api-endpoint-creation
Create Safe Next.js API Endpoints
Teams need consistent API routes that protect workspace data. This skill gives repeatable Next.js and Supabase patterns for validation, queries, and responses.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "api-endpoint-creation" from https://skillstore.io/skills/cleanexpo-api-endpoint-creation.md and its manifest at https://skillstore.io/api/skills/cleanexpo-api-endpoint-creation/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "api-endpoint-creation". Create a GET endpoint for projects.
Expected outcome:
A route outline that validates workspaceId, checks user access, queries projects by workspace_id, and returns a standard success response.
Using "api-endpoint-creation". Add a POST endpoint for tasks.
Expected outcome:
A creation flow that parses the request body, checks required fields, stores workspace ownership, and returns the created task.
Using "api-endpoint-creation". Review this endpoint against the checklist.
Expected outcome:
- Workspace access validation is required before database access.
- Every table query should include workspace_id filtering.
- Backend error details should be logged server-side, not returned to clients.
Security Audit
Medium RiskAll static external command and reconnaissance findings are false positives caused by Markdown code fences and workspace validation terminology. One semantic issue remains: the example handlers return raw Supabase error messages, which can expose internal backend details in generated endpoints.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (5)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/cleanexpo-api-endpoint-creation/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/cleanexpo-api-endpoint-creation?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/cleanexpo-api-endpoint-creation?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/cleanexpo-api-endpoint-creation/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/cleanexpo-api-endpoint-creation.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
CleanExpo. (2026). api-endpoint-creation security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/cleanexpo-api-endpoint-creation/audits/9BibTeX citation
@techreport{cleanexpo-cleanexpo-api-endpoint-creation-2026,
author = {CleanExpo},
title = {api-endpoint-creation security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/cleanexpo-api-endpoint-creation/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "api-endpoint-creation security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "CleanExpo"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/cleanexpo-api-endpoint-creation/audits/9"
identifiers:
- type: other
value: "skillstore:cleanexpo-api-endpoint-creation:audit:9"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Add a Tenant-Scoped Read Endpoint
Create a GET route that validates workspace access and filters Supabase results by workspace_id.
Build a Workspace Creation Route
Create a POST route that validates the request, writes workspace ownership fields, and returns a standard response.
Review API Route Consistency
Compare an endpoint against the checklist for error boundaries, Supabase access, workspace filtering, and TypeScript types.
Try These Prompts
Create a Next.js 15 GET endpoint for [resource]. Use Supabase, workspaceId validation, withErrorBoundary, and standard success and error responses.
Create a POST endpoint for [resource]. Validate workspace access, parse the body, require [fields], and save workspace_id and created_by.
Review this route for the skill checklist. Add missing workspace validation, Supabase server access, workspace_id filters, and standard responses.
Plan API endpoints for [resource]. Define GET and POST behavior, validation rules, workspace filtering, response handling, and production hardening notes.
Best Practices
- Always validate workspace access before reading or writing tenant data.
- Filter every Supabase query by workspace_id unless the table is global by design.
- Replace raw backend error messages with safe client messages and server logs.
Avoid
- Creating endpoints that trust workspaceId without validateUserAndWorkspace.
- Writing records without workspace_id or created_by ownership metadata.
- Returning database error details directly to client applications.