Agent skill

Arandu Integrations

by arandu-io in arandu-io/arandu

Reaching other systems from an Arandu (Go) application, and letting them reach it -- the client of an external API with its interface and fake, webhooks sent and received, and tools, resources and…

MITAuto-check passedBackend & APIs

Install Arandu Integrations

skills CLI
$ npx skills add arandu-io/arandu --skill arandu-integrations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install arandu-io/arandu arandu-integrations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/arandu-io/arandu.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/arandu-integrations .claude/skills/arandu-integrations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
arandu-integrations
GitHub stars
281
Token cost
~3.1k tokens
SKILL.md length
1,262 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Reaching other systems from an Arandu (Go) application, and letting them reach it -- the client of an external API with its interface and fake, webhooks sent and received, and tools, resources and…

  • Works in 5 steps: Generate the client: aru make:client… → Make the call idempotent when it changes… → Depend on the interface. The service… → …
  • The request is to call the payment provider
  • SKILL.md covers When to use, Before you start, Contracts and imports and Procedure, plus 8 more sections
  • Calls go and bash; needs NEWSLETTER_WEBHOOK_SECRET

What it does

Arandu Integrations is an agent skill from arandu-io/arandu. Reaching other systems from an Arandu (Go) application, and letting them reach it -- the client of an external API with its interface and fake, webhooks sent and received, and tools, resources and prompts an AI assistant calls over MCP. Use when the request is to "call the payment provider", "integrate with X", "send to Slack", "receive a webhook", "verify a signature", "expose this to Claude/an assistant/an agent", "add an MCP tool", or when an http.Client, an API key or app/Clients is involved. Covers aru…

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks and MCP servers. It works with Model Context Protocol, Slack and GitHub. The repository describes itself as: The Arandu project skeleton, which aru new clones. The licence is MIT.

When your agent uses it

  • The request is to call the payment provider
  • Integrate with X
  • Receive a webhook
  • Verify a signature

Example prompts

  • “call the payment provider”
  • “integrate with X”
  • “send to Slack”
  • “/arandu-integrations”

Requirements

  • A credential in NEWSLETTER_WEBHOOK_SECRET

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Generate the client: aru make:client Newsletter writes the config, the
  2. Make the call idempotent when it changes something on the other side
  3. Depend on the interface. The service takes clients.Newsletter, set
  4. Receive a webhook under /webhooks/, in a controller that
  5. Expose a capability to an assistant with `aru make:mcp-tool ShowNote

What it can do on your machine

Read from SKILL.md and the folder at commit b8a4273. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • NEWSLETTER_WEBHOOK_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Arandu Integrations loads about 3.1k tokens when it runs. Until then it costs about 150 tokens; SKILL.md has 1,262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~150
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from arandu-io/arandu at commit b8a4273, republished under its MIT licence (© arandu-io). 1,262 words, ~3,104 tokens.

Download SKILL.mdSave it as .claude/skills/arandu-integrations/SKILL.md (or your agent's skills folder).
name
arandu-integrations
description
Reaching other systems from an Arandu (Go) application, and letting them reach it -- the client of an external API with its interface and fake, webhooks sent and received, and tools, resources and prompts an AI assistant calls over MCP. Use when the request is to "call the payment provider", "integrate with X", "send to Slack", "receive a webhook", "verify a signature", "expose this to Claude/an assistant/an agent", "add an MCP tool", or when an http.Client, an API key or app/Clients is involved. Covers aru make:client, make:mcp-tool, make:mcp-resource and make:mcp-prompt.
license
MIT

Other systems

When to use

A call that leaves the process, a request another system sends in, or a capability handed to an assistant. The service that decides to make the call is arandu-module; the job or listener that makes it later is arandu-async.

