by morethanjustpassion · v0.0.1
Offline XML utilities - convert to JSON, extract by XPath, format and validate against XSD. No network access required.
This community listing does not yet include every recommended support, privacy, pricing, and permission disclosure. Review the available package permissions before installing.
Available inside your emploidai workspace after installation.
Available inside your emploidai workspace after installation.
Offline XML utilities for Dify: convert XML to JSON, extract values with XPath, format or minify documents, and validate against an XSD schema.
All processing happens inside the plugin runtime. The plugin makes no network requests, calls no third-party APIs, and requires no credentials.
Dify workflows frequently receive XML rather than JSON — SOAP responses, ERP and MES interface payloads, RSS bodies, and legacy system exports. Today the only way to handle these is a Code node with hand-written parsing, which requires editing the sandbox dependency list and gives every workflow author a fresh opportunity to write an XXE-vulnerable parser.
No existing Marketplace plugin covers XML parsing. json_process handles JSON
only; md_exporter can write XML files but cannot read them.
No configuration required. Install the plugin and the four tools are immediately available in Chatflow, Workflow, and Agent applications.
Converts an XML document into a JSON object. Attributes are prefixed (@ by
default) and text content is keyed as #text.
| Parameter | Type | Default | Description |
|---|---|---|---|
xml_content | string | — | The XML document to convert |
strip_namespace | boolean | true | Remove namespace prefixes from keys |
attr_prefix | string | @ | Prefix used for XML attributes |
Input:
<Order no="SI001"><Item code="M-001"><Qty>120</Qty></Item></Order>
Output:
{"Order": {"@no": "SI001", "Item": {"@code": "M-001", "Qty": "120"}}}
Extracts nodes, attributes, or text using an XPath 1.0 expression. Use this instead of converting the whole document when only a few fields are needed.
| Parameter | Type | Default | Description |
|---|---|---|---|
xml_content | string | — | The XML document to query |
xpath | string | — | XPath 1.0 expression |
strip_namespace | boolean | true | Strip namespaces so XPath needs no prefixes |
Returns {"count": n, "results": [...]}. Element matches include tag, text,
attributes, and the raw XML subtree.
Pretty-prints or minifies a document. Also serves as a well-formedness check.
| Parameter | Type | Default | Description |
|---|---|---|---|
xml_content | string | — | The XML document to format |
mode | select | pretty | pretty or minify |
recover | boolean | false | Tolerate minor syntax errors |
Validates a document against an XSD schema.
| Parameter | Type | Default | Description |
|---|---|---|---|
xml_content | string | — | The XML document to validate |
xsd_content | string | — | The XSD schema source |
Returns {"valid": bool, "errors": [{"line", "column", "message"}]}.
XML parsing of untrusted input is a well-known attack surface. This plugin constrains it explicitly:
| Risk | Mitigation |
|---|---|
| XXE (external entity injection) | resolve_entities=False (lxml), disable_entities=True (xmltodict) |
| SSRF via external entities | no_network=True (lxml) — the parser cannot make network requests |
| Billion Laughs / entity expansion | Entities disabled entirely, plus huge_tree=False |
| Memory exhaustion | Input capped at 10 MB (MAX_XML_BYTES in tools/_common.py) |
XSD schemas are accepted as inline source only. There is no parameter that accepts a URL, so no user input can direct the plugin at a network destination.
Errors are returned as plain messages. No credentials exist to leak, and stack traces are not exposed to the caller.
| Package | Purpose |
|---|---|
xmltodict | XML to JSON conversion |
lxml | XPath 1.0 and XSD validation |
lxml is a compiled extension. It is required because Python's standard library
has no XSD validation and only supports a limited XPath subset.
xpath() does not implement XPath 2.0/3.0)xs:import/xs:include from remote URLs
will not resolve, by design@xmlns:*) are retained on the root when
strip_namespace is enabledMIT