privacyPolicyURL should be present for marketplace readiness.
Val Town
Build and deploy serverless TypeScript on Val Town from Codex — hosted MCP server plus skills for HTTP vals, cron, SQLite, email, OAuth, and React UI.
val-town/vals · v0.4.0 · Tools & Integrations
Trust Score
62
Security
66
Surfaces
12
What is Val Town?
Val Town is a published tools & integrations plugin for AI coding agents in the mcp ecosystem, developed by Val Town and distributed through the HOL AI plugin registry. Build and deploy serverless TypeScript on Val Town from Codex — hosted MCP server plus skills for HTTP vals, cron, SQLite, email, OAuth, and React UI.
- Canonical slug
- val-town/vals
- Version
- v0.4.0 · updated Sep 25, 2026
- Open data
- entity.json (JSON-LD)
Trust & Reputation
Factor Analysis
Per-metric points (0–100 each) combined via a weighted average into the overall score.
Registry Snapshot
- Repository
- https://github.com/val-town/plugins
- Homepage
- https://val.town
- Canonical profile
- https://hol.org/registry/plugins/val-town%2Fvals
- Publisher verification
- No
- Marketplace source
- Unknown
- Scanner
- Broker fallback
- Safety label
- caution
- Digest verified
- Yes
Trust & reputation
Trust & Reputation
Factor Analysis
Per-metric points (0–100 each) combined via a weighted average into the overall score.
Provenance
- Plugin root
- plugin
- Source repo
- https://github.com/val-town/plugins
- Source commit
- 555ff7492c9c…
- Publisher verified
- No
- Owner verified
- Not owner verified
Continuous scanner CI not detected
This plugin remains listed. Its overall trust score is reduced by 10% because security checks are not maintained in the source repository's CI.
Optional: maintain the scanner in the source repository's CI to receive the full trust score. Listing does not require that change.
Verified badge not detected
Add the HOL verified badge to the repository README to score +2% trust. Plugin owners can open that pull request from Guard Plugins.
Security Posture
- Provider
- registry-broker-fallback
- Grade
- D · caution
- Version
- Unknown
Findings
termsOfServiceURL should be present for marketplace readiness.
MCP server valtown does not declare an auth posture.
Repository snapshot does not include a lockfile.
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Cisco skill scanner timed out after 60000 ms
Val Town — Frequently asked questions
- What is Val Town?
- Val Town is an AI plugin in the HOL registry. Build and deploy serverless TypeScript on Val Town from Codex — hosted MCP server plus skills for HTTP vals, cron, SQLite, email, OAuth, and React UI.
- How do I install Val Town?
- Install Val Town in your harness: Codex — codex plugin marketplace add val-town/plugins; Claude Code — /plugin marketplace add val-town/plugins; Cursor — npx skills add val-town/plugins. Full step-by-step guidance is on the HOL plugin page.
- How do I install Val Town in Codex?
- To install Val Town in Codex, start with codex plugin marketplace add val-town/plugins. The complete step-by-step install guide for Codex is on the HOL plugin page.
- How do I install Val Town in Claude Code?
- To install Val Town in Claude Code, start with /plugin marketplace add val-town/plugins. The complete step-by-step install guide for Claude Code is on the HOL plugin page.
- How do I install Val Town in Cursor?
- To install Val Town in Cursor, start with npx skills add val-town/plugins. The complete step-by-step install guide for Cursor is on the HOL plugin page.
- Is Val Town free?
- Pricing for Val Town is published on its HOL plugin page when the maker schedules a launch.
- Who publishes Val Town?
- Val Town is published by Val Town and listed on HOL.
- Is Val Town available now?
- Val Town availability is listed on its HOL plugin page.
Install Guidance
Install in Claude Code
Install through the Claude Code plugin marketplace.
- 1
Add the marketplace
Run this inside a Claude Code session.
claude code - 2
Install the plugin
Use the plugin name and the marketplace name shown by the previous command.
claude code - 3
Scripted alternative
Non-interactive equivalent for scripts and CI pipelines. Add --scope project to pin the install to one repository.
shell
Plugin Manifest
{
"name": "vals",
"displayName": "Val Town",
"version": "0.4.0",
"description": "Build and deploy on Val Town. Bundles the Val Town MCP server and platform skills (HTTP vals, cron/intervals, SQLite, email, OAuth, React UI, third-party integrations).",
"author": {
"name": "Val Town"
},
"homepage": "https://val.town",
"repository": "https://github.com/val-town/plugins",
"license": "MIT",
"keywords": [
"val-town",
"deno",
"serverless",
"typescript"
],
"skills": "./",
"mcpServers": "./.registry/mcp.json",
"interface": {
"displayName": "Val Town",
"developerName": "Val Town",
"shortDescription": "Build and deploy on Val Town",
"longDescription": "Bundles the hosted Val Town MCP server and platform skills (HTTP vals, cron/intervals, SQLite, email, OAuth, React UI, third-party integrations) for building and deploying TypeScript on Val Town.",
"category": "Coding",
"websiteURL": "https://val.town",
"composerIcon": "./assets/icon.svg"
