# Sn Scripting

> >

- **Type:** Skill
- **Install:** `agentstack add skill-aatrey882-servicenow-agent-skills-sn-scripting`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [aatrey882](https://agentstack.voostack.com/s/aatrey882)
- **Installs:** 0
- **Category:** [Agent Skills](https://agentstack.voostack.com/c/agent-skills)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [aatrey882](https://github.com/aatrey882)
- **Source:** https://github.com/aatrey882/servicenow-agent-skills/tree/main/sn-scripting

## Install

```sh
agentstack add skill-aatrey882-servicenow-agent-skills-sn-scripting
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# ServiceNow Legacy Scripting

ServiceNow legacy scripting uses the GlideRecord API for server-side data access, Script Include classes for reusable server-side logic, Business Rules for server-side automation, and g_form/g_user/g_list for client-side form manipulation. All APIs are described in the reference files below.

## References

Read these files when you need them — do not pre-load all references at session start. Paths are relative to the skill root (the directory containing this `SKILL.md` file).

| File | When to Read |
|------|-------------|
| `references/gliderecord.md` | Generating or reviewing GlideRecord queries, CRUD operations, or addQuery/getValue patterns |
| `references/server-side.md` | Generating Script Includes, Business Rules, or using GlideSystem (gs.*) logging |
| `references/client-side.md` | Generating Client Scripts using g_form, g_user, or g_list; or any client-side form manipulation |
| `references/gotchas.md` | Before generating or reviewing any ServiceNow script — check for hallucination traps |

## Scripts

| Script | When to use |
|--------|------------|
| `scripts/validate-script.sh` | When validating a ServiceNow script file for common issues before deploying |

## Examples

Use these as structural templates — only read the example that matches your target type, do not pre-load all examples:

| File | Demonstrates |
|------|-------------|
| `assets/examples/gliderecord-crud.js` | Complete GlideRecord CREATE, READ (single and multi), UPDATE, DELETE with correct getValue() usage |
| `assets/examples/script-include-class.js` | Script Include using Class.create() pattern with initialize(), utility methods, and type property |
| `assets/examples/client-script-gform.js` | Client Script onLoad/onChange handlers using g_form.getValue(), g_form.setMandatory(), g_user.hasRole() |

## Hard Rules

1. **Never use GlideRecord when ServiceNow Fluent SDK is present.**
   If the workspace contains `now.config.json`, `.now.ts` files, or imports from `@servicenow/sdk/core`,
   the developer is working in a Fluent SDK application. Stop and redirect:
   "I can see you're working in a Fluent SDK project. Use the sn-sdk-fluent skill to generate
   typed metadata definitions instead of GlideRecord scripts. GlideRecord is the legacy scripting
   API and does not work inside Fluent SDK `.now.ts` files."

2. **GlideRecord is server-side only** — never generate GlideRecord in a Client Script. Use GlideAjax.

3. **Always call query() before next()** — while(gr.next()) without gr.query() never executes.

4. **Use getValue() in loops** — gr.field_name returns a pointer; gr.getValue('field_name') returns the string value.

5. **Only use documented API methods** — do not invent methods like gr.getField(), gr.setQuery(), or gr.addOrder().

## Behavior by Task Type

### Generating

1. Check for Fluent SDK signals first (Hard Rule 1) — if detected, redirect immediately; do not generate GlideRecord code.
2. Identify the script context: server-side (Business Rule, Script Include) or client-side (Client Script).
3. For server-side: read `references/gliderecord.md` for CRUD patterns, `references/server-side.md` for Script Include structure and Business Rule context variables.
4. For client-side: read `references/client-side.md` for g_form/g_user/g_list APIs. Never generate GlideRecord in a client script (Hard Rule 2).
5. Use example files in `assets/examples/` as working templates.

### Reviewing

1. Check Hard Rules 3 and 4: query() before next(), getValue() in loops.
2. Verify no GlideRecord in client-side code (Hard Rule 2).
3. Verify no invented methods — compare against `references/gliderecord.md` documented API (Hard Rule 5).
4. Run `scripts/validate-script.sh ` to check for GlideRecord in client scripts, bare setAbortAction, and g_form misuse.

### Explaining

1. Route the developer to the relevant reference file for detailed method documentation.
2. For Fluent SDK questions, redirect to the sn-sdk-fluent skill.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [aatrey882](https://github.com/aatrey882)
- **Source:** [aatrey882/servicenow-agent-skills](https://github.com/aatrey882/servicenow-agent-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-aatrey882-servicenow-agent-skills-sn-scripting
- Seller: https://agentstack.voostack.com/s/aatrey882
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
