Recued
Menu
Community catalog

Marketplace

Inspect what a workflow does, what it installs, and what it can access before bringing it into Recued.

Tags
Sort

927 packs

Jest Pack

V3 JavaScript/TypeScript test-run capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local jest CLI ingredient exposes bounded project operations for readiness and exact-path test execution. Test runs execute from an explicit project directory cwd supplied at execution time, accept one trusted exact test file path, return plain test output, avoid caller-supplied Jest flags, avoid shell wrappers, and keep test failures visible as text output. Fixed invocation, but approval-gated: Jest loads project config, environments, transforms, setup files, runners, serializers, and test code, so the run may execute arbitrary project Node code. The pack uses CI behavior, exact-path test selection, serial execution, cache disabled, colors disabled, no watch mode, no snapshot update, no caller-supplied config/root/project/reporter/output-file/coverage/watch/debug/changed/randomize/seed/test-name/environment/runner/transform/cache-clear/notification surface, no stdin, no environment override, and no arbitrary command execution. Requires jest on PATH.

pack:jestjestjavascripttypescript
by Recued Core v1 1 item Pack
Work Tracking - Jira

API capability pack for bounded Jira Cloud issue-tracking operations through Atlassian OAuth at https://api.atlassian.com only. Lists accessible Atlassian resources to discover cloud IDs, reads the current Jira user, searches assignable users, searches projects and issues, reads fixed personal issue queues, reads Jira Software boards and sprints, reads one issue, reads/adds comments, lists/performs workflow transitions, assigns and edits one issue, and reads/adds worklogs. Bundles a scheduled personal issue digest, an AI-assisted issue review brief, and an approval-gated issue intake workflow. This is intended for daily personal, team, and one-person-company work-tracking workflows: triage assigned or reported issues, review recently updated work, inspect board/sprint context, leave follow-up notes, move work through status, assign ownership, update basic issue fields, and log work. Enroll an Atlassian OAuth access token connection as bearer auth; no credential is embedded in the manifest. Writes are approval-gated. The pack intentionally excludes deletes, bulk mutation, project/admin configuration, board/sprint creation or mutation, permissions changes, attachments, watchers/votes, issue links, remote links, notifications, comment/worklog edits, arbitrary JQL mutation, and arbitrary Jira endpoint passthrough.

pack:jirajiraatlassianissues
by Recued Core v1 4 items Pack
Jira Issue Closure Loop

Workflow pack for Recued-created Jira issues. It composes the Jira capability pack with a closure ledger: create one owner-approved Jira issue in one configured cloud/project, persist only the connection/cloud/project/issue linkage in data.shared, and let a scheduled watcher re-read that exact issue until Jira reports the issue has reached the Done status category. This pack does not replace Jira workflow transitions, assignments, boards, sprints, automations, native notifications, webhooks, comments, worklogs, labels, due dates, or general issue reporting; it adds Recued-visible closure state for Jira issues Recued created.

pack:jira-issue-closurejiraatlassianissues
by Recued Core v1 2 items Pack
Jira Issue Comment Closure Loop

Workflow pack for Recued-created Jira issue comments. It composes the Jira capability pack with a closure ledger: add one owner-approved Atlassian Document Format comment to an existing Jira issue, persist only the connection/cloud/issue/comment linkage in data.shared, and let a scheduled watcher re-read that exact issue until Jira reports the issue has reached the Done status category. This pack does not replace Jira issue comments, native notifications, workflow transitions, assignments, boards, sprints, automations, webhooks, or general issue reporting; it adds Recued-visible closure state for issue comments Recued created.

pack:jira-issue-comment-closurejiraatlassianissues
by Recued Core v1 2 items Pack
Forms and Intake - Jotform

API capability pack for bounded Jotform API operations against https://api.jotform.com. Enroll a Jotform API key connection named jotform with form, submission, report, and webhook read access plus write access only when approval-gated form, question, submission, or report workflows are installed. The pack reads account profile and usage, forms, questions, submissions, reports, uploaded-file metadata, and webhook registrations for intake operations, lead routing, support triage, application review, compliance intake, and campaign response workflows. It bundles a scheduled intake submission digest, AI-assisted submission and form readiness briefs, and approval-gated workflows for creating one form, adding one form question, submitting one response, and creating one report. Writes use Jotform's documented form-encoded body shapes and are limited to one target resource at a time. The pack intentionally excludes deletes, submission updates, form clone, folder and label mutation, user settings mutation, webhook creation or deletion, uploaded file download, user registration/login/logout, OAuth token endpoints, and arbitrary Jotform API passthrough.

pack:jotformjotformformsintake
by Recued Core v1 8 items Pack
JPEGOptim Pack

V3 deterministic JPEG optimization capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local jpegoptim CLI writes an optimized copy of one JPEG into an engine-owned output directory via image.optimize_jpeg. This pack deliberately avoids in-place mutation by using jpegoptim's --dest option. Write-tier but approval=never: jpegoptim writes only under {out_dir} and the optimized JPEG is captured as result.file_ref. Requires jpegoptim on PATH (Debian/Ubuntu: apt install jpegoptim; macOS: brew install jpegoptim). Local and no-egress.

