Agent skill

Arandu HTTP

by arandu-io in arandu-io/arandu

Controllers, requests and routes of an Arandu (Go) application -- the seven resource actions, a resource nested under another, a singleton, a single-action (invokable) controller, a named action…

MITAuto-check passed

Install Arandu HTTP

skills CLI
$ npx skills add arandu-io/arandu --skill arandu-http -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install arandu-io/arandu arandu-http --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/arandu-io/arandu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/arandu-http .claude/skills/arandu-http && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
arandu-http
GitHub stars
281
Token cost
~2.5k tokens
SKILL.md length
975 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Controllers, requests and routes of an Arandu (Go) application -- the seven resource actions, a resource nested under another, a singleton, a single-action (invokable) controller, a named action…

  • Works in 5 steps: Pick the shape. CRUD on a record is a… → Generate it. aru make:module writes the… → Write the action thin: read who is… → …
  • The request is to add a route
  • SKILL.md covers When to use, Before you start, Contracts and imports and Procedure, plus 8 more sections
  • Calls go and bash

What it does

Arandu HTTP is an agent skill from arandu-io/arandu. Controllers, requests and routes of an Arandu (Go) application -- the seven resource actions, a resource nested under another, a singleton, a single-action (invokable) controller, a named action such as publish or approve, the request struct and its validation, route guards and route names. Use when the request is to "add a route", "add an endpoint", "add an action", "publish/approve/cancel a record", "nest X under Y", "validate this form", "who can reach this page", or when ctx.Bind, ctx.User, r.Resource…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The Arandu project skeleton, which aru new clones. The licence is MIT.

When your agent uses it

  • The request is to add a route
  • Add an endpoint
  • Publish/approve/cancel a record
  • Validate this form

Example prompts

  • “add a route”
  • “add an endpoint”
  • “add an action”
  • “/arandu-http”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Pick the shape. CRUD on a record is a resource. A record reached
  2. Generate it. aru make:module writes the resource controller with the
  3. Write the action thin: read who is asking, bind the input, call the
  4. Write the request's rules in Validate, and leave calling it to the
  5. Register the route in the custom block, behind its guard, and give it a

What it can do on your machine

Read from SKILL.md and the folder at commit b8a4273. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Arandu HTTP loads about 2.5k tokens when it runs. Until then it costs about 176 tokens; SKILL.md has 975 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~176
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from arandu-io/arandu at commit b8a4273, republished under its MIT licence (© arandu-io). 975 words, ~2,547 tokens.

Download SKILL.mdSave it as .claude/skills/arandu-http/SKILL.md (or your agent's skills folder).
name
arandu-http
description
Controllers, requests and routes of an Arandu (Go) application -- the seven resource actions, a resource nested under another, a singleton, a single-action (invokable) controller, a named action such as publish or approve, the request struct and its validation, route guards and route names. Use when the request is to "add a route", "add an endpoint", "add an action", "publish/approve/cancel a record", "nest X under Y", "validate this form", "who can reach this page", or when ctx.Bind, ctx.User, r.Resource, r.ResourceAction, r.Singleton or r.Invokable is involved. Covers aru make:controller (--resource, --singleton, --invokable, --parent, --action), make:request and make:middleware.
license
MIT

Controllers, requests and routes

When to use

Anything between the router and the service: which address answers, behind which guard, which controller method takes it, and how the input becomes a request struct. What the answer looks like is arandu-view for a page and arandu-api for a program; what the service does is arandu-module.

Before you start

  • Read routes/web.go -- its custom block is the whole table of what this application answers -- and app/Http/Controllers/NoteController.go.
  • The service the controller calls exists first. A controller written before its service grows the service's work.

Contracts and imports

piececontract
actionfunc (c *X) Name(ctx *hhttp.Context) error, with hhttp "github.com/arandu-io/hesape/http"
resource controllerthe seven actions, each asserted: var _ fhttp.Indexer = (*X)(nil) and Creator, Storer, Shower, Editor, Updater, Destroyer, with fhttp "github.com/arandu-io/framework/http"; Resource registers only what is implemented
invokable controllerInvoke(ctx *hhttp.Context) error, asserted with var _ fhttp.Invoker = (*X)(nil)
requestapp/Http/Requests/<Entity>Request.go: fields with form:"..." tags, func (r X) Validate() validation.Errors, var _ validation.Validatable = X{}
who is askingwho, _ := ctx.User(), put there by the route's guard
inputctx.Bind(&in), which reads only the tagged fields; a conversion error comes back as validation.Errors
pathctx.Param("id") on a flat resource's member; ctx.Param("note") and ctx.Param("comment") under a nested one
an addressctx.URL("notes.show", id) and ctx.RedirectRoute("notes.show", id), by route name
an errorreturned; the router answers validation.Errors with a redirect back to the form (a 422 problem document to a JSON client), a missing row 404, a refusal 403, a duplicate key 409, and an error with HTTPStatus() int that status

