Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/qauth-labs/qauth/api-designnpx skills add qauth-labs/qauth --skill api-designgit clone --depth 1 https://github.com/qauth-labs/qauthWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00052 | $0.01348 |
| Opus 5 | $0.00026 | $0.00674 |
| Sonnet 5 | $0.00010 | $0.00270 |
| Haiku 4.5 | $0.00005 | $0.00135 |
Grade A, and why
api-design scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 100 lines — stays where its author put it; the contents beside it link to each section on GitHub.
API Design (QAuth)
Standards-aligned HTTP API design for QAuth auth-server. APIs are resource-oriented, schema-validated with Zod, and return consistent success and error payloads. Use this skill when defining new endpoints, schemas, or reviewing API contracts.
When to Use This Skill
- Adding or changing routes in
apps/auth-server - Defining or updating request/response schemas (Zod)
- Designing error response shape or status codes
- Questions about REST conventions, versioning, or OpenAPI
Quick Reference
| Concern | QAuth pattern |
|---|---|
| Validation | Zod schemas in app/schemas/; fastify-type-provider-zod on routes |
| Route schema | schema: { body?, querystring?, params?, response: { 200: schema } } |
| Success | 200/201/204 with typed body; no extra envelope unless needed |
| Errors | { error, statusCode, code?, feedback?, constraint?, retryAfter?, details? } |
| OAuth tokens | RFC 6749: snake_case (access_token, refresh_token, expires_in, token_type) |
| Other JSON | camelCase for app-specific fields (e.g. emailVerified, realmId) |
| Versioning | Not in use yet; prefer path /v1/ or header when introduced |
Route Structure (QAuth)
-
Schemas first
Define Zod schemas inapp/schemas/(e.g.auth.ts,oauth.ts,common.ts). Export schema and inferred type (z.infer<typeof schema>). Usez.email(),z.uuid(),z.url()(Zod v4 standalone validators). -
Register schema on route
Usefastify.withTypeProvider<ZodTypeProvider>().get|post|...(path, { schema, config }, handler). Setschema.body,schema.querystring,schema.params, andschema.response(e.g.response: { 200: responseSchema }). Fastify validates and types request/response.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 100 lines · 52 tokens per session scan A 4a953bfeab38
api-design is a skill published in the GitHub repository qauth-labs/qauth (24 stars, last pushed 7d ago), licensed Apache-2.0. It adds 52 tokens to every session and 1,348 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
write-e2e-test
Write end-to-end (e2e) tests for authgear-server. Use when the user asks to write, add, or create e2e tests. The tests live in e2e/tests/ and are YAML-driven.
add-portal-screen
Add screens or components to the portal frontend. Use when the user asks to create a new portal page, screen, tab, or UI component.
api-design
Review or design APIs for Authgear. In review mode, evaluates a design draft against the checklist. In ideation mode, develops a design from a description and self-reviews it.
update-deps
Audit and fix dependency vulnerabilities in Go and Node.js packages. Runs govulncheck for Go and npm audit for each package.json directory. Commits fixes directory by directory.
new-siteadmin-api
Full pipeline for adding a new Site Admin API feature — from OpenAPI spec through implementation plan to working service. Use when adding a new endpoint or filling in real data for an existing stub.
update-portal-ui
Guidelines for updating or designing pages in the portal React frontend (portal/src). Covers component conventions, link rendering rules, i18n patterns, and common pitfalls.