NetSuite 2026.1 SuiteCloud Agent Skills: Choose by Development Task
Choose the right SuiteCloud Agent Skill for SuiteScript migration, SDF permissions, UIF SPA components, record-field lookups, security reviews, and project documentation. This task-based guide explains what each development skill covers and where its scope ends.
NetSuite 2026.1 SuiteCloud Agent Skills provide structured guidance for common NetSuite and SuiteCloud workflows. Choose by the result you need: a migrated script, verified field metadata, reviewed permissions, a UIF component reference, or project documentation. A broad label such as “SDF development” is not enough to distinguish these tasks.
TL;DR: Use netsuite-suitescript-upgrade for version migration, netsuite-suitescript-records-reference for field lookups, netsuite-sdf-roles-and-permissions for access configuration, and netsuite-uif-spa-reference for component APIs. Separate skills address security, documentation, SAFE-based development practices, learning, and AI-to-NetSuite sessions. The finance analyst skill serves finance workflows, not general development.
How to choose a SuiteCloud Agent Skill
Start with the artifact or decision you need. “Improve our SDF project” could mean checking permission configuration, generating Object XML, explaining governance, or producing a deployment guide. Name that deliverable before selecting a skill.
The official SuiteCloud Agent Skills reference describes structured guidance intended to standardize processes, improve task accuracy, and reinforce security practices such as least-privilege access. The GitHub skill collection is another supplied reference. Treat the stated coverage as a way to frame work, not as a substitute for reviewing the resulting code or configuration.
| Task | Best-matched skill | Stated focus |
|---|---|---|
| Guide an AI-to-NetSuite session | netsuite-ai-connector-instructions |
Tool selection, safe SuiteQL, output formatting, subsidiaries, and currencies |
| Generate or review SDF permissions | netsuite-sdf-roles-and-permissions |
customrole XML, script deployment permissions, permission IDs and levels |
| Build or debug UIF SPA components | netsuite-uif-spa-reference |
API and type lookup for @uif-js/core and @uif-js/component |
| Review secure coding | netsuite-owasp-secure-coding |
OWASP practices, security patterns, and GOOD/BAD templates |
| Migrate SuiteScript to 2.1 | netsuite-suitescript-upgrade |
Analysis, conversion, explanation, and validation |
| Document an SDF project | netsuite-sdf-project-documentation |
Project analysis, README.md, diagrams, deployment guides, and troubleshooting tables |
| Look up record fields | netsuite-suitescript-records-reference |
Field IDs, types, required status, and search capabilities |
| Apply broader SDF practices | netsuite-sdf-safe-guide |
SAFE principles, Object XML, governance, and defensive coding |
| Learn NetSuite SDF development | netsuite-suitescript-learning |
Six learning modes with SAFE Guide integration |
| Support financial analysis | netsuite-finance-analyst |
Finance analysis and operations, not general development |
For the broader concept behind reusable guidance, see our overview of SuiteCloud Agent Skills for AI-assisted development. The sections below focus on choosing a named skill for the next piece of work.
AI-to-NetSuite sessions: netsuite-ai-connector-instructions
Use netsuite-ai-connector-instructions when the task concerns an AI session interacting with NetSuite through the NetSuite AI Service Connector. Its coverage includes correct tool selection, safe SuiteQL usage, consistent output formatting, and proper multi-subsidiary and currency handling.
For example, a request to retrieve and present information across subsidiaries calls for attention to both the query and its context. Frame the review around tool choice, SuiteQL safety, subsidiary and currency handling, and the answer’s format.
That is a different deliverable from converting a script or documenting an SDF project. Keep skill selection separate from client integration questions; our guide to using skills with Claude and ChatGPT in NetSuite 2026.1 addresses that related context.
SDF permissions: netsuite-sdf-roles-and-permissions
Choose netsuite-sdf-roles-and-permissions for generating or reviewing SDF permission configurations. Examples include customrole XML and script deployment permissions. The skill validates permission IDs and levels using NetSuite reference data.
The distinction from secure coding is the object of the review. A permission configuration can need reference checks without any application code changing; an injection-risk review concerns code behavior rather than permission identifiers.
For a focused request, provide the configuration and describe the intended access. Ask for permission ID and level validation separately from least-privilege recommendations. Before adopting changes, compare the proposed configuration with that intended access. Configuration assistance should not be treated as authorization to change settings.
UIF SPA components: netsuite-uif-spa-reference
Use netsuite-uif-spa-reference to build, modify, or debug NetSuite User Interface Framework Single Page Application components. It supplies API and type lookup for @uif-js/core and @uif-js/component, including constructors, methods, props, enums, hooks, and component options.
Scope the request around the uncertainty. If a component change depends on supported props or options, ask for that lookup before requesting a rewrite. For a method or hook investigation, include the relevant code and describe the behavior you are examining.
This skill addresses component references, not SuiteScript record-field metadata. Keep those questions separate so each answer can be reviewed against the appropriate reference. Do not infer an exact constructor signature from a component name alone.
Secure coding: netsuite-owasp-secure-coding
Select netsuite-owasp-secure-coding when the main question is whether code follows secure development practices. It is platform-agnostic, with JavaScript/Node.js patterns and NetSuite SuiteScript examples.
Coverage includes Open Worldwide Application Security Project (OWASP) Top 10 (2021), output encoding, injection prevention, CSP headers, file security, API hardening, AI agent security, and DRY security patterns. It also includes 48+ security pitfalls with GOOD/BAD code templates.
