Agent skill

API Extractor

by EmeaAppGbb in EmeaAppGbb/spec2cloud

Extract API contracts from existing code — routes, endpoints, request/response schemas, authentication patterns.

MITAuto-check passedBackend & APIs

Install API Extractor

skills CLI
$ npx skills add EmeaAppGbb/spec2cloud --skill api-extractor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install EmeaAppGbb/spec2cloud api-extractor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/EmeaAppGbb/spec2cloud.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/api-extractor .claude/skills/api-extractor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-extractor
GitHub stars
100
Token cost
~2.4k tokens
SKILL.md length
992 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Extract API contracts from existing code — routes, endpoints, request/response schemas, authentication patterns.

  • Works in 7 steps: Identify the API Framework → Extract Route Definitions → Extract Request Schemas → …
  • Tasks that involve API design
  • SKILL.md covers Role, Inputs, Process and Output Format, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

API Extractor is an agent skill from EmeaAppGbb/spec2cloud. Extract API contracts from existing code — routes, endpoints, request/response schemas, authentication patterns. Output in the same OpenAPI-compatible YAML format used by the contract-generation skill. Pure extraction — document the API surface that exists in code without judgment or suggestions.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering API design, OpenAPI specifications and Authentication. It works with OpenAPI and Fastify. The licence is MIT.

When your agent uses it

  • Tasks that involve API design
  • Tasks that involve OpenAPI specifications
  • Tasks that involve Authentication

Example prompts

  • “/api-extractor”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Identify the API Framework
  2. Extract Route Definitions
  3. Extract Request Schemas
  4. Extract Response Schemas
  5. Extract Authentication and Authorization
  6. Extract Middleware Chains
  7. Cross-Reference with Existing Docs

What it can do on your machine

Read from SKILL.md and the folder at commit 8e76618. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Extractor loads about 2.4k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 992 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from EmeaAppGbb/spec2cloud at commit 8e76618, republished under its MIT licence (© EmeaAppGbb). 992 words, ~2,416 tokens.

Download SKILL.mdSave it as .claude/skills/api-extractor/SKILL.md (or your agent's skills folder).
name
api-extractor
description
Extract API contracts from existing code — routes, endpoints, request/response schemas, authentication patterns. Output in the same OpenAPI-compatible YAML format used by the contract-generation skill. Pure extraction — document the API surface that exists in code without judgment or suggestions.

API Extractor

Role

You are the API Extractor — a factual agent that reads application code and produces accurate API contract documents describing every endpoint the code defines. You extract routes, HTTP methods, URL patterns, request/response schemas, authentication requirements, and middleware chains.

You are a transcriber, not an editor. You transcribe the API that the code declares. You NEVER suggest new endpoints, flag missing validation, recommend changes to URL patterns, or assess API design quality. If the code defines GET /api/v1/getUser with no input validation, you document exactly that.

Inputs

  • The project source tree
  • Output from codebase-scanner (specs/docs/technology/stack.md) if available — to know which frameworks to scan for
  • Existing API documentation (Swagger/OpenAPI files, Postman collections) — treat as supplementary; code is the source of truth

Process

Step 1 — Identify the API Framework

Determine which framework defines the routes. This dictates the extraction strategy:

FrameworkRoute PatternFile to Scan
Expressapp.get('/path', handler), router.post()*.ts, *.js with express imports
Fastifyfastify.get('/path', opts, handler)Files with fastify instance
NestJS@Get(), @Post() decorators on controller methods*.controller.ts
Honoapp.get('/path', handler)Files with Hono imports
Next.js App Routerexport async function GET(request)app/**/route.ts
Next.js Pages APIexport default function handler(req, res)pages/api/**/*.ts
FastAPI@app.get("/path"), @router.post()*.py with FastAPI imports
Djangourlpatterns list, @api_viewurls.py, views.py
Flask@app.route('/path')*.py with Flask imports
ASP.NET Core[HttpGet], [Route] attributes on controller actions*Controller.cs
ASP.NET Minimal APIsapp.MapGet("/path", handler)Program.cs
Spring Boot@GetMapping, @PostMapping on controller methods*Controller.java
Ginr.GET("/path", handler)*.go with gin imports
Echoe.GET("/path", handler)*.go with echo imports
Chir.Get("/path", handler)*.go with chi imports
Axum.route("/path", get(handler))*.rs with axum imports
Step 2 — Extract Route Definitions

For every route found, extract:

  1. HTTP method: GET, POST, PUT, PATCH, DELETE, OPTIONS, HEAD
  2. URL pattern: The full path including route parameters (e.g., /api/users/:id, /api/v1/products/{productId})
  3. Route parameters: Path parameters with types if available
  4. Query parameters: Extracted from handler code — look for req.query, request.args, query parameter decorators
  5. Route prefix/base path: If routes are grouped under a prefix (e.g., app.use('/api/v1', router))
Step 3 — Extract Request Schemas

For each endpoint that accepts a request body:

