claude-code-infrastructure-showcase: Command for Claude Code

.claude/commands/route-research-for-testing.md

route-research-for-testing is a command for Claude Code from diet103/claude-code-infrastructure-showcase. It costs 6 tokens per session (332 once invoked), scanned C, original, MIT.

A command that maps changed web routes to their API paths and tests them. A route is a URL handled by a web application, such as an endpoint that accepts or returns data.

In plain words
What is it for?
Use it after route edits to identify endpoints, document request and response shapes, send test requests, and report status codes or errors.
Why use it?
It reduces the manual work of finding affected endpoints and checking whether valid and invalid requests produce the expected responses.

Command for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: model in frontmatter; positional $N argument.

This is diet103/claude-code-infrastructure-showcase's own configuration. It tells Claude Code how to work on claude-code-infrastructure-showcase itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything claude-code-infrastructure-showcase configures →

About the project

Claude Code Infrastructure Showcase is a reference library of configuration patterns for Claude Code, including skills, hooks, agents, and commands that shape how the coding agent works. It helps developers organize and automate Claude Code in their own projects, especially larger TypeScript codebases. The catalogue entries are examples of infrastructure that users can copy into their projects.

diet103/claude-code-infrastructure-showcase · 10,016 stars · on GitHub

Reuse

Borrowing it

Nothing to install: this file belongs to diet103/claude-code-infrastructure-showcase. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/diet103/claude-code-infrastructure-showcase/main/.claude/commands/route-research-for-testing.md
Clone the repo
git clone --depth 1 https://github.com/diet103/claude-code-infrastructure-showcase

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for route-research-for-testing

README.md
[![agentmods](https://agentmods.dev/badge/commands/diet103/claude-code-infrastructure-showcase/route-research-for-testing.svg)](https://agentmods.dev/commands/diet103/claude-code-infrastructure-showcase/route-research-for-testing)
Your own site
<a href="https://agentmods.dev/commands/diet103/claude-code-infrastructure-showcase/route-research-for-testing"><img src="https://agentmods.dev/badge/commands/diet103/claude-code-infrastructure-showcase/route-research-for-testing.svg" alt="Measured on agentmods" height="20"></a>
Per session 6 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 332 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 3 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00006 $0.00332
Opus 5 $0.00003 $0.00166
Sonnet 5 $0.00001 $0.00066
Haiku 4.5 $0.00001 $0.00033

Measured 7d ago against content hash f984c65c6dcf, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade C, and why

route-research-for-testing scanned grade C with 3 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Sends data to an external URLmediumData exfiltration

A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.

curl -X POST -H "Content-Type: application/json" -d '{"key":"value"}' http://localhost:<YOUR_PORT>/api/route-path

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

!cat "$CLAUDE_PROJECT_DIR/.claude/tsc-cache"/\*/edited-files.log \

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -X GET http://localhost:<YOUR_PORT>/api/route-path
.claude/commands/route-research-for-testing.md · 39 lines

What it actually says

Context

Changed route files this session (auto-generated):

!cat "$CLAUDE_PROJECT_DIR/.claude/tsc-cache"/*/edited-files.log
| awk -F: '{print $2}'
| grep '/routes/'
| sort -u

User-specified additional routes: $ARGUMENTS

Your task

Follow the numbered steps exactly:

  1. Combine the auto list with $ARGUMENTS, dedupe, and resolve any prefixes defined in your API entry point (e.g. src/app.ts, src/server.ts, or wherever routes are registered).
  2. For each final route, output a JSON record with the path, method, expected request/response shapes, and valid + invalid payload examples.
  3. Now test each route using cURL or your project's test script:
# For each route, test with appropriate method and payload
curl -X GET http://localhost:<YOUR_PORT>/api/route-path
curl -X POST -H "Content-Type: application/json" -d '{"key":"value"}' http://localhost:<YOUR_PORT>/api/route-path

Substitute <YOUR_PORT> with your project's actual dev server port.

Report results for each route: status code, response shape, and any errors found.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago First seen · 39 lines · 6 tokens per session scan C f984c65c6dcf

Subscribe to this mod's changes

route-research-for-testing is a command published in the GitHub repository diet103/claude-code-infrastructure-showcase (10,016 stars, last pushed 1mo ago), licensed MIT. It adds 6 tokens to every session and 332 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it C with 3 findings (sends data to an external url, reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.