Before you start

  • Read the example's client: app/Clients/NewsletterClient.go, its fake app/Clients/NewsletterFake.go, the service that depends on it (NoteService.SendDigest) and newsletter at the end of bootstrap/app.go.
  • Read the example's received webhook: NewsletterWebhookController.Store, NewsletterEventService.Receive, the /webhooks/newsletter route and the middleware.CSRFExcept("/webhooks/") passed to CSRFProtect in bootstrap/app.go.
  • Ask arandu-ecosystem first whether the client belongs here at all: a client another project would reuse, and an engine that wraps another technology -- a model runtime, OCR, a camera -- is a github.com/hyz-is/arandu-* module.

Contracts and imports

piececontract
clientapp/Clients/<Vendor>Client.go: a typed <Vendor>Config (its secret kept out of logs and JSON), a small <Vendor> interface the callers depend on, and <Vendor>Client built with the config and a *client.Factory from github.com/arandu-io/hesape/http/client
fakeapp/Clients/<Vendor>Fake.go: the interface, answering what it was told and recording Calls
a requestonly through the factory: c.http.CreatePendingRequest().BaseURL(...), which carries a deadline, bounds the body and refuses an address inside the network
a callera service, a job or a listener, through the interface; never a controller, a model or a view
configurationa Credential in config/services.go, read from the environment, named in .env.example
webhook receivedapp/Http/Controllers/<Vendor>WebhookController.go, Store(ctx), under /webhooks/: it reads the raw body and checks webhook.Verify(secrets, timestamp, deliveryID, body, signature) from github.com/arandu-io/hesape/webhook -- the headers are X-Arandu-Timestamp, X-Arandu-Delivery-ID and X-Arandu-Signature -- and the timestamp's age, before it binds or stores anything; then a service records the delivery and the answer is 2xx
CSRF/webhooks/ is exempt by name, in bootstrap/app.go: middleware.CSRFProtect(csrf, sessions.IDFromRequest, middleware.CSRFExcept("/webhooks/")). A route under it has no protection but its own signature check
webhook secreta Credential in config/services.go (NEWSLETTER_WEBHOOK_SECRET), 32 bytes or more, named empty in .env.example; with none the controller answers 404
webhook sentwebhook.NewPublisher(manager, resolver) is an events.Publisher: a listener in listeners.Each that delivers outbox events, signed, with retries
MCPapp/Mcp/<Name>.go: a tool with Name, Description, Schema and Handle(ctx, r mcp.Request), calling a service with r.Subject(), from github.com/arandu-io/mcp

Procedure

  1. Generate the client: aru make:client Newsletter writes the config, the interface, the client, the fake and a test that runs the client against a faked factory. Add each call to the interface, the client and the fake together, in their custom blocks, with types of the client's own so no caller reads the vendor's wire format.
  2. Make the call idempotent when it changes something on the other side: carry a key that survives a retry, as NewsletterDigest.Key does, sent as Idempotency-Key.
  3. Depend on the interface. The service takes clients.Newsletter, set with WithNewsletter; bootstrap/app.go builds the real client from the configuration, or leaves it nil when nothing is configured, so the application runs with no credential and a test passes the fake.
  4. Receive a webhook under /webhooks/<vendor>, in a controller that reads the raw body, verifies the signature and the timestamp before anything else, binds the request from the same bytes, hands it to a service and answers 2xx. The service records the delivery -- the example stores an event in the outbox under the delivery id, which the relay hands to the listeners after the answer -- so a slow step never times the sender out. Work that needs retries is a job a listener of that event dispatches, never one the service dispatches: the job's package imports app/Services.
  5. Expose a capability to an assistant with aru make:mcp-tool ShowNote --service=Note (make:mcp-resource, make:mcp-prompt for the other two kinds). It writes the type in app/Mcp, its test and the wiring; the module is taken first with go get github.com/arandu-io/mcp@v0.4.0.