The routes, in the custom block of routes/web.go:

shaperegistrationaddresses and names
resourcer.Resource("notes", d.Note)/notes, /notes/{id}; notes.index ... notes.destroy
nested, shallowr.Resource("notes.comments", d.Comment)index, create, store under /notes/{note}/comments; show, edit, update, destroy at /comments/{comment}; notes.comments.*
named actionr.ResourceAction("POST", "notes", "publish", d.Note.Publish)POST /notes/{id}/publish, notes.publish
singletonr.Singleton("settings", d.Settings)show, edit, update at /settings, no id
invokabler.Invokable("POST", "/reports", d.RunReport).Name("reports")one address
one actionr.Action("GET", "/dashboard", d.Home.Index, guard).Name("dashboard")one address

A guard goes on the group or the route -- r.Group("", middleware.RequireAuth(d.Sessions)) -- with middleware "github.com/arandu-io/framework/http/middleware", never at the top of an action.

Procedure

  1. Pick the shape. CRUD on a record is a resource. A record reached through another is nested, and the parent in the path is where the person navigated -- the service loads it through the Grant. A verb on one record is a named action of its resource. One thing with no id per account is a singleton. One operation that is not a record's is an invokable controller.

  2. Generate it. aru make:module writes the resource controller with the module; one controller alone is aru make:controller Note --resource, --parent=notes, --singleton or --invokable, and --action=publish adds a named action. Each prints the route lines.

  3. Write the action thin: read who is asking, bind the input, call the service, answer. NoteController.Publish is the whole shape of a named action:

    go
    func (c *NoteController) Publish(ctx *hhttp.Context) error {
        who, _ := ctx.User()
        published, err := c.svc.Publish(ctx.Ctx(), who, ctx.Param("id"))
        if err != nil {
            return err
        }
        return ctx.RedirectRoute("notes.show", published.ID)
    }
  4. Write the request's rules in Validate, and leave calling it to the service, so a job and a command that call the same service pass the same validation.

  5. Register the route in the custom block, behind its guard, and give it a name if the generator did not.

Commands

  • aru make:controller <Name> --resource, --singleton, --invokable, with --parent=<resource> and --action=<name>
  • aru make:request <Name> --fields "title:string!,body:text"
  • aru make:middleware <Name>
  • aru route:list, the table the router built

aru make:controller --force rewrites the file and keeps only its custom block: on a controller finished by hand, as NoteController is, run it in a scratch copy and move the new method into the custom block.

Show full SKILL.md (401 more words)Show less

Example

A single-action controller and the routes of every shape, as they compile against this project:

go
package example

import (
	fhttp "github.com/arandu-io/framework/http"
	"github.com/arandu-io/framework/http/middleware"
	"github.com/arandu-io/framework/security"
	hhttp "github.com/arandu-io/hesape/http"

	controllers "<module>/app/Http/Controllers"
	services "<module>/app/Services"
)

// PublishNote is one operation with one address: an invokable controller.
type PublishNote struct {
	notes *services.NoteService
}

// NewPublishNote takes the service it calls, built in bootstrap/app.go.
func NewPublishNote(notes *services.NoteService) *PublishNote {
	return &PublishNote{notes: notes}
}

var _ fhttp.Invoker = (*PublishNote)(nil)

// Invoke publishes the note the form names in its path.
func (c *PublishNote) Invoke(ctx *hhttp.Context) error {
	who, _ := ctx.User()
	published, err := c.notes.Publish(ctx.Ctx(), who, ctx.Param("id"))
	if err != nil {
		return err
	}
	return ctx.RedirectRoute("notes.show", published.ID)
}

