Agent skill

API Test Suite Builder

by alirezarezvani in alirezarezvani/claude-skills

A skill your agent uses when the user asks to generate API tests, create integration test suites, test REST endpoints, or build contract tests.

MITAuto-check passedTesting & QA

Install API Test Suite Builder

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill api-test-suite-builder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills api-test-suite-builder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/skills/api-test-suite-builder .claude/skills/api-test-suite-builder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-test-suite-builder
GitHub stars
28k
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
573 words
Files
2 (incl. references)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user asks to generate API tests, create integration test suites, test REST endpoints, or build contract tests.

  • Works in 6 steps: Scan routes using the detection commands… → Read each route handler to understand → Generate test file per route group using… → …
  • The user asks to generate API tests
  • SKILL.md covers Overview, Core Capabilities, When to Use and Route Detection, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

API Test Suite Builder is an agent skill from alirezarezvani/claude-skills. Use when the user asks to generate API tests, create integration test suites, test REST endpoints, or build contract tests.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/example-test-files.md`).

It sits in Testing & QA, covering API testing, Integration testing and Test generation. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • The user asks to generate API tests
  • Create integration test suites
  • Test REST endpoints
  • Build contract tests

Example prompts

  • “/api-test-suite-builder”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Scan routes using the detection commands above
  2. Read each route handler to understand
  3. Generate test file per route group using the patterns above
  4. Name tests descriptively: "returns 401 when token is expired" not "auth test 3"
  5. Use factories/fixtures for test data — never hardcode IDs
  6. Assert response shape, not just status code

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Test Suite Builder loads about 1.6k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 37 tokens; SKILL.md has 573 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 573 words, ~1,565 tokens.

Download SKILL.mdSave it as .claude/skills/api-test-suite-builder/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
api-test-suite-builder
description
Use when the user asks to generate API tests, create integration test suites, test REST endpoints, or build contract tests.

API Test Suite Builder

Tier: POWERFUL Category: Engineering Domain: Testing / API Quality


Overview

Scans API route definitions across frameworks (Next.js App Router, Express, FastAPI, Django REST) and auto-generates comprehensive test suites covering auth, input validation, error codes, pagination, file uploads, and rate limiting. Outputs ready-to-run test files for Vitest+Supertest (Node) or Pytest+httpx (Python).


Core Capabilities

  • Route detection — scan source files to extract all API endpoints
  • Auth coverage — valid/invalid/expired tokens, missing auth header
  • Input validation — missing fields, wrong types, boundary values, injection attempts
  • Error code matrix — 400/401/403/404/422/500 for each route
  • Pagination — first/last/empty/oversized pages
  • File uploads — valid, oversized, wrong MIME type, empty
  • Rate limiting — burst detection, per-user vs global limits

When to Use

  • New API added — generate test scaffold before writing implementation (TDD)
  • Legacy API with no tests — scan and generate baseline coverage
  • API contract review — verify existing tests match current route definitions
  • Pre-release regression check — ensure all routes have at least smoke tests
  • Security audit prep — generate adversarial input tests

Route Detection

Next.js App Router
bash
# Find all route handlers
find ./app/api -name "route.ts" -o -name "route.js" | sort

# Extract HTTP methods from each route file
grep -rn "export async function\|export function" app/api/**/route.ts | \
  grep -oE "(GET|POST|PUT|PATCH|DELETE|HEAD|OPTIONS)" | sort -u

# Full route map
find ./app/api -name "route.ts" | while read f; do
  route=$(echo $f | sed 's|./app||' | sed 's|/route.ts||')
  methods=$(grep -oE "export (async )?function (GET|POST|PUT|PATCH|DELETE)" "$f" | \
    grep -oE "(GET|POST|PUT|PATCH|DELETE)")
  echo "$methods $route"
done
Express
bash
# Find all router files
find ./src -name "*.ts" -o -name "*.js" | xargs grep -l "router\.\(get\|post\|put\|delete\|patch\)" 2>/dev/null

