AGENT
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination,…
Copy this block per finding. Keep it to one anchor, one exploit sentence, one fix. Delete the guidance comments before shipping.
$ npx -y skills add vanara-agents/skills --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
Copy this block per finding. Keep it to one anchor, one exploit sentence, one fix. Delete the guidance comments before shipping.
Copy this block per finding. Keep it to one anchor, one exploit sentence, one fix. Delete the guidance comments before shipping.
### <CRITICAL | HIGH | MEDIUM | LOW> - `<path>:<line>` — **<Vulnerability name> (<OWASP category, e.g. A03>)**. <One sentence: which attacker-controlled input reaches which dangerous sink, and the concrete impact. Include the exploit string if it makes it real.> **Fix:** <the corrected code or precise action — a real control (parameterize / encode / allow-list / rotate), never a blocklist.>
### CRITICAL
- `orders/repo.js:88` — **SQL injection (A03)**. The `sort` query param is interpolated into the SQL
text (`ORDER BY ${req.query.sort}`); `?sort=id;DROP TABLE orders--` executes arbitrary SQL.
**Fix:** allow-list sortable columns (`{ created_at, total }`) and map the param through it; bind
all values as parameters. Identifiers can't be bound, so the allow-list is mandatory.🐒 Free agents, skills & packs for Claude Code One subscription. An army of Claude Code agents. 30 production-grade agents, skills, and packs for Claude Code — free, Apache-2.0, install with one command.
Repo: vanara-agents/skills
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination,…
This shows how the api-designer agent reviews a flawed draft. Findings are severity-ranked so the implementer fixes the contract-breakers first. Severity…
The contract is the deliverable. Express it as an **OpenAPI 3.1** document so it is human-readable *and* machine-checkable. This reference covers how to…
Run through this before declaring an API contract done. It is ordered the way you should *design*: resources first, cross-cutting rules last. Every box is a…
APIs are forever once published: a consumer you've never met may depend on any field you expose. Design so you can **add without breaking**, and version…
Copy-paste templates for leaving review comments. Keep each comment to one finding: an anchor, the problem, and the fix.