Skills api-and-interface-design
๐Ÿ“ฆ

api-and-interface-design

Content revision r2 Safe โš™๏ธ External commands

Design Stable APIs and Interfaces

Unclear contracts, inconsistent errors, and unsafe retries make APIs difficult to use and evolve. This skill provides practical patterns for typed interfaces, validation boundaries, compatibility, pagination, and idempotency.

Supports: Claude Codex Code(CC)
๐Ÿฅ‰ 78 Bronze

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "api-and-interface-design" from https://skillstore.io/skills/addyosmani-api-and-interface-design.md and its manifest at https://skillstore.io/api/skills/addyosmani-api-and-interface-design/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "api-and-interface-design". Create a contract for a task service with create, list, update, and delete operations.

Expected outcome:

  • Define typed inputs and outputs for each operation.
  • Use plural task resources, consistent status codes, structured errors, and paginated list responses.
  • Make deletion idempotent and specify behavior for missing tasks.

Using "api-and-interface-design". Review a charge endpoint that checks for an idempotency key, charges a card, then stores the key.

Expected outcome:

The sequence has a race because concurrent requests can both pass the check. Claim the key with a unique constraint before the charge, compare request hashes, and define a deliberate response for in-flight duplicates.

Using "api-and-interface-design". Plan a compatible addition of an optional priority field to task creation.

Expected outcome:

Add the optional field without changing existing types or removing fields. Document the default, validate it at the API boundary, update shared types, and add contract tests for old clients.

Security Audit

Safe
v2 โ€ข 9/19/2026 Open versioned report

All 52 static findings are false positives from Markdown backticks, TypeScript template literals, REST examples, and ordinary API terminology. The skill is documentation-only and contains no shell execution, system reconnaissance, prompt injection, or malicious intent.

1
Files scanned
368
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/addyosmani-api-and-interface-design/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/addyosmani-api-and-interface-design/security.svg)](https://skillstore.io/skills/addyosmani-api-and-interface-design?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/addyosmani-api-and-interface-design?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/addyosmani-api-and-interface-design/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/addyosmani-api-and-interface-design.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

addyosmani. (2026). api-and-interface-design security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/addyosmani-api-and-interface-design/audits/2

BibTeX citation

@techreport{addyosmani-addyosmani-api-and-interface-design-2026, author = {addyosmani}, title = {api-and-interface-design security audit report (audit version 2)}, institution = {Skillstore}, year = {2026}, number = {2}, url = {https://skillstore.io/skills/addyosmani-api-and-interface-design/audits/2}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "api-and-interface-design security audit report (audit version 2)" version: "unspecified" type: report authors: - name: "addyosmani" date-released: "2026-09-19" url: "https://skillstore.io/skills/addyosmani-api-and-interface-design/audits/2" identifiers: - type: other value: "skillstore:addyosmani-api-and-interface-design:audit:2" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
55
Architecture
85
Maintainability
87
Content
65
Community
83
Spec Compliance

What You Can Build

Plan a New REST API

Define resource URLs, typed payloads, error responses, pagination, filters, and compatibility rules before implementation.

Review a Public Interface

Inspect an existing API or module boundary for inconsistent contracts, breaking changes, weak validation, and unsafe retry behavior.

Design Reliable Payment Retries

Model idempotency keys, atomic request claims, payload matching, in-flight duplicates, and unknown outcomes for state-changing operations.

Try These Prompts

Draft an API Contract
Design a REST API for [resource]. Define endpoints, typed inputs and outputs, status codes, error bodies, pagination, and naming conventions.
Improve Interface Consistency
Review this API contract for inconsistent response shapes, validation placement, naming, and backward compatibility. Recommend specific changes: [paste contract].
Plan a Safe Interface Evolution
Design an additive migration from [current interface] to [target interface]. Identify consumer risks, compatibility steps, deprecation timing, and verification checks.
Harden a Retried Operation
Design an idempotent workflow for [operation]. Cover key derivation, unique storage, request hashing, concurrent duplicates, unknown outcomes, retention, and failure recovery.

Best Practices

  • Define typed contracts before implementation and keep input models separate from output models.
  • Validate untrusted data at system boundaries, then keep internal functions aligned with shared types.
  • Design state-changing operations for retries, atomic claims, explicit duplicate handling, and durable evidence.

Avoid

  • Returning different error shapes across endpoints or exposing internal server details.
  • Breaking existing fields, skipping pagination, or adding incompatible changes without a migration path.
  • Checking an idempotency key and acting later without an atomic uniqueness guarantee.

Frequently Asked Questions

What kinds of interfaces does this skill cover?
It covers REST APIs, GraphQL schemas, module boundaries, component props, and other public contracts between system parts.
Does this skill generate implementation code?
It provides design guidance and illustrative TypeScript examples. It does not implement, deploy, or test the complete system.
When should validation occur?
Validate external input at API, form, configuration, and third-party response boundaries. Internal code can rely on established contracts.
How does it approach backward compatibility?
Prefer additive optional fields and extensions. Avoid changing existing types or removing observable behavior that consumers may depend on.
Why are idempotency keys important?
Retries can repeat state-changing effects after timeouts. A durable, atomically claimed key lets the system distinguish one intent from repeated attempts.
Can it review an existing API?
Yes. Provide the contract or relevant documentation, and it can identify inconsistent semantics, compatibility risks, validation gaps, and retry hazards.

Developer Details

Author

addyosmani

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

5d5054f8a23586f9b500fece1cb613a9dffc787b

Maintenance freshness

9/19/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“„ SKILL.md

More from addyosmani

View all
View all