> ## Documentation Index
> Fetch the complete documentation index at: https://docs.oasm.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# manifest.yaml

> Declare a connector — the required and optional fields, input and config schemas, and how the catalog is generated

`manifest.yaml` is written by hand next to the connector's code and validated when the catalog is aggregated. Unknown fields are rejected, so typos fail the build instead of silently doing nothing.

```yaml theme={null}
name: Nuclei
slug: nuclei
version: 3.4.1
image: ghcr.io/oasm-platform/connector-nuclei:3.4.1
author: 'oasm'
pricingTier: [free]
homepage: 'https://projectdiscovery.io'
repositoryUrl: 'https://github.com/oasm-platform/oasm-connectors'
supportUrl: 'https://github.com/oasm-platform/oasm-connectors/issues'
shortDescription: 'Fast template-based vulnerability scanner'
description: 'Runs template-based scans against a target URL to detect known vulnerabilities, misconfigurations, and exposed secrets.'
capabilities: [vulnerabilities]
inputsSchema:
  type: object
  required: [target]
  properties:
    target:
      type: string
      format: uri
      title: Scan target
      description: 'Target URL or hostname to scan.'
      examples: [https://example.com]
      ui:placeholder: 'https://example.com'
  additionalProperties: false
configSchema:
  type: object
  additionalProperties: false
  properties:
    severity:
      type: array
      items:
        type: string
        enum: [info, low, medium, high, critical]
      title: Severity levels
      description: 'Only report findings at the selected severity levels.'
      default: [high, critical]
resourceDefaults:
  cpu: 500m
  memory: 4096Mi
  timeoutSeconds: 600
```

## Fields

| Field | Required | Notes |
| - | - | - |
| `name` | yes | Human display name. Free-form, may contain spaces and uppercase. |
| `slug` | yes | System-wide unique ID, `^[a-z0-9-]+$`. Drives the image tag and container naming. |
| `version` | yes | Version of the wrapped tool. Used as the default image tag. |
| `image` | yes | Fully qualified image reference for the build. |
| `author` | yes | Maintainer. |
| `pricingTier` | yes | Non-empty list of `free` / `paid` (case-normalized). |
| `shortDescription` | yes | One line, shown in list views. |
| `description` | yes | Full paragraph for the detail view. |
| `capabilities` | yes | At least one non-empty entry; also drives directory grouping by category. |
| `homepage` | no | Non-empty string when set. |
| `repositoryUrl` | no | Non-empty string when set. |
| `supportUrl` | no | Non-empty string when set. |
| `inputsSchema` | no | JSON Schema for the per-run inputs the operator supplies. |
| `configSchema` | no | JSON Schema for the tool profile. Adapters read it as `OASM_CONFIG`. |
| `resourceDefaults` | no | Scheduler hints, e.g. `cpu`, `memory`, `timeoutSeconds`. |

## Input and config schemas

`inputsSchema` describes the **per-run** inputs — a target, a scope. `configSchema` describes the **tool profile** — settings that persist across runs. Both are plain JSON Schema plus two annotation keys:

* `title` and `description` label fields in the console.
* `ui:placeholder` provides input hints.

Only `type`, `required`, `properties`, `items`, `enum`, `default`, `examples`, and `format` carry validation weight; the annotations are for rendering.

See [Inputs & config](/connectors/inputs-and-config) for how these values reach the adapter.

## Icon

An optional `logo.png` sibling is downscaled to a 128px long edge if larger, then embedded base64 in the generated `manifest.json`. Logos never appear in YAML.

## Aggregation rules

`manifest.json` is a **generated artifact** — regenerate it, never edit it by hand.

```bash theme={null}
task manifest
```

* Duplicate slugs across the repo are a hard error.
* Empty `capabilities` and invalid `pricingTier` entries fail the build.
* Entries in `manifest.json` are sorted by `name`; a `generatedAt` timestamp makes every regeneration a diff.
* An oversized `logo.png` is rewritten in place, so the repo file stays byte-identical to the embedded icon.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.