Agent skill

Skill Creator

by apollographql in apollographql/skills

Guide for creating effective skills for Apollo GraphQL and GraphQL development.

MITAuto-check: warningsAgent Workflows

Install Skill Creator

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add apollographql/skills --skill skill-creator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install apollographql/skills skill-creator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/apollographql/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-creator .claude/skills/skill-creator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-creator
GitHub stars
117
Token cost
~3k tokens
SKILL.md length
1,120 words
Files
2 (incl. references)
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Guide for creating effective skills for Apollo GraphQL and GraphQL development.

  • Works in 7 steps: Overview - Brief explanation of the… → Process - Step-by-step workflow (use… → Quick Reference - Common patterns and… → …
  • Users want to create a new skill
  • SKILL.md covers What is a Skill?, Directory Structure, SKILL.md Format and Body Content, plus 10 more sections
  • Calls curl and sh

What it does

Skill Creator is an agent skill from apollographql/skills. Guide for creating effective skills for Apollo GraphQL and GraphQL development. Use this skill when: (1) users want to create a new skill, (2) users want to update an existing skill, (3) users ask about skill structure or best practices, (4) users need help writing SKILL.md files.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/apollo-skills.md`). Compatibility notes: Works with Claude Code and similar AI coding assistants that support Agent Skills.

It sits in Agent Workflows, covering Skill authoring and GraphQL. It works with Apollo GraphQL and GraphQL. The repository describes itself as: Apollo GraphQL Agent Skills. The licence is MIT.

When your agent uses it

  • Users want to create a new skill
  • Users want to update an existing skill
  • Users ask about skill structure
  • Users need help writing SKILL.md files

Example prompts

  • “/skill-creator”

Requirements

  • Compatibility (from SKILL.md): Works with Claude Code and similar AI coding assistants that support Agent Skills.
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Glob, Grep

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Overview - Brief explanation of the skill's purpose
  2. Process - Step-by-step workflow (use checkboxes for multi-step processes)
  3. Quick Reference - Common patterns and syntax
  4. Security - Risks, mitigations, and validation (if the skill touches anything security-sensitive)
  5. Reference Files - Links to detailed documentation
  6. Key Rules - Important guidelines organized by topic
  7. Ground Rules - Critical do's and don'ts

What it can do on your machine

Read from SKILL.md and the folder at commit 5f02fcf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • sh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • agentskills.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Works with Claude Code and similar AI coding assistants that support Agent Skills.

    From compatibility in the SKILL.md frontmatter.

Context cost

Skill Creator loads about 3k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 1,120 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningPipes a downloaded script straight into a shellSKILL.md:350
    - NEVER include `Bash(curl:*)` in `allowed-tools` as it grants unrestricted network access and enables `curl | sh` remot

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from apollographql/skills at commit 5f02fcf, republished under its MIT licence (© apollographql). 1,120 words, ~3,031 tokens.

Download SKILL.mdSave it as .claude/skills/skill-creator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
skill-creator
description
Guide for creating effective skills for Apollo GraphQL and GraphQL development. Use this skill when: (1) users want to create a new skill, (2) users want to update an existing skill, (3) users ask about skill structure or best practices, (4) users need help writing SKILL.md files.
allowed-tools
Read, Write, Edit, Glob, Grep
compatibility
Works with Claude Code and similar AI coding assistants that support Agent Skills.
license
MIT
metadata.author
apollographql
metadata.version
1.1.1

Skill Creator Guide

This guide helps you create effective skills for Apollo GraphQL and GraphQL development following the Agent Skills specification.

What is a Skill?

A skill is a directory containing instructions that extend an AI agent's capabilities with specialized knowledge, workflows, or tool integrations. Skills activate automatically when agents detect relevant tasks.

Directory Structure

A skill requires at minimum a SKILL.md file:

skill-name/
├── SKILL.md              # Required - main instructions
├── references/           # Optional - detailed documentation
│   ├── topic-a.md
│   └── topic-b.md
├── scripts/              # Optional - executable helpers
│   └── validate.sh
├── templates/            # Optional - config/code templates
│   └── config.yaml
└── assets/               # Optional - static resources (images, schemas, data files)

SKILL.md Format

Frontmatter (Required)
yaml
---
name: skill-name
description: >
  A clear description of what this skill does and when to use it.
  Include trigger conditions: (1) first condition, (2) second condition.
license: MIT
compatibility: Works with Claude Code and similar AI coding assistants.
metadata:
  author: your-org
  version: "1.0.0"
allowed-tools: Read Write Edit Glob Grep
---
Frontmatter Fields
FieldRequiredDescription
nameYesLowercase, hyphens only. Must match directory name. Max 64 chars.
descriptionYesWhat the skill does and when to use it. Max 1024 chars.
licenseNoLicense name (e.g., MIT, Apache-2.0).
compatibilityNoEnvironment requirements. Max 500 chars.
metadataNoKey-value pairs for author, version, etc.
allowed-toolsNoSpace-delimited list of pre-approved tools. Do not include Bash(curl:*).
Name Rules
  • Use lowercase letters, numbers, and hyphens only
  • Do not start or end with a hyphen
  • Do not use consecutive hyphens (--)
  • Must match the parent directory name

