Recued
Menu
Community catalog

Marketplace

Inspect what a workflow does, what it installs, and what it can access before bringing it into Recued.

Kind
Tags
Sort

927 packs

Webhooks and Events - PayPal

PayPal webhook administration, event types, event history, signature verification, resend, and simulation. Generated from PayPal's immutable commit-pinned Webhooks Management OpenAPI 1.11. This source-pinned leaf carries 10 of the installed family's 109 catalog operations; the family covers 105 of 115 unique official routes with 10 exact fail-closed exclusions. Bearer authorization and merchant/partner identity remain connection-owned, new reads are uncached and not approval-gated, every mutation requires approval, documented PayPal-Request-Id values are mandatory for supported mutation retries, JSON inputs are bounded, and unsafe response integers remain exact strings. No financial or control-plane object is misrepresented as a task, note, or project Source.

pack:paypalpaypalwebhooksevents
by Recued Core v1 1 item Pack
PDFGrep Pack

V3 deterministic PDF text-search capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local pdfgrep CLI exposes readiness, bounded page-numbered PDF text search, fixed-string search, case-insensitive search, context search, match-only extraction, total match counts, and page-level match counts for one trusted local PDF path. This pack deliberately exposes bounded path-based value output rather than file_ref materialization, because matched PDF text is returned on stdout. No arbitrary pdfgrep flags, recursive directory search, password arguments, pattern-file inputs, cache writes, debug output, shell wrapper, stdin, or multi-file glob search are exposed, and exit code 1 (no matches) is treated as success for search/count operations. Requires pdfgrep on PATH (Debian/Ubuntu: apt install pdfgrep). Local and no-egress.

pack:pdfgreppdfgrepclipdf
by Recued Core v1 1 item Pack
PDFImages Pack

V3 deterministic PDF image-inventory capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdfimages CLI exposes readiness, full-document embedded-image inventory, fixed first-page image inventory, and bounded first-N-pages image inventory for one trusted local PDF path. This pack deliberately ships inventory modes only, not bulk image extraction, because pdfimages extraction writes one file per image and v1 output_capture expects exactly one produced file. The operations are path-based stdout text for the same reason as pdfinfo: the current CLI safety contract forbids materialized file_ref input with stdout value capture. It exposes no password arguments, image-root output prefix, extraction format flags, stdin mode, shell wrapper, arbitrary flags, or network egress. Requires pdfimages on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler).

pack:pdfimagespdfimagespopplercli
by Recued Core v1 1 item Pack
PDFInfo Pack

V3 deterministic PDF information capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdfinfo CLI exposes readiness, basic document/page information, page-box bounding boxes, document-level metadata stream output, and URL annotation listing for one trusted local PDF path. This pack deliberately exposes path-based stdout helpers, not file_ref materialization, because the current CLI safety contract forbids materialized file_ref input with stdout value capture. It exposes no password arguments, JavaScript dump, tagged-structure dump, arbitrary pdfinfo flags, stdin mode, shell wrapper, output-file path, or network egress. Requires pdfinfo on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler). Local and no-egress.

pack:pdfinfopdfinfopopplercli
by Recued Core v1 1 item Pack
PDFSeparate Pack

V3 deterministic PDF page-extraction capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdfseparate CLI exposes readiness, fixed first-page extraction, and single selected-page extraction for one source PDF. Fixed-function and reproducible: the executor materializes the source PDF and owns the throwaway output directory, while pdfseparate writes exactly one page PDF per operation that is captured as result.file_ref. The pack deliberately avoids arbitrary page ranges and full-document splitting because pdfseparate writes one PDF per page and the current output_capture contract expects a single produced file. It exposes no password arguments, caller-controlled output pattern, stdin mode, shell wrapper, arbitrary flags, or network egress. Requires pdfseparate on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler).

pack:pdfseparatepdfseparatepopplercli
by Recued Core v1 1 item Pack
PDFToText Pack

V3 deterministic PDF text-extraction capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdftotext CLI exposes readiness, layout-preserving extraction, default reading-order extraction, fixed first-page preview extraction, bounding-box XHTML layout extraction, and TSV word-position extraction for a source PDF. Bundles a direct text-extraction recipe plus a preview-first PDF notes workflow that summarizes the extracted text by file ref. Fixed-function and reproducible: extraction happens locally before any model sees the PDF. Write-tier but approval=never: pdftotext writes only to an engine-managed throwaway output dir and each extracted artifact is captured as result.file_ref; downstream ai-* steps consume text through Gateway-gated file refs. The source can be a data.file ref or a trusted local path. This pack exposes no password args, arbitrary flags, stdin mode, caller-controlled output path, shell wrapper, or network egress. Requires the pdftotext binary on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler).