},
"registryIndexVersion": 5
}Marketplace Source
- Repo URL
- https://github.com/val-town/plugins
- Marketplace path
- Unknown
- Source path
- plugins/val-town/plugins
- Install policy
- AVAILABLE
Skills
11 SKILL.md files ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.
blob-storage
skills/blob-storage/SKILL.md
Use when a val needs simple key/value persistence — JSON documents, cached responses, uploaded files, or binary assets. Covers the std/blob API, listing and deleting keys, account-global or val scoping, and storage limits.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
client-side-js
skills/client-side-js/SKILL.md
Use when a val needs to ship JavaScript that runs in the browser — React apps, vanilla DOM scripts, canvas/games, htmx/Alpine, or any client-side module beyond a single inline snippet. Explains how Val Town serves transpiled .ts/.tsx/.jsx modules with no build step, how the browser resolves their imports, and how to load third-party deps.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
create-skill
skills/create-skill/SKILL.md
Use when the user wants to persist a preference, skill, or knowledge. Use when it would aid future val development to store a memory of how best to build something.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
cron-and-intervals
skills/cron-and-intervals/SKILL.md
Use when building a val that runs on a schedule — periodic jobs, recurring tasks, polling, cron jobs, monitoring, alerting. Covers the interval handler signature, cron expressions, the UTC timezone constraint, and the `lastRunAt` pattern for detecting new items since the previous run.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
email
skills/email/SKILL.md
Use when a val sends email, receives email, or is triggered by an incoming email. Covers email-type vals (the Email handler shape, attachment limits, the assigned val email address) and sending mail via std/email.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
http-endpoints
skills/http-endpoints/SKILL.md
Use when building an HTTP val — a web endpoint, API route, webhook receiver, or any val that responds to HTTP requests. Covers the handler signature, Hono usage, the endpoint URL, CORS behavior, redirects, and Val Town-specific limitations.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
oauth
skills/oauth/SKILL.md
Use when a val needs to require login with a Val Town account — gating routes behind authentication, identifying the current user, building user-specific dashboards. Covers std/oauth's `oauthMiddleware` and `getOAuthUserData`, the auto-managed `/auth/*` routes, and session behavior. For third-party OAuth providers (Google, GitHub, etc.) see the `third-party-integrations` skill instead.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
react-ui
skills/react-ui/SKILL.md
Use when building any val with a user interface — dashboards, web apps, landing pages, forms, admin tools, anything users see in a browser. Covers JSX/React conventions, Twind/Tailwind styling, React version pinning, the view-source link requirement, and what to avoid (template-string HTML, external assets).
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
restricted-access
skills/restricted-access/SKILL.md
Use when a val's HTTP endpoints should not be open to the whole internet — limiting an app to a team, understanding why an endpoint redirects to a login page, letting a webhook through, or identifying which Val Town user is viewing an app. Covers app access (`httpPrivacy`), org grants, bypass tokens for automation, and the `X-Val-Town-User` identity header. For building your own login flow inside a val, see the `oauth` skill instead.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
sqlite-storage
skills/sqlite-storage/SKILL.md
Use when a val needs to store structured or relational data. Covers the std/sqlite API, parameterized queries, transactions, and the val-scoped vs organization-scoped database distinction.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
third-party-integrations
skills/third-party-integrations/SKILL.md
Use when a val talks to an external service — Slack, Discord, Telegram, Stripe, GitHub, Gmail, Google Sheets, Postgres/Supabase/Upstash/Neon, browser automation (Playwright, Browserbase, Kernel, Steel), web scraping, PDF generation, push notifications, RSS, or any other third-party API. Covers the required workflow (fetch the Val Town guide, get credentials, test, store secrets) and the catalog of available guides.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
File Inventory
.claude-plugin/plugin.json
file
499 bytes
82a5830745641727…
.codex-plugin/plugin.json
plugin-manifest
920 bytes
df0bb2acc447a825…
.cursor-plugin/plugin.json
file
492 bytes
baa4b4af0cf6ac69…
.mcp.json
file
114 bytes
b9faff1d7ee4e688…
.registry/mcp.json
mcp-config
78 bytes
9dc61e6ce38642c8…
assets/icon.svg
asset
795 bytes
c19c82a56aa25377…
skills/blob-storage/SKILL.md
skill
4,321 bytes
28d19fe232b86d7f…
skills/client-side-js/SKILL.md
skill
5,438 bytes
ad8a52fb99fe31b9…
skills/create-skill/SKILL.md
skill
2,475 bytes
faaa88bfddd22999…
skills/cron-and-intervals/SKILL.md
skill
2,399 bytes
77f8bb7e694784ce…
skills/email/SKILL.md
skill
2,624 bytes
198a78c43bf48757…
skills/http-endpoints/SKILL.md
skill
3,347 bytes
c98955e6bced467a…
skills/oauth/SKILL.md
skill
4,287 bytes
9fd4aa50769b3eb7…
skills/react-ui/SKILL.md
skill
3,638 bytes
6aa3e7fd43125b93…
skills/restricted-access/SKILL.md
skill
7,050 bytes
9f51352d63518bf8…
skills/sqlite-storage/SKILL.md
skill
2,882 bytes
6ab49326b577185b…
skills/third-party-integrations/SKILL.md
skill
3,574 bytes
1ce88c22c056f340…