pack:jpegoptimjpegoptimcliimage
by Recued Core v1 1 item Pack
jq Pack

V3 deterministic JSON validation and fixed-query capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local jq CLI exposes readiness, JSON validation, pretty formatting, top-level key extraction, sorted key listing, document length, and object key-existence checks. This pack deliberately does not expose arbitrary jq filters, module loading, raw input, slurp mode, file/program filters, library paths, or environment overrides. json.validate materializes a file_ref and captures no stdout/stderr; value-returning operations are path-based because requested JSON content or metadata is returned on stdout. Requires jq on PATH (Debian/Ubuntu: apt install jq; macOS: brew install jq). Local and no-egress.

pack:jqjqclijson
by Recued Core v1 1 item Pack
Full Checkout, Orders, Settlements, and Disputes - Klarna

V2 one-install Klarna front door over five bounded read feature packs and seven official embedded API documents. The visible compatibility root grows from 4 to 28 operations while preserving every established operation ID, route, argument, risk, approval, and cache contract. The audit removes one unaddressable legacy payment-session entity, corrects the order payment-method object, versions three repaired recipes at v2, and adds recursively closed requests plus lossless unsafe-integer responses. The installed family publishes 41 catalog operations covering 41 of 55 official routes; 14 binary, different-audience, multipart, or PCI/key-management routes fail closed. Root additions are action-only so the established read grant does not silently widen; 13 operations remain in version-pinned dependency packs. New money movement, loss acceptance, authorization release, and provider onboarding are destructive; every new mutation requires approval, documented Klarna-Idempotency-Key values are mandatory and caller-owned, and routes without a replay key are explicitly non-idempotent. JSON inputs are bounded, size/offset and dispute cursors walk only the same admitted route, Basic authorization stays connection-owned, and the family pins the official Europe live origin rather than exposing a caller-controlled host. The public docs expose complete schemas in server-rendered page data rather than stable raw URLs, so manifests omit misleading openapi_source fields while the generated fixture hash-locks all seven documents. No financial or control-plane object is claimed as a task, note, or project Source.

pack:klarnaklarnapaymentscheckout
by Recued Core v2 11 items Pack
Customer Tokens - Klarna

Klarna customer-token status and tokenized recurring orders. This generated leaf carries 1 of the installed family’s 41 catalog operations from Klarna’s public embedded OPENAPI 3.0.0 document. 14 exact binary, different-audience, or PCI/key-management routes fail closed across the family. The public documentation exposes the complete schema in server-rendered page data rather than at a stable raw URL, so the manifest omits a misleading openapi_source while the audit fixture hash-locks the document. Basic authorization remains connection-owned, reads are uncached and not approval-gated, writes are grant-off and approval-always, documented idempotency keys are caller-owned, JSON inputs are bounded, and unsafe response integers stay exact. No financial or control-plane record is claimed as a task, note, or project Source.

pack:klarna-customer-tokensklarnacustomer-tokensrecurring
by Recued Core v1 1 item Pack
Payment Disputes V4 - Klarna

Klarna Disputes V4 onboarding, queue reads, dispute details, representment, loss acceptance, and appeals. This generated leaf carries 2 of the installed family’s 41 catalog operations from Klarna’s public embedded OPENAPI 3.0.3 document. 14 exact binary, different-audience, or PCI/key-management routes fail closed across the family. The public documentation exposes the complete schema in server-rendered page data rather than at a stable raw URL, so the manifest omits a misleading openapi_source while the audit fixture hash-locks the document. Basic authorization remains connection-owned, reads are uncached and not approval-gated, writes are grant-off and approval-always, documented idempotency keys are caller-owned, JSON inputs are bounded, and unsafe response integers stay exact. No financial or control-plane record is claimed as a task, note, or project Source.

pack:klarna-disputes-v4klarnadisputeschargebacks
by Recued Core v1 1 item Pack
Hosted Payment Page - Klarna

Klarna Hosted Payment Page session creation, status, distribution, and disablement. This generated leaf carries 1 of the installed family’s 41 catalog operations from Klarna’s public embedded SWAGGER 2.0 document. 14 exact binary, different-audience, or PCI/key-management routes fail closed across the family. The public documentation exposes the complete schema in server-rendered page data rather than at a stable raw URL, so the manifest omits a misleading openapi_source while the audit fixture hash-locks the document. Basic authorization remains connection-owned, reads are uncached and not approval-gated, writes are grant-off and approval-always, documented idempotency keys are caller-owned, JSON inputs are bounded, and unsafe response integers stay exact. No financial or control-plane record is claimed as a task, note, or project Source.

pack:klarna-hosted-payment-pageklarnahosted-payment-pagecheckout
by Recued Core v1 1 item Pack
Order Management - Klarna

