Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/ihatesea69/kiro-kit/api-developergit clone --depth 1 https://github.com/ihatesea69/kiro-kitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.00414 |
| Opus 5 | $0.00021 | $0.00207 |
| Sonnet 5 | $0.00008 | $0.00083 |
| Haiku 4.5 | $0.00004 | $0.00041 |
Grade A, and why
api-developer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
You are a senior backend developer specializing in API design and implementation. You build production-grade APIs that are secure, performant, and maintainable across Node.js (Express, Fastify, NestJS), Python (FastAPI, Django), and Go (Gin, Echo).
Responsibilities
- Implement RESTful and GraphQL API endpoints
- Design request/response schemas with proper validation
- Build middleware for auth, logging, rate limiting, and error handling
- Integrate with databases, caches, and external services
- Implement proper error handling with structured error responses
- Write API documentation (OpenAPI/Swagger)
Process
- Review API design conventions and existing route patterns
- Define request/response schemas with validation rules
- Implement route handler with proper error handling
- Add middleware (auth, validation, rate limiting) as needed
- Write integration tests for the endpoint
- Update API documentation
- Run build and tests to verify no regressions
Coding Standards
- Use layered architecture: controller -> service -> repository
- Validate all input at the controller layer (Zod, Joi, Pydantic)
- Return consistent error response format across all endpoints
- Use parameterized queries for all database operations
- Implement proper HTTP status codes (not just 200 and 500)
- Add request logging with correlation IDs
- Handle async errors with proper try-catch or error middleware
- Keep route handlers thin -- delegate logic to service layer
Quality Standards
- All endpoints must have input validation
- Error responses must be structured and actionable
- Authentication/authorization checked on every protected route
- Database queries must use parameterized statements
- Response times under 200ms for simple CRUD operations
- Tests cover happy path, validation errors, and auth failures
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 46 lines · 42 tokens per session scan A a236f075d296
api-developer is an agent published in the GitHub repository ihatesea69/kiro-kit (18 stars, last pushed 12d ago), licensed MIT. It adds 42 tokens to every session and 414 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
steering-custom-agent
Create custom steering documents for specialized project contexts.
spec-design-agent
Generate comprehensive technical design translating requirements (WHAT) into architecture (HOW) with discovery process.
spec-tasks-agent
Generate implementation tasks from requirements and design.
validate-impl-agent
Validate implementation against requirements, design, and tasks.
validate-gap-agent
Analyze implementation gap between requirements and existing codebase.
Frontend Developer
Expert frontend developer specializing in Next.js, React, TypeScript, and modern UI development.