# Extract routes with line numbers
grep -rn "router\.\(get\|post\|put\|delete\|patch\)\|app\.\(get\|post\|put\|delete\|patch\)" \
  src/ --include="*.ts" | grep -oE "(get|post|put|delete|patch)\(['\"][^'\"]*['\"]"

# Generate route map
grep -rn "router\.\|app\." src/ --include="*.ts" | \
  grep -oE "\.(get|post|put|delete|patch)\(['\"][^'\"]+['\"]" | \
  sed "s/\.\(.*\)('\(.*\)'/\U\1 \2/"
FastAPI
bash
# Find all route decorators
grep -rn "@app\.\|@router\." . --include="*.py" | \
  grep -E "@(app|router)\.(get|post|put|delete|patch)"

# Extract with path and function name
grep -rn "@\(app\|router\)\.\(get\|post\|put\|delete\|patch\)" . --include="*.py" | \
  grep -oE "@(app|router)\.(get|post|put|delete|patch)\(['\"][^'\"]*['\"]"
Django REST Framework
bash
# urlpatterns extraction
grep -rn "path\|re_path\|url(" . --include="*.py" | grep "urlpatterns" -A 50 | \
  grep -E "path\(['\"]" | grep -oE "['\"][^'\"]+['\"]" | head -40

# ViewSet router registration
grep -rn "router\.register\|DefaultRouter\|SimpleRouter" . --include="*.py"

Test Generation Patterns

Auth Test Matrix

For every authenticated endpoint, generate:

Test CaseExpected Status
No Authorization header401
Invalid token format401
Valid token, wrong user role403
Expired JWT token401
Valid token, correct role2xx
Token from deleted user401
Input Validation Matrix

For every POST/PUT/PATCH endpoint with a request body:

Test CaseExpected Status
Empty body {}400 or 422
Missing required fields (one at a time)400 or 422
Wrong type (string where int expected)400 or 422
Boundary: value at min-1400 or 422
Boundary: value at min2xx
Boundary: value at max2xx
Boundary: value at max+1400 or 422
SQL injection in string field400 or 200 (sanitized)
XSS payload in string field400 or 200 (sanitized)
Null values for required fields400 or 422

Example Test Files

→ See references/example-test-files.md for details

Show full SKILL.md (265 more words)Show less

Generating Tests from Route Scan

When given a codebase, follow this process:

  1. Scan routes using the detection commands above
  2. Read each route handler to understand:
    • Expected request body schema
    • Auth requirements (middleware, decorators)
    • Return types and status codes
    • Business rules (ownership, role checks)
  3. Generate test file per route group using the patterns above
  4. Name tests descriptively: "returns 401 when token is expired" not "auth test 3"
  5. Use factories/fixtures for test data — never hardcode IDs
  6. Assert response shape, not just status code

Common Pitfalls

  • Testing only happy paths — 80% of bugs live in error paths; test those first
  • Hardcoded test data IDs — use factories/fixtures; IDs change between environments
  • Shared state between tests — always clean up in afterEach/afterAll
  • Testing implementation, not behavior — test what the API returns, not how it does it
  • Missing boundary tests — off-by-one errors are extremely common in pagination and limits
  • Not testing token expiry — expired tokens behave differently from invalid ones
  • Ignoring Content-Type — test that API rejects wrong content types (xml when json expected)

Best Practices

  1. One describe block per endpoint — keeps failures isolated and readable
  2. Seed minimal data — don't load the entire DB; create only what the test needs
  3. Use beforeAll for shared setup, afterAll for cleanup — not beforeEach for expensive ops
  4. Assert specific error messages/fields, not just status codes
  5. Test that sensitive fields (password, secret) are never in responses
  6. For auth tests, always test the "missing header" case separately from "invalid token"
  7. Add rate limit tests last — they can interfere with other test suites if run in parallel

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in engineering/skills/api-test-suite-builder of alirezarezvani/claude-skills.