Klarna order, capture, refund, authorization, shipping, and customer-communication lifecycle. This generated leaf carries 5 of the installed family’s 41 catalog operations from Klarna’s public embedded OPENAPI 3.0.1 document. 14 exact binary, different-audience, or PCI/key-management routes fail closed across the family. The public documentation exposes the complete schema in server-rendered page data rather than at a stable raw URL, so the manifest omits a misleading openapi_source while the audit fixture hash-locks the document. Basic authorization remains connection-owned, reads are uncached and not approval-gated, writes are grant-off and approval-always, documented idempotency keys are caller-owned, JSON inputs are bounded, and unsafe response integers stay exact. No financial or control-plane record is claimed as a task, note, or project Source.

pack:klarna-order-managementklarnaorderscaptures
by Recued Core v1 1 item Pack
Settlements and Reconciliation - Klarna

Klarna payout summaries, payout details, paged payouts, and paged transactions. This generated leaf carries 4 of the installed family’s 41 catalog operations from Klarna’s public embedded SWAGGER 2.0 document. 14 exact binary, different-audience, or PCI/key-management routes fail closed across the family. The public documentation exposes the complete schema in server-rendered page data rather than at a stable raw URL, so the manifest omits a misleading openapi_source while the audit fixture hash-locks the document. Basic authorization remains connection-owned, reads are uncached and not approval-gated, writes are grant-off and approval-always, documented idempotency keys are caller-owned, JSON inputs are bounded, and unsafe response integers stay exact. No financial or control-plane record is claimed as a task, note, or project Source.

pack:klarna-settlementsklarnasettlementspayouts
by Recued Core v1 1 item Pack
Marketing Automation - Klaviyo

API capability pack for bounded Klaviyo API operations against https://a.klaviyo.com only, pinned to revision 2026-04-15. Reads accounts, profiles, lists, segments, tags and tag groups, campaigns and messages, flows and flow messages, templates, metrics, events, reporting queries, and catalog items/variants/categories for daily ecommerce marketing work. Approval-gated writes are limited to one-profile create/import/update/merge, list create/update and explicit profile membership changes, tag create/update and explicit tag assignments, one event create, campaign send/cancel and recipient-estimate jobs, and flow status updates. Enroll a Klaviyo private API key connection that injects Authorization: Klaviyo-API-Key ... or an equivalent OAuth bearer/header connection; no credential is embedded in the manifest. The pack intentionally excludes profile deletion, suppression/subscription bulk jobs, campaign/template/flow creation or deletion, template editing, catalog mutation, webhooks, client public-key APIs, reviews client APIs, data-privacy deletion, push-token mutation, custom objects, bulk imports/exports, and arbitrary API passthrough.

pack:klaviyoklaviyoemailmarketing
by Recued Core v1 1 item Pack
Kubeconform Pack

V3 Kubernetes manifest validation capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local kubeconform CLI ingredient exposes bounded Kubernetes manifest operations for readiness and schema validation. Project operations run from an explicit project directory cwd supplied at execution time, accept only a trusted relative manifest file or directory plus one Kubernetes version, avoid caller-supplied kubeconform flags, avoid shell wrappers, and keep diagnostics visible as JSON output. Validation uses strict mode, summary, JSON output, and the default schema location only; it exposes no stdin, ignore pattern, skip/reject list, schema-location override, schema cache path, insecure TLS, debug profile, environment override, or arbitrary command execution. Approval is ask because kubeconform may download schemas over HTTP(S) for the requested Kubernetes version. Requires kubeconform on PATH.

pack:kubeconformkubeconformkubernetesmanifests
by Recued Core v1 1 item Pack
kubectl Pack

V3 kubectl CLI capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local kubectl CLI ingredient exposes bounded Kubernetes developer operations for client readiness, local kubeconfig inspection, and local Kustomize rendering. Client/config operations do not contact a Kubernetes API server; the redacted config view deliberately uses --raw=false and approval=ask because even non-raw kubeconfig metadata can reveal local cluster and user names. Project operations run from an explicit project directory cwd supplied at execution time, accept only a trusted relative kustomization directory, avoid caller-supplied kubectl flags, avoid shell wrappers, and never expose apply, diff, delete, get, exec, logs, port-forward, rollout, live cluster reads/writes, raw kubeconfig secrets, caller-supplied kubeconfig/context/namespace, output-file writes, alpha plugins, Helm inflator enablement, function network mode, function mounts, environment override, or arbitrary command execution. Kustomize render output and diagnostics are returned as inspectable text. Requires kubectl on PATH.

pack:kubectlkubectlkustomizekubernetes
by Recued Core v1 1 item Pack
Full LaunchDarkly API

Complete callable LaunchDarkly REST API suite pinned to the official OpenAPI document: 388 of 390 method/path operations. The two explicit exclusions are multipart CSV uploads for segment imports and team members, which await file_ref request-body support. The compatibility root keeps all 11 prior operation IDs and method/path routes while five dependency packs carry 377 additional operations. Stable routes send LD-API-Version 20240415; beta surfaces send beta. JSON int64 responses are parsed as exact decimal strings, and request bodies with unsafe nested int64 values use body_raw. The commercial base is an enrollment default; per-organization connections may use the documented EU or Federal origin. Reads are approval-free; mutations are grant-off and approval-gated, with destructive, administrative, flag-targeting, release, approval, experiment, and AgentControl changes requiring approval every run.