A useful review request identifies how input reaches a query, how content reaches output, or how a file-handling operation is protected. Ask for the relevant pattern and an explanation of the proposed change, rather than only a list of concerns. Keep SDF permission validation with the permissions skill: the reviews are complementary, not interchangeable. A template is a review aid, not proof that the surrounding application is secure.
SuiteScript migration: netsuite-suitescript-upgrade
Choose netsuite-suitescript-upgrade for SuiteScript 1.0, 2.0, and 2.x migrations to 2.1. It analyzes, converts, explains, and validates upgrades, making it more directly suited to modernization than a request to “clean up this script.”
Its stated coverage is specific:
- 125+ API mappings.
- 34 object conversions.
- 13 unmapped API workarounds.
- All script type entry point changes.
- SuiteScript 2.0/2.x to 2.1 upgrade guidance.
- 16 categories of breaking behavioral changes.
These counts describe coverage, not guarantees for an individual migration. A practical request sequence is to provide the existing script and source version, request analysis of relevant mappings and entry points, then ask for conversion with explanations of behavioral changes and workarounds. Review the validation output and test affected behavior before accepting the migration.
Keep whole-script migration separate from individual API syntax questions. Our SuiteScript 2.1 guide to documentCapture.getRemainingFreeUsage.promise() addresses a particular method rather than the migration process.
Project documentation: netsuite-sdf-project-documentation
Use netsuite-sdf-project-documentation when the deliverable is documentation rather than code conversion or a learning exercise. It analyzes scripts, object XML files, manifest.xml, and SuiteQL queries to produce README.md, Mermaid/ASCII architecture diagrams, deployment guides, and troubleshooting tables.
For a handover, name the audience and required outputs. A maintainer may need architecture explanations; a deployment audience may need a guide grounded in the project’s artifacts. Review generated descriptions against those inputs so assumptions do not become instructions.
Post-deployment integration is conditional: the skill can integrate with documentation workflows when automation, such as hooks, is available. Establish the project’s automation arrangement before planning documentation as an automatic post-deployment step. The source does not claim that a hook is already configured.
Record-field lookup: netsuite-suitescript-records-reference
Use netsuite-suitescript-records-reference when building SuiteScript requires record or field metadata. It looks up field IDs, types, required status, and search capabilities for all 272 NetSuite record types.
Name the record type and request the metadata needed for the decision. An identifier alone may not answer the question: field type, required status, and search capability can also matter. Ask for those attributes together when relevant.
Even on the same script, this is distinct from migration. The upgrade assistant addresses version changes; records reference addresses record and field usage. For work involving account-specific customization, review the account configuration rather than assuming general reference coverage resolves every local detail.
Broader SDF guidance: netsuite-sdf-safe-guide
Choose netsuite-sdf-safe-guide for broader SuiteApp and Account Customization development guidance. It is based on the SAFE Guide’s 12 principles plus appendices. Coverage includes Object XML generation for all 14 script types, governance limits, security patterns, and defensive coding.
Its scope also includes N/cache, N/query, concurrency limits, OAuth 2.0 guidance, legacy TBA guardrails, CustomTool runtime patterns, REST Web Services (2026.1 features), and 139+ documented pitfalls.
For a practice-oriented review, ask for the relevant SAFE principles and applicable pitfalls. If Object XML is the deliverable, specify the script type and intended purpose. Keep numeric governance or concurrency decisions tied to applicable guidance: listing those topics does not establish a universal limit value.
Developer learning: netsuite-suitescript-learning
Despite its name, netsuite-suitescript-learning is described as an interactive learning system for NetSuite SDF development. It offers six modes: learn, review, explain, annotate, quiz, and final. SAFE Guide integration supports topics such as governance, N/cache, and security, and the skill produces compliance-reviewed learning documentation.
Choose a mode by the learning outcome. Explanation can focus on why a practice matters; annotation can help examine existing code; quizzes can use code or SAFE Guide content to test comprehension.
For onboarding, pair a concrete code example with the concept being taught, then use a review or quiz to check understanding. A completed learning exercise and a validated production change are different deliverables.
Finance scope: netsuite-finance-analyst
The available list also includes netsuite-finance-analyst. It supports Director of Financial Analysis workflows, including period-end and month-end close guidance, financial statement analysis, budget-versus-actual and variance review, AR/AP aging, reconciliation and journal entry review, SOX-oriented checks, cash reporting, and CFO- or board-ready narratives.
It is explicitly not for general NetSuite development or non-finance administration. A developer selecting a skill for code, components, or SDF configuration should therefore choose from the development-focused entries above rather than treating this as a general-purpose option.
FAQ
Should I use the upgrade skill or records reference for an existing script?
Choose by the question. Use netsuite-suitescript-upgrade for version migration; use netsuite-suitescript-records-reference for field IDs, types, required status, and search capabilities. A script review may contain both questions, but they should be framed separately.
How do SDF permissions and SAFE guidance differ?
netsuite-sdf-roles-and-permissions focuses on permission configurations and permission ID/level validation. netsuite-sdf-safe-guide covers broader development practices, including Object XML, governance, security patterns, and defensive coding.
Can documentation generation run after deployment?
The documentation skill can integrate with post-deployment workflows when automation, such as hooks, is available. Confirm that prerequisite before treating it as an automatic workflow.
Related reading
For narrower API questions rather than skill selection: