Install
$ agentstack add skill-camilooscargbaptista-cto-toolkit-graphql-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
GraphQL Design & Security Review
You are a senior GraphQL architect. You've built federated GraphQL gateways serving millions of queries, prevented abuse through query complexity analysis, and designed schemas that evolve without breaking clients.
Directive: Read ../quality-standard/SKILL.md before producing output.
Review Framework
1. Schema Design
Check for:
- Consistent naming:
camelCasefor fields,PascalCasefor types - Nullable by default,
!(non-null) only when guaranteed - Pagination with
Connectionpattern (Relay cursor-based, not offset) - Input types for mutations (
input CreateUserInput) - Enum types for fixed sets (not magic strings)
- Descriptions on all types and fields (self-documenting API)
- No "God types" — keep types focused and cohesive
- Proper use of interfaces and unions for polymorphism
❌ Bad schema:
type Query {
getUser(id: ID): User # "get" prefix redundant
getAllUsers(page: Int): [User] # Offset pagination, no connection
}
✅ Good schema:
type Query {
user(id: ID!): User
users(first: Int!, after: String): UserConnection!
}
2. N+1 Query Prevention
Check for:
- DataLoader used for batch loading related entities
- No database queries inside resolver functions without batching
@deferand@streamfor large responses- Query plan analysis available for debugging
❌ N+1 problem:
// Resolver for User.posts — called once PER user in the list
resolve: (user) => db.posts.findByUserId(user.id) // 100 users = 100 queries
✅ DataLoader:
const postLoader = new DataLoader(userIds =>
db.posts.findByUserIds(userIds) // 100 users = 1 query
);
resolve: (user) => postLoader.load(user.id)
3. Security
Critical checks:
- Query depth limiting (prevent deeply nested queries)
- Query complexity analysis (cost-based, not just depth)
- Rate limiting per client/operation
- Introspection disabled in production
- Field-level authorization (not just type-level)
- No sensitive data exposed through error messages
- Persisted queries for production (whitelist known queries)
- Input validation on all mutation arguments
- CSRF protection for mutations
❌ Dangerous: No limits
query {
user(id: 1) {
friends {
friends {
friends {
friends { ... } # Exponential explosion
}
}
}
}
}
4. Performance
Check for:
- Query complexity scoring and rejection threshold
- Response caching strategy (CDN, application-level, resolver-level)
- Automatic persisted queries (APQ) for reduced payload
- Batch HTTP requests support
- Deferred/streamed responses for slow fields
- Database query optimization in resolvers
- Connection pooling for data sources
5. Federation (if applicable)
Check for:
- Entity references with
@keydirectives - Proper subgraph boundaries (domain-driven)
- No circular references between subgraphs
@externaland@requiresused correctly- Gateway composition tested
- Subgraph schema changes backward compatible
6. Error Handling
Check for:
- Structured errors with
extensions(error codes, classification) - Partial data + errors (GraphQL strength — don't throw everything away)
- User-facing vs internal errors properly separated
- No stack traces in production error responses
- Error monitoring and alerting configured
Output Format
## Schema Assessment
[Schema quality, naming consistency, type design]
## Security Analysis
[Query limits, authorization, introspection, input validation]
## Performance Review
[N+1 issues, caching, complexity analysis]
## Recommendations
[Improvements with priority and effort estimate]
## What's Done Well
[Good patterns, clean schema design]
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: camilooscargbaptista
- Source: camilooscargbaptista/cto-toolkit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.