pack:pdftotextpdftotextpopplercli
by Recued Core v1 3 items Pack
PDFUnite Pack

V3 deterministic PDF merge capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local Poppler pdfunite CLI exposes readiness, exact two-PDF merge, and bounded multi-PDF merge operations. The executor materializes ordered file_ref arrays into engine-managed temp paths, expands them into discrete argv elements in caller order, and owns the output path captured as result.file_ref. The pack exposes no arbitrary pdfunite flags, encrypted-PDF password handling, caller-controlled output path, stdin mode, shell wrapper, or network egress. Requires pdfunite on PATH (Debian/Ubuntu: apt install poppler-utils; macOS: brew install poppler).

pack:pdfunitepdfunitepopplercli
by Recued Core v1 1 item Pack
Research Intelligence - Perplexity

API capability pack for bounded Perplexity REST API operations against https://api.perplexity.ai only. Enroll a Perplexity API key bearer connection named perplexity; no credential is embedded in this manifest. The pack reads the model catalog, creates bounded Web Search API responses, creates non-streaming Sonar responses with citations and search results, and creates text embeddings for research, competitive intelligence, source-backed answer review, semantic search preparation, and RAG readiness. It bundles a cited answer brief, a web search brief, an embedding readiness brief, and a model catalog brief. The pack intentionally excludes streaming, async chat jobs, Agent API responses, browser sessions, file and response content download, custom tools and tool-choice routing, MCP or code execution, contextualized embeddings, People Search, analytics, auth-token issue or revoke endpoints, arbitrary Perplexity API passthrough, dynamic outbound callbacks, and any operation outside api.perplexity.ai.

pack:perplexityperplexityairesearch
by Recued Core v1 5 items Pack
Personal CRM

Keep up with the people you actually know, from the mail and calendar you already sync. Four recipes over your own warehouse — no CRM, no contact upload, nothing leaves your machine. keep-in-touch-cadence is a weekly nudge list of people you have real history with who have gone quiet; personal-circle-health-brief ranks your closest contacts and shows who is carrying each relationship; keep-gift-idea-ledger captures 'remember Sam likes X' as a note on Sam; draft-introduction-mail turns two contacts plus your reason into an intro you copy and send yourself. The two digests are read-only. Only two things ever write, and only what they name: the gift ledger creates one note linked to the person, and nothing else is touched. No recipe here sends mail, creates or edits a contact, or notifies anyone. Both digests read enrichment rollups that the housekeeping producers maintain, so a contact you have never exchanged mail with will not appear in them.

pack:personal-crmcontactrelationshipswarehouse
by Recued Core v1 Pack
Personal Finance & Subscriptions

Find the money leaking out of your inbox, without any of it leaving your machine. Eight warehouse-first recipes over mail you already sync and files you already have — no bank connection, no aggregator, no statement upload to anyone: audit-subscriptions-from-mail ranks recurring charges by cost; renewal-radar surfaces annual renewals before they auto-charge; categorize-expenses-from-statement parses a dropped statement locally with docling and categorizes it into a table plus a CSV; detect-spend-anomalies-statement compares two months per category with pure arithmetic and no model call; price-increase-detector watches new mail behind deterministic subject-then-body gates; track-warranty-from-receipt turns a receipt into a warranty reminder with the receipt linked to it; assemble-tax-document-packet checks off the documents for a tax year and collects the files; collect-receipts-monthly-packet gathers a month of receipt mail and receipt files into one markdown evidence file. The read-side recipes never write. Two recipes write, and only what they name: track-warranty-from-receipt creates a Recued task, and collect-receipts-monthly-packet writes its packet into a file collection you nominate (it needs one with the write capability, and writes nothing until you set it). Nothing here pays, cancels, unsubscribes, or replies to anyone, and nothing moves, renames, or deletes a file. The two mail watchers install disarmed — you arm them.

pack:personal-financepersonal-financesubscriptionsspend
by Recued Core v1 Pack
Full People, Time, Recruiting, and Webhooks - Personio

