API Audit
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
Version-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs.
$ npx skills add apollographql/skills --skill apollo-router -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install apollographql/skills apollo-router --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/apollographql/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/apollo-router .claude/skills/apollo-router && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "apollo-router" agent skill from https://github.com/apollographql/skills/tree/main/skills/apollo-router into .claude/skills/apollo-router/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apollo-router", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/apollographql/skills/tree/main/skills/apollo-routerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add apollographql/skills --skill apollo-router -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install apollographql/skills apollo-router --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apollographql/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/apollo-router .agents/skills/apollo-router && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "apollo-router" agent skill from https://github.com/apollographql/skills/tree/main/skills/apollo-router into .agents/skills/apollo-router/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apollo-router", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add apollographql/skills --skill apollo-router -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install apollographql/skills apollo-router --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apollographql/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/apollo-router .cursor/skills/apollo-router && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "apollo-router" agent skill from https://github.com/apollographql/skills/tree/main/skills/apollo-router into .cursor/skills/apollo-router/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apollo-router", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/apollographql/skills.git --path skills/apollo-router--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add apollographql/skills --skill apollo-router -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install apollographql/skills apollo-router --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apollographql/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/apollo-router .gemini/skills/apollo-router && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "apollo-router" agent skill from https://github.com/apollographql/skills/tree/main/skills/apollo-router into .gemini/skills/apollo-router/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apollo-router", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install apollographql/skills apollo-routerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add apollographql/skills --skill apollo-router -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/apollographql/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/apollo-router .github/skills/apollo-router && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "apollo-router" agent skill from https://github.com/apollographql/skills/tree/main/skills/apollo-router into .github/skills/apollo-router/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apollo-router", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add apollographql/skills --skill apollo-router -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install apollographql/skills apollo-router --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/apollographql/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/apollo-router .opencode/skills/apollo-router && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "apollo-router" agent skill from https://github.com/apollographql/skills/tree/main/skills/apollo-router into .opencode/skills/apollo-router/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "apollo-router", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
apollo-routerVersion-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs.
Apollo Router is an agent skill from apollographql/skills. Version-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs. Generates correct YAML for both Router v1.x and v2.x. Use this skill when: (1) setting up Apollo Router to run a supergraph, (2) configuring routing, headers, or CORS, (3) implementing custom plugins (Rhai scripts or coprocessors), (4) configuring telemetry (tracing, metrics, logging), (5) troubleshooting Router performance or connectivity issues, (6) securing the graph with JWT, declarative field-level authorization…
Its SKILL.md is about 5.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 34 other files, including reference files (for example `divergence-map.md`, `references/configuration.md` and `references/connectors.md`). Compatibility notes: Linux/macOS/Windows. Requires a composed supergraph schema from Rover or GraphOS.
It sits in Backend & APIs, covering Authentication, GraphQL and Authorization and RBAC. It works with Apollo GraphQL and GraphQL. The repository describes itself as: Apollo GraphQL Agent Skills. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 5f02fcf. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(router:*)Bash(./router:*)Bash(rover:*)Bash(curl:*)Bash(docker:*)ReadWriteEditGlobGrepFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
APOLLO_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Linux/macOS/Windows. Requires a composed supergraph schema from Rover or GraphOS.
From compatibility in the SKILL.md frontmatter.
Apollo Router loads about 5.4k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 163 tokens; SKILL.md has 2,272 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from apollographql/skills at commit 5f02fcf, republished under its MIT licence (© apollographql). 2,272 words, ~5,387 tokens.
.claude/skills/apollo-router/SKILL.md (or your agent's skills folder). This skill also uses 30 other files; get the full folder from GitHub.Apollo Router is a high-performance graph router written in Rust for running Apollo Federation 2 supergraphs. It sits in front of your subgraphs and handles query planning, execution, and response composition.
This skill generates version-correct configuration. Router v1 and v2 have incompatible config schemas in several critical sections (CORS, JWT auth, connectors). Always determine the target version before generating any config.
Ask the user before generating any config:
Which Apollo Router version are you targeting?
[1] Router v2.x (recommended — current LTS, required for Connectors)
[2] Router v1.x (legacy — end-of-support announced, security patches only)
[3] Not sure — help me decideIf the user picks [3], display:
Quick guide:
• Pick v2 if: you're starting fresh, using Apollo Connectors for REST APIs,
or want backpressure-based overload protection.
• Pick v1 if: you have an existing deployment and haven't migrated yet.
Note: Apollo ended active support for v1.x. The v2.10 LTS (Dec 2025)
is the current baseline. Migration is strongly recommended.
Tip: If you have an existing router.yaml, you can auto-migrate it:
router config upgrade router.yamlStore the selection as ROUTER_VERSION=v1|v2 to gate all subsequent template generation.