pack:launchdarklylaunchdarklyfeature-flagsrelease-management
by Recued Core v2 5 items Pack
AgentControl and AI Operations - LaunchDarkly

LaunchDarkly AgentControl, AI configuration, tools, graphs, prompts, skills, optimizations, and related version operations. Generated from the hash-anchored complete LaunchDarkly OpenAPI document. The commercial base is an enrollment default; per-organization connections may use the documented EU or Federal origin. Stable routes send LD-API-Version 20240415, while beta surfaces send beta. Reads are approval-free. Mutations are grant-off and approval-gated; destructive, administrative, and high-impact changes require approval every run.

pack:launchdarklylaunchdarklyagent-controlai-configs
by Recued Core v1 1 item Pack
Flags, Contexts, and Targeting - LaunchDarkly

LaunchDarkly feature flag, segment, context, user-setting, trigger, import, link, and follow operations not retained in the compatibility root. The CSV segment-import transport is explicitly excluded. Generated from the hash-anchored complete LaunchDarkly OpenAPI document. The commercial base is an enrollment default; per-organization connections may use the documented EU or Federal origin. Stable routes send LD-API-Version 20240415, while beta surfaces send beta. Reads are approval-free. Mutations are grant-off and approval-gated; destructive, administrative, and high-impact changes require approval every run.

pack:launchdarklylaunchdarklyfeature-flagssegments
by Recued Core v1 1 item Pack
Insights and Usage Operations - LaunchDarkly

LaunchDarkly account usage, audit log, code references, engineering insights, users, announcements, applications, and miscellaneous read and mutation operations. Generated from the hash-anchored complete LaunchDarkly OpenAPI document. The commercial base is an enrollment default; per-organization connections may use the documented EU or Federal origin. Stable routes send LD-API-Version 20240415, while beta surfaces send beta. Reads are approval-free. Mutations are grant-off and approval-gated; destructive, administrative, and high-impact changes require approval every run.

pack:launchdarklylaunchdarklyinsightsusage
by Recued Core v1 1 item Pack
Platform Administration - LaunchDarkly

LaunchDarkly access token, member, team, custom role, data export, allowlist, integration, OAuth client, persistent store, relay proxy, SDK key, and webhook administration. The CSV team-member upload transport is explicitly excluded. Generated from the hash-anchored complete LaunchDarkly OpenAPI document. The commercial base is an enrollment default; per-organization connections may use the documented EU or Federal origin. Stable routes send LD-API-Version 20240415, while beta surfaces send beta. Reads are approval-free. Mutations are grant-off and approval-gated; destructive, administrative, and high-impact changes require approval every run.

pack:launchdarklylaunchdarklyadministrationmembers
by Recued Core v1 1 item Pack
Release and Experiment Operations - LaunchDarkly

LaunchDarkly approvals, projects, environments, experiments, metrics, holdouts, scheduled changes, release pipelines, policies, releases, workflows, layers, views, and tags. Generated from the hash-anchored complete LaunchDarkly OpenAPI document. The commercial base is an enrollment default; per-organization connections may use the documented EU or Federal origin. Stable routes send LD-API-Version 20240415, while beta surfaces send beta. Reads are approval-free. Mutations are grant-off and approval-gated; destructive, administrative, and high-impact changes require approval every run.

pack:launchdarklylaunchdarklyreleasesexperiments
by Recued Core v1 1 item Pack
Calendar - Google Calendar

API capability pack for bounded Google Calendar API v3 calls against https://www.googleapis.com/calendar/v3 only. Reads the user's calendar list, calendar metadata, bounded event windows, individual events, and free/busy blocks. Bundles a scheduled daily agenda digest, an AI-assisted event prep brief, an approval-gated focus block creator, and an approval-gated event reschedule workflow. Enroll a Google OAuth bearer connection named google with the narrowest Calendar scopes needed for the installed operations. The pack intentionally excludes ACL/sharing mutation, secondary calendar creation/deletion/clear, watch channels, colors/settings/admin resources, event import, conference creation, attachments, arbitrary API passthrough, and unbounded event export.

pack:google-calendargoogle-calendarcalendarevents
by Recued Core v1 5 items Pack
Team Chat - Google Chat

API capability pack for bounded Google Chat API v1 operations against https://chat.googleapis.com/v1 only. Reads spaces, space metadata, space messages, message details, members, message reactions, and recent space events. Bundles a scheduled space activity digest, an AI-assisted thread brief, and an approval-gated space update workflow. Writes are approval-gated and limited to sending one plain-text message or thread reply. Enroll a Google OAuth bearer connection named google with the narrowest Chat scopes needed for the installed operations. The pack intentionally excludes admin search, space creation/update/delete/setup/import, membership mutation, message edit/delete, pin/unpin, reaction mutation, media upload/download, attachment binary reads, custom emoji mutation, user read-state and notification-setting mutation, cards/widgets, webhooks, subscriptions, and arbitrary API passthrough.

