phase-4-api

phase-4-api is a skill for Claude Code, Codex from ww-w-ai/bkit-claude-code. It costs 28 tokens per session (1,867 once invoked), scanned A, original, Apache-2.0.

Design and implement backend APIs with Zero Script QA validation. Triggers: API design, REST API, backend, endpoint.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/ww-w-ai/bkit-claude-code/phase-4-api
Any agent
npx skills add ww-w-ai/bkit-claude-code --skill phase-4-api
Clone the repo
git clone --depth 1 https://github.com/ww-w-ai/bkit-claude-code

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for phase-4-api

README.md
[![agentmods](https://agentmods.dev/badge/skills/ww-w-ai/bkit-claude-code/phase-4-api.svg)](https://agentmods.dev/skills/ww-w-ai/bkit-claude-code/phase-4-api)
Your own site
<a href="https://agentmods.dev/skills/ww-w-ai/bkit-claude-code/phase-4-api"><img src="https://agentmods.dev/badge/skills/ww-w-ai/bkit-claude-code/phase-4-api.svg" alt="Measured on agentmods" height="20"></a>
Per session 28 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,867 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin unknown No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00028 $0.01867
Opus 5 $0.00014 $0.00933
Sonnet 5 $0.00006 $0.00373
Haiku 4.5 $0.00003 $0.00187

Measured today against content hash a9b0f56f423c, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

phase-4-api scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/phase-4-api/SKILL.md · 284 lines

How it starts

The opening of the file, as written. The whole thing — 284 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Phase 4: API Design/Implementation + Zero Script QA

Backend API implementation and script-free QA

Purpose

Implement backend APIs that can store and retrieve data. Validate with structured logs instead of test scripts.

What to Do in This Phase

  1. API Design: Define endpoints, requests/responses
  2. API Implementation: Write actual backend code
  3. Zero Script QA: Log-based validation

Deliverables

docs/02-design/
└── api-spec.md             # API specification

src/api/                    # API implementation
├── routes/
├── controllers/
└── services/

docs/03-analysis/
└── api-qa.md               # QA results

PDCA Application

  • Plan: Define required API list
  • Design: Design endpoints, requests/responses
  • Do: Implement APIs
  • Check: Validate with Zero Script QA
  • Act: Fix bugs and proceed to Phase 5

Level-wise Application

Level Application Method
Starter Skip this Phase (no API)
Dynamic Use bkend.ai BaaS (see below)
Enterprise Implement APIs directly

Dynamic Level: bkend.ai BaaS API Implementation

Step 1: MCP Setup
claude mcp add bkend --transport http https://api.bkend.ai/mcp
Step 2: Table Design (via MCP tools)

Natural language request: "Create a users table with name(required), email(required, unique), age fields" -> MCP backend_table_create auto-invoked

Step 3: Service API Integration
Method Endpoint Description
GET /v1/data/{table} List (filter, sort, page)
POST /v1/data/{table} Create data
GET /v1/data/{table}/{id} Get single
PATCH /v1/data/{table}/{id} Partial update
DELETE /v1/data/{table}/{id} Delete

Required Headers: x-project-id, x-environment, Authorization

Step 4: Auth Implementation

Reference MCP tools 3_howto_implement_auth and 6_code_examples_auth

Step 5: Zero Script QA
  • Check bkend REST API call logs in browser DevTools Network tab
  • Verify API behavior via response code/body

Read the full file on GitHub · 284 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today First seen · 284 lines · 28 tokens per session scan A a9b0f56f423c

Subscribe to this mod's changes

phase-4-api is a skill published in the GitHub repository ww-w-ai/bkit-claude-code (595 stars, last pushed 18d ago), licensed Apache-2.0. It adds 28 tokens to every session and 1,867 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

deep-research

Professional deep research report generation — multi-agent collaboration with parallel chapter writing, automatic latest-data targeting, multilingual output, and built-in quality checks.

hoolulu/deep-research · 32 tokens

ai-native-sdlc

Run the AI-native SDLC loop — Plan, Design, Build, Test, Deploy, Maintain — with versioned artifacts and human approval gates at every handoff. Use when the user states a goal, idea, feature, or change request and expects the agent to scaffold and drive the project through the full lifecycle instead of jumping…

bashebr/ai-native-sdlc · 75 tokens

code-auditor

Independent pre-merge review of a git diff, PR, or named files. Use when the user asks to review a PR, inspect current git changes, or hunt functional regressions, missed scenarios, wrong assumptions, concurrency bugs, and test gaps as an independent reviewer who does not defend the author's approach /…

bahayonghang/my-ai-cli-toolkit · 176 tokens

三月七 Agent 角色扮演

让AI Agent以《崩坏:星穹铁道》看板娘「三月七」的语气、思维方式和人设完成所有任务—— 回答、思考、编写文档、写代码、分析数据等。三月七自称"本姑娘",称呼对话发起者为"开拓者"。 支持中文、英文、日文、韩文四种语言。 当用户明确要求"用三月七的风格"、"像三月七一样"、"按三月七人设"等指令时触发; 也可由用户通过 /march7 命令手动调用。.

denceee/march-7th-skill · 156 tokens

sast-horusec

Multi-language static application security testing using Horusec with support for 18+ programming languages and 20+ security analysis tools. Performs SAST scans, secret detection in git history, and provides vulnerability findings with severity classification. Use when: (1) Analyzing code for security vulnerabilities…

AgentSecOps/SecOpsAgentKit · 121 tokens

notebooklm-slides

This skill should be used when generating pedagogically-aligned slide decks from educational content using NotebookLM. It addresses the convergence toward generic, text-heavy slides by providing structured prompts that create engaging, proficiency-appropriate presentations aligned with specific educational frameworks.

mjunaidca/robolearn · 54 tokens