One-install Personio front door over 5 bounded v2 capability packs and 29 non-chat read workflows. It admits 69 callable operations from 72 official endpoint fragments and explicitly excludes 3 credential-lifecycle routes. Coverage includes people and employments, organization reference data, compensation and salary bands, reports, document management and binary download, attendance, absence, time-tracking projects and memberships, recruiting, and webhook administration. Personnel access and recruiting access remain separate bearer enrollments because Personio documents distinct credential contexts. Personnel tokens are stable for 24 hours but require manual renewal until the connection substrate supports client-credentials renewal. All reads are uncached, sensitive reads are marked sensitive-read, every mutation requires approval, cursor pagination follows same-operation token replay, and no operation receives an implicit default grant. The genuine Personio Project entity is not declared as a Source in this commit because the repository requires a separate human field-path verification gate.

pack:personiopersoniohrispeople
by Recued Core v1 29 items Pack
Compensation, Reports, and Documents - Personio

Personio compensation records and types, custom reports, and document metadata, download, update, and deletion. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf uses a manually enrolled personnel bearer produced by Personio client credentials. Personio documents a stable 24-hour token, while the Recued connection contract has no client-credentials renewal mode, so automatic renewal is not claimed. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.

pack:personiopersoniocompensationreports
by Recued Core v1 1 item Pack
People and Organization - Personio

Personio people, employments, org units, legal entities, cost centers, workplaces, jobs, and salary bands. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf uses a manually enrolled personnel bearer produced by Personio client credentials. Personio documents a stable 24-hour token, while the Recued connection contract has no client-credentials renewal mode, so automatic renewal is not claimed. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.

pack:personiopersoniopeopleemployments
by Recued Core v1 1 item Pack
Recruiting - Personio

Personio recruiting applications, candidates, jobs, categories, and application stage transitions. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf is isolated to the separately enrolled Recruiting API bearer documented by Personio; it does not claim that a personnel token can authorize recruiting endpoints. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.

pack:personiopersoniorecruitingcandidates
by Recued Core v1 1 item Pack
Time, Absence, and Projects - Personio

Personio attendance periods, absence periods and types, time-tracking projects, and project membership. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf uses a manually enrolled personnel bearer produced by Personio client credentials. Personio documents a stable 24-hour token, while the Recued connection contract has no client-credentials renewal mode, so automatic renewal is not claimed. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.

pack:personiopersonioattendanceabsence
by Recued Core v1 1 item Pack
Webhooks - Personio

Personio webhook configuration, delivery activity, event inspection, redelivery, ping, and test-event controls. Generated from Personio current v2 reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Personio publishes split per-endpoint fragments rather than one current aggregate spanning this surface. This leaf uses a manually enrolled personnel bearer produced by Personio client credentials. Personio documents a stable 24-hour token, while the Recued connection contract has no client-credentials renewal mode, so automatic renewal is not claimed. All reads are uncached; sensitive HR, compensation, document, applicant, and webhook reads are marked sensitive-read; every mutation is grant-off and approval-gated. Cursor walks replay only the cursor extracted from the documented same-origin next link. Binary document downloads are captured directly into the warehouse CAS. Beta headers are fixed where the reference requires them, request attribution uses X-Personio-App-ID: RECUED, and no operation receives an implicit default grant. A project Source is deliberately deferred because the repository Source brief requires a separate human field-path verification gate before commit.

pack:personiopersoniowebhooksevents
by Recued Core v1 1 item Pack
pip-audit Pack

V3 Python dependency-vulnerability audit capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local pip-audit CLI ingredient exposes bounded project operations for readiness and dependency vulnerability audits. Audits run from an explicit project directory cwd supplied at execution time, audit one trusted, fully pinned requirements file, and return JSON findings via the python.dependency_audit catalog operation. Fixed-function and bounded: requirements-file mode only, JSON output, fixed PyPI vulnerability service, no dependency resolution, no pip resolver, no package fixing/upgrading, no local environment/project scan, no lockfile/project-path scan, no caller-supplied package indexes, no ignored vulnerability list, no output-file write, no arbitrary pip-audit flags, and no shell wrapper. Approval is ask because package names and versions are sent to PyPI vulnerability data services. Vulnerability findings are represented as successful JSON output; real collection or invocation errors still fail. Requires pip-audit on PATH with Python 3.10+. Network egress to PyPI vulnerability data services.

pack:pip-auditpip-auditpythonaudit
by Recued Core v1 1 item Pack
Administration and Platform v1 - Pipedrive

