Discover API
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
A skill your agent uses when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only…
$ npx skills add ericrisco/rsc-harness --skill api-connector-builder -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness api-connector-builder --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-connector-builder .claude/skills/api-connector-builder && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "api-connector-builder" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/api-connector-builder into .claude/skills/api-connector-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-connector-builder", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/api-connector-builderType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill api-connector-builder -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness api-connector-builder --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/api-connector-builder .agents/skills/api-connector-builder && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "api-connector-builder" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/api-connector-builder into .agents/skills/api-connector-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-connector-builder", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill api-connector-builder -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness api-connector-builder --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/api-connector-builder .cursor/skills/api-connector-builder && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "api-connector-builder" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/api-connector-builder into .cursor/skills/api-connector-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-connector-builder", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/api-connector-builder--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill api-connector-builder -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness api-connector-builder --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/api-connector-builder .gemini/skills/api-connector-builder && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "api-connector-builder" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/api-connector-builder into .gemini/skills/api-connector-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-connector-builder", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness api-connector-builderInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill api-connector-builder -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/api-connector-builder .github/skills/api-connector-builder && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "api-connector-builder" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/api-connector-builder into .github/skills/api-connector-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-connector-builder", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill api-connector-builder -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness api-connector-builder --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/api-connector-builder .opencode/skills/api-connector-builder && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "api-connector-builder" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/api-connector-builder into .opencode/skills/api-connector-builder/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-connector-builder", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
api-connector-builderA skill your agent uses when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only…
API Connector Builder is an agent skill from ericrisco/rsc-harness. Use when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only, rate-limit-aware throttling. NOT inbound callbacks (that is webhooks), NOT chaining services (that is automation-flows), NOT designing your own API (that is api-design).
Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/auth-flows.md`).
It sits in Backend & APIs, covering Rate limiting, API design and GraphQL. It works with GraphQL. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.vendor.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
VENDOR_API_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
API Connector Builder loads about 3.6k tokens when it runs, and up to ~6k if it reads all its reference files. Until then it costs about 93 tokens; SKILL.md has 1,127 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,127 words, ~3,614 tokens.
.claude/skills/api-connector-builder/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.You are writing a client for someone else's HTTP API. You do not own the contract; you obey it. The deliverable is one typed connector module per vendor that authenticates, walks the whole result set, retries only transient failures with backoff, and stays under the rate limit without getting the key banned. One connector = one vendor: mixed clients tangle two auth schemes and two rate-limit budgets into something no one can reason about.
Four pillars, every time: auth, pagination, retries, rate limits. If your connector skips any one of them it works in the demo and breaks in production — on page 2, on token expiry, on the first 429, or on a flaky network.
Read the vendor docs before writing a line — invented endpoints and guessed field names 404 in prod. Extract these first; each one changes what you write, so missing one means a rewrite.
| Find in their docs | Why it changes your code |
|---|---|
| Auth scheme + token TTL | Picks the flow below; TTL decides if you need refresh |
| Base URL and version | Wrong version = silent 404s or deprecated field shapes |
| Rate-limit header names | You cannot throttle to a budget you cannot read |
| Pagination style | Cursor vs offset vs Link vs Relay = different loop |
| Error envelope shape | Where the real error code lives (body, not always status) |
| Idempotency support | Decides whether POST is safe to retry (key header?) |
If a fact is not in the docs, probe one real call and read the response headers and body — do not assume.
OAuth 2.1 is the current baseline. Three deltas you must honor: PKCE is mandatory for every authorization-code client, the Implicit and Resource-Owner-Password grants are removed, and bearer tokens may not travel in query strings (header only) — query strings end up in logs and referrers. (oauth.net/2.1, accessed 2026-06-02.)
| Flow | Pick it when | Secret lives | Refresh strategy |
|---|---|---|---|
| API key in header | Simple server-to-server, vendor issues key | env / secret store | none; rotate manually |
| Bearer static token | Personal access token, long-lived | env / secret store | none; treat as a key |
| OAuth2 Client Credentials | Machine-to-machine, no end user | client_id + secret | re-mint on 401; cache until expiry |
| OAuth2 Auth-Code + PKCE | Acting on behalf of a user | refresh token | rotate on every refresh (see below) |
| Device flow | CLI / TV / input-constrained device | refresh token | poll then rotate as auth-code |
Refresh-token rule (public clients): refresh tokens must be sender-
constrained or one-time-use — rotated on every refresh, with the old one
invalidated. Keep access tokens short-lived. Never log a raw token; log a partial
or hash if you must correlate. (OAuth 2.0 Security BCP / RFC 9700, accessed
2026-06-02.) Full per-flow walkthroughs, token storage, and a DPoP note are in
references/auth-flows.md.
