Docs

wilow-tool.json reference

Every field of the marketplace manifest, precisely.

Every published tool has a wilow-tool.json at its project root. Create it with wilow-market init and edit freely. Types accepted: app · website · agent · skill · plugin. Platforms: android · ios · windows · macos · linux.

Fields

FieldTypeRequiredNotes
namestringyes1–80 chars, must contain a letter or digit. The display name.
slugstringyes^[a-z0-9][a-z0-9-]{1,60}$ — the stable identifier used everywhere. Reuse the folder slug.
typeenumyesOne of app | website | agent | skill | plugin.
versionsemveryesx.y.z. Must strictly increase on each update.
taglinestringno≤ 140 chars. One-line pitch.
descriptionstringno≤ 20,000 chars. Markdown-ish long description.
platformsstring[]noSubset of android | ios | windows | macos | linux.
licensestringnoSPDX identifier (e.g. MIT). Private/proprietary tools may declare a proprietary license.
tagsstring[]noUp to 10 discovery tags.
iconstringnoRelative path to an icon.
screenshotsstring[]noRelative paths.
homepagestringnoRequired for type: website. The live URL.
repostringnoRequired for wilow_powered public tools; not needed when private is true.
wilow_poweredbooleannoThe tool runs locally on the installer's AI setup. See the Runtime contract.
privatebooleannoPublish private-source (code escrowed with Wilow, never public). Mutually exclusive with enterprise publishing.
agentsstring[]cond.Required (≥1) for type: agent. Relative paths to agent markdown files.
skillsstring[]cond.Required (≥1) for type: skill. Relative paths to skill folders.
commandsstring[]noRelative paths to slash-command files.
mcpsobjectnoMCP server definitions merged into the installer's config (keys validated; content re-scanned server-side).
cli_depsstring[]noEach entry npm:<pkg> or uv:<pkg>.
setupstring[]noLifecycle commands, allow-listed: npm install · npm ci · npm run <name> · uv sync.
store_linksobjectno{ ios?, android? } app-store URLs for non-Wilow-powered apps.
artifactsobject[]noExtra binary artifacts, each { path, platform? }.
permissionsobjectno{ network?: string[], connectors?: string[], runs_local_code?: boolean } — disclosed on the consent screen.
price_centsnumbernoMust be 0. Paid tools are not enabled.

These docs are generated-checked

The field list, types, and platforms above are cross-checked against the CLI's own manifest definition by npm run docs:check in every release. If a field is added or an enum changes in the code, the check fails until this page is updated — so the reference cannot silently fall behind the shipping tool.

Example

{
  "name": "Repo Summarizer",
  "slug": "repo-summarizer",
  "type": "agent",
  "version": "1.0.0",
  "tagline": "Summarizes a repository's structure and recent changes.",
  "license": "MIT",
  "repo": "https://github.com/acme/repo-summarizer",
  "agents": ["agents/summarizer.md"],
  "tags": ["docs", "productivity"],
  "permissions": { "network": ["api.github.com"] }
}

Path & safety rules

  • All path fields must be safe relative paths — no .., absolute paths, drive letters, or backslashes.
  • mcps, cli_deps, and setup are re-scanned server-side for secrets and injection; they run or merge on the installer's machine, so they are held to the allow-listed grammar above.