Good: apollo-client, graphql-schema, rover Bad: Apollo-Client, -apollo, apollo--client

Description Best Practices

Write descriptions that help agents identify when to activate the skill:

yaml
# Good - specific triggers and use cases
description: >
  Guide for designing GraphQL schemas following industry best practices. Use this skill when:
  (1) designing a new GraphQL schema or API,
  (2) reviewing existing schema for improvements,
  (3) deciding on type structures or nullability,
  (4) implementing pagination or error patterns.

# Bad - vague and unhelpful
description: Helps with GraphQL stuff.

Body Content

The markdown body contains instructions the agent follows. Structure it for clarity:

  1. Overview - Brief explanation of the skill's purpose
  2. Process - Step-by-step workflow (use checkboxes for multi-step processes)
  3. Quick Reference - Common patterns and syntax
  4. Security - Risks, mitigations, and validation (if the skill touches anything security-sensitive)
  5. Reference Files - Links to detailed documentation
  6. Key Rules - Important guidelines organized by topic
  7. Ground Rules - Critical do's and don'ts
Example Structure
markdown
# Skill Title

Brief overview of what this skill helps with.

## Process

Follow this process when working on [task]:

- [ ] Step 1: Research and understand requirements
- [ ] Step 2: Implement the solution
- [ ] Step 3: Validate the result

## Quick Reference

### Common Pattern

\`\`\`graphql
type Example {
  id: ID!
  name: String
}
\`\`\`

## Security

> **Risk: [brief description of what can go wrong].**
> [What the user MUST do to prevent it.]

- ALWAYS [secure default behavior]
- NEVER [dangerous configuration] in production

## Reference Files

- [Topic A](references/topic-a.md) - Detailed guide for topic A
- [Topic B](references/topic-b.md) - Detailed guide for topic B

## Key Rules

### Category One

- Rule about this category
- Another rule

### Category Two

- Rule about this category

## Ground Rules

- ALWAYS do this important thing
- NEVER do this problematic thing
- PREFER this approach over that approach

Security-Sensitive Content

When a skill generates configuration, code, or guidance that could cause security issues if misused, the skill MUST make those risks explicit and visible to the LLM. An LLM cannot infer security implications from context alone — it needs clearly labeled signals.

When does a skill need security guidance?

If any of these apply, the skill is security-sensitive:

  • Generates config that controls access to data (caching, auth, CORS, permissions)
  • Handles secrets, credentials, or tokens
  • Produces code that runs with elevated privileges
  • Controls what data is shared, public, or exposed to users
  • Configures network bindings, endpoints, or external access
How to surface security in a skill
  1. Dedicated Security section in SKILL.md or a reference file, labeled ## Security. Not "Private data" or "Customization" — use the word "Security" so the LLM recognizes the category.

  2. Explicit warnings at the point of risk — place security guidance next to the config or code that creates the risk, not in a separate file the LLM may not load:

    markdown
    ### Response caching scope
    
    > **Security: data leakage risk.** All cached data is PUBLIC by default.
    > User-specific fields MUST use `scope: PRIVATE` with a `private_id`
    > configured, or they will be shared across all users.
  3. Validation checklist items — every security-sensitive feature must have corresponding checks in the validation checklist. Group them under a ## Security heading.

  4. Ground rules — add ALWAYS/NEVER rules for security-critical behavior. These are the strongest signal to the LLM.

  5. Require the data model — if correct security configuration depends on understanding the user's data model (e.g., which fields are user-specific), the skill must instruct the LLM to ask the user before generating config. Do not let the LLM guess.

Anti-patterns
  • Describing a security-sensitive default (like "public by default") without labeling it as a security concern
  • Placing security guidance only in reference files that load on demand — the SKILL.md itself must contain the key warnings
  • Using soft language ("you may want to consider") for hard security requirements — use "MUST" and "NEVER"
  • Assuming the LLM understands which fields in a schema are private — require explicit user input

Progressive Disclosure

Structure skills to minimize context usage:

  1. Metadata (~100 tokens): name and description load at startup for all skills
  2. Instructions (< 5000 tokens): Full SKILL.md loads when skill activates
  3. References (as needed): Files in references/ load only when required

Keep SKILL.md under 500 lines. Move detailed documentation to reference files.

