Securely inspect and automate microscopy data workflows against OMERO.server with omero-py, BlitzGateway, OMERO CLI, tables, annotations, ROIs, rendering, and documented OMERO.web APIs. Use for scoped OMERO inventory, metadata export, import/export planning, or reviewed write workflows.
79
100%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Use current OME documentation and the smallest explicit data scope. OMERO data may contain unpublished images, identifiers, annotations, original files, and derived measurements.
This skill was refreshed on 2026-07-23:
omero-py==5.22.1 requires Python 3.10 or newer. The OMERO support matrix
supports 3.10 and 3.11, recommends 3.12, and still labels 3.13/3.14
“upcoming.”The pin above is a reproducible skill snapshot, not a promise that every
OMERO.server release accepts that client. For another server version, consult
its release entry and use the OMERO.py version tested with it. See
references/sources.md.
OMERO_* variables in the frontmatter.
Never search parent directories or load .env files.secure=True. OMERO encrypts login by default, but post-login
data and the session ID may otherwise travel unencrypted. secure=True does
not by itself guarantee certificate hostname verification.BlitzGateway, table handles, raw stores, thumbnail stores, rendering
engines, script clients, and other stateful services in finally blocks or
documented context-manager patterns.omero-py): primary Python client for object traversal,
pixels, annotations, ROIs, rendering, and services.OMERODIR.api and webgateway: the only OMERO.web apps that official
documentation calls stable public APIs. The documented JSON API is
version-discovered and has limited object coverage; it is not evidence that
every webclient URL is a supported REST endpoint.scripts/.Create a Python 3.12 environment:
uv venv --python 3.12 .venv
source .venv/bin/activateInstall the exact IcePy 3.6.5 wheel matching the interpreter, OS, architecture, and wheel tags, then OMERO.py:
# Download the matching 3.6.5 wheel from the official OMERO-linked matrix.
uv pip install "/absolute/path/to/zeroc_ice-3.6.5-<matching-tags>.whl"
uv pip install "omero-py==5.22.1"Do not substitute Ice 3.7: the OMERO 5.6 support matrix marks Ice 3.6 as recommended and 3.7 as unsupported. A plain install may attempt to compile IcePy from source; prefer a reviewed matching wheel. The upstream package is GPL-2.0-or-later; this skill’s own files are MIT.
For import/admin commands only, OMERODIR must point to a compatible extracted
OMERO.server directory. A normal remote BlitzGateway client does not require
that server tree. Read references/connection.md
before installation or authentication work.
Set named variables in the calling environment or secret manager. Do not put
the password on an omero CLI command:
export OMERO_HOST="omero.example.org"
export OMERO_PORT="4064"
export OMERO_USER="researcher"
export OMERO_SECURE="true"
# Supply OMERO_PASSWORD through the environment/secret manager, or use
# OMERO_SESSION_KEY as an alternative. Do not echo either value.A password-authenticated, exception-safe read pattern is:
import os
from omero.gateway import BlitzGateway
conn = None
try:
conn = BlitzGateway(
os.environ["OMERO_USER"],
os.environ["OMERO_PASSWORD"],
host=os.environ["OMERO_HOST"],
port=int(os.environ.get("OMERO_PORT", "4064")),
secure=True,
)
if not conn.connect():
raise RuntimeError("OMERO connection failed")
images = conn.getObjects(
"Image",
opts={"limit": 25, "offset": 0, "order_by": "obj.id"},
)
for image in images:
print(image.getId()) # Do not print names unless requested.
finally:
if conn is not None:
conn.close()For existing-session and CLI prompt patterns, certificate verification,
group context, and cleanup details, read
references/connection.md.
All helpers use argparse; --help works without OMERO installed. Remote
helpers are dry-run by default and require --execute.
python -B scripts/validate_config.py --help
python -B scripts/inventory.py --help
python -B scripts/export_image_metadata.py --help
python -B scripts/plan_transfer.py --helpvalidate_config.py: validates only named endpoint/auth variables locally;
optional DNS resolution still does not contact OMERO.inventory.py: bounded, read-only object inventory with paged JSON output.export_image_metadata.py: explicit-image annotation/ROI JSON export with
redaction defaults and per-category limits; it never downloads file bytes or
pixels.plan_transfer.py: local-only import scan or per-image export plan; it never
invokes OMERO and never emits credential flags.Read references/scripts.md before using them.
references/connection.mdreferences/data_access.mdreferences/metadata.mdreferences/image_processing.mdreferences/rois.mdreferences/tables.mdreferences/scripts.mdreferences/advanced.md757b63b
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.