analysis-pipeline
Reverse engineering - multi-source product intelligence analysis with provenance tracking. Master methodology for all analysis agents.
Layer 1 skill for parsing machine-readable API contracts. OpenAPI/Swagger, GraphQL, Protobuf/gRPC, and JSON Schema detection, extraction, and behavioral claim generation. Loaded by the analyzer agent during Layer 1.
$ npx -y skills add prime-radiant-inc/greenfield --skill contract-detection --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/contract-detectionContext preview
The summary Claude sees to decide when to auto-load this skill.
Layer 1 skill for parsing machine-readable API contracts. OpenAPI/Swagger, GraphQL, Protobuf/gRPC, and JSON Schema detection, extraction, and behavioral claim generation. Loaded by the analyzer agent during Layer 1.
name: contract-detection description: Layer 1 skill for parsing machine-readable API contracts. OpenAPI/Swagger, GraphQL, Protobuf/gRPC, and JSON Schema detection, extraction, and behavioral claim generation. Loaded by the analyzer agent during Layer 1.
Extract behavioral intelligence from machine-readable API contracts. These are formal, published definitions of system interfaces -- the strongest possible specification source. A contract file is an explicit promise about what the system accepts and returns.
Contract detection activates when:
This mode runs independently of all other intelligence sources. All output is **PUBLIC** -- machine-readable contracts are published definitions intended for external consumption. Output goes to `workspace/public/contracts/`.
Machine-readable contracts are unique among intelligence sources because they are:
A single OpenAPI specification can contain more behavioral intelligence than the entire official documentation site, because every endpoint, parameter, response schema, and error code is defined with machine precision.
# Find OpenAPI/Swagger files find . -maxdepth 5 -type f \( \ -name "openapi.*" -o -name "swagger.*" -o \ -name "api-spec.*" -o -name "api-docs.*" \ \) \( -name "*.json" -o -name "*.yaml" -o -name "*.yml" \) 2>/dev/null # Check for OpenAPI version markers in YAML/JSON files grep -rl '"openapi":\|openapi:' --include="*.json" --include="*.yaml" --include="*.yml" . 2>/dev/null | head -20 grep -rl '"swagger":\|swagger:' --include="*.json" --include="*.yaml" --include="*.yml" . 2>/dev/null | head -20 # Check for hosted spec endpoints (common locations) # /api-docs, /swagger.json, /openapi.json, /v2/api-docs, /v3/api-docs
For each OpenAPI/Swagger specification, extract:
| Field | What It Tells You | |-------|-------------------| | `paths` | Every endpoint the API exposes | | HTTP method | The operation type (GET=read, POST=create, PUT=replace, PATCH=update, DELETE=remove) | | `operationId` | The canonical name for the operation | | `summary` / `description` | Behavioral description of what the endpoint does | | `tags` | Logical grouping of endpoints |
| Field | What It Tells You | |-------|-------------------| | `parameters` (path, query, header, cookie) | Required inputs and their types | | `required` | Whether the parameter is mandatory | | `schema` with `enum` | Allowed values (behavioral constraint) | | `schema` with `minimum` / `maximum` | Value range (behavioral constraint) | | `schema` with `pattern` | Validation regex (behavioral constraint) | | `schema` with `default` | Default value when omitted |
| Field | What It Tells You | |-------|-------------------| | `requestBody` | What the endpoint accepts (content type, schema) | | `responses` | Every possible response code and its schema | | `responses.4xx` | Client error conditions and their structure | | `responses.5xx` | Server error conditions | | `components/schemas` | Shared data models with field types, constraints, and relationships |
| Field | What It Tells You | |-------|-------------------| | `securityDefinitions` / `components/securitySchemes` | Auth methods (API key, OAuth2, Bearer, Basic) | | `security` (global or per-operation) | Which endpoints require which auth |
Write to `workspace/public/contracts/openapi-summary.md`:
## API: {title} v{version}
### Endpoints
| Method | Path | Operation | Auth Required | Description |
|--------|------|-----------|---------------|-------------|
| GET | /users | listUsers | Bearer | List all users with pagination |
| POST | /users | createUser | Bearer | Create a new user |
### Data Models
#### User
| Field | Type | Required | Constraints | Description |
|-------|------|----------|-------------|-------------|
| id | string (uuid) | yes | read-only | Unique identifier |
| email | string | yes | format: email | User's email address |
### Error Responses
| Code | Meaning | Schema |
|------|---------|--------|
| 400 | Validation error | { message: string, errors: [{field, code}] } |
| 401 | Unauthorized | { message: string } |
| 404 | Not found | { message: string } |# Find GraphQL schema files
find . -maxdepth 5 -type f \( \
-name "schema.graphql" -o -name "*.graphqls" -o -name "schema.gql" -o \
-name "*.graphql" \
\) 2>/dev/null
# Find GraphQL codegen config (indicates GraphQL usage)
find . -maxdepth 3 -type f \( \
-name "codegen.*" -o -name ".graphqlrc*" -o -name "apollo.config.*" \
\) 2>/dev/null
# Check for GraphQL in dependencies
grep -l "graphql\|apollo\|@graphql" package.json requirements.txt Gemfile go.mod 2>/dev/null
# Check for introspection endpoint (if running instance available)
# POST /graphql with { "query": "{ __schema { types { name } } }" }For each GraphQL schema, extract:
| Element | What It Tells You | |---------|-------------------| | Query type fields | Every read operation the API exposes | | Arguments | Required and optional parameters with types | | Return types | Shape of the response data | | Directives (`@deprecated`, `@auth`) | Behavioral modifiers |
Reverse engineer clean behavioral specs from any codebase. Greenfield reads source code, documentation, SDKs, runtime behavior, and binaries, then produces behavioral specifications, test vectors, acceptance criteria, and a full provenance trail.
Repo: prime-radiant-inc/greenfield
Reverse engineering - multi-source product intelligence analysis with provenance tracking. Master methodology for all analysis agents.
Layer 1 intelligence source discovery - auto-detect available sources, search for public information, negotiate with user, produce inventory manifest
Layer 3 deep documentation methodology. Per-module behavioral specifications, external and behavioral integration contracts, behavior documentation, end-to-end…
Layer 1 methodology for extracting behavioral intelligence from compiled binaries, bytecode archives, managed assemblies, and bundled applications. Covers…
Layer 1 skill for community intelligence gathering. Search channels, extraction methodology, consensus analysis, version-aware behavioral changes, structural…
Infrastructure skill for containerized target execution. Runtime detection, container lifecycle, security restrictions, interaction patterns.