CU

custom-builtin-functions

Guidance for creating and registering custom Go functions for Rego policies.

Install

mkdir -p .claude/skills/custom-builtin-functions && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/8538" && unzip -o skill.zip -d .claude/skills/custom-builtin-functions && rm skill.zip

Installs to .claude/skills/custom-builtin-functions

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Create a custom builtin function to be used in the Rego policy engine
69 charsno explicit “when” trigger
Advanced

Key capabilities

  • Define custom Go functions for OPA
  • Register functions with the OPA engine
  • Implement logic using BuiltinContext
  • Use custom functions in Rego policies

How it works

Custom functions are written in Go, registered with the OPA engine, and then invoked within Rego policy files using the chainloop namespace.

Inputs & outputs

You give it
String value passed to the custom function
You get back
String result returned to the Rego policy

When to use custom-builtin-functions

  • Extend OPA policy engine
  • Register custom Go logic for policies
  • Implement complex policy validation

About this skill

Policy Engine Extension

The OPA/Rego policy engine supports custom built-in functions written in Go.

Adding Custom Built-ins:

  1. Create Built-in Implementation (e.g., pkg/policies/engine/rego/builtins/myfeature.go):
package builtins

import (
    "github.com/open-policy-agent/opa/ast"
    "github.com/open-policy-agent/opa/topdown"
    "github.com/open-policy-agent/opa/types"
)

const myFuncName = "chainloop.my_function"

func RegisterMyBuiltins() error {
    return Register(&ast.Builtin{
        Name: myFuncName,
        Description: "Description of what this function does",
        Decl: types.NewFunction(
            types.Args(types.Named("input", types.S).Description("this is the input")),
            types.Named("result", types.S).Description("this is the result"),
        ),
    }, myFunctionImpl)
}

func myFunctionImpl(bctx topdown.BuiltinContext, operands []*ast.Term, iter func(*ast.Term) error) error {
    // Extract arguments
    input, ok := operands[0].Value.(ast.String)
    if !ok {
        return fmt.Errorf("input must be a string")
    }

    // Implement logic
    result := processInput(string(input))

    // Return result
    return iter(ast.StringTerm(result))
}

// Autoregisters on package load
func init() {
    if err := RegisterMyBuiltins(); err != nil {
        panic(fmt.Sprintf("failed to register built-ins: %v", err))
    }
}
  1. Use in Policies (*.rego):
package example
import rego.v1

result := {
    "violations": violations,
    "skipped": false
}

violations contains msg if {
    output := chainloop.my_function(input.value)
    output != "expected"
    msg := "Function returned unexpected value"
}

Guidelines:

  • Use chainloop.* namespace for all custom built-ins
  • Functions that call third party services should be marked as non-restrictive by adding the NonRestrictiveBuiltin category to the builtin definition
  • Always implement proper error handling and return meaningful error messages
  • Use context from BuiltinContext for timeout/cancellation support
  • Document function signatures and behavior in the Description field and parameter definitions

When not to use it

  • When standard Rego built-ins are sufficient

Prerequisites

Go development environment

Limitations

  • Input must be a string
  • Requires Go implementation for every new function

How it compares

This approach allows extending the OPA engine with custom Go logic rather than relying solely on native Rego expressions.

Compared to similar skills

custom-builtin-functions side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
custom-builtin-functions (this skill)09moNo flagsAdvanced
backend-development05moNo flagsAdvanced
crypto-firewall-security07moNo flagsAdvanced
security-owasp02moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

Search skills

Search the agent skills registry