api-designer
Design Production-Ready APIs
Inconsistent API contracts create integration errors and costly migrations. This skill guides REST, GraphQL, OpenAPI, authentication, versioning, validation, and documentation decisions.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "api-designer" from https://skillstore.io/skills/autumnsgrove-api-designer.md and its manifest at https://skillstore.io/api/skills/autumnsgrove-api-designer/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "api-designer". Design user and order REST resources for a commerce service.
Expected outcome:
- Resource map covering users, orders, order items, and payment references.
- Endpoint table with methods, permissions, status codes, pagination, and idempotency requirements.
- Consistent validation and error response guidance.
Using "api-designer". Review an OpenAPI contract for authentication and consistency.
Expected outcome:
- Findings grouped by authentication, naming, schemas, errors, and compatibility.
- Recommended OAuth scopes, reusable security definitions, and response corrections.
- A prioritized list of contract changes and unresolved assumptions.
Using "api-designer". Plan the migration from a legacy user endpoint to version two.
Expected outcome:
- A compatibility plan with parallel versions and an adapter period.
- Deprecation milestones, client communication, telemetry, and removal criteria.
- Rollback conditions and tests for old and new clients.
Security Audit
SafeAll 146 static findings are false positives caused by Markdown syntax, example URLs and credentials, validation text, and intended local file output. The Python helper does not spawn commands, read environment variables, access certificate files, or make network requests. No prompt injection, exfiltration intent, or other semantic security issue was found.
Risk Factors
โ๏ธ External commands (50)
๐ Network access (37)
๐ Env variables (4)
๐ Filesystem access (2)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/autumnsgrove-api-designer/audits/14?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/autumnsgrove-api-designer?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/autumnsgrove-api-designer?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/autumnsgrove-api-designer/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/autumnsgrove-api-designer.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
AutumnsGrove. (2026). api-designer security audit report (audit version 14) [Author version unspecified]. Skillstore. https://skillstore.io/skills/autumnsgrove-api-designer/audits/14BibTeX citation
@techreport{autumnsgrove-autumnsgrove-api-designer-2026,
author = {AutumnsGrove},
title = {api-designer security audit report (audit version 14)},
institution = {Skillstore},
year = {2026},
number = {14},
url = {https://skillstore.io/skills/autumnsgrove-api-designer/audits/14},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "api-designer security audit report (audit version 14)"
version: "unspecified"
type: report
authors:
- name: "AutumnsGrove"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/autumnsgrove-api-designer/audits/14"
identifiers:
- type: other
value: "skillstore:autumnsgrove-api-designer:audit:14"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Design a Service Contract
Define resources, operations, schemas, errors, pagination, and authentication for a new backend service.
Establish API Governance
Standardize naming, versioning, deprecation, compatibility, and security rules across multiple services.
Improve Developer Documentation
Turn an OpenAPI specification into structured Markdown and identify missing examples or descriptions.
Try These Prompts
Design a REST API for [product]. List resources, endpoints, methods, request fields, response fields, status codes, and a consistent error format.
Review this API design: [paste design]. Identify inconsistent naming, HTTP semantics, pagination, error handling, and security gaps. Propose specific corrections.
Create an OpenAPI 3.0 contract for [service]. Include authentication, reusable schemas, validation constraints, pagination, errors, and realistic examples. State assumptions.
Plan a backward-compatible migration from [current API] to [target API]. Define versioning, deprecation headers, compatibility layers, rollout stages, monitoring, and client communication.
Best Practices
- Provide domain rules, actors, permissions, data sensitivity, and expected traffic before requesting a design.
- Ask for explicit assumptions and review them before adopting the generated contract.
- Validate generated specifications with production tooling and test representative client workflows.
Avoid
- Do not expose credentials, private keys, production tokens, or confidential payloads in prompts.
- Do not treat example URLs, identifiers, or security settings as production defaults.
- Do not release breaking changes without a versioning, deprecation, migration, and monitoring plan.
Frequently Asked Questions
Does this skill support REST and GraphQL?
Can it create OpenAPI specifications?
Does the helper make network requests?
Will it implement my API?
How complete is the included validator?
What information should I provide?
Developer Details
Author
AutumnsGroveLicense
MIT
Skillstore revision
r3
Version notice
The author did not declare a version.
Ref
89edfdc710d0846129dcee6a929477b04f08052c
Maintenance freshness
7/24/2026
Usage
34 downloads ยท 267 views
File structure
๐ examples/
๐ openapi_spec.yaml
๐ README.md
๐ references/
๐ authentication.md
๐ common-patterns.md
๐ scripts/
๐ api_helper.py
๐ SKILL.md