Commands

  • aru make:client <Vendor>
  • aru make:mcp-tool <Name> --service=<Entity>, aru make:mcp-resource <Name> --service=<Entity>, aru make:mcp-prompt <Name>

Example

Code that calls an external system, and the two stand-ins a test builds for it -- neither reaches the network:

go
package example

import (
	"context"
	"net/http"

	"github.com/arandu-io/hesape/http/client"

	clients "<module>/app/Clients"
)

// Announce takes the client's interface, never the concrete type, so a test
// hands it the fake.
func Announce(ctx context.Context, newsletter clients.Newsletter, title string) error {
	return newsletter.SendDigest(ctx, clients.NewsletterDigest{
		Key:   "announce-" + title,
		Notes: []clients.NewsletterNote{{Title: title}},
	})
}

// Offline builds the fake, which records the call, and the real client over a
// faked factory, which records the request it would have sent.
func Offline() (*clients.NewsletterFake, *clients.NewsletterClient) {
	fake := &clients.NewsletterFake{}
	factory := client.NewFactory(nil).Fake(func(*http.Request) (*http.Response, error) {
		return client.NewResponseFromBytes(http.StatusAccepted, nil, nil).HTTPResponse(), nil
	})
	faked := clients.NewNewsletterClient(clients.NewsletterConfig{BaseURL: "https://newsletter.example.test"}, factory)
	return fake, faked
}

A received webhook, reduced to its order: the signature over the exact bytes, then the request, then the service, then 202 -- as NewsletterWebhookController.Store does it:

go
package example

import (
	"bytes"
	"io"
	"net/http"

	"github.com/arandu-io/hesape/exception"
	hhttp "github.com/arandu-io/hesape/http"
	"github.com/arandu-io/hesape/webhook"

	requests "<module>/app/Http/Requests"
	services "<module>/app/Services"
)

// Receive refuses a delivery whose signature does not verify before it reads
// a single field of it.
func Receive(ctx *hhttp.Context, secrets webhook.SecretSet, events *services.NewsletterEventService) error {
	body, err := io.ReadAll(ctx.Request.Body)
	if err != nil {
		return err
	}
	delivery := ctx.Header("X-Arandu-Delivery-ID")
	if !webhook.Verify(secrets, ctx.Header("X-Arandu-Timestamp"), delivery, body, ctx.Header("X-Arandu-Signature")) {
		return exception.Abort(http.StatusUnauthorized, "this delivery is not signed by the provider")
	}
	ctx.Request.Body = io.NopCloser(bytes.NewReader(body))
	var in requests.NewsletterEventRequest
	if err := ctx.Bind(&in); err != nil {
		return err
	}
	if err := events.Receive(ctx.Ctx(), delivery, in); err != nil {
		return err
	}
	return ctx.Status(http.StatusAccepted)
}

The controller also refuses a timestamp more than five minutes from its clock, which this reduction leaves out: the signature covers the timestamp, so a captured delivery replayed later is refused even though it still verifies.

An MCP tool, as aru make:mcp-tool ShowNote --service=Note writes it. It is not compiled here, because this project does not require the mcp module:

go
func (t ShowNote) Handle(ctx context.Context, r mcp.Request) (mcp.Response, error) {
	id, _ := r.String("id")
	found, err := t.svc.Get(ctx, r.Subject(), id)
	if err != nil {
		return mcp.Response{}, err
	}
	return mcp.JSON(resources.NewNoteResource(found)), nil
}
Show full SKILL.md (534 more words)Show less

Do not

  • Make an HTTP call outside app/Clients, or with an http.Client of your own: client-outside-clients. The factory is what bounds it.
  • Hand a client a model, a Grant or the session (client-reaches-the-model): it answers about the other system, and the service decides about ours.
  • Put a vendor's SDK behind app/Services with a *Port or *Adapter name: the client is the one shape for an external system.
  • Let an MCP tool reach a model, a repository or a client: it calls a service as who is asking, exactly as a controller does.
  • Put a secret in code or in a test. A test gets the fake or a faked factory, and a credential comes from the environment.
  • Bind, validate or store a webhook's body before its signature verified, or exempt a path from CSRF anywhere but the CSRFExcept in bootstrap/app.go. A route under /webhooks/ that skips the check is a form any site can post.

Extending it

New calls go in the custom blocks of the client, its interface and its fake -- all three, or the fake stops standing in. A field the config needs goes in the config struct and in its LogValue only if it is not a secret.