// Routes registers each shape behind the sign-in guard.
func Routes(r *fhttp.Router, sessions *security.SessionStore, note *controllers.NoteController,
	comment *controllers.CommentController, publish *PublishNote) {
	signedIn := r.Group("", middleware.RequireAuth(sessions))
	signedIn.Resource("notes", note)
	signedIn.ResourceAction("POST", "notes", "publish", note.Publish)
	signedIn.Resource("notes.comments", comment)
	signedIn.Invokable("POST", "/notes/{id}/publish-now", publish).Name("notes.publish-now")
}

Do not

  • Read the form field by field, parse it, or decode a body by hand: input-read-by-hand. ctx.Bind into the request is the one conversion.
  • Call Validate() in the controller: validate-called-by-controller.
  • Answer a rejected form with a 422 of your own -- htmx discards its body and a reload posts again -- or redirect to a path written as a literal: invalid-form-answered-by-hand, redirect-to-literal-path.
  • Load the session in a controller outside app/Http/Controllers/Auth: session-loaded-in-controller. ctx.User() is who is asking.
  • Reach a model, a repository or a client from a controller: handler-reaches-the-model, controller-reaches-repository.
  • Choose the operation by a form field (operation-chosen-by-form-field), put a state change behind GET, or grow a controller past twelve actions (controller-too-many-actions): a verb is a named action or its own controller.

Extending it

Actions beyond the seven go in the controller's custom block, and their route lines in the custom block of routes/web.go. Rules a request needs beyond the generated ones -- a range, a format, a field that depends on another -- go in the custom block of Validate.

Wiring

  • routes/web.go: the controller's field on Deps, and the route lines in the custom block, behind a guard.
  • bootstrap/app.go: the constructor in the routes.Deps literal, with the service built once and shared -- the example builds notes once and hands it to both controllers that need it.
  • A middleware of the application is constructed in bootstrap/app.go and put on the route or the group that needs it.

Acceptance test

A feature test through the router, signed in with tests.SignedIn:

  • the success, with the status and the Location it redirects to;
  • another member's record (403) and another tenant's (404), for every action that takes an id, under the nested resource and the named action too;
  • a rejected form: 303 back with the messages, 204 with HX-Redirect to htmx, 422 problem document to JSON;
  • a guest redirected to the sign-in page, and a GET on a state-changing route answered 405.

tests/Feature/Notes_test.go and tests/Feature/Comments_test.go hold each.

Limits

ctx.View(name, ...) and route names are strings: a typo compiles, and is found by aru doctor (view-does-not-exist) and by the tests, not by the compiler. The router answers the errors it knows; a domain error it should answer with another status carries HTTPStatus() int rather than being mapped in the action.

Gates

Run them all, in this order, as AGENTS.md lists them:

sh
export GOWORK=off
aru model:build --check
aru view:build
gofmt -l $(find . -name '*.go' -not -path '*/testdata/*' -not -name '*.kyse.go')
go vet ./...
bash tests/test-layout-guard.sh
go test -race ./...
go build ./...
aru doctor
<!-- arandu:begin custom -->
<!-- arandu:end custom -->

© arandu-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/arandu-http of arandu-io/arandu.

Open the folder on GitHubat commit b8a4273

Compare with similar skills

Arandu HTTP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Arandu HTTP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Arandu HTTP this skillarandu-io/arandu281—~2.5kAutomated safety check: PassMIT
Control UIopenclaw/openclaw392k—~1.8kAutomated safety check: PassMIT
OmniRoute Routing CLIdiegosouzapw/OmniRoute75k—~342Automated safety check: PassMIT
OmniRoute Combo Routingdiegosouzapw/OmniRoute75k—~2.1kAutomated safety check: PassMIT
Intelligence Routeruvnet/ruflo74k—~874Automated safety check: NotesMIT
Control UI Solidopenclaw/openclaw392k—~3.9kAutomated safety check: PassMIT

Similar skills

  • Control UI

    openclaw/openclaw

    Operate and troubleshoot the OpenClaw Control UI: navigate connected clients, organize sessions, build session dashboards, and handle direct or Tailscale-hosted Gateways.

    392k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • OmniRoute Routing CLI

    diegosouzapw/OmniRoute

    Creates, switches, and inspects OmniRoute model-routing combos, plus a suggestion command with cost and latency constraints.

    75k GitHub stars~342 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • OmniRoute Combo Routing

    diegosouzapw/OmniRoute

    Manages OmniRoute routing combos through its REST API: create and update combos, choose from 19 strategies, set fallback chains, test outcomes and read metrics.

