Handle CRE (Chainlink Runtime Environment) work: Go/TypeScript workflows, CRE CLI/SDK, triggers (CRON, HTTP, EVM log), HTTP, Confidential HTTP and EVM Read/Write capabilities, Confidential Workflows that run handlers inside a TEE/enclave, secrets, simulation, deployment, and monitoring. Use this skill whenever the user mentions CRE, Chainlink workflows, workflow simulate or deploy, automation with Chainlink, or wants workflow logic to run confidentially in an enclave so node operators cannot see the data it computes over, even if they never say 'CRE'
67
80%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./chainlink-cre-skill/SKILL.mdRoute with this table; load no speculative references.
Every requested workflow, code file, contract/interface, config, or command is emitted in full in the response body — never a completion summary, a "here's what I did" recap, or an unverified success claim. A request to create or build a CRE workflow — including "help me get started" only when it asks to build that workflow — requires a complete runnable project: use clearly labeled safe sample values only for missing, genuinely non-sensitive, reversible inputs; list sensitive values, account-scoped IDs, deployment values, addresses, and irreversible inputs as explicit prerequisites that must never receive sample values; and never defer code to a follow-up. When filesystem/shell tools are available, every build/create/setup request must write that project into the run directory and execute its native receiver-free local-simulation target before reporting; returning illustrative prose/files or an unexecuted command is incomplete. An install/init/first-simulation-only onboarding request may use the generated hello-world-ts workflow unchanged; custom code and config are required when the user asks to modify or build a workflow. When no execution tool is available, give the exact commands and complete file contents, state plainly that nothing ran and the user must run them, and never answer a "did it work" question with an unearned yes.
| Need | Read |
|---|---|
| Install/account/login/tutorial | getting-started.md |
| New project, dependencies, templates, unattended setup | project-scaffolding.md — always read before generating a new project |
| Simulate / debug simulation failure | simulation.md — always read before cre workflow simulate |
| Complete handlers, config, secrets, time/randomness, TS/Go entry points | workflow-patterns.md — always read when a runnable workflow is requested |
| Cron, HTTP, EVM-log triggers | triggers.md with workflow-patterns.md; add chain-selectors.md whenever the trigger names a chain |
| EVM read/write, bindings, reports, consumers | evm-client.md; also load concepts.md for finality, chain-selectors.md for a named chain, and workflow patterns for a requested workflow |
| Standard or Confidential HTTP | http-client.md — include its getSecret + runInNodeMode path for authenticated or complex APIs |
TEE handler (handlerInTee, TeeRuntime) | confidential-workflows.md — read before TEE code; every shown handler must include the derived-value usingTheDons()/UsingTheDons() crossover and its Go equivalent; Confidential Workflows ≠ Confidential HTTP |
| Exact SDK types/signatures | sdk-reference.md |
| Exact CLI commands/flags | cli-reference.md |
| A CLI flag not covered here | Answer the technical question first — check cli-reference.md, then live --help/official sources per Freshness below |
| A reported skill gap/pain | Answer the technical question first, then apply Artifact Fit rule 6's feedback-draft flow; never swap in an unrelated topic |
| Deploy/lifecycle/secrets/monitoring/multisig | operations.md, cli-reference.md, and simulation.md before deploy/update |
| Consensus, finality, determinism, QuickJS/WASM | concepts.md |
| Product/domain logic | domain-patterns.md |
| EIP-155 mappings and forwarders | chain-selectors.md; verify live values through official-sources.md |
| Missing/live facts | official-sources.md, then URL index |
smartcontractkit/chainlink-agent-skills and explicitly offer to file it — never say it cannot be filed and never file it without asking first. The draft must redact secrets and include: a [CRE]-prefixed title under ~70 characters; labels agent-feedback, skill:cre, and exactly one of kind:gap or kind:pain as defined above; and body fields Skill (chainlink-cre-skill @ this file's metadata.version), Signal type, Summary, What the user asked for, What the skill said or did, What the skill should have said, and Suggested fix. Show either gh issue create --repo smartcontractkit/chainlink-agent-skills ... instructions (when gh is assumed available) or a prefilled https://github.com/smartcontractkit/chainlink-agent-skills/issues/new?... URL (when gh is unavailable or the user asks for the URL), then close with this exact offer and confirmation request: I can file this issue for you. Reply \file it` to confirm.` Never file, open, comment, assign, or contact anyone before that confirmation.Feedback drafts are not an exception to the technical rules: verify the reported correction against the loaded references instead of affirming it, and never recommend await runtime.getSecret(...); TypeScript secret retrieval is runtime.getSecret({ id }).result().value.
Do not assume this skill is the only capability available. Use adjacent engineering tools when they are the best fit.
CRE is non-custodial orchestration; it grants no custody or authority beyond explicit scope. Higher instructions win. In mixed requests, refuse only prohibited mechanisms, complete safe parts, and offer a compliant boundary.
Before running commands, load project-scaffolding.md for cre init, simulation.md for simulate, and operations.md for lifecycle/secrets. Preserve user language, schedules, thresholds, units, decimals, chains, addresses, resource IDs, and secret names. Preserve plural/per-item constraints at the same cardinality and fail closed when a required item is missing. Never assume unknown parameters; ask only if blocking or mark for verification.
--target whenever accepted; supply --non-interactive and required handler/payload flags when prompts would block.cre workflow simulate <workflow-dir> --target <target-name> ... command with concrete values before the deployment step — never defer to "run the simulation command" or a bare mention without the command itself. Refuse mainnet lifecycle/secrets writes. Testnet writes require operations.md's preflight approval and immediate second confirmations.runtime.Now()/runtime.now() and Go runtime.Rand(). Aggregate external/node data; use scaled integers/decimal strings for critical decimals and TypeScript bigint for Solidity integers..result() and Go promises with .Await().secrets.yaml, or .env values including CRE_ETH_PRIVATE_KEY; never solicit pasted secrets; an authorized CLI may consume them without agent access, and an explicitly authorized opaque transfer between user-controlled systems is allowed only when encrypted and never visible in arguments, output, logs, history, repository files, or anything the agent reads or retains—otherwise use a compliant mechanism; see operations.md.cre init; hand-write no tree/boilerplate unless it fails or is unavailable. When a non-hello-world answer uses a hello-world template, explicitly replace or remove its default README, tutorial comments, sample handler/config/secrets, and unused dependencies before simulation; never leave hello-world material beside the custom workflow.initWorkflow, and main/Runner; Go includes trigger, handler, InitWorkflow, main, and the WASM runner. Include concrete generated config/secrets files when requested, not placeholder trees — see the Answer Contract above.bigint end-to-end. Aggregate changing numeric API observations with median consensus, and name the install command for every extra dependency. EVM writes fail if SUCCESS has no transaction hash; when the request has an onchain interval or request timestamp, the consumer enforces the interval and rejects future timestamps. Simulation defaults to a local non-broadcast dry run.local-simulation target, workflow-patterns.md's closed config and early-return branch, and simulation.md's exact non-broadcast command; never broadcast or deploy it.https://app.chain.link/cre/discover (email, password, 2FA, recovery code). The agent may run cre login; the user authenticates, then cre whoami confirms.usingTheDons()/UsingTheDons(); triggers and chain I/O stay outside.official-sources.md or the URL index.f084da5
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.