— No reviews yet
0 installs
14 views
0.0% view→install
Install
$ agentstack add skill-kentoshimizu-sw-agent-skills-api-design-graphql ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Are you the author of Api Design Graphql? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claimAbout
API Design GraphQL
Scope Boundaries
- Use when GraphQL schema boundaries, resolver contracts, and query safety must be defined.
- Use proactively when GraphQL SDL/resolver diffs appear in specs, manifests, or source.
- Use when clients need flexible field selection but query safety and authz boundaries are not yet explicit.
- Do not use for REST-first endpoint design; use
api-design-rest. - Do not use for storage internals; use
db-*.
Goal
Deliver GraphQL contracts that are safe to evolve and efficient at runtime.
Shared API Contract (Canonical)
- Use
../api-design-rest/references/api-governance-contract.mdas the canonical contract. - Optional consistency checks (only if your repository enforces manifest validation):
python3 ../api-design-rest/scripts/validate_api_contract.py --manifest- Use valid templates in
../api-design-rest/assets/. - Use transport decision reference:
../api-design-rest/references/transport-selection-matrix.md- Use threshold derivation reference:
../api-design-rest/references/threshold-derivation-framework.md- Do not redefine API artifact ID formats, states, or approval gates.
Implementation Templates
- GraphQL SDL template:
../api-design-rest/assets/graphql-schema-template.graphql
Inputs
- Required queries/mutations and consumer usage patterns
- Entity ownership and field-level authorization requirements
- Performance budgets for depth, complexity, and resolver latency
Outputs
- Schema contract (types, inputs, mutations, deprecation tags)
- Resolver behavior contract (authz, caching, batching, nullability semantics)
- Query safety controls (complexity/depth limits and abuse controls)
Workflow
- Define schema boundaries aligned with domain ownership, not backend table layout.
- Model inputs and payloads for forward-compatible evolution and explicit nullability.
- Set resolver authorization rules and avoid N+1 with batching strategy.
- Decide whether GraphQL is the primary transport or a gateway facade, and document alternatives.
- Define query complexity/depth limits and abuse safeguards for public access paths.
- Define error extension fields and trace correlation behavior.
- Derive threshold methods for query latency, complexity limits, and resolver concurrency.
- Validate compatibility, operational readiness, and canonical API contract compliance.
Quality Gates
- Schema evolution rules are explicit, including deprecations and migration notes.
- Resolver behavior is deterministic, authorized, and free of unbounded fan-out paths.
- Query safety limits are defined and enforced.
- Observability and error semantics are consistent with API governance contract.
Failure Handling
- Stop when schema changes break existing client contracts without approved version plan.
- Stop when resolver performance or query safety controls are undefined.
- Escalate when required security/governance approvers are missing.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: KentoShimizu
- Source: KentoShimizu/sw-agent-skills
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.