  • SKILL.md
  • references/example-test-files.md

Open the folder on GitHubat commit 19392f7

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in alirezarezvani/claude-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

API Test Suite Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Test Suite Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Test Suite Builder this skillalirezarezvani/claude-skills28k1 repos~1.6kAutomated safety check: PassMIT
API Testing RESTPramodDutta/qaskills232—~4.9kAutomated safety check: PassMIT
Rust API Test Harnesshashgraph-online/awesome-codex-plugins1.2k—~1.7kAutomated safety check: PassMIT
Specialist Integration Test GeneratorHoangNguyen0403/agent-skills-standard571—~548Automated safety check: PassMIT
Automate Integration Testopenshift/oc-mirror124—~862Automated safety check: PassApache-2.0
Agent Integration Testingav/mi102—~908Automated safety check: PassNone

Similar skills

  • API Testing REST

    PramodDutta/qaskills

    Comprehensive RESTful API testing patterns covering HTTP methods, status codes, request/response validation, authentication, error handling, and contract testing.

    232 GitHub stars~4.9k tokensUpdated 4 days ago
    Testing & QAAuto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.2k GitHub stars~1.7k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Specialist Integration Test Generator

    HoangNguyen0403/agent-skills-standard

    Generates one integration/E2E test from an approved test case spec using existing project patterns.

    571 GitHub stars~548 tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Automate Integration Test

    openshift/oc-mirror

    Convert a manual test case description into a Ginkgo oc-v2 integration test for oc-mirror

    124 GitHub stars~862 tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Writes plain-English integration test specs with verifiable steps and expectations, then runs each one through a subagent that reports pass or fail with logs.

    102 GitHub stars~908 tokensUpdated 12 days ago
    Testing & QAAuto-check passed
  • Migrate E2E To Integration

    openshift/oc-mirror

    Migrate an oc-mirror e2e test case to the integration test suite, translating framework, registry, invocation, and assertion patterns

    124 GitHub stars~1.5k tokensUpdated yesterday
    Testing & QAAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Categories

Questions about API Test Suite Builder

What does API Test Suite Builder do?

A skill your agent uses when the user asks to generate API tests, create integration test suites, test REST endpoints, or build contract tests. API Test Suite Builder is an agent skill from alirezarezvani/claude-skills. Use when the user asks to generate API tests, create integration test suites, test REST endpoints, or build contract tests.

When should I use API Test Suite Builder?

API Test Suite Builder fits situations like: the user asks to generate API tests; create integration test suites; test REST endpoints; build contract tests.

How do I install API Test Suite Builder in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill api-test-suite-builder -a claude-code`. Or copy the skill folder (engineering/skills/api-test-suite-builder in alirezarezvani/claude-skills) into .claude/skills/api-test-suite-builder in your project. Claude Code loads it when a task matches its description.

How do I install API Test Suite Builder in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill api-test-suite-builder -a codex`. Or copy the skill folder (engineering/skills/api-test-suite-builder in alirezarezvani/claude-skills) into .agents/skills/api-test-suite-builder in your project. Codex loads it when a task matches its description.

Can I use API Test Suite Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill api-test-suite-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-test-suite-builder, .gemini/skills/api-test-suite-builder, .github/skills/api-test-suite-builder and .opencode/skills/api-test-suite-builder in your project.

What does API Test Suite Builder need to run?

SKILL.md names no scripts, command-line tools or credentials: API Test Suite Builder is instructions for the agent only.

Does API Test Suite Builder access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Test Suite Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Test Suite Builder use?

API Test Suite Builder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Test Suite Builder use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.

What are the alternatives to API Test Suite Builder?

Skills that share tags, products or a category with API Test Suite Builder: API Testing REST (PramodDutta/qaskills, 232 stars), Rust API Test Harness (hashgraph-online/awesome-codex-plugins, 1.2k stars), Specialist Integration Test Generator (HoangNguyen0403/agent-skills-standard, 571 stars) and Automate Integration Test (openshift/oc-mirror, 124 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Test Suite Builder?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,829 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.