Docs
wilow-tool.json reference
Every field of the marketplace manifest, precisely.
Every published tool has a wilow-tool.json at its project root. Create it with wilow-market init and edit freely. Types accepted: app · website · agent · skill · plugin. Platforms: android · ios · windows · macos · linux.
Fields
| Field | Type | Required | Notes |
|---|---|---|---|
name | string | yes | 1–80 chars, must contain a letter or digit. The display name. |
slug | string | yes | ^[a-z0-9][a-z0-9-]{1,60}$ — the stable identifier used everywhere. Reuse the folder slug. |
type | enum | yes | One of app | website | agent | skill | plugin. |
version | semver | yes | x.y.z. Must strictly increase on each update. |
tagline | string | no | ≤ 140 chars. One-line pitch. |
description | string | no | ≤ 20,000 chars. Markdown-ish long description. |
platforms | string[] | no | Subset of android | ios | windows | macos | linux. |
license | string | no | SPDX identifier (e.g. MIT). Private/proprietary tools may declare a proprietary license. |
tags | string[] | no | Up to 10 discovery tags. |
icon | string | no | Relative path to an icon. |
screenshots | string[] | no | Relative paths. |
homepage | string | no | Required for type: website. The live URL. |
repo | string | no | Required for wilow_powered public tools; not needed when private is true. |
wilow_powered | boolean | no | The tool runs locally on the installer's AI setup. See the Runtime contract. |
private | boolean | no | Publish private-source (code escrowed with Wilow, never public). Mutually exclusive with enterprise publishing. |
agents | string[] | cond. | Required (≥1) for type: agent. Relative paths to agent markdown files. |
skills | string[] | cond. | Required (≥1) for type: skill. Relative paths to skill folders. |
commands | string[] | no | Relative paths to slash-command files. |
mcps | object | no | MCP server definitions merged into the installer's config (keys validated; content re-scanned server-side). |
cli_deps | string[] | no | Each entry npm:<pkg> or uv:<pkg>. |
setup | string[] | no | Lifecycle commands, allow-listed: npm install · npm ci · npm run <name> · uv sync. |
store_links | object | no | { ios?, android? } app-store URLs for non-Wilow-powered apps. |
artifacts | object[] | no | Extra binary artifacts, each { path, platform? }. |
permissions | object | no | { network?: string[], connectors?: string[], runs_local_code?: boolean } — disclosed on the consent screen. |
price_cents | number | no | Must be 0. Paid tools are not enabled. |
These docs are generated-checked
The field list, types, and platforms above are cross-checked against the CLI's own manifest definition by
npm run docs:check in every release. If a field is added or an enum changes in the code, the check fails until this page is updated — so the reference cannot silently fall behind the shipping tool.Example
{
"name": "Repo Summarizer",
"slug": "repo-summarizer",
"type": "agent",
"version": "1.0.0",
"tagline": "Summarizes a repository's structure and recent changes.",
"license": "MIT",
"repo": "https://github.com/acme/repo-summarizer",
"agents": ["agents/summarizer.md"],
"tags": ["docs", "productivity"],
"permissions": { "network": ["api.github.com"] }
}Path & safety rules
- All path fields must be safe relative paths — no
.., absolute paths, drive letters, or backslashes. mcps,cli_deps, andsetupare re-scanned server-side for secrets and injection; they run or merge on the installer's machine, so they are held to the allow-listed grammar above.