Ask: Production or Development?
Load the appropriate base template from:
templates/{version}/production.yamltemplates/{version}/development.yamlAsk which features to include:
@authenticated / @requiresScopes / @policy directives — requires GraphOS + request claims)connectors, early v2 preview key was preview_connectors)For each selected feature, collect required values.
templates/{version}/sections/ for auth, cors, headers, limits, telemetry, and traffic-shaping.templates/v2/sections/connectors.yaml as the source.templates/{version}/production.yaml or templates/{version}/development.yaml) or from references.ROUTER_VERSION=v2."*" for production)issuer, v2 uses plural issuers arrayField- and type-level access control enforced in the router, via the
@authenticated,@requiresScopes, and@policydirectives applied in subgraph schemas. This is the layer that the globalauthorization.require_authenticationgate cannot express. It is a GraphOS feature (Enterprise; Developer/Standard plans require Router v2.6.0+) and requires a router connected to GraphOS. Directives are enabled by default — config only turns them off.
Confirm prerequisites before recommending these:
apollo::authentication::jwt_claims context key. Populate it via JWT authentication (configure that feature too) or a coprocessor that injects claims.@policy additionally requires a Supergraph plugin (Rhai script or coprocessor) to evaluate each policy — the router extracts required policies into apollo::authorization::required_policies but does not decide them itself.Ask:
@authenticated = any valid identity; @requiresScopes = specific scopes; @policy = custom logic.)The directives live in the subgraph schemas, not in router.yaml. The router config only enables/disables the feature and (for @policy) wires the evaluating plugin. See references/configuration.md → Authorization.
Not the same as APQ. APQ (
apq) is a runtime bandwidth optimization that caches any operation a client sends — it provides no security. Safelisting uses a GraphOS-managed Persisted Query List (PQL) that clients register at build time; the router then rejects operations not on the list. This is the "persisted query safelisting" security control. It is a GraphOS feature requiring a router connected to GraphOS (APOLLO_KEY+APOLLO_GRAPH_REF).
Pick a security level (increasing restrictiveness):
| Level | Config | Behavior |
|---|---|---|
| Audit (recommended first) | persisted_queries.log_unknown: true | Logs unregistered operations; rejects nothing. Use to confirm all clients are registered before enforcing. |
| Safelist | safelist.enabled: true | Rejects operations not in the PQL. IDs and full strings both accepted if registered. |
| Safelist, IDs only | safelist.enabled: true + require_id: true | Rejects unregistered operations and any freeform operation string, even if the string is registered. |
Then gather:
local_manifests for offline licenses).rover persisted-queries publish in their CI/CD)? If not, start in audit mode.safelist, APQ must be disabled (apq.enabled: false) — they are mutually exclusive.Config key history: GA persisted_queries since v1.32.0 (was preview_persisted_queries in v1.25.0–v1.32.0); GA in all v2. See references/configuration.md → Persisted Query Safelisting.
connectors.sources.<subgraph>.<source>)$config values for connector runtime configurationpreview_connectors to connectorsPresent the tuning guidance:
Operation depth limit controls how deeply nested a query can be.
Router default: 100 (permissive — allows very deep queries)
Recommended starting point: 50
Lower values (15–25) are more secure but will reject legitimate queries
in schemas with deep entity relationships or nested fragments.
Higher values (75–100) are safer for compatibility but offer less
protection against depth-based abuse.
Tip: Run your router in warn_only mode first to see what depths your
real traffic actually uses, then tighten:
limits:
warn_only: true
What max_depth would you like? [default: 50]The same principle applies to max_height, max_aliases, and max_root_fields.
http://otel-collector:4317)9090)0.1 = 10%)Security: data leakage risk. Before generating any response cache config, you MUST ask the user which types and fields return user-specific data. Cached data defaults to shared — subgraph responses without
Cache-Control: privateare visible to all users. User-specific subgraphs must returnCache-Control: privateand haveprivate_idconfigured on the router.
