AGENT
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination,…
A standalone data-flow diagram with its trust boundaries explained, to illustrate the notation before you build your own. The system: a file-upload feature where users upload documents that a worker processes.
$ npx -y skills add vanara-agents/skills --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
A standalone data-flow diagram with its trust boundaries explained, to illustrate the notation before you build your own. The system: a file-upload feature where users upload documents that a worker processes.
A standalone data-flow diagram with its trust boundaries explained, to illustrate the notation before you build your own. The system: a file-upload feature where users upload documents that a worker processes.
TRUST BOUNDARY A: Internet ││ App tier TRUST BOUNDARY B: App tier ┊┊ Worker tier
(E1) User ──1: HTTPS PUT /files (JWT)──►││──► (P2) Upload API ──2: store object──►││──► (DS3) Object Store
││ │ ││
││ └──3: enqueue job────────────►││──► (DS4) Job Queue
││ ┊┊
││ (P5) Worker ◄──4: dequeue──┊┊── (DS4) Job Queue
││ │
││ └──5: read object──► (DS3) Object Store
││ │
││ └──6: write result──► (DS6) Results DB
Legend: (E)=external entity (P)=process (DS)=data store
N: numbered data flow ││ = network/privilege boundary ┊┊ = process/tier boundarybytes, the filename, the content-type header, and the JWT. Everything arriving here must be authenticated (Spoofing), authorized (Elevation of privilege), and validated (Tampering). This is the single most important boundary in the system.
The worker (P5) consumes whatever the Upload API enqueued plus the object it stored. If an attacker can influence the filename or object contents, the worker is processing attacker-controlled data — so parsing in P5 (think: image/PDF/zip parsers) is a prime Tampering and Elevation-of-privilege target, even though no public flow touches the worker directly.
Reading along the crossing flows:
privilege / stored XSS. Path traversal in the filename → Tampering of the object store.
Missing ownership check on later retrieval → IDOR (Elevation of privilege).
decompression-bomb DoS in the parser. The worker often runs with more privileges than the API — a parser exploit here is high impact.
1. Internal queues and worker tiers are still behind trust boundaries — model them. 2. The most dangerous element is often not the public API but the *background process* that parses what the public API accepted. 3. Number flows so the threat table can reference them unambiguously (e.g. "T-flow1-E", "T-flow4-T").
🐒 Free agents, skills & packs for Claude Code One subscription. An army of Claude Code agents. 30 production-grade agents, skills, and packs for Claude Code — free, Apache-2.0, install with one command.
Repo: vanara-agents/skills
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination,…
This shows how the api-designer agent reviews a flawed draft. Findings are severity-ranked so the implementer fixes the contract-breakers first. Severity…
The contract is the deliverable. Express it as an **OpenAPI 3.1** document so it is human-readable *and* machine-checkable. This reference covers how to…
Run through this before declaring an API contract done. It is ordered the way you should *design*: resources first, cross-cutting rules last. Every box is a…
APIs are forever once published: a consumer you've never met may depend on any field you expose. Design so you can **add without breaking**, and version…
Copy-paste templates for leaving review comments. Keep each comment to one finding: an anchor, the problem, and the fix.