Reference Files

Use references/ for detailed documentation:

references/
├── setup.md          # Installation and configuration
├── patterns.md       # Common patterns and examples
├── troubleshooting.md # Error solutions
└── api.md            # API reference

Reference files should be:

  • Focused on a single topic
  • Self-contained (readable without other files)
  • Under 300 lines each

Link to references from SKILL.md:

markdown
## Reference Files

- [Setup](references/setup.md) - Installation and configuration
- [Patterns](references/patterns.md) - Common patterns and examples
Show full SKILL.md (472 more words)Show less

Scripts

Use scripts/ for executable helpers agents can run:

scripts/
├── validate.sh       # Validation commands
├── setup.py          # Setup automation
└── check-version.sh  # Version checking

Scripts should be self-contained, include error handling, and have a usage comment at the top. Pre-approve them in allowed-tools (e.g., Bash(./scripts/validate.sh:*)).

Templates

Use templates/ for config files, boilerplate, or starter code:

templates/
├── config.yaml       # Default configuration
├── config-v2.yaml    # Version-specific variant
└── example-app/      # Starter project

Templates are copied or adapted by the agent — not executed directly.

Writing Style

Follow the Apollo Voice for all skill content:

Tone
  • Approachable and helpful
  • Opinionated and authoritative (prescribe the "happy path")
  • Direct and action-oriented
Language
  • Use American English
  • Keep language simple; avoid idioms
  • Use present tense and active voice
  • Use imperative verbs for instructions
Formatting
  • Use sentence casing for headings
  • Use code font for symbols, commands, file paths, and URLs
  • Use bold for UI elements users click
  • Use hyphens (-) for unordered lists
Avoid
  • "Simply", "just", "easy" (can be condescending)
  • Vague phrases like "click here"
  • Semicolons (use periods instead)
  • "We" unless clearly referring to Apollo

Reference Files

For Apollo GraphQL-specific guidance:

  • Apollo Skills - Patterns and examples for Apollo GraphQL skills

Versioning

Use semantic versioning ("X.Y.Z") for the version field in metadata:

yaml
metadata:
  author: apollographql
  version: "1.0.0"
  • Major (X): Breaking changes that alter how the skill behaves or activates (e.g., renamed triggers, removed sections, changed ground rules)
  • Minor (Y): New content or capabilities that are backward-compatible (e.g., added reference files, new sections, expanded examples)
  • Patch (Z): Small fixes that don't change behavior (e.g., typo corrections, wording tweaks, formatting fixes)

Start new skills at "1.0.0".

Checklist for New Skills

Before publishing a skill, verify:

  • name matches directory name and follows naming rules
  • description clearly states what the skill does and when to use it
  • SKILL.md is under 500 lines
  • Reference files are focused and under 300 lines each
  • Instructions are clear and actionable
  • Code examples are correct and tested
  • Ground rules use ALWAYS/NEVER/PREFER format
  • Content follows Apollo Voice guidelines

Ground Rules

  • ALWAYS include trigger conditions in the description (use numbered list)
  • ALWAYS use checkboxes for multi-step processes
  • ALWAYS link to reference files for detailed documentation
  • NEVER exceed 500 lines in SKILL.md
  • NEVER use vague descriptions that don't help agents identify when to activate
  • PREFER specific examples over abstract explanations
  • PREFER opinionated guidance over listing multiple options
  • USE allowed-tools to pre-approve tools the skill needs
  • NEVER include Bash(curl:*) in allowed-tools as it grants unrestricted network access and enables curl | sh remote code execution patterns
  • ALWAYS include a ## Security section when the skill generates config or code that controls access, caching, auth, secrets, or data exposure
  • NEVER bury security-critical guidance only in reference files — the key warnings must appear in SKILL.md where the LLM will always see them
  • ALWAYS instruct the LLM to ask the user about their data model before generating security-sensitive config (e.g., which fields are user-specific, which data is public)
  • USE explicit blockquote warnings (> **Security: ...**) next to config or code that creates security risks
  • ALWAYS add validation checklist items for every security-sensitive feature, grouped under a ## Security heading

© apollographql, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/skill-creator of apollographql/skills.

  • SKILL.md
  • references/apollo-skills.md

Open the folder on GitHubat commit 5f02fcf

Compare with similar skills

Skill Creator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Creator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Creator this skillapollographql/skills117—~3kAutomated safety check: WarnMIT
GraphQL Operations with CodegenChrisWiles/claude-code-showcase6.1k3 repos~1.5kAutomated safety check: PassNone
Graphqldavila7/claude-code-templates32k5 repos~625Automated safety check: PassMIT
Neo4j Graphql Skillneo4j-contrib/neo4j-skills114—~3.8kAutomated safety check: NotesMIT
Graphqlaiskillstore/marketplace4304 repos~6.5kAutomated safety check: PassNone
Apollo GraphqlKilo-Org/kilo-marketplace1901 repos~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • GraphQL Operations with Codegen

    ChrisWiles/claude-code-showcase

    Sets the rules for writing GraphQL queries and mutations in .gql files, running codegen, and using generated Apollo hooks with proper error and loading handling.

