Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/getlytos/lytos-cli/api-designnpx skills add getlytos/lytos-cli --skill api-designgit clone --depth 1 https://github.com/getlytos/lytos-cliWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00044 | $0.02412 |
| Opus 5 | $0.00022 | $0.01206 |
| Sonnet 5 | $0.00009 | $0.00482 |
| Haiku 4.5 | $0.00004 | $0.00241 |
Grade A, and why
api-design scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 294 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Skill — API Design
This skill defines how to design and review REST APIs on a project using Lytos. An agent loaded with this skill knows the conventions, patterns, and checks required to produce a consistent, production-ready API.
When to invoke this skill
- When designing a new API or a new set of endpoints
- When reviewing an existing API for consistency or quality
- When adding endpoints to an existing API — ensure they follow established conventions
- When a team disagrees on URL structure, status codes, or error format
Procedure
1. REST conventions
Resources are plural nouns, never verbs. The HTTP method carries the action.
| Method | Purpose | Idempotent | Example |
|---|---|---|---|
| GET | Read a resource or collection | Yes | GET /users/42 |
| POST | Create a new resource | No | POST /users |
| PUT | Full replacement of a resource | Yes | PUT /users/42 |
| PATCH | Partial update of a resource | No | PATCH /users/42 |
| DELETE | Remove a resource | Yes | DELETE /users/42 |
Nested resources — use them when the child has no meaning without the parent:
GET /users/{id}/orders # orders belong to a user
GET /users/{id}/orders/{orderId}
Flat routes — prefer them when the child is independently addressable or queried across parents:
GET /orders?user_id=42 # orders can be searched globally
GET /orders/{orderId}
Rule of thumb: nest at most one level deep. If you reach /a/{id}/b/{id}/c, flatten.
2. URL design
- kebab-case for multi-word segments:
/order-items, not/orderItems - Plural nouns for collections:
/users,/products - No verbs in URLs — use HTTP methods instead
- Query parameters for filtering, sorting, pagination
# ✅ Good
GET /users?role=admin&sort=-created_at&page=2&per_page=20
# ❌ Bad
GET /getAdminUsers
3. HTTP status codes
| Code | Name | When to use |
|---|---|---|
| 200 | OK | Successful GET, PUT, PATCH, or DELETE that returns a body |
| 201 | Created | Successful POST — include Location header |
| 204 | No Content | Successful operation that returns no body |
| 400 | Bad Request | Malformed JSON, missing required field, invalid type |
| 401 | Unauthorized | No credentials or expired token |
| 403 | Forbidden | Valid credentials, but the user lacks permission |
| 404 | Not Found | Resource does not exist |
| 409 | Conflict | Duplicate creation, version conflict |
| 422 | Unprocessable Entity | Valid JSON but fails business rules |
| 429 | Too Many Requests | Rate limit exceeded |
| 500 | Internal Server Error | Unexpected server failure — never intentional |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 294 lines · 44 tokens per session scan A 597efc9be63f
api-design is a skill published in the GitHub repository getlytos/lytos-cli (2 stars, last pushed 2d ago), licensed MIT. It adds 44 tokens to every session and 2,412 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.
chat-perf
Run chat perf benchmarks and memory leak checks against the local dev build or any published VS Code version. Use when investigating chat rendering regressions, validating perf-sensitive changes to chat UI, or checking for memory leaks in the chat response pipeline.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…