Change apps/api — an endpoint or controller, a route's @RouteAccess, a service's accessibleQuery scoping, a Prisma model or a CASL permission — or an environment variable anywhere in the repo.

Apache-2.0Auto-check passedDatabases

Install Odc API

skills CLI
$ npx skills add DouglasNeuroInformatics/OpenDataCapture --skill odc-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DouglasNeuroInformatics/OpenDataCapture odc-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DouglasNeuroInformatics/OpenDataCapture.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/odc-api .claude/skills/odc-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
odc-api
GitHub stars
119
Token cost
~2k tokens
SKILL.md length
838 words
Files
2
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Change apps/api — an endpoint or controller, a route's @RouteAccess, a service's accessibleQuery scoping, a Prisma model or a CASL permission — or an environment variable anywhere in the repo.

  • Tasks that involve ORMs and data access
  • SKILL.md covers The scope is the half nothing…, The guard: @RouteAccess, The two lists that must agree and Where the procedure lives, plus 1 more section
  • Calls pnpm
  • Tasks that involve Secrets management

What it does

Odc API is an agent skill from DouglasNeuroInformatics/OpenDataCapture. Change apps/api — an endpoint or controller, a route's @RouteAccess, a service's accessibleQuery scoping, a Prisma model or a CASL permission — or an environment variable anywhere in the repo. Use also when asked who can see or do what.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Databases, covering ORMs and data access and Secrets management. It works with Prisma. The repository describes itself as: An electronic data capture platform for administering remote and in-person clinical instruments. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve ORMs and data access
  • Tasks that involve Secrets management

Example prompts

  • “s @RouteAccess, a service”
  • “/odc-api”

What it can do on your machine

Read from SKILL.md and the folder at commit c7a6364. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Odc API loads about 2k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 838 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DouglasNeuroInformatics/OpenDataCapture at commit c7a6364, republished under its Apache-2.0 licence (© DouglasNeuroInformatics). 838 words, ~1,998 tokens.

Download SKILL.mdSave it as .claude/skills/odc-api/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
odc-api
description
Change apps/api — an endpoint or controller, a route's `@RouteAccess`, a service's `accessibleQuery` scoping, a Prisma model or a CASL permission — or an environment variable anywhere in the repo. Use also when asked who can see or do what.

apps/api serves clinical data segregated by group. Access is decided in two independent places: a guard that sees the request and no data, and a scope in the Prisma where that sees the rows. The only half a tool checks is the guard's presence (REQUIRE_ROUTE_ACCESS in the root eslint.config.js); the guard's value, and the scope entirely, are silent — no compiler, no test — so satisfying one and forgetting the other is green everywhere.

The scope is the half nothing checks

accessibleQuery(undefined, …) returns {}. apps/api/src/auth/ability.utils.ts opens the function with if (!ability) { return {}; } — an empty where, which reads every group's rows. The ability is optional by type (EntityOperationOptions in apps/api/src/core/types.ts is { ability?: AppAbility }), so tsc is satisfied, and a service spec running against a mocked model asserts back whatever arguments you passed it. This is the highest-severity mistake available in this repo, and the only thing standing in front of it is you reading the where (.agents/docs/architecture/auth-and-permissions.md, Layer 2).

Forwarding is the other half, and it has two shapes. Either the service method takes { ability }: EntityOperationOptions and its controller forwards @CurrentUser('ability'), or it takes currentUser?: RequestUser and reads .ability off it itself while its controller forwards @CurrentUser() — the second shape is apps/api/src/instruments/instruments.service.ts and apps/api/src/instrument-records/files/files.service.ts. In instruments.service.ts only findBundleById takes it as optional, because the gateway resolves an assignment's bundle unscoped, so a call site there that omits it compiles and queries every group.

Unscoped is a decision, not an omission. AuditService.find takes no ability at all, because a manage-all guard is the whole check on GET /v1/audit/logs; the inventory of routes that are deliberately unscoped is in .agents/docs/architecture/auth-and-permissions.md.

  • Done when every Prisma query in your diff is accounted for — each one either names accessibleQuery in its where, or is unscoped for a reason your reply states. Every query, not a sample of them.
  • Done when every handler whose service method receives an ability forwards it — @CurrentUser('ability') for the EntityOperationOptions shape, @CurrentUser() for the RequestUser shape — established by opening each handler, because nothing else establishes it.

