API Audit
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
Create and update QuickStack Elysia REST API routes using the project's established /api/v1 route conventions.
$ npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install biersoeckli/QuickStack elysia-api-routes --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/biersoeckli/QuickStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/elysia-api-routes .claude/skills/elysia-api-routes && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "elysia-api-routes" agent skill from https://github.com/biersoeckli/QuickStack/tree/main/.agents/skills/elysia-api-routes into .claude/skills/elysia-api-routes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elysia-api-routes", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/biersoeckli/QuickStack/tree/main/.agents/skills/elysia-api-routesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install biersoeckli/QuickStack elysia-api-routes --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/biersoeckli/QuickStack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/elysia-api-routes .agents/skills/elysia-api-routes && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "elysia-api-routes" agent skill from https://github.com/biersoeckli/QuickStack/tree/main/.agents/skills/elysia-api-routes into .agents/skills/elysia-api-routes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elysia-api-routes", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install biersoeckli/QuickStack elysia-api-routes --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/biersoeckli/QuickStack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/elysia-api-routes .cursor/skills/elysia-api-routes && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "elysia-api-routes" agent skill from https://github.com/biersoeckli/QuickStack/tree/main/.agents/skills/elysia-api-routes into .cursor/skills/elysia-api-routes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elysia-api-routes", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/biersoeckli/QuickStack.git --path .agents/skills/elysia-api-routes--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install biersoeckli/QuickStack elysia-api-routes --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/biersoeckli/QuickStack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/elysia-api-routes .gemini/skills/elysia-api-routes && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "elysia-api-routes" agent skill from https://github.com/biersoeckli/QuickStack/tree/main/.agents/skills/elysia-api-routes into .gemini/skills/elysia-api-routes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elysia-api-routes", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install biersoeckli/QuickStack elysia-api-routesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/biersoeckli/QuickStack.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/elysia-api-routes .github/skills/elysia-api-routes && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "elysia-api-routes" agent skill from https://github.com/biersoeckli/QuickStack/tree/main/.agents/skills/elysia-api-routes into .github/skills/elysia-api-routes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elysia-api-routes", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install biersoeckli/QuickStack elysia-api-routes --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/biersoeckli/QuickStack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/elysia-api-routes .opencode/skills/elysia-api-routes && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "elysia-api-routes" agent skill from https://github.com/biersoeckli/QuickStack/tree/main/.agents/skills/elysia-api-routes into .opencode/skills/elysia-api-routes/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elysia-api-routes", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
elysia-api-routesCreate and update QuickStack Elysia REST API routes using the project's established /api/v1 route conventions.
Elysia API Routes is an agent skill from biersoeckli/QuickStack. Create and update QuickStack Elysia REST API routes using the project's established /api/v1 route conventions. Use when adding or editing files under src/server/api/v1, defining Elysia query/params/body/response schemas, or handling REST API authorization and errors.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering REST APIs and Authorization and RBAC. The repository describes itself as: Open-source, self-hostable alternative to Vercel, Netlify, Railway and Heroku. Self-host any app on your own servers in minutes. The licence is GPL-3.0.
Read from SKILL.md and the folder at commit 32bca57. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
yarnFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use yarn, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Elysia API Routes loads about 1.1k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 307 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from biersoeckli/QuickStack at commit 32bca57, republished under its GPL-3.0 licence (© biersoeckli). 307 words, ~1,065 tokens.
