— No reviews yet
0 installs
16 views
0.0% view→install
Install
$ agentstack add skill-kentoshimizu-sw-agent-skills-api-design-rest ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Are you the author of Api Design Rest? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claimAbout
API Design REST
Scope Boundaries
- Use when REST resources, URI structures, and HTTP behavior are being designed or changed.
- Use proactively when route, method, status, or schema diffs appear in specs, manifests, or source.
- Use when request-response transport options are being compared and REST is a candidate.
- Do not use for GraphQL-first schema work; use
api-design-graphql. - Do not use for storage internals; use
db-*.
Goal
Deliver REST contracts that are stable, predictable, and operationally safe.
Shared API Contract (Canonical)
- Use
references/api-governance-contract.mdas the primary reference for recommended structure. - Optional consistency checks (only if your repository enforces manifest validation):
python3 scripts/validate_api_contract.py --manifest- Start from valid templates in
assets/. - Use transport decision reference:
references/transport-selection-matrix.md- Use threshold derivation reference:
references/threshold-derivation-framework.md- Do not define alternate ID formats, lifecycle states, or compatibility policies locally.
Implementation Templates
- REST OpenAPI template:
assets/openapi-rest-template.yaml- Queue/event API template:
assets/asyncapi-queue-template.yaml- WebSocket contract template:
assets/websocket-message-contract-template.yaml- SSE contract template:
assets/sse-event-contract-template.yaml
Inputs
- Product behavior and consumer integration requirements
- Resource model candidates and domain invariants
- Security, compliance, and SLO constraints
- Interaction model candidates (
sync,async,streaming,bidirectional_realtime) - Transport options (
rest,graphql,grpc,websocket,sse,queue)
Outputs
- Resource map and endpoint matrix (
method,path,status,error) - Request/response schema contract including pagination and filtering rules
- Authorization, rate-limit, idempotency, and observability decisions
Workflow
- Model resources as nouns and define stable identifiers before endpoint naming.
- Select interaction mode and primary transport with explicit rationale and rejected alternatives.
- Define method semantics with explicit idempotency strategy for retry-sensitive writes.
- Fix status and error semantics so clients can branch without string parsing.
- Define naming conventions for paths, fields, and error codes.
- Define authz scope, rate-limit policy, and trace/log fields for every operation class.
- Derive threshold types and methods (latency, timeout, capacity, concurrency, retry, delivery).
- Validate backward compatibility and publish deprecation/migration notes when behavior changes.
- Validate the artifact against the canonical API contract before approval.
Quality Gates
- URI and method choices follow resource-oriented conventions and HTTP semantics.
- Contract is backward compatible or includes approved version transition evidence.
- Error contract is machine-actionable and trace-correlated.
- Authz, rate-limit, and runbook updates are complete and reviewable.
- Decision context captures internal/external audience and sync/async/real-time transport rationale.
- Threshold derivation methods are explicit and tied to SLO/risk evidence.
Failure Handling
- Stop when URI design leaks internal implementation or method semantics are inconsistent.
- Stop when compatibility impact is unknown.
- Escalate when required approvers or compliance evidence are missing.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: KentoShimizu
- Source: KentoShimizu/sw-agent-skills
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.