The guard: @RouteAccess

Every controller handler carries one; REQUIRE_ROUTE_ACCESS in the root eslint.config.js flags a missing decorator, which is a 500 at request time rather than an open route. That rule sees nothing else — a wrong value is silent, and two of them are traps:

ValueGrants
'public'No authentication at all. Adding one is a security decision — raise it rather than deciding alone.
[]Any authenticated user, because [].every(...) is true. Easy to write by accident.

{ action, subject } runs ability.can against the subject type, never against rows; an array of them is .every(...).

Done when every handler your diff adds or changes names a @RouteAccess value and your reply says which — 'public' and [] in writing, because neither is distinguishable from a considered choice once written.

Show full SKILL.md (382 more words)Show less

The two lists that must agree

What a user can be granted through additionalPermissions is not the CASL subject list Prisma derives: it is enum AppSubject (apps/api/prisma/schema.prisma) and $AppSubjectName (packages/schemas/src/core/core.ts), hand-written and deliberately narrower. A grant may also be confined to one group, and the subjects that allows are $GroupScopableSubjectName (the same list minus all and Instrument); GROUP_SCOPED_CONDITIONS in apps/api/src/auth/ability.factory.ts names each one's group field and is typed over that list, so tsc reports a missing entry.

Done when a model users must hold a permission on appears in both lists in the same commit — and in GROUP_SCOPED_CONDITIONS unless $GroupScopableSubjectName excludes it — or your reply says you left the pair narrower deliberately.

Where the procedure lives

The order of operations is silent when skipped, and lives in files this skill does not restate:

WhenOpen
Adding or reshaping an endpoint.agents/docs/playbooks/add-api-endpoint.md — read it before writing the first file; it carries the registration steps
Any environment variable, in any workspace.agents/docs/playbooks/add-env-var.md — $Env (apps/api) and apps/gateway/src/config.ts are separate declaration sites; declaring it in one and stopping there is the usual failure
Judging who may see or do what, or picking a @RouteAccess value.agents/docs/architecture/auth-and-permissions.md — the route-by-route inventory, where an ability comes from, and which models are grantable to nobody
Writing anything in this appapps/api/AGENTS.md — libnest replaces enough of NestJS that stock Nest tutorials mislead; read apps/api/node_modules/@douglasneuroinformatics/libnest/src for a signature
Your change moved who can see what.agents/skills/odc-testing/SKILL.md — row scoping is not observable in the tier apps/api tests itself in

Consumers the compiler does not connect

Each hard-codes the path, the method and the expected status, so a rename or a changed status code reaches it even when tsc sees the schema change:

ConsumerBreaks as
apps/web/src/hooks/a 404 in the clinician SPA at runtime — .agents/docs/playbooks/add-web-data-hook.md
cli/odc-clinothing at all; it is outside the pnpm workspace and every check — cli/AGENTS.md holds its endpoint table
testing/src/support/api-client.tsa red pnpm test:e2e, which CI does run — a failed run rather than a compile error

Done when every hit of grep -rn '<segment>' apps/web/src cli/odc-cli testing/src is accounted for — grep the bare segment, because api-client.ts builds every path as ${API}/<segment> — and an endpoint an e2e test would otherwise reach through the UI has a method on that file, or your reply names the one that already seeds it.

© DouglasNeuroInformatics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/odc-api of DouglasNeuroInformatics/OpenDataCapture.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit c7a6364

Compare with similar skills

Odc API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Odc API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Odc API this skillDouglasNeuroInformatics/OpenDataCapture119—~2kAutomated safety check: PassApache-2.0
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Content Create Hero Imageprisma/web1.1k—~6.9kAutomated safety check: PassNone
Prisma Client APIcurvenote/curvenote1692 repos~1.6kAutomated safety check: PassMIT
Docs Writerprisma/web1.1k—~5.2kAutomated safety check: NotesNone
Prismablencorp/claude-code-kit106—~2.7kAutomated safety check: PassMIT

Similar skills

  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Official

    A skill your agent uses when the operator wants a hero or meta image for a Prisma blog post; asks to create or generate a blog hero, cover, social card, Open Graph, or YouTube image; mentions cover…

    1.1k GitHub stars~6.9k tokensUpdated today
    DatabasesAuto-check passed
  • Prisma Client API

    curvenote/curvenote

    Prisma Client API reference covering model queries, filters, operators, and client methods.

    169 GitHub starsUsed in 2 repos~1.6k tokens
    DatabasesAuto-check passed
  • Docs Writer

    prisma/web

    Official

    A skill your agent uses when writing, rewriting, or improving technical docs (quickstarts, how-tos, tutorials, concept pages, or API references).