Retry only transient failures, and only when the operation is safe to repeat.
| Status / error | Retry? | Note |
|---|---|---|
| 429 Too Many Requests | yes | honor Retry-After (see rate limits) |
| 502 / 503 / 504 | yes | server-side transient |
| Connection reset / timeout / DNS | yes | network transient |
| 400 / 401 / 403 / 404 / 409 / 422 | no | replay returns the same error — fix the call |
| 2xx | n/a | success |
Idempotency gate. GET/PUT/DELETE are idempotent by semantics and safe to retry. POST is not — only retry it if you send a stable idempotency key so the server dedupes the duplicate. (AWS Builders' Library, accessed 2026-06-02.)
Backoff with jitter. Use delay = min(cap, base * 2^attempt) + random_jitter.
The jitter is not optional: without it, every client that failed at the same
instant retries at the same instant — a synchronized thundering herd that DDoSes
the recovering server. Full or decorrelated jitter is preferred. Always set stop
conditions: max attempts 3–5, a total deadline, and a per-attempt timeout.
(AWS Builders' Library, accessed 2026-06-02.)
# Bad: retries everything, flat sleep, no jitter, no cap, no deadline.
for _ in range(10):
r = httpx.get(url)
if r.status_code == 200:
return r.json()
time.sleep(1) # 4xx will never recover; herds synchronize on flat 1s# Good: transient-only, exponential backoff WITH jitter, bounded.
import random, time, httpx
RETRYABLE = {429, 502, 503, 504}
def get(url, *, attempts=5, base=0.5, cap=20.0, deadline=60.0):
started = time.monotonic()
for attempt in range(attempts):
try:
r = httpx.get(url, timeout=10.0) # per-attempt timeout
except (httpx.ConnectError, httpx.ReadTimeout):
pass # network transient -> fall through to backoff
else:
if r.status_code == 200:
return r.json()
if r.status_code not in RETRYABLE:
r.raise_for_status() # 4xx: do not retry, surface it
if time.monotonic() - started > deadline:
raise TimeoutError("retry deadline exceeded")
delay = min(cap, base * 2 ** attempt) + random.uniform(0, base)
time.sleep(delay)
raise RuntimeError("max attempts exhausted")In Python prefer tenacity 9.1.4 (@retry with wait_exponential_jitter,
stop_after_attempt, retry_if_exception_type) over a hand loop; in Node/TS use
undici (the engine behind global fetch() since Node 18) with its retry
interceptor. (PyPI/tenacity, nodejs/undici, accessed 2026-06-02.)
Do not guess the wait — the server tells you. Precedence:
Retry-After present (on a 429 or 503) → wait exactly that. It is either
a number of seconds or an HTTP-date; handle both.Retry-After → compute the wait from X-RateLimit-Reset (a Unix epoch
or a delta-seconds, per vendor docs).X-RateLimit-Remaining — slow down before you
hit zero rather than absorbing a wall of 429s. (iotools.cloud rate-limiting
guidance, accessed 2026-06-02.)# Bad: ignore the headers, hammer, eat 429s, get the key throttled or banned.
while more:
resp = client.get(next_url) # no remaining check, no Retry-After
process(resp)# Good: header-aware. Honor Retry-After, else reset; brake near the limit.
def wait_for_rate_limit(resp):
ra = resp.headers.get("Retry-After")
if ra is not None:
return float(ra) if ra.isdigit() else _seconds_until_httpdate(ra)
remaining = int(resp.headers.get("X-RateLimit-Remaining", "1"))
if remaining <= 1:
reset = float(resp.headers.get("X-RateLimit-Reset", "0"))
return max(0.0, reset - time.time()) # or reset directly if delta-seconds
return 0.0For sustained pulls, gate every request through a token-bucket sized to the documented budget (e.g. 60 req/min → refill 1 token/sec, capacity 60) so bursts smooth out instead of slamming the wall.
There is no single best strategy; the vendor chose one and you follow it. The
universal rule: loop until the API says there is no next page — never a fixed
page count. A hardcoded for page in range(10) silently drops everything after
page 10.
| Style | Signal of "next" | Trade-off |
|---|---|---|
| Offset / page number | ?offset= / ?page= until empty page | simple; drifts on inserts, slow at depth |
| Cursor / keyset | opaque next_cursor in body | stable under writes, fixed cost — prefer it |
| Link header (REST) | Link: <...>; rel="next" | parse the header, follow until no next |
| Relay (GraphQL) | pageInfo.hasNextPage + endCursor | pass endCursor as after next query |
(graphql.org/learn/pagination + pagination pattern guides, accessed 2026-06-02.)
Expose results as a generator / async-iterator so callers stream instead of buffering everything:
def iter_records(client):
cursor = None
while True:
page = client.get("/items", params={"cursor": cursor, "limit": 100})
body = page.json()
yield from body["data"]
cursor = body.get("next_cursor")
if not cursor: # exhaustion signal, not a counter
returnFull code for every style — offset, keyset, Link-header parsing, GraphQL Relay
connection walking, in Python and TS, plus dedup-on-overlap notes — is in
references/pagination.md.
A minimal connector wires all four pillars plus env config and structured logging.
# connector.py — Python: httpx + tenacity
import os, logging, httpx
from tenacity import retry, stop_after_attempt, wait_exponential_jitter, retry_if_exception_type
log = logging.getLogger("connector")
TOKEN = os.environ["VENDOR_API_TOKEN"] # from env, never hardcoded
class Transient(Exception): ...
