1C:Enterprise Agent Toolkit
Universal Agent Skills for safely working with 1C extensions: an isolated session, selective export and validation before applying changes
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Runs the batch Configurator and can create, load and delete extensions
- Direct work against a live base is only possible through the explicit --allow-live-base and --no-sandbox flags
Install
Manual install
py install.py --agent codexAfter cloning the repo, restart Codex and invoke the skill with $onec-dev.
This is third-party code. Review the repository files before installing.
What it does
The toolkit provides four skills that work with any 1C:Enterprise application configuration: onec-dev picks a safe workflow and tracks change boundaries, onec-selective-export exports only the needed objects using the batch Configurator's -listFile flag, onec-extension-lifecycle creates, exports, imports, backs up, rolls back and deletes a single extension, onec-extension-validate checks BSL, the configuration, applicability and the resulting cfe file. Work always happens in an isolated, marked copy of the file-based infobase: cleanup rejects a disk root, the home and current folders, and an incorrect marker; the password is passed only through an environment variable name. The shared scripts/onec.py CLI is written in the Python standard library with no third-party dependencies, and installs as a plugin via install.py for Codex or Claude Code; the skills/<name>/SKILL.md structure is portable to other agents.
Who it is for. For 1C developers who give an agent access to configuration extensions and want a guarantee it will not touch the main infobase.
Good fit when
- You need an agent to edit 1C extensions in an isolated copy rather than the working base
- You need a selective export of only the needed metadata objects, not a full dump
- You work with both Claude Code and Codex and want the same skills for both
Not a fit when
- You need out-of-the-box handling of UNF-specific objects: the toolkit has no ties to a specific configuration
- You do not have the 1C platform and an infobase installed: they are not part of the project
- You need to work directly against a live base without an isolated session: that only turns on with the explicit --allow-live-base flag
Example request
Create an isolated session for the C:\1cbase infobase, export only the Nomenclature catalog from it and show the structureLimitations
The 1C platform and an infobase are not included in the project and must be available separately. It is integration-tested against a UNF configuration and platform 8.5.1.1343; other configurations and versions carry weaker guarantees. Working against a live base requires the explicit --allow-live-base flag and, for a file-based base, --no-sandbox as well. The README explicitly asks to verify the workflow on a disposable base copy before first use.
How to disable. Remove the skills/onec-* folders and the .claude-plugin/plugin.json or .codex-plugin/plugin.json files from the agent install, or simply stop using the $onec-dev commands.
Security check
- Runs the batch Configurator and can create, load and delete extensions
- Direct work against a live base is only possible through the explicit --allow-live-base and --no-sandbox flags
README in short
The README describes a 60-second install via install.py, a table of four skills, a diagram of the safe cycle (copying the base, an isolated session, selective export, extension change, validation, removing only the session's data), guarantees around cleanup and password handling, a first safe run example via scripts/onec.py, a compatibility table with Codex, Claude Code and other agents, testing requirements via unittest, and a roadmap.
FAQ
Does the toolkit only work with UNF?
No, metadata object names are never hardcoded and are always passed explicitly; UNF was only used for the integration test.
How does the agent get the database password?
The password is never passed directly, only through an environment variable name whose value the agent does not see.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything