AGENT
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination,…
A complete review of a hypothetical PR, in the standard format. Use this as the model for tone, structure, and the anchor → problem → fix pattern.
$ npx -y skills add vanara-agents/skills --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
Context preview
The summary Claude sees to decide when to auto-load this agent.
A complete review of a hypothetical PR, in the standard format. Use this as the model for tone, structure, and the anchor → problem → fix pattern.
A complete review of a hypothetical PR, in the standard format. Use this as the model for tone, structure, and the anchor → problem → fix pattern.
---
is never checked against the session. Any logged-in user can read others' financial data. **Fix:** `if (req.params.id !== req.session.userId) return res.status(404).end();` before the query (404, not 403, to avoid leaking existence).
**Fix:** whitelist sortable columns:
const SORTABLE = { date: 'created_at', total: 'amount' };
const col = SORTABLE[req.query.sort] ?? 'created_at';500s with a stack trace in the body. **Fix:** wrap in try/catch, log server-side, return a generic error envelope.
asserting a non-owner gets 404 and an owner gets 200.
rendering. **Fix:** extract `assertOwnership()`, `loadInvoices()`, `renderPdf()`.
**Verdict: Block** — two CRITICAL issues (IDOR + SQL injection) must be fixed before merge. The HIGH items (error handling + missing tests) should land in the same change. Structure is otherwise reasonable; the medium refactor is a nice-to-have.
🐒 Free agents, skills & packs for Claude Code One subscription. An army of Claude Code agents. 30 production-grade agents, skills, and packs for Claude Code — free, Apache-2.0, install with one command.
Repo: vanara-agents/skills
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination,…
This shows how the api-designer agent reviews a flawed draft. Findings are severity-ranked so the implementer fixes the contract-breakers first. Severity…
The contract is the deliverable. Express it as an **OpenAPI 3.1** document so it is human-readable *and* machine-checkable. This reference covers how to…
Run through this before declaring an API contract done. It is ordered the way you should *design*: resources first, cross-cutting rules last. Every box is a…
APIs are forever once published: a consumer you've never met may depend on any field you expose. Design so you can **add without breaking**, and version…
Copy-paste templates for leaving review comments. Keep each comment to one finding: an anchor, the problem, and the fix.