Still-live Pipedrive API v1 administration and platform features, including billing, goals, teams, permissions, roles, projects, users, settings, recents, and webhooks. Generated from the current hash-pinned official Pipedrive v1 OpenAPI document. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and requires approval every run. Documented continuations are bounded by 25 pages and 1,000 records, and int64 values are handled losslessly.

pack:pipedrivepipedrivev1billing
by Recued Core v1 1 item Pack
CRM and Products v2 - Pipedrive

Preferred Pipedrive API v2 coverage for activities, deals, deal products and installments, people, organizations, products, leads, search, stages, and pipelines. Generated from the current hash-pinned official Pipedrive v2 OpenAPI document. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and requires approval every run. Documented continuations are bounded by 25 pages and 1,000 records, and int64 values are handled losslessly.

pack:pipedrivepipedrivev2activities
by Recued Core v1 1 item Pack
Projects and Fields v2 - Pipedrive

Preferred Pipedrive API v2 coverage for field administration, projects, templates, tasks, boards, phases, and user followers. Generated from the current hash-pinned official Pipedrive v2 OpenAPI document. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and requires approval every run. Documented continuations are bounded by 25 pages and 1,000 records, and int64 values are handled losslessly.

pack:pipedrivepipedrivev2activity_fields
by Recued Core v1 1 item Pack
Sales and Engagement v1 - Pipedrive

Still-live Pipedrive API v1 features without a complete v2 replacement, including sales history, calls, channels, files, mail, notes, contact relationships, filters, and lead metadata. Generated from the current hash-pinned official Pipedrive v1 OpenAPI document. Reads are uncached; sensitive reads are marked sensitive-read. Every mutation is grant-off and requires approval every run. Documented continuations are bounded by 25 pages and 1,000 records, and int64 values are handled losslessly.

pack:pipedrivepipedrivev1activity_types
by Recued Core v1 1 item Pack
Full Developer Data Platform - MongoDB Atlas

One-install MongoDB Atlas Admin API v2 front door over 8 bounded capability packs and 31 non-chat, uncached, read-only workflows. It admits all 429 nondeprecated operations across 306 official paths and excludes exactly 58 provider-deprecated operations. Organizations, projects, users, billing, credentials, identity, clusters, networking, backups, observability, Search, Data Federation, and Streams are covered. The mutable official OpenAPI URL must retain 4,590,007 bytes and SHA-256 5040b0d3973e891f9e9048f6c305ed54977d0d69153ad073b232a39d90a50c77 before regeneration. Calls stay on cloud.mongodb.com and carry the exact per-resource versioned media types. The supported credential path is MongoDB's recommended OAuth2 service-account bearer token; Atlas documents a one-hour token lifetime, this pack does not claim automatic token exchange, and legacy HTTP Digest API keys are unsupported. Seventy-one exact page-number collections are automatic; one correlated multi-array response remains explicitly manual. Six non-JSON downloads become private file_refs. Six validation, verification, report, or download POSTs are read-tier; disruptive restores, resets, cutovers, migrations, access removals, and infrastructure reconfiguration are destructive. JSON bodies remain verbatim and unsafe response integers remain exact strings. Reads are uncached and not approval-gated; every mutation requires approval. No task, note, or user-work project Source is claimed for infrastructure tenancy containers.

pack:mongodb-atlasmongodb-atlasdatabase-platformclusters
by Recued Core v1 31 items Pack
Networking and Integrations - MongoDB Atlas

MongoDB Atlas cloud-provider access, network peering, private endpoints, project IP access lists, and third-party integrations. Generated from MongoDB's hash-locked official Atlas Admin API v2 OpenAPI 3.0.1 snapshot (5040b0d3973e…) and carries 36 of the suite's 429 nondeprecated operations. Calls are fixed to cloud.mongodb.com and preserve each operation's exact versioned Accept and Content-Type media types. Use a MongoDB Atlas bearer connection containing a current OAuth2 service-account access token; the documented token lifetime is one hour, and this pack does not claim automatic client-credential exchange. Legacy Digest API keys are deliberately unsupported. JSON bodies remain verbatim, unsafe response integers remain exact strings, downloads become private file_refs, reads are uncached and not approval-gated, and every mutation requires approval. No infrastructure tenancy container is misrepresented as a task, note, or user-work project Source.

pack:mongodb-atlasmongodb-atlasdatabase-platformnetworking
by Recued Core v1 1 item Pack
Observability, Alerts, and Performance - MongoDB Atlas