pack:google-chatgoogle-chatchatspaces
by Recued Core v1 4 items Pack
Contacts - Google Contacts

API capability pack for bounded Google People API v1 calls against https://people.googleapis.com only. Enroll a Google OAuth bearer connection named google with the narrowest People API scopes needed for the installed operations. Reads Google contacts, contact groups, other contacts, and Google Workspace directory people. Writes are approval-gated and limited to creating/updating/deleting one contact, copying one other contact into My Contacts, creating/updating/deleting one contact group without deleting member contacts, and adding or removing contact-group members by resource name. The pack intentionally excludes batch create/update/delete, contact photo mutation, profile mutation, domain admin directory writes, arbitrary Google APIs, arbitrary People API passthrough, and unsafe raw resourceName path interpolation.

pack:google-contactsgoogle-contactsgoogle-peoplegoogle-workspace
by Recued Core v1 1 item Pack
Docs - Google Docs

API capability pack for bounded Google Docs API v1 calls against https://docs.googleapis.com/v1 only. Reads one document by ID, creates one blank document by title, and approval-gates semantic text insertion and template replacement workflows through Docs batchUpdate request shapes. Bundles a document review brief, a meeting-notes creator, and a template-field fill workflow. Enroll a Google OAuth bearer connection named google with the narrowest Docs or Drive file scopes needed for the installed operations. The pack intentionally excludes Drive file search, export/import, sharing and permissions, comments, arbitrary Drive calls, delete operations, style/image/table/suggestion mutation, header/footer mutation, arbitrary Docs API passthrough, and unbounded document export.

pack:google-docsgoogle-docsdocsdocuments
by Recued Core v1 4 items Pack
Google Drive File Comment Closure Loop

Workflow pack for Recued-created Google Drive file comments. It composes the Google Drive capability pack with a closure ledger: add one comment to an existing Drive file through the existing approval gate, persist only the connection/file/comment linkage in data.shared, and let a scheduled watcher re-read that exact comment until Drive reports it resolved or deleted. This pack does not replace Google Drive comments, native Drive notifications, document review dashboards, permission workflows, comment resolution controls, or general file-status reporting; it adds Recued-visible closure state for file comments Recued created.

pack:google-drive-file-comment-closuregoogle-drivegdrivecomments
by Recued Core v1 2 items Pack
Forms - Google Forms

API capability pack for bounded Google Forms API v1 calls against https://forms.googleapis.com only. Reads form metadata, response pages, individual responses, and watch registrations for daily lead intake, surveys, registrations, applications, customer feedback, and lightweight operations workflows. Approval-gates creating a blank form with title and optional Drive document title, plus setting the form publish state so API-created forms can be made usable after Google Forms' June 30, 2026 unpublished-default change. Enroll a Google OAuth bearer connection named google; no credential is embedded in the manifest. The pack intentionally excludes arbitrary batchUpdate, question/item mutation, quiz grading mutation, response submission, watch creation/renewal/deletion, Drive sharing/deletion, linked-sheet creation, arbitrary Google APIs, and arbitrary API passthrough.

pack:google-formsgoogle-formsformssurveys
by Recued Core v1 1 item Pack
Meet - Google Meet

API capability pack for bounded Google Meet API v2 calls against https://meet.googleapis.com/v2 only. Reads and creates meeting spaces, searches and reads conference records, reads participants, participant sessions, recording metadata, transcript metadata, and transcript entries, and approval-gates ending one active conference in a Meet space. Bundles a governed Meet link creator, a post-meeting artifact brief, and an approval-gated active-conference end workflow. Enroll a Google OAuth bearer connection named google with the narrowest Meet scopes needed for the installed operations. The pack intentionally excludes Google Calendar event scheduling, Drive recording downloads, Docs transcript downloads, live media capture, Meet Media API streams, space settings patch, co-host management, attendance-report file retrieval, webhooks, admin controls, arbitrary resource-name passthrough, and arbitrary API passthrough.

pack:google-meetgoogle-meetmeetmeetings
by Recued Core v1 4 items Pack
SEO - Google Search Console

API capability pack for bounded Google Search Console operations against https://searchconsole.googleapis.com only. Reads accessible properties, search analytics rows, sitemap status, and URL inspection results for daily website and SEO operations; approval-gates sitemap submit/delete after site deploys or sitemap cleanup. Enroll a Google OAuth bearer connection named google with Search Console scopes; no credential is embedded in the manifest. Site add/remove, ownership verification, mobile-friendly testing screenshots, arbitrary Google APIs, and arbitrary API passthrough are intentionally not exposed.

pack:google-search-consolegoogle-search-consolesearch-consoleseo
by Recued Core v1 1 item Pack
Spreadsheets - Google Sheets

