api-designer

api-designer is a skill for Claude Code, Codex from LambdaTest/agent-skills. It costs 207 tokens per session (1,475 once invoked), scanned A, original, MIT.

A guide for designing REST APIs, which are web interfaces that let software exchange data through defined URLs and request methods. It creates endpoint specifications for a system or domain described by the user.

In plain words
What is it for?
Use it to plan API endpoints and document their methods, headers, request bodies, successful responses, and error codes. It can provide either a short endpoint list or a detailed design when the requirements specify the level of detail.
Why use it?
It helps turn a broad product idea into a clear list of URLs, inputs, outputs, and errors. This reduces ambiguity between the systems and developers building or using the API.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/lambdatest/agent-skills/api-designer
Any agent
npx skills add LambdaTest/agent-skills --skill api-designer
Clone the repo
git clone --depth 1 https://github.com/LambdaTest/agent-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for api-designer

README.md
[![agentmods](https://agentmods.dev/badge/skills/lambdatest/agent-skills/api-designer.svg)](https://agentmods.dev/skills/lambdatest/agent-skills/api-designer)
Your own site
<a href="https://agentmods.dev/skills/lambdatest/agent-skills/api-designer"><img src="https://agentmods.dev/badge/skills/lambdatest/agent-skills/api-designer.svg" alt="Measured on agentmods" height="20"></a>
Per session 207 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,475 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00207 $0.01475
Opus 5 $0.00103 $0.00737
Sonnet 5 $0.00041 $0.00295
Haiku 4.5 $0.00021 $0.00147

Measured 6d ago against content hash aae1fc69f5c1, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

api-designer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

api-skill/api-designer/SKILL.md · 170 lines

How it starts

The opening of the file, as written. The whole thing — 170 lines — stays where its author put it; the contents beside it link to each section on GitHub.

API Designer Skill

You are an expert API architect.

Ask the user if they want just the endpoints or complete detailed response (Enpoints Only/Detail Design). Do not ask these options if the user has specified the details of his requirement in the input already. If the user says Endpoints Only:

  • Output only the endpoints If the user says Detail Design:
  • Output complete design as the structure described in this skill.

Output Format

First list down all the endpoints one after another as output then expand each in this exact structure for each endpoint group (resource):


RESOURCE NAME

METHOD /path/to/endpoint

Short description of what this endpoint does. Not more than two lines.

Headers

Header Value Required
Content-Type application/json Yes
Authorization Bearer <token> Yes/No
X-Api-Key <api-key> Yes/No
(add others as relevant)

Request Body (omit for GET/DELETE if no body)

{
  "field": "type — description",
  "field2": "type — description"
}

Success ResponseSTATUS_CODE Description

{
  "field": "value or type"
}

Error Codes

Code Meaning
400 Bad Request — invalid or missing fields
401 Unauthorized — missing or invalid token
403 Forbidden — insufficient permissions
404 Not Found
409 Conflict — e.g. duplicate resource
422 Unprocessable Entity — validation failed
500 Internal Server Error

Rules for Output

  1. Cover all major resources for the described system. Infer resources if the user doesn't list them.
  2. Always include CRUD (Create, Read, Update, Delete) where applicable, plus domain-specific actions.
  3. Use RESTful conventions: plural nouns for collections, nested paths for relationships (e.g. /hotels/{id}/rooms).
  4. Auth: Default to Bearer token (JWT) for protected routes. Add API key header where relevant (e.g. third-party integrations). Mark public endpoints clearly.
  5. Request body: Show realistic JSON with field names, types, and brief descriptions. Mark required vs optional fields in comments.
  6. Responses: Show the success response shape with realistic fields. Always include the HTTP status code.
  7. Error codes: List the relevant subset per endpoint — don't always paste all 7. Use judgement.
  8. Pagination: For list endpoints, include query params (page, limit, sort, filter) and wrap responses in a paginated envelope.
  9. Versioning: Prefix all paths with /api/v1/ unless the user specifies otherwise.
  10. Group endpoints by resource (e.g. "Authentication", "Hotels", "Rooms", "Bookings", "Payments", "Reviews").

Read the full file on GitHub · 170 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 170 lines · 207 tokens per session scan A aae1fc69f5c1

Subscribe to this mod's changes

api-designer is a skill published in the GitHub repository LambdaTest/agent-skills (366 stars, last pushed 1mo ago), licensed MIT. It adds 207 tokens to every session and 1,475 once invoked, about $0.0010 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

detecting-broken-object-property-level-authorization

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.

xalgorix/xalgorix · 36 tokens

API Test Suite Generator

Automatically generate comprehensive API test suites from OpenAPI specifications covering CRUD operations, error handling, authentication, pagination, and edge cases.

PramodDutta/qaskills · 29 tokens

JMeter Load Testing

Load and performance testing skill using Apache JMeter, covering test plans, thread groups, assertions, listeners, timers, and distributed testing.

PramodDutta/qaskills · 32 tokens

api-testing

API testing patterns for Playwright -- apiRequest fixture usage, Zod response schema creation and validation, test.step wrapping for multi-call tests, per-field negative/validation testing, path parameter fuzzing, and helper fixtures for shared setup/teardown. Use when writing or updating API test specs, adding tests…

idavidov13/agentic-playwright · 132 tokens

debugging

Playwright test debugging conventions for the scaffold — reading failure messages, classifying failure modes (TimeoutError, ZodError, strict-mode violation, locator not found, network errors, schema drift), the playwright.config.ts capture defaults (trace on-first-retry, screenshot only-on-failure, video…

idavidov13/agentic-playwright · 179 tokens

pr-reviewer

Reviews a Git branch as a pull request against the base branch (auto-resolved from origin/HEAD — usually main or master) using this repo's own rules — the CLAUDE.md constitution and the .claude/skills/ that apply to the changed files. Fetches the branch, switches to it, diffs it against the merge-base, routes the…

idavidov13/agentic-playwright · 278 tokens