MongoDB Atlas activity feeds, events, alerts, process and database metrics, logs, Performance Advisor, query insights, and log export. Generated from MongoDB's hash-locked official Atlas Admin API v2 OpenAPI 3.0.1 snapshot (5040b0d3973e…) and carries 65 of the suite's 429 nondeprecated operations. Calls are fixed to cloud.mongodb.com and preserve each operation's exact versioned Accept and Content-Type media types. Use a MongoDB Atlas bearer connection containing a current OAuth2 service-account access token; the documented token lifetime is one hour, and this pack does not claim automatic client-credential exchange. Legacy Digest API keys are deliberately unsupported. JSON bodies remain verbatim, unsafe response integers remain exact strings, downloads become private file_refs, reads are uncached and not approval-gated, and every mutation requires approval. No infrastructure tenancy container is misrepresented as a task, note, or user-work project Source.

pack:mongodb-atlasmongodb-atlasdatabase-platformmonitoring
by Recued Core v1 1 item Pack
Organizations, Projects, and Billing - MongoDB Atlas

MongoDB Atlas organizations, projects, teams, Cloud users, memberships, settings, delegation, and invoices. Generated from MongoDB's hash-locked official Atlas Admin API v2 OpenAPI 3.0.1 snapshot (5040b0d3973e…) and carries 61 of the suite's 429 nondeprecated operations. Calls are fixed to cloud.mongodb.com and preserve each operation's exact versioned Accept and Content-Type media types. Use a MongoDB Atlas bearer connection containing a current OAuth2 service-account access token; the documented token lifetime is one hour, and this pack does not claim automatic client-credential exchange. Legacy Digest API keys are deliberately unsupported. JSON bodies remain verbatim, unsafe response integers remain exact strings, downloads become private file_refs, reads are uncached and not approval-gated, and every mutation requires approval. No infrastructure tenancy container is misrepresented as a task, note, or user-work project Source.

pack:mongodb-atlasmongodb-atlasdatabase-platformorganizations
by Recued Core v1 1 item Pack
Search, Data Federation, and Streams - MongoDB Atlas

MongoDB Atlas Search deployments and indexes, Data Federation, private network settings, and Atlas Stream Processing workspaces, connections, and processors. Generated from MongoDB's hash-locked official Atlas Admin API v2 OpenAPI 3.0.1 snapshot (5040b0d3973e…) and carries 64 of the suite's 429 nondeprecated operations. Calls are fixed to cloud.mongodb.com and preserve each operation's exact versioned Accept and Content-Type media types. Use a MongoDB Atlas bearer connection containing a current OAuth2 service-account access token; the documented token lifetime is one hour, and this pack does not claim automatic client-credential exchange. Legacy Digest API keys are deliberately unsupported. JSON bodies remain verbatim, unsafe response integers remain exact strings, downloads become private file_refs, reads are uncached and not approval-gated, and every mutation requires approval. No infrastructure tenancy container is misrepresented as a task, note, or user-work project Source.

pack:mongodb-atlasmongodb-atlasdatabase-platformsearch
by Recued Core v1 1 item Pack
MuTool Pack

V3 deterministic MuPDF document-manipulation capability pack. By-value connector composition (service_kind=cli, no separate ingredient): the local mutool CLI cleans a PDF, extracts a caller-selected page range into one PDF, or renders the first page to PNG via fixed catalog operations. Write-tier but approval=never: mutool writes only to an engine-managed throwaway output dir and each result is captured as result.file_ref; source PDF bytes never flow through stdout values. Requires mutool on PATH (Debian/Ubuntu: apt install mupdf-tools; macOS: brew install mupdf). Local and no-egress.

pack:mutoolmutoolmupdfcli
by Recued Core v1 1 item Pack
mypy Pack

V3 Python type-check capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local mypy CLI ingredient exposes bounded project operations for readiness and Python type-check diagnostics. Type checks run from an explicit project directory cwd supplied at execution time, inspect one trusted Python file or directory, and return plain diagnostics via the python.type_check catalog operation. Fixed-function and reproducible: ignores discovered project config, ignores missing third-party imports, disables incremental cache reads, disables cache writes on Unix-like hosts, disables color and summary noise, no daemon, no command/eval string, no module/package selector, no caller-supplied config/plugin/cache path, no install/stubgen/stubtest, no arbitrary mypy flags, no shell wrapper, and no network egress. Type errors are represented as successful text findings; real invocation failures still fail. Requires mypy on PATH. Local and no-egress.