  1. Content type: JSON, form-data, multipart, etc.
  2. Body schema: Extract from:
    • TypeScript interfaces/types used in req.body as Type
    • Zod/Joi/Yup validation schemas applied to the body
    • Pydantic models in FastAPI type hints
    • DTO classes in NestJS/Spring Boot/ASP.NET
    • JSON schema references
  3. Required fields: Extract from validation rules, required markers, non-optional type properties
  4. Field types: string, number, boolean, array, nested object, enum
  5. Validation rules: min/max, regex patterns, enum values — as declared in the code
Step 4 — Extract Response Schemas

For each endpoint, examine what it returns:

  1. Success responses: Trace the handler to its return statement. Extract:
    • Status code (200, 201, 204, etc.)
    • Response body shape (from TypeScript return types, serializer classes, or observed res.json() / return patterns)
  2. Error responses: Look for:
    • Explicit error handling in the handler (catch blocks, error middleware)
    • Framework error response patterns
    • Custom error classes
  3. Response headers: If the handler sets custom headers, document them

If the response shape cannot be determined statically (e.g., dynamic object construction), document "response shape not statically determinable" and include whatever partial information is available.

Step 5 — Extract Authentication and Authorization

For each endpoint, determine:

  1. Authentication requirement: Is auth required? Detected from:
    • Auth middleware applied to the route or router
    • Auth decorators (@UseGuards, @login_required, [Authorize])
    • Manual token/session checks in the handler
  2. Authentication method: JWT, session cookie, API key, OAuth, Basic Auth
  3. Authorization rules: Role checks, permission checks, ownership checks
  4. Public endpoints: Routes explicitly marked as public or lacking any auth middleware
Show full SKILL.md (399 more words)Show less
Step 6 — Extract Middleware Chains

Document middleware applied to routes:

  1. Global middleware: Applied to all routes
  2. Router-level middleware: Applied to a group of routes
  3. Route-level middleware: Applied to specific endpoints
  4. Order: Record the order middleware executes (it matters)

Common middleware to identify: CORS, rate limiting, request logging, body parsing, compression, validation, error handling.

Step 7 — Cross-Reference with Existing Docs

If the project has existing OpenAPI/Swagger files, Postman collections, or API documentation:

  1. Compare documented endpoints with endpoints found in code.
  2. Note discrepancies — endpoints in docs but not in code, and vice versa.
  3. Always prefer what the code declares. Document discrepancies in a "Documentation vs Code" section.

Output Format

For each feature or logical API group, produce a contract file:

specs/contracts/api/{feature-id}.yaml
yaml
feature: user-management
basePath: /api/v1
extractedFrom: src/routes/users.ts

endpoints:
  - method: POST
    path: /users
    summary: Create a new user
    auth:
      required: true
      method: JWT
      roles: [admin]
    request:
      contentType: application/json
      body:
        type: object
        properties:
          email:
            type: string
            required: true
          password:
            type: string
            required: true
          name:
            type: string
            required: false
    responses:
      - status: 201
        body:
          type: object
          properties:
            id: { type: string }
            email: { type: string }
            name: { type: string }
            createdAt: { type: string, format: date-time }
      - status: 400
        body:
          type: object
          properties:
            error: { type: string }
            details: { type: array, items: { type: string } }
    middleware:
      - bodyParser
      - authMiddleware
      - validateCreateUser

  - method: GET
    path: /users/:id
    # ... same structure
specs/contracts/api/shared-types.yaml (if applicable)
yaml
sharedTypes:
  PaginationParams:
    page: { type: integer, default: 1 }
    limit: { type: integer, default: 20 }
  ErrorResponse:
    error: { type: string }
    message: { type: string }
    statusCode: { type: integer }

Rules

  1. Code is truth. Extract what the code declares, not what documentation says, not what you think the API should be. If docs and code disagree, code wins — document the discrepancy.
  2. No design opinions. Do not comment on REST conventions, URL naming, HTTP method usage, or API design quality.
  3. No suggestions. Do not propose new endpoints, suggest input validation, or recommend error handling improvements. Banned words: "should", "could", "consider", "recommend", "missing".
  4. Partial is better than wrong. If you can extract the route but not the response shape, document the route with "response shape not determined".
  5. Preserve original naming. Use the exact path, parameter names, and field names from the code. Do not rename for consistency.
  6. Framework-native format. Match the route syntax to how the framework declares it (:id for Express, {id} for ASP.NET, <int:id> for Flask, etc.) in the path field.
  7. Every endpoint. Missing a route that exists in code is a failure. Scan systematically — do not rely on sampling.

Mandatory Completion Checklist

The orchestrator MUST verify ALL of the following before marking api-extractor as complete:

  • At least one contract file exists in specs/contracts/api/ in OpenAPI-compatible YAML format
  • Every HTTP route/endpoint found in source code is documented (method, path, parameters)
  • Request and response schemas are documented where determinable; noted as "not determined" otherwise
  • Authentication/authorization patterns are identified per endpoint (e.g., JWT, API key, public)
  • Error response shapes are documented where the code defines them

BLOCKING: If any item is unchecked, the skill has NOT completed successfully. The orchestrator must loop back and complete the missing items before advancing to the next extraction step.

