Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/cveralyon/axel-setup/api-designgit clone --depth 1 https://github.com/cveralyon/axel-setupWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00020 | $0.00402 |
| Opus 5 | $0.00010 | $0.00201 |
| Sonnet 5 | $0.00004 | $0.00080 |
| Haiku 4.5 | $0.00002 | $0.00040 |
Grade A, and why
api-design scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Design a new API endpoint by auditing existing patterns first.
Step 1: Understand the Requirement
- What resource/action? (CRUD on a model, custom action, aggregation)
- Who can access it? (roles: admin, manager, recruiter, freelance)
- What data goes in / comes out?
Step 2: Audit Existing Patterns
- Find similar endpoints:
grep -r "def <action>" app/controllers/api/v1/ - Check how similar services are structured
- Review the routes file for namespace conventions
- Read
docs/Doc-Tecnica-enero-2025.mdfor business context if relevant
Step 3: Design Proposal
Route: PATCH /api/v1/{resource}/{id}/{action}
Controller: Api::V1::{Resource}Controller#{action}
Service: {Domain}::{Action}Service
Serializer: {Model}Serializer (existing or new)
Policy: {Model}Policy#{action}?
Request
- Method, path, params (required/optional)
- Auth: token required? Which roles?
Response
- Success: status code, body structure (via serializer)
- Errors: 401, 403, 404, 422 — what triggers each
Side Effects
- Sidekiq jobs enqueued?
- Emails sent?
- Audit trail (PaperTrail)?
- State transitions (AASM)?
Step 4: Files to Create/Modify
List every file with its path and what goes in it. Don't create anything — just propose.
Rules
- Use PATCH, not PUT
- Thin controller, logic in service
- Pundit for authorization
- ActiveModelSerializers for response formatting
- All code in English
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 52 lines · 20 tokens per session scan A ac03b028702b
api-design is an agent published in the GitHub repository cveralyon/axel-setup (4 stars, last pushed 1mo ago), licensed MIT. It adds 20 tokens to every session and 402 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other agents, from other repositories
syllago-author
/home/hhewett/.local/src/syllago/content/agents/syllago-author/AGENT.md.
feature-flow
Build, test, verify, and review an already planned feature. Operates on a feature branch off trunk; prepares a PR but does not merge.
review
Review PR and build output for quality, security, and compliance. Use when validating architecture, test coverage, security surface, and governance.
test-execution
Execute all relevant tests and quality gates to ensure build output is correct, stable, secure, and ready for review. This is feature-flow's Phase 3 (and Phase 3.5 for live-system verification) — local, pre-push verification. Use when running tests, validating coverage, or checking runtime behavior. Distinct from the…
design
Convert the specification into a clear, actionable technical design with architecture, components, interfaces, and data flows. Use when translating requirements into a buildable system design.
learn
Product retrospective agent. Runs after a release, after a measure agent anomaly flag, or at end of sprint. Maps findings to DORA AI capabilities and produces plan agent action items. Distinct from fawkes learn.md which handles platform incident postmortems.