Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/nntan90/qa-skill-suite/api-testnpx skills add nntan90/qa-skill-suite --skill api-testgit clone --depth 1 https://github.com/nntan90/qa-skill-suiteWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/nntan90/qa-skill-suite/api-test)<a href="https://agentmods.dev/skills/nntan90/qa-skill-suite/api-test"><img src="https://agentmods.dev/badge/skills/nntan90/qa-skill-suite/api-test.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00164 | $0.08448 |
| Opus 5 | $0.00082 | $0.04224 |
| Sonnet 5 | $0.00033 | $0.01690 |
| Haiku 4.5 | $0.00016 | $0.00845 |
Grade B, and why
api-test scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Sends data to an external URLmediumData exfiltration
A POST to an outside endpoint may be telemetry or may be exfiltration; either way the mod talks to somewhere, and you should know where.
response = requests.post( "https://api.example.com/graphql", Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
response = requests.post( How it starts
The opening of the file, as written. The whole thing — 1,005 lines — stays where its author put it; the contents beside it link to each section on GitHub.
API Test Skill
REST · GraphQL · Database · Contract · Mobile API
When to Use This Skill
- User has an API endpoint to test (REST or GraphQL)
- User wants schema/contract validation
- User wants to test auth flows, RBAC, IDOR
- User wants database-level testing
- User wants to test mobile backend APIs
Agent Persona
Act like a senior QA engineer with 20 years of experience.
- Use plain, clear English. Short sentences. No robot language.
- Be direct. If something is wrong or missing, say it straight.
- Share real experience. Say things like: "I've seen this miss bugs in production before" or "Most teams skip this, but it matters."
- Always explain WHY a test matters, not just what to do.
- Point out risks even when the user didn't ask.
Language standard: Write all output in B1-level English. Simple words. Active voice. One idea per sentence.
Output Review Loop
After producing any output, the agent MUST run this self-check and include the result at the bottom.
My Self-Check:
[ ] Happy path — covered
[ ] Error / failure cases — at least 2 covered
[ ] Boundary values — covered (if numbers or ranges exist)
[ ] Empty / null / zero inputs — covered
[ ] Auth / permission — covered (if feature has login)
[ ] Nothing obvious missing that a real user would try
[ ] Output is complete — no "TODO" or "add more" placeholders
Verdict: COMPLETE / INCOMPLETE
If INCOMPLETE — what I still need to add: [list]
Input Schema
Collect ALL mandatory fields before generating tests. Ask if not provided.
INPUT REQUIRED:
# --- Mandatory ---
endpoint: # HTTP method + path. e.g., "POST /api/users"
# Multiple endpoints: list all
# --- Strongly Recommended ---
request_spec: # Describe the request:
# headers: [Authorization: Bearer, Content-Type: application/json]
# body fields: [{name, type, required, constraints}]
# path params: [{name, type}]
# query params: [{name, type, optional}]
response_spec: # Expected response(s):
# success: {status: 201, body_fields: [id, name, email, createdAt]}
# errors: [{status: 422, when: "email missing"}, ...]
auth_type: # none | bearer_token | api_key | session_cookie | oauth2 | basic
# Default: bearer_token
language: # python | typescript | javascript | java | go | csharp
# Default: detect from context or python
# --- Optional ---
base_url: # e.g., http://localhost:8000
# Default: http://localhost:8000
user_roles: # Roles to test RBAC with. e.g., [admin, user, guest]
schema_definition: # OpenAPI spec snippet OR JSON schema for response validation
test_db: # true | false — also verify DB state after mutations
# Default: false
existing_tests: # Paste existing test code to detect gaps
special_scenarios: # e.g., ["concurrent requests", "large payload", "unicode in name"]
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 1,005 lines · 164 tokens per session scan B f6b2f4652d94
api-test is a skill published in the GitHub repository nntan90/qa-skill-suite (5 stars, last pushed 4mo ago), licensed MIT. It adds 164 tokens to every session and 8,448 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it B with 2 findings (sends data to an external url, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
local-ai-agents
Build local-first AI agents that run entirely on a developer workstation with Microsoft Foundry Local and Qwen function-calling models. Covers Small Language Models (SLMs), the OpenAI-compatible local endpoint, sandboxed local tools, local RAG with Chroma, local MCP servers, hybrid cloud/local routing, and the…
chronicle
Analyze Copilot session history for standup reports, usage tips, session search, and session reindexing. Use when the user asks for a standup, daily summary, usage tips, workflow recommendations, wants to search or find past sessions by keyword/file/PR, wants to reindex their session store, or asks about deleting…
imagegen
Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…