Wiring

  • config/services.go and .env.example: the credential.
  • bootstrap/app.go: the client built once, from the credential, with client.NewFactory(nil), and handed to the services that call it.
  • A received webhook: the controller built in bootstrap/app.go with its secret and its service, handed to the routes through Deps, and its route under /webhooks/ in the custom block of routes/web.go, with no guard. The CSRFExcept("/webhooks/") is already there; a vendor under another prefix is a second argument to it, never a second exemption elsewhere.
  • MCP: the server composed in bootstrap/app.go and mounted in routes/web.go with r.Action("POST", "/mcp", mcp.Web(d.MCP), ...) behind a guard; there is no routes/ai.go. Behind RequireToken a client holding a personal access token reaches it -- see arandu-api.

Acceptance test

  • The generated client test, and one per call: the request it builds against a faked factory -- method, path, headers, body -- and its answer to a failure.
  • The caller tested with the fake: what it was asked, and what the caller does when the fake answers an error.
  • No test reaches the network: the fake, or a factory faked with Fake, answers inside the process, and PreventStrayRequests(true) makes a request nothing stubbed an error.
  • A received webhook, as tests/Feature/NewsletterWebhook_test.go does: a delivery signed with webhook.Sign and no CSRF token answers 2xx and is recorded; another secret, a changed body, no signature and an old timestamp answer 401 with nothing recorded; no secret configured answers 404.

Limits

The example verifies the wire format github.com/arandu-io/hesape/webhook sends, which is what another Arandu application delivers. A vendor that signs another way -- another header, another string signed -- is verified with that vendor's scheme in its own controller, still before anything else. A delivery the provider retries is recorded again; whatever acts on it keys on the delivery id, as every consumer of an at-least-once relay has to.

There is no MCP example in this project, because requiring the mcp module is a decision for the project that exposes itself.

Gates

Run them all, in this order, as AGENTS.md lists them:

sh
export GOWORK=off
aru model:build --check
aru view:build
gofmt -l $(find . -name '*.go' -not -path '*/testdata/*' -not -name '*.kyse.go')
go vet ./...
bash tests/test-layout-guard.sh
go test -race ./...
go build ./...
aru doctor
<!-- arandu:begin custom -->
<!-- arandu:end custom -->

© arandu-io, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/arandu-integrations of arandu-io/arandu.

Open the folder on GitHubat commit b8a4273

Compare with similar skills

Arandu Integrations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Arandu Integrations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Arandu Integrations this skillarandu-io/arandu281—~3.1kAutomated safety check: PassMIT
Frontmcp Channelsagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0
ComposioComposioHQ/composio30k1 repos~1.7kAutomated safety check: PassMIT
Setup Context A8cwoocommerce/woocommerce-ios358—~627Automated safety check: NotesGPL-2.0
X Twitter ScraperXquik-dev/x-twitter-scraper2111 repos~2.6kAutomated safety check: PassMIT
Zalo AgentPhucMPham/zalo-agent-cli166—~2.3kAutomated safety check: PassMIT

Similar skills

  • Frontmcp Channels

    agentfront/frontmcp

    A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Composio

    ComposioHQ/composio

    Route and complete Composio work across Composio For You and Composio Platform.

    30k GitHub starsUsed in 1 repo~1.7k tokens
    Productivity & AutomationAuto-check passed
  • Setup Context A8c

    woocommerce/woocommerce-ios

    Set up the ContextA8C MCP server for accessing Automattic internal resources (Slack, Linear, P2s, GitHub Enterprise, etc.)

    358 GitHub stars~627 tokensUpdated yesterday
    Agent WorkflowsAuto-check: notes
  • X Twitter Scraper

    Xquik-dev/x-twitter-scraper

    Use Xquik to fetch X (Twitter) data or act through a connected account: search, profiles, followers, replies, threads, timelines, media downloads, bulk exports, trends, monitors, signed webhooks…

    211 GitHub starsUsed in 1 repo~2.6k tokens
    Backend & APIsAuto-check passed
  • Zalo Agent

    PhucMPham/zalo-agent-cli

    Automate Zalo messaging, Official Account (OA), and MCP server integration via zalo-agent-cli.