pack:mypymypypythontype-check
by Recued Core v1 1 item Pack
n8n Pack

Manage n8n through the bounded Public API: workflows, executions, credentials metadata, tags, users, variables, data tables, projects, folders, insights, community packages, source-control pulls, audit reports, and package export. Enroll an n8n API connection with X-N8N-API-KEY and set base_url to the tenant API root, such as https://example.app.n8n.cloud/api/v1 or https://n8n.example.com/api/v1. Enterprise API keys should grant only the listed required_scopes; non-enterprise n8n API keys may have full account access. Pagination is exposed through query.limit and query.cursor because n8n returns a top-level nextCursor token. Package export/import and arbitrary webhook/raw API passthrough are intentionally excluded: export is a POST binary response while current REST pack file capture is GET-only, and import requires multipart binary upload.

pack:n8nn8nautomationworkflow
by Recued Core v1 1 item Pack
Neon Pack

API capability pack for bounded Neon API v2 operations against https://console.neon.tech/api/v2 only. Enroll a Neon API key bearer connection named neon with the narrowest project, branch, endpoint, database, role, operation, region, and organization read scopes plus explicit write scopes for project rename, preview branch creation, branch rename, and compute start/suspend/restart. No credential is embedded in this manifest. The pack reads current-user context, organizations, regions, projects, branches, compute endpoints, databases, roles, and project operations for developer database operations, preview branch workflows, cost-control checks, and production-readiness reviews. It bundles a project operations digest, an AI-assisted branch readiness brief, and approval-gated workflows for creating one preview branch and suspending one compute endpoint. Writes are limited to one project rename, one branch create/rename, one database create, or one compute start/suspend/restart at a time. The pack intentionally excludes API-key create/revoke, role create/reset/reveal-password, connection URI retrieval, SQL/data API execution, storage object download, project/branch/endpoint/database deletes, branch restore/recover/reset/default changes, snapshots/backup mutation, VPC/project transfer, auth administration, consumption billing changes, OAuth token exchange, and arbitrary Neon API passthrough.

pack:neonneonpostgresdatabase
by Recued Core v1 5 items Pack
Hosting - Netlify

API capability pack for bounded Netlify REST API operations against https://api.netlify.com/api/v1 by default. Enroll a netlify OAuth or personal-access-token bearer connection; no credential is embedded in the manifest. The pack reads the current user, accounts, account audit events, sites, TLS certificate status, deploys, builds, deployed branches, function bundles, forms, submissions, files, assets, snippets, site metadata, DNS zones and records, split tests, public add-on service metadata, database migration metadata, and database snapshots. Approval-gated writes are limited to one site/deploy/build/cache/env/split-test action at a time: enable or disable a site, cancel/restore/rollback/lock/unlock a deploy, trigger a non-upload build, purge cache for one site or tag set, update or remove one environment variable/value, and create/update/publish/unpublish one branch split test. The pack intentionally excludes deploy creation and file/function upload, build-hook reads or writes, deploy keys, OAuth tickets, account/member/billing mutation, site creation/deletion/update, DNS mutation, form/submission deletes, snippet injection writes, asset uploads/deletes, service instance mutation, AI gateway token reads, database connection-string reads, database create/delete/reset/restore/migration-run operations, agent-runner endpoints, plugin mutation, webhooks, and arbitrary API passthrough.

pack:netlifynetlifyhostingdeploys
by Recued Core v1 1 item Pack
Geocoding - Nominatim

No-auth API capability pack for occasional address geocoding and reverse geocoding through the public OpenStreetMap Nominatim service. The pack exposes only bounded single-lookup operations against https://nominatim.openstreetmap.org, fixes JSON output, caps search results at five, and sends an identifying User-Agent. This pack is not for bulk or periodic geocoding; cache results and stay within the public service policy.

pack:nominatimgeocodingmapsaddresses
by Recued Core v1 1 item Pack
Full PaaS, GPU, Delivery, and Infrastructure - Northflank