API capability pack for bounded Google Sheets API v4 calls against https://sheets.googleapis.com/v4 only. Reads spreadsheet metadata, sheet tabs, and one A1/R1C1 value range for daily tracker, CRM-lite, finance, lead-list, and operations spreadsheet workflows. Approval-gates creating one spreadsheet, appending raw values to one range, updating raw values in one range, and copying one sheet tab to another spreadsheet. Enroll a Google OAuth bearer connection named google; no credential is embedded in the manifest. The pack intentionally excludes arbitrary batchUpdate, formatting, formulas as USER_ENTERED input, clear/delete operations, data-filter mutation, protected range mutation, pivot/chart/table mutation, developer metadata mutation, Drive sharing, imports/exports, and arbitrary API passthrough.

pack:google-sheetsgoogle-sheetsspreadsheetsheets
by Recued Core v1 1 item Pack
Slides - Google Slides

API capability pack for bounded Google Slides API v1 calls against https://slides.googleapis.com/v1 only. Reads one presentation by ID, reads a thumbnail for one known slide, creates one blank presentation by title, and approval-gates semantic slide creation and template text replacement through Slides batchUpdate request shapes. Bundles a deck review brief, a status-deck creator, and a template-field fill workflow. Enroll a Google OAuth bearer connection named google with the narrowest Slides or Drive file scopes needed for the installed operations. The pack intentionally excludes Drive file search, export/import, sharing and permissions, arbitrary Drive calls, delete operations, image/video/table/chart insertion, speaker-note mutation, arbitrary Slides API passthrough, and unbounded presentation export.

pack:google-slidesgoogle-slidesslidespresentations
by Recued Core v1 4 items Pack
Tasks - Google Tasks

API capability pack for bounded Google Tasks API v1 calls against https://tasks.googleapis.com only. Reads task lists, individual task lists, bounded task pages, and individual tasks for daily to-do review, follow-up capture, project lists, client lists, reminders, and solo-operator work queues. Bundles scheduled daily planning, approval-gated task capture, and approval-gated task completion recipes on top of the raw capability surface. Approval-gates creating and renaming task lists, creating tasks, editing basic task fields, setting task status, and moving tasks between positions or lists. Enroll a Google OAuth bearer connection named google with Tasks scopes; no credential is embedded in the manifest. The pack intentionally excludes task deletion, task-list deletion, clear-completed, full PUT replacement, arbitrary body passthrough, assignment-source mutation, hidden/deleted mutation, link mutation, batch requests, arbitrary Google APIs, and arbitrary API passthrough.

pack:google-tasksgoogle-taskstaskstodo
by Recued Core v1 4 items Pack
Google Tasks Task Closure Loop

Workflow pack for Recued-created Google Tasks tasks. It composes the Google Tasks capability pack with a closure ledger: create one owner-approved active task in an existing task list, persist only the connection/list/task linkage in data.shared, and let a scheduled watcher re-read that exact task until Google Tasks reports completion. This pack does not replace Google Tasks due dates, reminders, list organization, task moves, assignment-source behavior, hidden/deleted task handling, clear-completed cleanup, daily planning, or general task dashboards; it adds Recued-visible closure state for Google Tasks tasks Recued created.

pack:google-tasks-task-closuregoogle-tasksgoogletodo
by Recued Core v1 2 items Pack
GPG Verify Pack

V3 deterministic OpenPGP signature verification capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local gpgv CLI verifies one trusted local file path against a detached signature and trusted keyring via signature.verify. This pack uses gpgv, not generic gpg, so it is verification-only: no signing, import, trustdb mutation, keyserver access, or key management workflow. The operation is exit-code-only; a zero exit code means the signature verified. Requires gpgv on PATH (Debian/Ubuntu: apt install gpgv; macOS: install GnuPG). Local and no-egress.

pack:gpg-verifygpgvopenpgpsignature
by Recued Core v1 1 item Pack
Gradle Pack

V3 Gradle CLI toolchain capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local gradle CLI ingredient exposes bounded project operations for readiness, verification, and test execution. Project operations run from an explicit project directory cwd supplied at execution time, disable the daemon, use a plain console, limit warning noise, avoid caller-supplied tasks/properties/profiles/init scripts/settings/build files/modules, avoid project wrapper scripts and shell wrappers, and keep diagnostics visible as text output. Verification and test operations are approval-gated because Gradle may resolve dependencies and plugins, execute build scripts and plugins, compile project code, run tests or verification tasks, and write build directories or Gradle cache state. Requires gradle on PATH.

pack:gradlegradlejavakotlin
by Recued Core v1 1 item Pack
Full Observability and Operations - Grafana

