Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add williamzujkowski/standards --skill graphqlgit clone --depth 1 https://github.com/williamzujkowski/standardsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/williamzujkowski/standards/graphql)<a href="https://agentmods.dev/skills/williamzujkowski/standards/graphql"><img src="https://agentmods.dev/badge/skills/williamzujkowski/standards/graphql/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/williamzujkowski/standards/graphql"><img src="https://agentmods.dev/badge/skills/williamzujkowski/standards/graphql.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00022 | $0.03202 |
| Opus 5.5 | $0.00009 | $0.01281 |
| Sonnet 5.5 | $0.00004 | $0.00640 |
| Haiku 4.5 | $0.00002 | $0.00320 |
Grade A, and why
graphql-api-design scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
7 near-identical copies found in the catalogue:
- database-advanced-optimization — 94% identical, 680 lines differ
- serverless — 89% identical, 551 lines differ
- monitoring-observability — 88% identical, 513 lines differ
- service-mesh — 86% identical, 697 lines differ
- infrastructure-as-code — 84% identical, 546 lines differ
- react-native-mobile — 84% identical, 539 lines differ
- threat-modeling — 80% identical, 562 lines differ
How it starts
The opening of the file, as written. The whole thing — 617 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GraphQL API Design Skill
Level 1: Quick Reference (~800 tokens)
GraphQL vs REST: When to Use GraphQL
Use GraphQL When:
- Clients need flexible data fetching (avoid over/under-fetching)
- Multiple client types with different data requirements (mobile, web, IoT)
- Real-time data updates via subscriptions
- Complex data relationships and nested queries
- Rapid frontend iteration without backend changes
Use REST When:
- Simple CRUD operations with predictable access patterns
- File uploads/downloads (though GraphQL can handle with multipart)
- HTTP caching is critical (GET requests)
- Team unfamiliarity with GraphQL tooling
Schema Design Principles
Core Concepts:
- Type System: Strongly typed schema defines API contract
- Query: Read operations (like GET)
- Mutation: Write operations (like POST/PUT/DELETE)
- Subscription: Real-time data streams over WebSocket
- Resolver: Function that returns data for a field
Design Rules:
- Use nouns for types, verbs for mutations
- Prefer pagination over large lists
- Design for client use cases, not database structure
- Use interfaces for polymorphic types
- Leverage custom scalars (DateTime, Email, URL)
Essential Checklist
Schema Design
- Define clear type hierarchy (Query, Mutation, Subscription roots)
- Use descriptive field names and types
- Add field-level descriptions for documentation
- Implement input validation with custom scalars
- Design pagination with cursor-based approach
Resolvers & Performance
- Implement DataLoader for N+1 query prevention
- Batch database queries within request context
- Add resolver-level caching strategy
- Use field-level resolvers only when needed
- Implement query complexity analysis
Authorization & Security
- Context-based authentication (verify tokens)
- Field-level authorization with directives
- Query depth limiting (prevent deeply nested attacks)
- Query complexity cost analysis
- Rate limiting per client/operation
What ships with it
8 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 617 lines · 22 tokens per session scan A d3c8a7002995
graphql-api-design is a skill published in the GitHub repository williamzujkowski/standards (18 stars, last pushed 1mo ago), licensed MIT. It adds 22 tokens to every session and 3,202 once invoked, about $0.0001 per session on Opus 5.5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-29.
Other skills, from other repositories
api-rate-limit-handler
Implement bounded, idempotency-aware API throttling, backoff, and retry handling for 429 and transient 5xx responses.
api-integration-architect
Design, implement, debug, and optimize API integrations with expert-level patterns for REST, GraphQL, webhooks, and authentication flows.
nextjs-pages-router
Set up tRPC in Next.js Pages Router with createNextApiHandler, createTRPCNext, withTRPC HOC, SSR via ssr option and ssrPrepass, SSG via createServerSideHelpers with getStaticProps, and server-side helpers for getServerSideProps prefetching.
middlewares
Create and compose tRPC middleware with t.procedure.use(), extend context via opts.next({ ctx }), build reusable middleware with .concat() and .unstablepipe(), define base procedures like publicProcedure and authedProcedure. Access raw input with getRawInput(). Logging, timing, OTEL tracing patterns.
non-json-content-types
Handle FormData, file uploads, Blob, Uint8Array, and ReadableStream inputs in tRPC mutations. Use octetInputParser from @trpc/server/http for binary data. Route non-JSON requests with splitLink and isNonJsonSerializable() from @trpc/client. FormData and binary inputs only work with mutations (POST).
server-side-calls
Call tRPC procedures directly from server code using t.createCallerFactory() and router.createCaller(context) for integration testing, internal server logic, and custom API endpoints. Catch TRPCError and extract HTTP status with getHTTPStatusCodeFromError(). Error handling via onError option.