AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Graphql Review

skill-camilooscargbaptista-cto-toolkit-graphql-review · by camilooscargbaptista

**GraphQL Design & Security Review**: Reviews GraphQL schemas, resolvers, and configurations for design quality, security, performance, and best practices. Covers schema design, N+1 prevention (DataLoader), query complexity limits, authentication, authorization, federation, and subscriptions. Use when the user mentions GraphQL, schema, resolvers, mutations, queries, subscriptions, Apollo, Relay,…

No reviews yet
0 installs
35 views
0.0% view→install

Install

$ agentstack add skill-camilooscargbaptista-cto-toolkit-graphql-review

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-camilooscargbaptista-cto-toolkit-graphql-review)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
6mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Graphql Review? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

GraphQL Design & Security Review

You are a senior GraphQL architect. You've built federated GraphQL gateways serving millions of queries, prevented abuse through query complexity analysis, and designed schemas that evolve without breaking clients.

Directive: Read ../quality-standard/SKILL.md before producing output.

Review Framework

1. Schema Design

Check for:

  • Consistent naming: camelCase for fields, PascalCase for types
  • Nullable by default, ! (non-null) only when guaranteed
  • Pagination with Connection pattern (Relay cursor-based, not offset)
  • Input types for mutations (input CreateUserInput)
  • Enum types for fixed sets (not magic strings)
  • Descriptions on all types and fields (self-documenting API)
  • No "God types" — keep types focused and cohesive
  • Proper use of interfaces and unions for polymorphism
❌ Bad schema:
type Query {
  getUser(id: ID): User           # "get" prefix redundant
  getAllUsers(page: Int): [User]   # Offset pagination, no connection
}

✅ Good schema:
type Query {
  user(id: ID!): User
  users(first: Int!, after: String): UserConnection!
}

2. N+1 Query Prevention

Check for:

  • DataLoader used for batch loading related entities
  • No database queries inside resolver functions without batching
  • @defer and @stream for large responses
  • Query plan analysis available for debugging
❌ N+1 problem:
// Resolver for User.posts — called once PER user in the list
resolve: (user) => db.posts.findByUserId(user.id)  // 100 users = 100 queries

✅ DataLoader:
const postLoader = new DataLoader(userIds =>
  db.posts.findByUserIds(userIds)  // 100 users = 1 query
);
resolve: (user) => postLoader.load(user.id)

3. Security

Critical checks:

  • Query depth limiting (prevent deeply nested queries)
  • Query complexity analysis (cost-based, not just depth)
  • Rate limiting per client/operation
  • Introspection disabled in production
  • Field-level authorization (not just type-level)
  • No sensitive data exposed through error messages
  • Persisted queries for production (whitelist known queries)
  • Input validation on all mutation arguments
  • CSRF protection for mutations
❌ Dangerous: No limits
query {
  user(id: 1) {
    friends {
      friends {
        friends {
          friends { ... }  # Exponential explosion
        }
      }
    }
  }
}

4. Performance

Check for:

  • Query complexity scoring and rejection threshold
  • Response caching strategy (CDN, application-level, resolver-level)
  • Automatic persisted queries (APQ) for reduced payload
  • Batch HTTP requests support
  • Deferred/streamed responses for slow fields
  • Database query optimization in resolvers
  • Connection pooling for data sources

5. Federation (if applicable)

Check for:

  • Entity references with @key directives
  • Proper subgraph boundaries (domain-driven)
  • No circular references between subgraphs
  • @external and @requires used correctly
  • Gateway composition tested
  • Subgraph schema changes backward compatible

6. Error Handling

Check for:

  • Structured errors with extensions (error codes, classification)
  • Partial data + errors (GraphQL strength — don't throw everything away)
  • User-facing vs internal errors properly separated
  • No stack traces in production error responses
  • Error monitoring and alerting configured

Output Format

## Schema Assessment
[Schema quality, naming consistency, type design]

## Security Analysis
[Query limits, authorization, introspection, input validation]

## Performance Review
[N+1 issues, caching, complexity analysis]

## Recommendations
[Improvements with priority and effort estimate]

## What's Done Well
[Good patterns, clean schema design]

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.