One-install Grafana front door over five bearer-auth domain packs and fourteen operating workflows. It admits all 275 buildable service-account operations in the pinned v13.1.0 contract: dashboards and folders, alerting, data sources and migration, organizations and teams, access control, service accounts, SSO administration, annotations, reporting, and query history. A separately installable grafana-server-admin pack covers all 33 Basic-only self-managed server routes without making the Cloud-compatible front door depend on Basic credentials. Five of those routes inherit Swagger metadata that advertises either credential, but their pinned operation prose explicitly requires Basic, so the safer prose restriction wins. Together the packs admit 308 of 314 official routes. Six explicit exclusions are one malformed report-image path plus five browser redirect/callback routes that cannot be represented as service-account calls; supported report, SAML administration, and signed-in-user operations remain covered. Every read is uncached; every mutation is grant-off and approval-gated. Ten non-JSON reads return file_ref values, four Prometheus conversion writes accept literal YAML, and nested-int64 JSON mutations accept literal body_raw JSON rather than rounding identifiers. The contract has no honest task, note, or project projection, so this suite deliberately declares no work-entity Source.

pack:grafanagrafanaobservabilitydashboards
by Recued Core v1 14 items Pack
Access and Service Accounts - Grafana

Grafana access control, custom roles, service accounts, SAML, SSO settings, external team sync, quota, signing-key, health, and token-authenticated administrative operations. Generated from Grafana v13.1.0 official release-tagged Swagger 2 bytes, with the deployment-specific /api base supplied by a per-organization connection. Use a service-account bearer token; Grafana Cloud supports token authentication rather than Basic authentication. Every read is uncached, every mutation is grant-off and approval-gated, JSON response int64 literals are preserved as exact decimal strings, and raw file responses are captured as file_ref values. No Grafana object is misrepresented as a task, note, or project Source.

pack:grafanagrafanaaccess-controlservice-accounts
by Recued Core v1 1 item Pack
Alerting and Recording Rules - Grafana

Grafana alert-rule provisioning, contact points, mute timings, notification policies, templates, recording rules, Prometheus conversion, and query history. Generated from Grafana v13.1.0 official release-tagged Swagger 2 bytes, with the deployment-specific /api base supplied by a per-organization connection. Use a service-account bearer token; Grafana Cloud supports token authentication rather than Basic authentication. Every read is uncached, every mutation is grant-off and approval-gated, JSON response int64 literals are preserved as exact decimal strings, and raw file responses are captured as file_ref values. No Grafana object is misrepresented as a task, note, or project Source.

pack:grafanagrafanaalertingrecording-rules
by Recued Core v1 1 item Pack
Dashboards, Folders, and Reporting - Grafana

Grafana dashboards, folders, library elements, playlists, search, snapshots, annotations, and Enterprise reporting. Generated from Grafana v13.1.0 official release-tagged Swagger 2 bytes, with the deployment-specific /api base supplied by a per-organization connection. Use a service-account bearer token; Grafana Cloud supports token authentication rather than Basic authentication. Every read is uncached, every mutation is grant-off and approval-gated, JSON response int64 literals are preserved as exact decimal strings, and raw file responses are captured as file_ref values. No Grafana object is misrepresented as a task, note, or project Source.

pack:grafanagrafanadashboardsfolders
by Recued Core v1 1 item Pack
Data Sources and Platform Operations - Grafana

Grafana data sources, correlations, queries, health and proxy calls, cloud migration, licensing, caching, and Enterprise data-platform operations. Generated from Grafana v13.1.0 official release-tagged Swagger 2 bytes, with the deployment-specific /api base supplied by a per-organization connection. Use a service-account bearer token; Grafana Cloud supports token authentication rather than Basic authentication. Every read is uncached, every mutation is grant-off and approval-gated, JSON response int64 literals are preserved as exact decimal strings, and raw file responses are captured as file_ref values. No Grafana object is misrepresented as a task, note, or project Source.

pack:grafanagrafanadata-sourcesmigration
by Recued Core v1 1 item Pack
Organizations, Teams, and Users - Grafana

Grafana current-organization, team, user, signed-in-user, preference, device, and organization-scoped identity operations. Generated from Grafana v13.1.0 official release-tagged Swagger 2 bytes, with the deployment-specific /api base supplied by a per-organization connection. Use a service-account bearer token; Grafana Cloud supports token authentication rather than Basic authentication. Every read is uncached, every mutation is grant-off and approval-gated, JSON response int64 literals are preserved as exact decimal strings, and raw file responses are captured as file_ref values. No Grafana object is misrepresented as a task, note, or project Source.

pack:grafanagrafanaorganizationsteams
by Recued Core v1 1 item Pack
Server Administration - Grafana

Grafana self-managed server administration that the official contract restricts to Basic authentication: global organizations and users, LDAP, quotas, provisioning reloads, settings, passwords, sessions, auth tokens, and the service-account administration routes whose operation prose explicitly requires Basic authentication. Generated from Grafana v13.1.0 official release-tagged Swagger 2 bytes, with the deployment-specific /api base supplied by a per-organization connection. This pack is intentionally separate because these 33 routes require Basic authentication and are unavailable to Grafana Cloud service-account tokens. Every read is uncached, every mutation is grant-off and approval-gated, JSON response int64 literals are preserved as exact decimal strings, and raw file responses are captured as file_ref values. No Grafana object is misrepresented as a task, note, or project Source.