    75k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Intelligence Route

    ruvnet/ruflo

    Route tasks via the 3-tier model selector and learned patterns; emits a routing rationale via hooksexplain

    74k GitHub stars~874 tokensUpdated today
    DevelopmentAuto-check: notes
  • Control UI Solid

    openclaw/openclaw

    Port or review OpenClaw Control UI code moving from Lit 3 and Web Awesome to Solid 2, including components, projections, lifecycle boundaries, and migration proof.

    392k GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • Control UI E2E

    openclaw/openclaw

    A skill your agent uses when designing, testing, fixing, or extending the OpenClaw Control UI GUI, including UI stress-test galleries with feedback inputs, Vitest + Playwright end-to-end checks…

    392k GitHub stars~2.9k tokensUpdated today
    Testing & QAAuto-check passed

More from arandu-io/arandu

All 12 skills in this repo
  • Arandu API

    arandu-io/arandu

    Answering a program rather than a person in an Arandu (Go) application -- a JSON Resource, a JSON answer from the same routes the pages use, problem+json errors, bearer-token authentication and…

    281 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Arandu Async

    arandu-io/arandu

    Work that does not happen inside the request in an Arandu (Go) application -- background jobs and the worker, scheduled tasks, domain events through the outbox, listeners, notifications, mail and…

    281 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.

    281 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Arandu Feature

    arandu-io/arandu

    Start here for any change to an Arandu (Go) application that adds or changes behaviour -- "add invoices", "let users publish a post", "send a weekly report", "call the payment provider", "expose…

    281 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Arandu Integrations

    arandu-io/arandu

    Reaching other systems from an Arandu (Go) application, and letting them reach it -- the client of an external API with its interface and fake, webhooks sent and received, and tools, resources and…

    281 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Arandu Module Generator

    arandu-io/arandu

    Adds a new entity, resource or CRUD module to an Arandu Go application by writing a YAML specification instead of hand-writing the Go code.

    281 GitHub stars~2.4k tokensUpdated today
    Auto-check passed

Questions about Arandu HTTP

What does Arandu HTTP do?

Controllers, requests and routes of an Arandu (Go) application -- the seven resource actions, a resource nested under another, a singleton, a single-action (invokable) controller, a named action…. Arandu HTTP is an agent skill from arandu-io/arandu. Controllers, requests and routes of an Arandu (Go) application -- the seven resource actions, a resource nested under another, a singleton, a single-action (invokable) controller, a named action such as publish or approve, the request struct and its validation, route guards and route names.

When should I use Arandu HTTP?

Arandu HTTP fits situations like: the request is to add a route; add an endpoint; publish/approve/cancel a record; validate this form.

How do I install Arandu HTTP in Claude Code?

Run `npx skills add arandu-io/arandu --skill arandu-http -a claude-code`. Or copy the skill folder (.agents/skills/arandu-http in arandu-io/arandu) into .claude/skills/arandu-http in your project. Claude Code loads it when a task matches its description.

How do I install Arandu HTTP in Codex?

Run `npx skills add arandu-io/arandu --skill arandu-http -a codex`. Or copy the skill folder (.agents/skills/arandu-http in arandu-io/arandu) into .agents/skills/arandu-http in your project. Codex loads it when a task matches its description.

Can I use Arandu HTTP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add arandu-io/arandu --skill arandu-http -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/arandu-http, .gemini/skills/arandu-http, .github/skills/arandu-http and .opencode/skills/arandu-http in your project.

What does Arandu HTTP need to run?

Going by SKILL.md and its folder, Arandu HTTP needs the command-line tools its instructions call (go and bash).

Does Arandu HTTP access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Arandu HTTP safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Arandu HTTP use?

Arandu HTTP is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Arandu HTTP use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Arandu HTTP?

Skills that share tags, products or a category with Arandu HTTP: Control UI (openclaw/openclaw, 392k stars), OmniRoute Routing CLI (diegosouzapw/OmniRoute, 75k stars), OmniRoute Combo Routing (diegosouzapw/OmniRoute, 75k stars) and Intelligence Route (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Arandu HTTP?

arandu-io (a GitHub organization) maintains it in arandu-io/arandu, which has 281 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 10, 2026.

Source: arandu-io/arandu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.