sub claim, session token, API key)redis://localhost:6379)5m)templates/v2/sections/response-caching.yamlreferences/response-caching.md (start with the Security section)templates/{version}/Run the post-generation checklist:
router: (client-facing), not only all: (subgraph)issuers (v2) not issuer (v1), or vice versarouter config validate <file> if Router binary is availableAfter generating or editing any router.yaml, you MUST:
validation/checklist.md and report pass/fail for each checklist item.router config validate <path-to-router.yaml> if Router CLI is available.router.yaml is the router's contract with every request — treat it like application code, not an ops afterthought. Whenever you generate or edit config, steer the user toward this workflow:
router.yaml to version control. It should live in git alongside the service, with changes reviewed via pull request. This gives you history, blame, and rollback for the most safety-critical file in the API layer.APOLLO_KEY, JWKS URLs, Redis URLs, and invalidation keys out of the file — reference them with ${env.*} expansion and inject at deploy time. The committed file should be safe to read by anyone with repo access.router config validate router.yaml on every PR so a malformed or version-mismatched config fails the build before it ships. Pin the Router version used in CI to the version you deploy.rover subgraph check / rover subgraph publish (the rover skill); config changes flow through this validate-in-CI gate. Both gate the same deploy.A minimal CI step (provide actual commands only if asked):
# Validate router config on every pull request
- run: router config validate router.yamlAfter answering any Apollo Router request (config generation, edits, validation, or general Router guidance), decide whether the user already has runnable prerequisites:
APOLLO_KEY + APOLLO_GRAPH_REF, orsupergraph.graphql plus reachable subgraphsIf prerequisites are already present, do not add extra handoff text.
If prerequisites are missing or unknown, end with a concise Next steps handoff (1-3 lines max) that is skill-first and command-free:
rover skill to compose or fetch the supergraph schema.apollo-router once the supergraph is ready to validate and run with the generated config.apollo-server, graphql-schema, and graphql-operations skills to scaffold and test.Do not include raw shell commands in this handoff unless the user explicitly asks for commands.
apollo-router skill to generate or refine router.yaml for your environment.APOLLO_KEY and APOLLO_GRAPH_REF (no local supergraph composition required).graphql-schema + apollo-server to define/run subgraphs, then use graphql-operations for smoke tests, then use the rover skill to compose or fetch supergraph.graphql.apollo-router skill to validate readiness (validation/checklist.md) and walk through runtime startup inputs.Default endpoint remains http://localhost:4000 when using standard Router listen defaults.
If the user asks for executable shell commands, provide them on request. Otherwise keep Quick Start guidance skill-oriented.
| Mode | Command | Use Case |
|---|---|---|
| Local schema | router --supergraph ./schema.graphql | Development, CI/CD |
| GraphOS managed | APOLLO_KEY=... APOLLO_GRAPH_REF=my-graph@prod router | Production with auto-updates |
| Development | router --dev --supergraph ./schema.graphql | Local development |
| Hot reload | router --hot-reload --supergraph ./schema.graphql | Schema changes without restart |
| Variable | Description |
|---|---|
APOLLO_KEY | API key for GraphOS |
APOLLO_GRAPH_REF | Graph reference (graph-id@variant) |
APOLLO_ROUTER_CONFIG_PATH | Path to router.yaml |
APOLLO_ROUTER_SUPERGRAPH_PATH | Path to supergraph schema |
APOLLO_ROUTER_LOG | Log level (off, error, warn, info, debug, trace) |
APOLLO_ROUTER_LISTEN_ADDRESS | Override listen address |
router [OPTIONS]
Options:
-s, --supergraph <PATH> Path to supergraph schema file
-c, --config <PATH> Path to router.yaml configuration
--dev Enable development mode
--hot-reload Watch for schema changes
--log <LEVEL> Log level (default: info)
--listen <ADDRESS> Override listen address
-V, --version Print version
-h, --help Print help--dev mode for local development (enables introspection and sandbox)--hot-reload for local development with file-based schemasAPOLLO_KEY in logs or version control${env.VAR}) for all secrets and sensitive configallow_any_origin or wildcard CORS in productionrouter config upgrade router.yaml for v1 → v2 migration instead of regenerating from scratchvalidation/checklist.md after every router config generation or editrouter config validate <file> when Router CLI is availablemax_depth: 50 as the default starting point, not 15 (too aggressive) or 100 (too permissive)warn_only: true for initial limits rollout to observe real traffic before enforcingROUTER_VERSION=v2 (requires v2.6.0+)${env.*} for Redis URLs, passwords, and invalidation shared keysresponse_cache.debug: true in production configprivate_id for subgraphs that serve user-specific data, and ensure those subgraphs return Cache-Control: private (via @cacheControl(scope: PRIVATE) in Apollo Server, or by setting the header directly in other frameworks)127.0.0.1, NEVER 0.0.0.0 in productionapq) is a bandwidth optimization with no security value; safelisting (persisted_queries.safelist) is the operation allowlist. If a user asks to "lock down which queries can run", point them to safelisting, not APQapq.enabled: false) when enabling persisted_queries.safelist — they are mutually exclusivelog_unknown: true) to confirm all clients are registered before turning on safelist.enabledAPOLLO_KEY + APOLLO_GRAPH_REF, or local_manifests for offline licenses)persisted_queries (GA, v1.32.0+ and all v2), NOT preview_persisted_queries (v1.25.0–v1.32.0)authorization.require_authentication and declarative directives as different layers: the former gates the whole request, the latter (@authenticated / @requiresScopes / @policy) does field- and type-level filteringapollo::authentication::jwt_claims)authorization.directives.enabled: false only turns them off; never imply config is required to "turn them on"@policy additionally requires a Rhai script or coprocessor at the Supergraph stage to evaluate apollo::authorization::required_policiesrouter.yaml — router config only enables/disables the featurerouter.yaml to version control and running router config validate in CI on every PR, with all secrets referenced via ${env.*} and injected at deploy timeAPOLLO_KEY, JWKS/Redis URLs, invalidation keys) to the config file; the committed router.yaml must be safe to share with anyone holding repo access© apollographql, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 30 other files (references) in skills/apollo-router of apollographql/skills.
