XML Tools · emploidai Marketplace
emploidai Marketplace
Add-onsAppletsPlugins
Search tools, teams, and capabilitiesPublish
MarketplacePluginsXML Tools
Plugin
Limited listing

XML Tools

by morethanjustpassion · v0.0.1

Offline XML utilities - convert to JSON, extract by XPath, format and validate against XSD. No network access required.

132 installsUpdated Jul 17, 2026
Publisher information is incomplete

This community listing does not yet include every recommended support, privacy, pricing, and permission disclosure. Review the available package permissions before installing.

Capabilities

Tools

Available inside your emploidai workspace after installation.

Data sources

Available inside your emploidai workspace after installation.

Category

tool

Version

0.0.1morethanjustpassion

Requirements

Maximum memory 256MB

Pricing

Not disclosed by publisher

Security & access

Review before installing

CompatibleRequires emploidai 1.0.0+

Permissions

No permissions were declared by the publisher.

Dependencies

No additional dependencies

Resources

Privacy policy
emploidai Marketplace

Discover capabilities. Review access. Install inside your workspace.

DocumentationSecuritySupportPrivacyTerms

XML Tools

Offline XML utilities for Dify: convert XML to JSON, extract values with XPath, format or minify documents, and validate against an XSD schema.

All processing happens inside the plugin runtime. The plugin makes no network requests, calls no third-party APIs, and requires no credentials.

  • Source repository: https://github.com/morethanjustpassion/dify-plugin-xml-tools
  • Contact: hsyhushuyou@163.com

Why this plugin

Dify workflows frequently receive XML rather than JSON — SOAP responses, ERP and MES interface payloads, RSS bodies, and legacy system exports. Today the only way to handle these is a Code node with hand-written parsing, which requires editing the sandbox dependency list and gives every workflow author a fresh opportunity to write an XXE-vulnerable parser.

No existing Marketplace plugin covers XML parsing. json_process handles JSON only; md_exporter can write XML files but cannot read them.

Setup

No configuration required. Install the plugin and the four tools are immediately available in Chatflow, Workflow, and Agent applications.

  • Required APIs: none
  • Required credentials: none
  • Network access: none
  • Connection requirements: none

Tools

XML to JSON

Converts an XML document into a JSON object. Attributes are prefixed (@ by default) and text content is keyed as #text.

ParameterTypeDefaultDescription
xml_contentstring—The XML document to convert
strip_namespacebooleantrueRemove namespace prefixes from keys
attr_prefixstring@Prefix used for XML attributes

Input:

<Order no="SI001"><Item code="M-001"><Qty>120</Qty></Item></Order>

Output:

{"Order": {"@no": "SI001", "Item": {"@code": "M-001", "Qty": "120"}}}

XPath Extract

Extracts nodes, attributes, or text using an XPath 1.0 expression. Use this instead of converting the whole document when only a few fields are needed.

ParameterTypeDefaultDescription
xml_contentstring—The XML document to query
xpathstring—XPath 1.0 expression
strip_namespacebooleantrueStrip namespaces so XPath needs no prefixes

Returns {"count": n, "results": [...]}. Element matches include tag, text, attributes, and the raw XML subtree.

XML Format

Pretty-prints or minifies a document. Also serves as a well-formedness check.

ParameterTypeDefaultDescription
xml_contentstring—The XML document to format
modeselectprettypretty or minify
recoverbooleanfalseTolerate minor syntax errors

XML Validate

Validates a document against an XSD schema.

ParameterTypeDefaultDescription
xml_contentstring—The XML document to validate
xsd_contentstring—The XSD schema source

Returns {"valid": bool, "errors": [{"line", "column", "message"}]}.

Security boundary

XML parsing of untrusted input is a well-known attack surface. This plugin constrains it explicitly:

RiskMitigation
XXE (external entity injection)resolve_entities=False (lxml), disable_entities=True (xmltodict)
SSRF via external entitiesno_network=True (lxml) — the parser cannot make network requests
Billion Laughs / entity expansionEntities disabled entirely, plus huge_tree=False
Memory exhaustionInput capped at 10 MB (MAX_XML_BYTES in tools/_common.py)

XSD schemas are accepted as inline source only. There is no parameter that accepts a URL, so no user input can direct the plugin at a network destination.

Errors are returned as plain messages. No credentials exist to leak, and stack traces are not exposed to the caller.

Dependencies

PackagePurpose
xmltodictXML to JSON conversion
lxmlXPath 1.0 and XSD validation

lxml is a compiled extension. It is required because Python's standard library has no XSD validation and only supports a limited XPath subset.

Limitations

  • XPath 1.0 only (lxml's xpath() does not implement XPath 2.0/3.0)
  • XSD schemas must be supplied inline; xs:import/xs:include from remote URLs will not resolve, by design
  • Namespace declarations (@xmlns:*) are retained on the root when strip_namespace is enabled

License

MIT