    6.1k GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Graphql

    davila7/claude-code-templates

    GraphQL gives clients exactly the data they need - no more, no less.

    32k GitHub starsUsed in 5 repos~625 tokens
    Backend & APIsAuto-check passed
  • Neo4j Graphql Skill

    neo4j-contrib/neo4j-skills

    Build and configure a GraphQL API backed by Neo4j using @neo4j/graphql v7 (current) or v5 (LTS).

    114 GitHub stars~3.8k tokensUpdated 2 days ago
    Backend & APIsAuto-check: notes
  • Graphql

    aiskillstore/marketplace

    GraphQL gives clients exactly the data they need - no more, no less.

    430 GitHub starsUsed in 4 repos~6.5k tokens
    Backend & APIsAuto-check passed
  • Apollo Graphql

    Kilo-Org/kilo-marketplace

    Guidelines for developing GraphQL APIs and React applications using Apollo Client for state management, data fetching, and caching

    190 GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed
  • Build Error Adapter

    ArcadeAI/arcade-mcp

    Build new Arcade error adapters from scratch using public Arcade TDK patterns.

    1k GitHub stars~2k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

More from apollographql/skills

All 12 skills in this repo
  • Apollo Federation

    apollographql/skills

    Guide for authoring Apollo Federation subgraph schemas. An agent skill from apollographql/skills.

    117 GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Apollo iOS

    apollographql/skills

    Guide for building Apple-platform applications with Apollo iOS, the strongly-typed GraphQL client for Swift.

    117 GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Graphos Factory

    apollographql/skills

    Build and iterate on an Apollo Connectors subgraph for a GraphOS supergraph from a REST API, with or without an OpenAPI or Swagger spec, in a dedicated git workspace that records what the API…

    117 GitHub stars~15k tokensUpdated yesterday
    Auto-check passed
  • Graphql Operations

    apollographql/skills

    Guide for writing GraphQL operations (queries, mutations, fragments) following best practices.

    117 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Apollo Client

    apollographql/skills

    Guide for building React applications with Apollo Client 4.x.

    117 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Apollo Connectors

    apollographql/skills

    DEPRECATED: superseded by the graphos-factory skill (npx skills add apollographql/skills@graphos-factory), which builds and maintains a Connectors subgraph from a REST API with recorded decisions…

    117 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed

Questions about Skill Creator

What does Skill Creator do?

Guide for creating effective skills for Apollo GraphQL and GraphQL development. Skill Creator is an agent skill from apollographql/skills. Guide for creating effective skills for Apollo GraphQL and GraphQL development.

When should I use Skill Creator?

Skill Creator fits situations like: users want to create a new skill; users want to update an existing skill; users ask about skill structure; users need help writing SKILL.md files.

How do I install Skill Creator in Claude Code?

Run `npx skills add apollographql/skills --skill skill-creator -a claude-code`. Or copy the skill folder (skills/skill-creator in apollographql/skills) into .claude/skills/skill-creator in your project. Claude Code loads it when a task matches its description.

How do I install Skill Creator in Codex?

Run `npx skills add apollographql/skills --skill skill-creator -a codex`. Or copy the skill folder (skills/skill-creator in apollographql/skills) into .agents/skills/skill-creator in your project. Codex loads it when a task matches its description.

Can I use Skill Creator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add apollographql/skills --skill skill-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-creator, .gemini/skills/skill-creator, .github/skills/skill-creator and .opencode/skills/skill-creator in your project.

What does Skill Creator need to run?

Going by SKILL.md and its folder, Skill Creator needs the command-line tools its instructions call (curl and sh). Its frontmatter pre-approves these tools: Read, Write, Edit, Glob, Grep. Compatibility (from SKILL.md): Works with Claude Code and similar AI coding assistants that support Agent Skills..

Does Skill Creator access the network?

SKILL.md names 1 domain. As links in the text: agentskills.io. This is read from the text; nothing was executed.

Is Skill Creator safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): pipes a downloaded script straight into a shell. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Skill Creator use?

Skill Creator is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Creator use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Skill Creator?

Skills that share tags, products or a category with Skill Creator: GraphQL Operations with Codegen (ChrisWiles/claude-code-showcase, 6.1k stars), Graphql (davila7/claude-code-templates, 32k stars), Neo4j Graphql Skill (neo4j-contrib/neo4j-skills, 114 stars) and Graphql (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Creator?

apollographql (a GitHub organization) maintains it in apollographql/skills, which has 117 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.

Source: apollographql/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.