Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/gerard-labs/superpowers-api-platform/api-platform-errorsnpx skills add gerard-labs/superpowers-api-platform --skill api-platform-errorsgit clone --depth 1 https://github.com/gerard-labs/superpowers-api-platformWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00314 | $0.00871 |
| Opus 5 | $0.00157 | $0.00436 |
| Sonnet 5 | $0.00063 | $0.00174 |
| Haiku 4.5 | $0.00031 | $0.00087 |
Grade A, and why
api-platform-errors scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.
API Platform 4.3 — Errors (RFC 7807, ErrorResource, custom Error Provider)
Use when
- Designing a new domain exception and how it surfaces in the API.
- Mapping exception → status code globally or per operation.
- Hiding 500 stack traces in production while keeping meaningful 4xx errors.
- Adding
errors: [DomainException::class]so OpenAPI documents the failure case. - Customizing the error provider to enrich Problem Detail payloads (
type,title,instance).
Default workflow
- Confirm
rfc_7807_compliant_errors: trueis set (default in 4.x — Problem Detail format). - For each domain exception, decide:
exceptionToStatusmapping,#[ErrorResource](documented + customizable), or rely on the default. - Add
errors: [...]on relevant operations so OpenAPI documents the failure cases. - Implement a custom Error Provider only when you need to enrich the Problem payload (
setDetail,type,instance). - Verify: 422 / 404 / 409 / 410 / 500 all round-trip with the correct
Content-Type: application/problem+json.
Guardrails
- No stack traces / file paths in production. A 500 always gets a generic
detail. - No business details in 401 / 403. Enumeration risk — generic "Access denied".
- Stable
typeURIs. Clients pattern-match on them — version them (/errors/v1/stock-unavailable). ValidationExceptionnamespace: in 4.x it lives atApiPlatform\Validator\Exception\ValidationException. The legacyApiPlatform\Symfony\…path is removed.
Progressive disclosure
SKILL.mdcovers posture and rules.reference.mdcarries the full config,exceptionToStatuslevels,#[ErrorResource]template, custom Error Provider withError::createFromException, status resolution order, validation error provider, prod-safe pattern, type versioning.
Output contract
- Domain exceptions either mapped via
exceptionToStatusor modeled as#[ErrorResource]withProblemExceptionInterface. - Operations declaring
errors: [...]for documented failure modes. - Tests asserting
application/problem+jsonContent-Type and the exacttype/title/statusfields. - Production environment configured to hide stack traces.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 47 lines · 0 tokens per session scan A 3ef5ea4ae145
api-platform-errors is a skill published in the GitHub repository gerard-labs/superpowers-api-platform (2 stars, last pushed 3mo ago), licensed MIT. It adds 314 tokens to every session and 871 once invoked, about $0.0016 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
nextjs-pages-router
Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.
react-query-setup
Set up @trpc/tanstack-react-query with createTRPCContext(), TRPCProvider, useTRPC() hook, queryOptions/mutationOptions factories, query invalidation via queryClient.invalidateQueries with queryFilter, and type inference with inferInput/inferOutput.
non-json-content-types
Handle FormData, file uploads, Blob, Uint8Array, and ReadableStream inputs in tRPC mutations. Use octetInputParser from @trpc/server/http for binary data. Route non-JSON requests with splitLink and isNonJsonSerializable() from @trpc/client. FormData and binary inputs only work with mutations (POST).
openapi-glossary
Use consistent OpenAPI terminology and definitions when writing documentation, educational material, and tooling guidance.
scalar-docs
Skill for writing and updating scalar.config.json — Scalar Docs configuration reference for users and LLMs.
create-tutorial
Scaffold a new Membrane API Gateway tutorial in the api-gateway repo — the numbered self-teaching YAML under distribution/tutorials/ /, its support files and README links, and the matching auto-discovered integration test. Use whenever the user asks to create, add, write, or scaffold a tutorial (or a tutorial step)…