One-install Northflank front door over 9 bounded domain packs and 13 non-chat, uncached, read-only workflows. It admits all 609 nondeprecated operations across 422 official paths and excludes exactly 76 provider-deprecated operations. Projects, services, jobs, pipelines, workflows, addons, storage, secrets, integrations, networking, cloud and GPU clusters, AI models, templates, previews, teams, roles, tags, and billing are covered. The vendor-hosted OpenAPI is mutable but generation fails closed unless its 5,911,172 bytes retain SHA-256 59fdc2ce6fe8a7652715b2e0a24f762b2e248666393843d019af019159fa1d3b; official Markdown pins repair the schema's placeholder server and empty security declarations with the documented api.northflank.com origin and Bearer authorization. Two team billing paths omit teamId from their reused operation objects, so the exact path placeholder is repaired as a required string; eight collection operations incorrectly carry an ID path parameter absent from their own path, so those phantom inputs are omitted. Twelve optional repeated-value query selectors expose their official scalar alternative because closed operation args cannot serialize duplicate query keys. All repairs and reductions are recorded in the audit fixture. 112 exact cursor loops are automatic; 14 contradictory cursor shapes stay explicitly manual. JSON bodies remain verbatim and unsafe response integers remain exact strings, with compact response schemas accepting both safe numeric and unsafe decimal-string forms. Reads are uncached and not approval-gated; every mutation requires approval. No task, note, or project Source is claimed for infrastructure or runtime records.

pack:northflanknorthflankpaasgpu
by Recued Core v1 13 items Pack
Account, Teams, Roles, Tags, and Billing - Northflank

Northflank teams, organization and team roles, members, tags, billing, plans, regions, DNS identity, and account administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 53 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaasaccount
by Recued Core v1 1 item Pack
Addons - Northflank

Northflank managed addon types, instances, credentials, backups, restores, logs, metrics, versions, and lifecycle administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 73 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaasaddons
by Recued Core v1 1 item Pack
Cloud, GPU, AI Models, and OpenTofu - Northflank

Northflank cloud-provider and cluster management, node operations, regions and node types, AI model deployments, and OpenTofu logs. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 47 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaascloud
by Recued Core v1 1 item Pack
Integrations and Workload Identities - Northflank

Northflank VCS, registry, notification, log-sink, SSH, cloud-identity, and workload-identity integration discovery and administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 70 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaasintegrations
by Recued Core v1 1 item Pack
Jobs, Pipelines, and Workflows - Northflank

Northflank job, pipeline, preview-flow, release-flow, and workflow discovery, execution, build, and lifecycle administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 92 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaasjobs
by Recued Core v1 1 item Pack
Networking and Delivery - Northflank

Northflank domains, subdomains, egress IPs, load balancers, network policies, gradual rollouts, and delivery configuration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 86 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaasnetworking
by Recued Core v1 1 item Pack
Projects and Services - Northflank

Northflank project and long-running service discovery, provisioning, build, deployment, runtime, metrics, and lifecycle administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 66 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaasprojects
by Recued Core v1 1 item Pack
Storage, Secrets, and Backup Destinations - Northflank

Northflank global and project secrets, volumes, backups, backup destinations, and external addon discovery and administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 76 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaasstorage
by Recued Core v1 1 item Pack
Templates and Preview Blueprints - Northflank

Northflank reusable templates, template runs, preview blueprints, preview environments, and blueprint-run lifecycle administration. Generated from Northflank's hash-locked official OpenAPI 3.0.1 snapshot (59fdc2ce6fe8…) and carries 46 of the suite's 609 nondeprecated operations. The mutable vendor URL must retain the reviewed byte length and SHA-256 before regeneration. Pick the Northflank connection whose Authorization header contains the complete Bearer token value for api.northflank.com. JSON bodies remain verbatim, unsafe response integers remain exact strings, and 112 suite operations follow provable cursor contracts. Reads are uncached and not approval-gated; every mutation requires approval. No infrastructure record is misrepresented as a task, note, or project Source.

pack:northflanknorthflankpaastemplates
by Recued Core v1 1 item Pack
Workspace - Notion

API capability pack for bounded Notion page, block, comment, user, and data-source operations against https://api.notion.com only. The pack uses Notion API version 2026-03-11, reads token identity, workspace users, shared pages/data sources, page properties, page markdown, block children, comments, and one page of data-source entries, searches shared pages/data sources by title, and creates or updates daily workspace content. It also bundles a scheduled workspace digest, an AI-assisted page/data-source brief, and approval-gated page intake workflow. Enroll a Notion personal access token or OAuth access token connection as bearer auth; no credential is embedded in the manifest. Writes are limited to page create/update, appending child blocks, creating/updating comments, and updating one to-do block, all approval-gated. The bundled recipes only use page.create and optional comment.create as writes. The pack intentionally excludes arbitrary fetches, deletes, trash/restore, moving pages, broad block updates beyond to-do content/state, comment delete, file upload flows, admin configuration, and workspace-wide export.