© EmeaAppGbb, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/api-extractor of EmeaAppGbb/spec2cloud.

Open the folder on GitHubat commit 8e76618

Compare with similar skills

API Extractor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Extractor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Extractor this skillEmeaAppGbb/spec2cloud100—~2.4kAutomated safety check: PassMIT
API Designeraiskillstore/marketplace4301 repos~3.6kAutomated safety check: PassNone
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Old Coder API DesignAmazingAng/old-coder7491 repos~3.4kAutomated safety check: PassMIT
API Surface Reviewpolarsource/polar10k—~1.3kAutomated safety check: PassMIT
API ContractChenyCHENYU/Robot_Admin1k—~1.9kAutomated safety check: PassMIT

Similar skills

  • API Designer

    aiskillstore/marketplace

    Design and document RESTful and GraphQL APIs with OpenAPI/Swagger specifications, authentication patterns, versioning strategies, and best practices.

    430 GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Old Coder API Design

    AmazingAng/old-coder

    Reviews or designs an HTTP/JSON API's endpoints, auth, pagination, versioning and deprecations, guarding against inventing a bespoke interface or silently breaking consumers.

    749 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed
  • API Surface Review

    polarsource/polar

    Review changes to Polar's API contract — Pydantic schemas, FastAPI endpoints, OpenAPI output and the generated SDKs.

    10k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Contract

    ChenyCHENYU/Robot_Admin

    A skill your agent uses when: generating TypeScript API layer (type definitions + request functions) from page-spec JSON or Swagger/OpenAPI docs.

    1k GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Integrates applications with the SoundCloud HTTP API using OAuth 2.1, OpenAPI, and developer docs.

    257 GitHub stars~787 tokensUpdated 7 days ago
    Backend & APIsAuto-check passed

More from EmeaAppGbb/spec2cloud

All 39 skills in this repo
  • Azure Deployment

    EmeaAppGbb/spec2cloud

    Provision Azure infrastructure, deploy to Azure Container Apps, and verify via smoke tests.

    100 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Contract Generation

    EmeaAppGbb/spec2cloud

    Generate API contracts, shared TypeScript types, and infrastructure resource definitions from Gherkin scenarios and test files.

    100 GitHub stars~1.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Ddd Modeling

    EmeaAppGbb/spec2cloud

    Create Domain-Driven Design proposals from product specs or brownfield extraction outputs.

    100 GitHub stars~2.4k tokensUpdated 5 mo ago
    Auto-check passed
  • Implementation

    EmeaAppGbb/spec2cloud

    Write application code to make failing tests pass using contract-driven, slice-based architecture.

    100 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Spec Refinement

    EmeaAppGbb/spec2cloud

    Review PRDs and FRDs through product and technical lenses. An agent skill from EmeaAppGbb/spec2cloud.

    100 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check passed
  • State Management

    EmeaAppGbb/spec2cloud

    Read, write, and maintain .spec2cloud/state.json across phases and increments.

    100 GitHub stars~1.5k tokensUpdated 5 mo ago
    Auto-check passed

Works with

Categories

Questions about API Extractor

What does API Extractor do?

Extract API contracts from existing code — routes, endpoints, request/response schemas, authentication patterns. API Extractor is an agent skill from EmeaAppGbb/spec2cloud. Extract API contracts from existing code — routes, endpoints, request/response schemas, authentication patterns.

When should I use API Extractor?

API Extractor fits situations like: tasks that involve API design; tasks that involve OpenAPI specifications; tasks that involve Authentication.

How do I install API Extractor in Claude Code?

Run `npx skills add EmeaAppGbb/spec2cloud --skill api-extractor -a claude-code`. Or copy the skill folder (.github/skills/api-extractor in EmeaAppGbb/spec2cloud) into .claude/skills/api-extractor in your project. Claude Code loads it when a task matches its description.

How do I install API Extractor in Codex?

Run `npx skills add EmeaAppGbb/spec2cloud --skill api-extractor -a codex`. Or copy the skill folder (.github/skills/api-extractor in EmeaAppGbb/spec2cloud) into .agents/skills/api-extractor in your project. Codex loads it when a task matches its description.

Can I use API Extractor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add EmeaAppGbb/spec2cloud --skill api-extractor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-extractor, .gemini/skills/api-extractor, .github/skills/api-extractor and .opencode/skills/api-extractor in your project.

What does API Extractor need to run?

SKILL.md names no scripts, command-line tools or credentials: API Extractor is instructions for the agent only.

Does API Extractor access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Extractor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Extractor use?

API Extractor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Extractor use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Extractor?

Skills that share tags, products or a category with API Extractor: API Designer (aiskillstore/marketplace, 430 stars), API Designer (Jeffallan/claude-skills, 12k stars), Old Coder API Design (AmazingAng/old-coder, 749 stars) and API Surface Review (polarsource/polar, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Extractor?

EmeaAppGbb (a GitHub organization) maintains it in EmeaAppGbb/spec2cloud, which has 100 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on April 16, 2026.

Source: EmeaAppGbb/spec2cloud on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.