill when writing browser tests with bx-playwright in BoxLang: TestBox's BrowserSpec (testbox.system.BrowserSpec, browse(), this.playwright(), browserProfile and baseURL annotations), the TestBox browser matchers (toSee, toHaveTitle, toHavePath, toHaveURL, toHaveText, toBeVisible, toBeHidden, toHaveCount, toHaveValue), automatic screenshot/trace/video attachments, spec retries and the --failed and --web-server runner options, ColdBox's BrowserTestCase (routeURL, visitRoute, assertRouteIs), logged-in tests with saved sessions, plain TestBox specs with playwright().browse(), artifact policies, debugging with traces, page objects (models.PageObject@playwright), page components, macros, console error and smoke checks, axe-core accessibility audits, and visual regression with assertScreenshotMatches().

Use this skill when writing, running, or debugging tests for BoxLang applications using TestBox: BDD-style describe/it specs, xUnit-style test classes, expectations (expect/toBe matchers), assertions ($assert), life-cycle methods (beforeAll/afterAll/beforeEach/afterEach/aroundEach), MockBox mocking (createMock/prepareMock/$()/$results()), mock data generation (mockData()), async testing, exception testing, focused/skipped specs, attaching files to specs (attach()), spec retries (it retries argument, retries annotation, --retries), rerunning only failures (--failed, the Run Failed button of the HTML reports, TestResult.getFailedTargets()), choosing reporters (HTML reporters with Run Failed and Ask AI, the Agent reporter for AI agents), and running tests via the BoxLang CLI runner. For browser tests (BrowserSpec, BrowserTestCase) also load bx-playwright-testing.

Use this skill when building RAG (Retrieval-Augmented Generation) systems with BoxLang AI: aiDocuments() loaders, chunking and toMemory() ingestion, aiEmbed() embeddings and providers, vector memory stores, retrieval with getRelevant(), and exposing retrieval to agents as a tool.

Use this skill when implementing memory in BoxLang AI: aiMemory() types (window, summary, session, file, cache, jdbc, hybrid, vector stores), multi-tenant isolation with userId and conversationId, the memory API, using memory with agents, and choosing the right memory type.

Use this skill when writing BoxLang markup templates (.bxm files), mixing HTML with BoxLang output expressions, using template components like bx:output, bx:loop, bx:if, bx:include, bx:script, building views, or creating any HTML-generating template files.

Use this skill when writing business rules with RuleBox, the natural-language rules engine for BoxLang and ColdBox. Covers RuleBook classes and defineRules(), the given/when/except/then/using/ withPriority/stop/active/withDescription DSL, facts and the Result object, declaring and enforcing the facts a RuleBook takes (defineFacts, fact(), withFacts, enforceFacts, strictFacts, validateFacts), describing rulebooks and rules, the Builder, declared rulebooks (ruleBook( "name" ), inject="rulebook:name"), loading rules from JSON, YAML or a database with the condition grammar and registered actions/predicates, the audit trail, dryRun(), rule metrics, error handling, thread safety, the Rule Visualizer, and testing rulebooks with TestBox.

Use this skill when working with audio in bx-ai: text-to-speech with aiSpeak(), streaming speech with aiSpeakStream() (voice agents, telephony, browser playback), speech-to-text with aiTranscribe(), audio translation with aiTranslate(), choosing audio providers (Cartesia, ElevenLabs, OpenAI, Mistral, Gemini, Grok, Groq), voice gender keywords, and audio events and settings.

Use this skill when creating AI tools (function calling) with aiTool(): parameter descriptions, tool registries, using tools with aiChat() and agents, the aiToolRegistry() BIF (register, scanClass with @AITool annotations, built-in tool sets), aiGlobalSkills(), and best practices for tool design.

Use this skill when configuring AI models with aiModel(): selecting providers, the full provider list with capabilities and API key resolution, setting default parameters, using aiService(), and pre-configuring providers in module settings (provider, apiKey, defaultParams, providers).

Use this skill when building AI agents with aiAgent(): instructions, custom models, tools, skills (always-on and lazy), MCP servers, memory, fluent configuration, sub-agents and multi-agent hierarchies, streaming, middleware (logging, retry, guardrails, flight recorder), human in the loop approvals with suspend/resume, run control (cancelRun/steerRun), and gateways (aiGateway, aiGatewaySession).

Use this skill when building AI pipelines with BoxLang AI: aiMessage() templates, aiModel() steps, aiTransform() steps and extractors, aiParallel(), chaining with .to() and .transform(), the _input system variable, multi-model pipelines, streaming pipelines, and structured output in pipelines.

Use this skill when writing BoxLang AI chat code: aiChat(), aiChatAsync(), aiChatStream(), aiMessage(), params (temperature, max_tokens, model), options (provider, apiKey, returnFormat, timeout), provider selection, return formats, multi-turn conversations, normalized reasoning, and error handling.

Set up and write a blog, versioned docs, translated (i18n) locales, and numbered courses in bx-sites (ortus-boxlang/bx-sites) - docs/blog/posts frontmatter and authors.yml, post:new, categories/archives/RSS, docs/versions/ and version:new, bxsites.yaml's versions.default (publish a version at the site root, docs/ at /next/), docs/i18n/ and i18n:new, composing versions with locales, theme-chrome translation strings, redirects (frontmatter redirect_from and bxsites.yaml's redirects), and docs/data/courses.yaml with per-lesson progress tracking. Use this whenever a user wants to add a blog post, cut a new docs version, add a translated locale, keep an old URL working after a page moves, or turn a set of pages into a guided lesson-by-lesson course. For the ::: course ::: index block itself, see bx-sites-content-blocks.

Choose, customize, override, install, or write a theme for a bx-sites (ortus-boxlang/bx-sites) site - the 10 built-in themes, air-gapped/offline considerations, the ThemeProvider contract (layout.bxm/page.bxm, plus optional search.bxm/blog.bxm/blog-page.bxm and any frontmatter-named layout), the layout: frontmatter key (outer shell + body), bootstrap's marketing homepage (home.bxm), color-only customization via extraCss, ejecting/overriding a theme, writing one from scratch, installing a published theme from ForgeBox, importing an mkdocs/jekyll/hugo theme, and the homepage hero banner. Use this whenever a user wants to change a bx-sites site's look, brand colors, or write/override its templates.

Use this skill when working with the network in bx-playwright: mocking and blocking requests with page.intercept() (respondJson, respond, abort, resume, handle), listening to console, requests, responses, page errors and dialogs, HTTP API testing with playwright().request(), cookies and permissions, and saving/reusing logged-in sessions with playwright().session().

Use this skill when installing or configuring bx-playwright (BoxLang browser automation with Playwright): the bx-playwright vs bx-playwright-full distributions, the bxPlaywright CLI (install, doctor, devices, profiles, codegen, show-trace, mcp), module settings in boxlang.json, built-in and custom profiles, BX_PLAYWRIGHT_* environment variables, and CI setup.