Install
$ agentstack add skill-christopherlouet-claude-base-dev-api ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Develop an API
Objective
Create well-structured, documented and testable APIs.
Instructions
1. Define the contract
Before coding, define:
- Endpoint (URL, HTTP method)
- Request (body, query params, headers)
- Response (status codes, body)
- Possible errors
2. RESTful structure
GET /resources → List (with pagination)
GET /resources/:id → Detail
POST /resources → Create
PUT /resources/:id → Full update
PATCH /resources/:id → Partial update
DELETE /resources/:id → Delete
3. Standard response format
// Success
{
"success": true,
"data": { ... },
"meta": {
"page": 1,
"limit": 20,
"total": 100
}
}
// Error
{
"success": false,
"error": {
"code": "VALIDATION_ERROR",
"message": "Email is required",
"details": [
{ "field": "email", "message": "Required" }
]
}
}
4. Input validation
// With Zod
const createUserSchema = z.object({
email: z.string().email(),
name: z.string().min(2).max(100),
role: z.enum(['user', 'admin']).default('user')
});
// In the handler
const data = createUserSchema.parse(req.body);
5. OpenAPI documentation
paths:
/users:
post:
summary: Create a user
tags: [Users]
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CreateUser'
responses:
'201':
description: User created
content:
application/json:
schema:
$ref: '#/components/schemas/User'
'400':
$ref: '#/components/responses/ValidationError'
6. API tests
describe('POST /api/users', () => {
it('should create user with valid data', async () => {
const response = await request(app)
.post('/api/users')
.send({ email: 'test@example.com', name: 'Test' })
.expect(201);
expect(response.body.success).toBe(true);
expect(response.body.data.email).toBe('test@example.com');
});
it('should return 400 for invalid email', async () => {
const response = await request(app)
.post('/api/users')
.send({ email: 'invalid', name: 'Test' })
.expect(400);
expect(response.body.error.code).toBe('VALIDATION_ERROR');
});
});
7. tRPC (type-safe TypeScript)
For a full-stack TypeScript monorepo, tRPC gives end-to-end type safety with no codegen.
// Server: initTRPC + Zod-validated procedures
const t = initTRPC.context().create({ transformer: superjson });
const protectedProcedure = t.procedure.use(({ ctx, next }) => {
if (!ctx.session) throw new TRPCError({ code: 'UNAUTHORIZED' });
return next({ ctx: { ...ctx, user: ctx.session.user } });
});
export const userRouter = t.router({
list: t.procedure.input(z.object({ cursor: z.string().nullish() }))
.query(({ input, ctx }) => ctx.userService.paginate(input)), // cursor-based pagination
create: protectedProcedure.input(createUserSchema)
.mutation(({ input, ctx }) => ctx.userService.create(input)),
});
- Build the context (prisma, session, user); use
protectedProcedurefor authenticated operations. - Group routers per domain (public queries / protected queries / mutations).
- Client:
httpBatchLink+ transformer + provider; hooksuseQuery,useMutation,useInfiniteQuery. - IMPORTANT: always validate inputs with Zod; NEVER expose sensitive data in public queries.
8. API versioning
Let the API evolve while keeping existing clients working. URL Path versioning (/v1/, /v2/) is recommended for most cases.
- Choose the strategy: URL Path (default), Query Param, Header, or Content Negotiation.
- Structure the code: versioned API layer, non-versioned Service layer.
- Classify changes: additive = safe (same version), breaking = new version.
- Deprecation timeline: Active → Deprecated → Sunset → Off, with
Deprecation,SunsetandLink(successor-version) headers. - Document every breaking change with a migration guide; monitor per version (requests, clients, errors, latency).
- IMPORTANT: never remove a version without a deprecation period; NEVER make breaking changes in a minor version.
API Checklist
- [ ] RESTful endpoint
- [ ] Input validation (Zod/Joi)
- [ ] Centralized error handling
- [ ] Appropriate status codes
- [ ] OpenAPI documentation
- [ ] Integration tests
- [ ] Rate limiting (if public)
- [ ] Authentication (if private)
Expected output
## API: [Endpoint name]
### Endpoint
`POST /api/v1/resources`
### Request
```json
{
"field1": "string",
"field2": 123
}
Response (201)
{
"success": true,
"data": { ... }
}
Errors
| Code | Status | Description | |------|--------|-------------| | VALIDATIONERROR | 400 | Invalid data | | NOTFOUND | 404 | Resource not found | | UNAUTHORIZED | 401 | Not authenticated |
## Rules
- IMPORTANT: Always validate inputs
- IMPORTANT: Document with OpenAPI
- YOU MUST return appropriate HTTP status codes
- NEVER expose internal errors in production
## Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- **Author:** [christopherlouet](https://github.com/christopherlouet)
- **Source:** [christopherlouet/claude-base](https://github.com/christopherlouet/claude-base)
- **License:** MIT
- **Homepage:** https://christopherlouet.github.io/claude-base/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.