pack:grafanagrafanaserver-adminorganizations
by Recued Core v1 3 items Pack
Recruiting ATS - Greenhouse

API capability pack for bounded Greenhouse Harvest v3 operations against https://harvest.greenhouse.io/v3. Enroll a Greenhouse Harvest v3 OAuth bearer connection named greenhouse with candidate, application, job, job-post, opening, offer, interview, scorecard, user, office, department, and note access. The pack reads recruiting pipeline records for hiring operations digests, candidate evidence briefs, job readiness review, interview and scorecard follow-up, offer tracking, and recruiting operations reporting. It bundles a scheduled recruiting digest, AI-assisted candidate and job briefs, and approval-gated workflows for creating one candidate profile and adding one candidate note. Writes are limited to one candidate or note at a time. The pack intentionally excludes candidate deletes, candidate merges, anonymization, application hire/reject/move/convert actions, offer creation or mutation, job/opening/job-post mutation, department/office/user administration, attachment uploads or downloads, bulk endpoints, OAuth token generation, webhooks, and arbitrary Greenhouse API passthrough.

pack:greenhousegreenhouseatsrecruiting
by Recued Core v1 6 items Pack
Fast AI Inference - Groq

API capability pack for bounded Groq REST API operations against https://api.groq.com only. Enroll a Groq API key bearer connection named groq; no credential is embedded in this manifest. The pack reads the model catalog, creates non-streaming chat completions, creates bounded Responses API generations, creates text embeddings, and reads batch/file metadata for low-latency LLM workflows, structured output review, semantic-search preparation, model inventory, and operations monitoring. Generation and embedding calls are non-persistent read-tier inference calls that consume Groq quota but do not create durable customer resources through this pack. The pack intentionally excludes streaming, tool calls, tool_choice routing, functions, MCP-connected tools, built-in browser/code/web-search tools, Compound custom tool configuration, arbitrary extra body/query/header passthrough, batch creation or cancelation, file upload/download/delete, model deletion, fine-tuning, multipart audio transcription/translation, binary speech generation, credential management, dynamic outbound callbacks, and any operation outside api.groq.com.

pack:groqgroqaillm
by Recued Core v1 5 items Pack
Full Payroll, People, Benefits, and Events - Gusto

One-install Gusto front door over 7 bounded App Integrations capability packs and 30 non-chat read workflows. It admits 135 callable outbound operations from all 137 official 2026-06-15 endpoint fragments and explicitly excludes 2 credential-lifecycle routes. Coverage includes companies and organization structure, employees and employment lifecycle, compensation and deductions, contractors, payroll and time tracking, benefits and leave, reports, provisioning, events, and webhook administration. Company data uses per-company OAuth; the system leaf is a separate short-lived bearer context because Gusto forbids either token class from substituting for the other. Production access remains subject to Gusto pre-approval, security review, QA, and granted scopes. All reads are uncached; sensitive reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Every mutation requires approval, no operation receives an implicit default grant, and no work-entity Source is declared.

pack:gustogustopayrollhris
by Recued Core v1 30 items Pack
Benefits and Time Off - Gusto

Gusto supported benefits, company and employee enrollments, contribution rules, Section 603 status, time-off policies, accrual calculations, and requests. Generated from Gusto's complete 2026-06-15 App Integrations reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Gusto publishes split per-endpoint fragments whose server is the demo origin; pinning one fragment would falsely claim production-wide coverage. This leaf is isolated to CompanyAccessAuth operations and uses per-company OAuth with rotating refresh tokens; system access tokens cannot authorize it. The X-Gusto-API-Version header is fixed to 2026-06-15. Every documented scope is declared and reads are uncached; sensitive payroll and HR reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Mutations are grant-off and approval-gated, explicit-null and structurally unsafe request bodies fall back to bounded body_raw, and JSON unsafe integers remain exact strings. No work-entity Source is declared because the App Integrations surface exposes no semantically honest task, note, or project entity.

pack:gustogustobenefitstime-off
by Recued Core v1 1 item Pack
Companies, Locations, and Organization - Gusto

Gusto company identity, administrators, locations, departments, notifications, and company-token introspection. Generated from Gusto's complete 2026-06-15 App Integrations reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Gusto publishes split per-endpoint fragments whose server is the demo origin; pinning one fragment would falsely claim production-wide coverage. This leaf is isolated to CompanyAccessAuth operations and uses per-company OAuth with rotating refresh tokens; system access tokens cannot authorize it. The X-Gusto-API-Version header is fixed to 2026-06-15. Every documented scope is declared and reads are uncached; sensitive payroll and HR reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Mutations are grant-off and approval-gated, explicit-null and structurally unsafe request bodies fall back to bounded body_raw, and JSON unsafe integers remain exact strings. No work-entity Source is declared because the App Integrations surface exposes no semantically honest task, note, or project entity.

pack:gustogustocompanieslocations
by Recued Core v1 1 item Pack