Open the folder on GitHubat commit 5f02fcf
Apollo Router next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Apollo Router this skillapollographql/skills | 117 | — | ~5.4k | Automated safety check: Pass | MIT | |
| API Auditbriiirussell/cybersecurity-skills | 413 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Discover APIrand/cc-polymath | 181 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Neo4j Graphql Skillneo4j-contrib/neo4j-skills | 114 | — | ~3.8k | Automated safety check: Notes | MIT | |
| API Designeraiskillstore/marketplace | 430 | — | ~3.6k | Automated safety check: Pass | None | |
| GraphQL Operations with CodegenChrisWiles/claude-code-showcase | 6.1k | 3 repos | ~1.5k | Automated safety check: Pass | None |
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
neo4j-contrib/neo4j-skills
Build and configure a GraphQL API backed by Neo4j using @neo4j/graphql v7 (current) or v5 (LTS).
aiskillstore/marketplace
Design and document RESTful and GraphQL APIs with OpenAPI/Swagger specifications, authentication patterns, versioning strategies, and best practices.
ChrisWiles/claude-code-showcase
Sets the rules for writing GraphQL queries and mutations in .gql files, running codegen, and using generated Apollo hooks with proper error and loading handling.
goSprinto/compliance-skills
Proactive PII add-on — augments the main response with PII guidance.
apollographql/skills
Build and iterate on an Apollo Connectors subgraph for a GraphOS supergraph from a REST API, with or without an OpenAPI or Swagger spec, in a dedicated git workspace that records what the API…
apollographql/skills
Guide for building React applications with Apollo Client 4.x.
apollographql/skills
DEPRECATED: superseded by the graphos-factory skill (npx skills add apollographql/skills@graphos-factory), which builds and maintains a Connectors subgraph from a REST API with recorded decisions…
apollographql/skills
Guide for authoring Apollo Federation subgraph schemas. An agent skill from apollographql/skills.
apollographql/skills
Guide for building Apple-platform applications with Apollo iOS, the strongly-typed GraphQL client for Swift.
apollographql/skills
Guide for writing Apollo Router native Rust plugins. An agent skill from apollographql/skills.
Works with
Categories
Version-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs. Apollo Router is an agent skill from apollographql/skills. Version-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs.
Apollo Router fits situations like: setting up Apollo Router to run a supergraph; configuring routing; implementing custom plugins (Rhai scripts; configuring telemetry (tracing.
Run `npx skills add apollographql/skills --skill apollo-router -a claude-code`. Or copy the skill folder (skills/apollo-router in apollographql/skills) into .claude/skills/apollo-router in your project. Claude Code loads it when a task matches its description.
Run `npx skills add apollographql/skills --skill apollo-router -a codex`. Or copy the skill folder (skills/apollo-router in apollographql/skills) into .agents/skills/apollo-router in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apollographql/skills --skill apollo-router -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apollo-router, .gemini/skills/apollo-router, .github/skills/apollo-router and .opencode/skills/apollo-router in your project.
Going by SKILL.md and its folder, Apollo Router needs credentials named APOLLO_KEY. Our summary lists: Docker; A credential in APOLLO_KEY. Its frontmatter pre-approves these tools: Bash(router:*), Bash(./router:*), Bash(rover:*), Bash(curl:*), Bash(docker:*), Read, Write, Edit, Glob, Grep. Compatibility (from SKILL.md): Linux/macOS/Windows. Requires a composed supergraph schema from Rover or GraphOS..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Apollo Router is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.4k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Apollo Router: API Audit (briiirussell/cybersecurity-skills, 413 stars), Discover API (rand/cc-polymath, 181 stars), Neo4j Graphql Skill (neo4j-contrib/neo4j-skills, 114 stars) and API Designer (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
apollographql (a GitHub organization) maintains it in apollographql/skills, which has 117 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.
Source: apollographql/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.