moodle-external-api-development
Build Secure Moodle External APIs
Custom Moodle web services are easy to expose incorrectly or structure inconsistently. This skill provides patterns for parameters, permissions, registration, database access, testing, and troubleshooting.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "moodle-external-api-development" from https://skillstore.io/skills/sickn33-moodle-external-api-development.md and its manifest at https://skillstore.io/api/skills/sickn33-moodle-external-api-development/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "moodle-external-api-development". Create a read endpoint for course progress.
Expected outcome:
A file-by-file implementation outline with parameter definitions, course context checks, required capabilities, response fields, and service registration.
Using "moodle-external-api-development". Review a quiz-attempt endpoint for security.
Expected outcome:
A prioritized review identifying missing authorization, unsafe diagnostics, query concerns, and focused remediation steps.
Using "moodle-external-api-development". Plan testing for a Moodle write service.
Expected outcome:
A test matrix covering roles, invalid parameters, denied access, transaction rollback, duplicate requests, and return-schema validation.
Security Audit
High RiskAll 109 static findings are false positives caused by Markdown syntax, fixed Moodle examples, placeholder endpoints, or official documentation links. Semantic review found a high-severity authorization omission plus medium-severity logging and credential-handling risks in the guidance.
Confirmed security concerns (3)
Risk Factors
⚡ Contains scripts (1)
⚙️ External commands (50)
🌐 Network access (6)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-moodle-external-api-development/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-moodle-external-api-development?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-moodle-external-api-development?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-moodle-external-api-development/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-moodle-external-api-development.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
sickn33. (2026). moodle-external-api-development security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-moodle-external-api-development/audits/5BibTeX citation
@techreport{sickn33-sickn33-moodle-external-api-development-2026,
author = {sickn33},
title = {moodle-external-api-development security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/sickn33-moodle-external-api-development/audits/5},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "moodle-external-api-development security audit report (audit version 5)"
version: "unspecified"
type: report
authors:
- name: "sickn33"
date-released: "2026-08-04"
url: "https://skillstore.io/skills/sickn33-moodle-external-api-development/audits/5"
identifiers:
- type: other
value: "skillstore:sickn33-moodle-external-api-development:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Create a Plugin Endpoint
Draft a Moodle external function with validated parameters, permissions, return definitions, and service registration.
Review an Existing Service
Check an endpoint for framework structure, database safety, permission enforcement, and response consistency.
Connect an External Client
Plan REST or AJAX access, token usage, testing steps, and expected Moodle configuration.
Try These Prompts
Create a read-only Moodle endpoint for [resource]. Include parameter definitions, context validation, capability checks, return structure, and service registration.
Review this Moodle endpoint for validation, context, capabilities, SQL safety, return accuracy, and information disclosure. Explain each required change.
Design a transactional Moodle API that creates [activity]. Include rollback behavior, capability checks, idempotency decisions, and tests.
Compare REST and AJAX exposure for this Moodle function. Cover tokens, authorization, sensitive logging, rate limits, and failure responses.
Best Practices
- Validate parameters, context, and capabilities inside every endpoint.
- Use parameterized Moodle database methods and short transactions.
- Test authorized and unauthorized roles with production-safe logging enabled.
Avoid
- Do not trust a user identifier merely because it passed type validation.
- Do not log tokens, full SQL statements, or stack traces in production.
- Do not expose write functions without explicit capabilities and rollback tests.