pack:notionnotionworkspacepages
by Recued Core v1 4 items Pack
Notion Page Comment Closure Loop

Workflow pack for Recued-created Notion page comments. It composes the Notion capability pack with a closure ledger: add one owner-approved comment to an existing Notion page, persist only the connection/page/status-property/comment linkage in data.shared, and let a scheduled watcher re-read that exact page and configured status property until Notion reports a terminal status such as done, complete, completed, closed, or archived, or until the page is in trash. This pack does not replace Notion comments, status properties, native notifications, database views, dashboards, reminders, automations, templates, or project management workflows; it adds Recued-visible closure state for page comments Recued created.

pack:notion-page-comment-closurenotionpagescomments
by Recued Core v1 2 items Pack
npm Pack

V3 npm toolchain capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local npm CLI ingredient exposes bounded project operations for readiness, package manifest inspection, lockfile dependency tree inspection, test execution, dependency audit, and CycloneDX SBOM generation. Project operations run from an explicit project directory cwd supplied at execution time, avoid caller-supplied npm flags, avoid shell wrappers, and keep diagnostics visible as text or JSON output. Manifest and lockfile inspection are local and read-only. Test execution is approval-gated because package scripts execute project-defined code. Dependency audit is approval-gated because npm sends dependency inventory to the fixed npm registry. SBOM generation is local and read-only. Requires npm on PATH.

pack:npmnpmjavascriptnodejs
by Recued Core v1 1 item Pack
OCRmyPDF Pack

V3 deterministic searchable-PDF and OCR-text capability pack. By-value connector composition (service_kind=cli, no separate ingredient): one local OCRmyPDF CLI ingredient exposes bounded operations for readiness, searchable-PDF generation, and OCR sidecar text extraction. Bundles a direct searchable-PDF recipe plus a scanned-document notes workflow that chains OCRmyPDF with PDF text extraction and preview-first AI summarization. Fixed-function and reproducible: the executor materializes the source file and owns the throwaway output directory, while OCRmyPDF writes fixed captured outputs. Write-tier but approval=never: OCRmyPDF writes only to engine-managed output dirs, exposes no arbitrary plugin/config flags, no caller-supplied output paths, no deskew/clean/rotate mutators, no force-ocr, no Tesseract config overrides, and source bytes never flow through op-step values. Requires ocrmypdf plus Tesseract language data on PATH (Debian/Ubuntu: apt install ocrmypdf tesseract-ocr-eng). Local and no-egress.

pack:ocrmypdfocrmypdfcliocr
by Recued Core v1 3 items Pack
Identity Governance - Okta

API capability pack for bounded Okta Management API v1 operations. Enroll an okta API connection with base_url set to the tenant API root, for example https://example.okta.com/api/v1, and authenticate with a scoped OAuth/OIDC bearer token where available; a tightly scoped SSWS-token header connection can also be used when the tenant still relies on API tokens. The pack reads users, user groups, user app links, groups, group members, applications, application users, and System Log events for access governance, offboarding review, and identity incident triage. It bundles a scheduled access hygiene digest, an AI-assisted user access brief, and approval-gated workflows for suspending/unsuspending one user and adding/removing one user from one group. The pack intentionally excludes user creation, deactivation, deletion, password and factor reset flows, authenticator enrollment mutation, role/admin assignment, app assignment mutation, policy/profile/schema mutation, token/session/recovery-factor administration, domain/network/brand/rate-limit/admin APIs, and arbitrary API passthrough.

pack:oktaoktaidentityaccess-governance
by Recued Core v1 7 items Pack
Files - OneDrive

API capability pack for bounded OneDrive metadata operations through Microsoft Graph at https://graph.microsoft.com/v1.0 only. Reads the current user, current drive, root drive item, drive-item metadata, folder children, root-folder children, root delta changes, file versions, sharing permissions, and followed items. It supports approval-gated daily organization actions: create folders, rename drive items, move drive items within a drive, asynchronously copy drive items, and follow or unfollow drive items. File upload/download, sharing-link creation, permission mutation, delete/trash, conflict-behavior tuning, and arbitrary Microsoft Graph passthrough are intentionally not exposed in this metadata pack. Enroll a Microsoft Graph OAuth access token connection as bearer auth; no credential is embedded in the manifest.

pack:onedriveonedrivemicrosoft-graphfiles
by Recued Core v1 1 item Pack