    1.1k GitHub stars~5.2k tokensUpdated today
    DatabasesAuto-check: notes
  • Prisma

    blencorp/claude-code-kit

    Prisma ORM patterns including Prisma Client usage, queries, mutations, relations, transactions, and schema management.

    106 GitHub stars~2.7k tokensUpdated 10 mo ago
    DatabasesAuto-check passed
  • Prisma Expert

    davila7/claude-code-templates

    Prisma ORM expert for schema design, migrations, query optimization, relations modeling, and database operations.

    32k GitHub starsUsed in 6 repos~2.6k tokens
    DatabasesAuto-check passed

More from DouglasNeuroInformatics/OpenDataCapture

All 16 skills in this repo
  • Odc Agent Docs

    DouglasNeuroInformatics/OpenDataCapture

    Write or correct this repo's agent documentation — a workspace AGENTS.md (or its CLAUDE.md symlink), a playbook under .agents/docs/playbooks, an architecture doc, or the workspace map.

    119 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Odc Testing

    DouglasNeuroInformatics/OpenDataCapture

    Test a change in Open Data Capture. An agent skill from DouglasNeuroInformatics/OpenDataCapture.

    119 GitHub stars~1.5k tokensUpdated today
    Auto-check: notes
  • Review PR

    DouglasNeuroInformatics/OpenDataCapture

    Triage pull requests against upstream main — one verdict, action items, and whether it needs the user's eyes.

    119 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Odc Open PR

    DouglasNeuroInformatics/OpenDataCapture

    Open a pull request against main for the current branch. An agent skill from DouglasNeuroInformatics/OpenDataCapture.

    119 GitHub stars~533 tokensUpdated today
    Auto-check passed
  • Opening Issues

    DouglasNeuroInformatics/OpenDataCapture

    File a GitHub issue for Open Data Capture with its labels. An agent skill from DouglasNeuroInformatics/OpenDataCapture.

    119 GitHub stars~614 tokensUpdated today
    Auto-check passed
  • Odc Debugging

    DouglasNeuroInformatics/OpenDataCapture

    What actually breaks in Open Data Capture — a failing build, lint, unit test or e2e run; a change with no visible effect; a suite that stays green after you broke the code on purpose; an error…

    119 GitHub stars~2.8k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Odc API

What does Odc API do?

Change apps/api — an endpoint or controller, a route's @RouteAccess, a service's accessibleQuery scoping, a Prisma model or a CASL permission — or an environment variable anywhere in the repo. Odc API is an agent skill from DouglasNeuroInformatics/OpenDataCapture. Change apps/api — an endpoint or controller, a route's @RouteAccess, a service's accessibleQuery scoping, a Prisma model or a CASL permission — or an environment variable anywhere in the repo.

When should I use Odc API?

Odc API fits situations like: tasks that involve ORMs and data access; tasks that involve Secrets management.

How do I install Odc API in Claude Code?

Run `npx skills add DouglasNeuroInformatics/OpenDataCapture --skill odc-api -a claude-code`. Or copy the skill folder (.agents/skills/odc-api in DouglasNeuroInformatics/OpenDataCapture) into .claude/skills/odc-api in your project. Claude Code loads it when a task matches its description.

How do I install Odc API in Codex?

Run `npx skills add DouglasNeuroInformatics/OpenDataCapture --skill odc-api -a codex`. Or copy the skill folder (.agents/skills/odc-api in DouglasNeuroInformatics/OpenDataCapture) into .agents/skills/odc-api in your project. Codex loads it when a task matches its description.

Can I use Odc API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DouglasNeuroInformatics/OpenDataCapture --skill odc-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/odc-api, .gemini/skills/odc-api, .github/skills/odc-api and .opencode/skills/odc-api in your project.

What does Odc API need to run?

Going by SKILL.md and its folder, Odc API needs the command-line tools its instructions call (pnpm).

Does Odc API access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Odc API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Odc API use?

Odc API is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Odc API use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Odc API?

Skills that share tags, products or a category with Odc API: Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars), Content Create Hero Image (prisma/web, 1.1k stars), Prisma Client API (curvenote/curvenote, 169 stars) and Docs Writer (prisma/web, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Odc API?

DouglasNeuroInformatics (a GitHub organization) maintains it in DouglasNeuroInformatics/OpenDataCapture, which has 119 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 7, 2026.

Source: DouglasNeuroInformatics/OpenDataCapture on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.