    166 GitHub stars~2.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Yolfi Payments

    yolfinance/yolfi-agent

    Add Yolfi crypto checkout, payment links, and webhook handling to an app through @yolfi/agent or the Yolfi MCP server.

    178 GitHub stars~1.2k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed

More from arandu-io/arandu

All 12 skills in this repo
  • Arandu API

    arandu-io/arandu

    Answering a program rather than a person in an Arandu (Go) application -- a JSON Resource, a JSON answer from the same routes the pages use, problem+json errors, bearer-token authentication and…

    281 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Arandu Async

    arandu-io/arandu

    Work that does not happen inside the request in an Arandu (Go) application -- background jobs and the worker, scheduled tasks, domain events through the outbox, listeners, notifications, mail and…

    281 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Decides whether a feature belongs in the application or in one of five shared Arandu modules before adding permissions, wallets, tags, Markdown rendering or API docs.

    281 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Arandu Feature

    arandu-io/arandu

    Start here for any change to an Arandu (Go) application that adds or changes behaviour -- "add invoices", "let users publish a post", "send a weekly report", "call the payment provider", "expose…

    281 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Arandu HTTP

    arandu-io/arandu

    Controllers, requests and routes of an Arandu (Go) application -- the seven resource actions, a resource nested under another, a singleton, a single-action (invokable) controller, a named action…

    281 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Arandu Module Generator

    arandu-io/arandu

    Adds a new entity, resource or CRUD module to an Arandu Go application by writing a YAML specification instead of hand-writing the Go code.

    281 GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Arandu Integrations

What does Arandu Integrations do?

Reaching other systems from an Arandu (Go) application, and letting them reach it -- the client of an external API with its interface and fake, webhooks sent and received, and tools, resources and…. Arandu Integrations is an agent skill from arandu-io/arandu. Reaching other systems from an Arandu (Go) application, and letting them reach it -- the client of an external API with its interface and fake, webhooks sent and received, and tools, resources and prompts an AI assistant calls over MCP.

When should I use Arandu Integrations?

Arandu Integrations fits situations like: the request is to call the payment provider; integrate with X; receive a webhook; verify a signature.

How do I install Arandu Integrations in Claude Code?

Run `npx skills add arandu-io/arandu --skill arandu-integrations -a claude-code`. Or copy the skill folder (.agents/skills/arandu-integrations in arandu-io/arandu) into .claude/skills/arandu-integrations in your project. Claude Code loads it when a task matches its description.

How do I install Arandu Integrations in Codex?

Run `npx skills add arandu-io/arandu --skill arandu-integrations -a codex`. Or copy the skill folder (.agents/skills/arandu-integrations in arandu-io/arandu) into .agents/skills/arandu-integrations in your project. Codex loads it when a task matches its description.

Can I use Arandu Integrations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add arandu-io/arandu --skill arandu-integrations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/arandu-integrations, .gemini/skills/arandu-integrations, .github/skills/arandu-integrations and .opencode/skills/arandu-integrations in your project.

What does Arandu Integrations need to run?

Going by SKILL.md and its folder, Arandu Integrations needs the command-line tools its instructions call (go and bash) and credentials named NEWSLETTER_WEBHOOK_SECRET. Our summary lists: A credential in NEWSLETTER_WEBHOOK_SECRET.

Does Arandu Integrations access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Arandu Integrations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Arandu Integrations use?

Arandu Integrations is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Arandu Integrations use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Arandu Integrations?

Skills that share tags, products or a category with Arandu Integrations: Frontmcp Channels (agentfront/frontmcp, 146 stars), Composio (ComposioHQ/composio, 30k stars), Setup Context A8c (woocommerce/woocommerce-ios, 358 stars) and X Twitter Scraper (Xquik-dev/x-twitter-scraper, 211 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Arandu Integrations?

arandu-io (a GitHub organization) maintains it in arandu-io/arandu, which has 281 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 10, 2026.

Source: arandu-io/arandu on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.