.claude/skills/elysia-api-routes/SKILL.md (or your agent's skills folder).For QuickStack REST routes under src/server/api/v1, follow the current examples in app/route.ts and project/route.ts:
export const resourceRoutes = new Elysia()
.derive(ApiUtils.deriveFunc)
.get('/resources/:id', async ({ params, identity }) => {
if (!identity) throw new ApiUnauthorizedException()
const resource = await resourceService.getByIdOrUndefined(params.id);
if (!resource) throw new ApiNotFoundException();
ensureReadResource(identity, resource.id);
return resource;
}, {
params: z.object({
id: z.string(),
}),
response: ApiUtils.mapResponseModel(ResourceModel),
detail: { summary: 'Get resource by id', security: [{ bearerAuth: [] }] }
});new Elysia().derive(ApiUtils.deriveFunc) so handlers receive identity.ApiUtils from src/server/utils/api-response.utils.ApiUnauthorizedException, ApiNotFoundException, and ServiceException from src/shared/model/service.exception.model as needed.query, params, and body directly in route options with Zod schemas.response with ApiUtils.mapResponseModel(successSchema).detail, with a short summary and security: [{ bearerAuth: [] }] for protected routes.identity is missing, throw new ApiUnauthorizedException().new ApiNotFoundException().ensureReadApp, ensureWriteApp, ensureCreateAppInProject, ensureDeleteAppInProject, ensureReadProject, and ensureAdmin.ServiceException for expected domain validation errors, such as immutable projectId violations.{ data }, { status }, or error envelopes.ApiUtils.problem(...), raw Response, or Elysia status(...) for expected route errors.AppExtendedWriteZodModel or a local projectWriteSchema, for bodies.query, params, or body inside the handler if the route option already declares the schema.schema: { query, params, body } in these route modules.undefined and declare response: ApiUtils.mapResponseModel(z.undefined()).{ deploymentId } and declare response: ApiUtils.mapResponseModel(z.object({ deploymentId: z.string() })).Use POST upsert semantics:
.post('/projects', async ({ body, identity }) => {
if (!identity) throw new ApiUnauthorizedException()
ensureAdmin(identity);
let existing: Project | null = null;
if (body.id) {
existing = await projectService.getByIdOrUndefined(body.id);
if (!existing) throw new ApiNotFoundException();
}
return projectService.save({ id: existing?.id, name: body.name });
}, {
body: projectWriteSchema,
response: ApiUtils.mapResponseModel(ProjectModel),
detail: { summary: 'Create or update project', security: [{ bearerAuth: [] }] }
})yarn tsc --noEmit after route changes.response: ApiUtils.mapResponseModel(...).ApiUtils.mapError(...).CONTEXT.md for REST API domain terms and write semantics before changing behavior.© biersoeckli, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/elysia-api-routes of biersoeckli/QuickStack.
Open the folder on GitHubat commit 32bca57
Elysia API Routes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Elysia API Routes this skillbiersoeckli/QuickStack | 361 | — | ~1.1k | Automated safety check: Pass | GPL-3.0 | |
| API Auditbriiirussell/cybersecurity-skills | 413 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Shadmin CLIahaodev/shadmin | 174 | — | ~1.1k | Automated safety check: Notes | MIT | |
| Project Mapgjovanovicst/golang-auth-api | 130 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Add API Resourcewso2/agent-manager | 108 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Discover APIrand/cc-polymath | 181 | — | ~1.5k | Automated safety check: Pass | MIT |
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
ahaodev/shadmin
A skill your agent uses when the user asks to query Shadmin admin platform resources (users, roles, menus, registered API resources) from a terminal — for example "list shadmin users", "show shadmin…
gjovanovicst/golang-auth-api
Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.
wso2/agent-manager
Add or change a REST API resource in agent-manager-service (the Go control plane).
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
alirezarezvani/claude-skills
Comprehensive REST API design review with automated linting, breaking-change detection, and design scorecards.
biersoeckli/QuickStack
Create and update QuickStack backend services, adapters, standalone services, and server actions using the project's established singleton, adapter, caching, and error-handling patterns.
biersoeckli/QuickStack
Create and review QuickStack backend unit and integration tests using the project's Vitest, Prisma, SQLite, and k3s conventions.
biersoeckli/QuickStack
Create and update QuickStack frontend pages, React components, forms, dialogs, tables, streaming UI, and Zustand-backed state using the project's established UI conventions.
Categories
Create and update QuickStack Elysia REST API routes using the project's established /api/v1 route conventions. Elysia API Routes is an agent skill from biersoeckli/QuickStack. Create and update QuickStack Elysia REST API routes using the project's established /api/v1 route conventions.
Elysia API Routes fits situations like: editing files under src/server/api/v1; defining Elysia query/params/body/response schemas; handling REST API authorization and errors.
Run `npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a claude-code`. Or copy the skill folder (.agents/skills/elysia-api-routes in biersoeckli/QuickStack) into .claude/skills/elysia-api-routes in your project. Claude Code loads it when a task matches its description.
Run `npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a codex`. Or copy the skill folder (.agents/skills/elysia-api-routes in biersoeckli/QuickStack) into .agents/skills/elysia-api-routes in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add biersoeckli/QuickStack --skill elysia-api-routes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elysia-api-routes, .gemini/skills/elysia-api-routes, .github/skills/elysia-api-routes and .opencode/skills/elysia-api-routes in your project.
Going by SKILL.md and its folder, Elysia API Routes needs the command-line tools its instructions call (yarn).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Elysia API Routes is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Elysia API Routes: API Audit (briiirussell/cybersecurity-skills, 413 stars), Shadmin CLI (ahaodev/shadmin, 174 stars), Project Map (gjovanovicst/golang-auth-api, 130 stars) and Add API Resource (wso2/agent-manager, 108 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
biersoeckli (a GitHub user) maintains it in biersoeckli/QuickStack, which has 361 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.
Source: biersoeckli/QuickStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.