@retry(stop=stop_after_attempt(5),
wait=wait_exponential_jitter(initial=0.5, max=20),
retry=retry_if_exception_type(Transient))
def _request(client, method, path, **kw):
r = client.request(method, path, timeout=10.0, **kw) # per-request timeout
log.info("req id=%s %s status=%s", r.headers.get("x-request-id"), path, r.status_code)
if r.status_code in (429, 502, 503, 504):
raise Transient(r.status_code)
r.raise_for_status()
return r
def client():
return httpx.Client(base_url="https://api.vendor.com/v2",
headers={"Authorization": f"Bearer {TOKEN}"}) # header, not query// connector.ts — Node/TS: global fetch (undici) + bounded retry
const TOKEN = process.env.VENDOR_API_TOKEN!; // from env, never hardcoded
const RETRYABLE = new Set([429, 502, 503, 504]);
export async function request(path: string, init: RequestInit = {}, attempt = 0): Promise<Response> {
const res = await fetch(`https://api.vendor.com/v2${path}`, {
...init,
headers: { Authorization: `Bearer ${TOKEN}`, ...init.headers },
signal: AbortSignal.timeout(10_000), // per-request timeout
});
console.info(JSON.stringify({ id: res.headers.get("x-request-id"), path, status: res.status, attempt }));
if (RETRYABLE.has(res.status) && attempt < 4) {
const ra = Number(res.headers.get("retry-after"));
const wait = Number.isFinite(ra) && ra > 0 ? ra * 1000 : Math.min(20_000, 500 * 2 ** attempt) + Math.random() * 500;
await new Promise((r) => setTimeout(r, wait));
return request(path, init, attempt + 1);
}
return res; // caller checks res.ok / paginates
}| Anti-pattern | Consequence | Fix |
|---|---|---|
| Retry 4xx (401/403/404/422) | Burns attempts; same error every time | Retry only 429 + 5xx + network errors |
for page in range(N) fixed loop | Silently drops records past page N | Loop on cursor / Link / hasNextPage |
Flat sleep(1) between retries | Synchronized herd hammers recovering API | Exponential backoff with jitter + cap |
| Log the token / Authorization header | Leaked credential in shipped logs | Log request id + status + attempt only |
| Hardcode the API key in source | Leaks via git; cannot rotate cleanly | Read from env / secret store |
| No request timeout | One hung socket stalls the whole run | Set a per-request timeout always |
Ignore Retry-After | Keep 429-ing; key gets throttled/banned | Honor Retry-After, else X-RateLimit-Reset |
| Re-POST on retry with no idempotency | Duplicate charges / records | Send an idempotency key, or do not retry POST |
| Token in query string | Token ends up in logs / referrers | Bearer in the Authorization header |
| Implicit / password OAuth grant | Removed in OAuth 2.1; insecure | Auth-Code + PKCE, or Client Credentials |
Run scripts/verify.sh over the connector you write: it greps for hardcoded
secrets, asserts a retry mechanism and a pagination loop and a request timeout
exist, and flags localStorage token storage or plaintext token logging. It is a
structure linter (read-only), not a behavior test — exit 0 on a clean target.
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/api-connector-builder of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
API Connector Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| API Connector Builder this skillericrisco/rsc-harness | 156 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Discover APIrand/cc-polymath | 181 | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Shopify APIMicrock/ordinary-claude-skills | 401 | 1 repos | ~4.3k | Automated safety check: Pass | Custom licence | |
| API ForgeEliasOulkadi/shokunin | 114 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Saleor GraphQL API Change Checklistsaleor/saleor | 23k | — | ~1.2k | Automated safety check: Pass | BSD-3-Clause | |
| Pii DetectorgoSprinto/compliance-skills | 133 | — | ~1.6k | Automated safety check: Pass | MIT |
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
Microck/ordinary-claude-skills
Complete API integration guide for Shopify including GraphQL Admin API, REST Admin API, Storefront API, Ajax API, OAuth authentication, rate limiting, and webhooks.
EliasOulkadi/shokunin
Design REST/GraphQL APIs with OpenAPI 3.1, error handling, pagination, rate limiting, webhooks, and idempotency.
saleor/saleor
Checklist for adding, changing, deprecating or removing Saleor GraphQL fields, mutations, enums and webhook event types so the change passes review first time.
goSprinto/compliance-skills
Proactive PII add-on — augments the main response with PII guidance.
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only…. API Connector Builder is an agent skill from ericrisco/rsc-harness. Use when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only, rate-limit-aware throttling.
API Connector Builder fits situations like: writing a client for someone elses REST; graphQL API: auth flow choice and token refresh; pagination to exhaustion; retry-with-jitter on transient failures only.
Run `npx skills add ericrisco/rsc-harness --skill api-connector-builder -a claude-code`. Or copy the skill folder (skills/api-connector-builder in ericrisco/rsc-harness) into .claude/skills/api-connector-builder in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill api-connector-builder -a codex`. Or copy the skill folder (skills/api-connector-builder in ericrisco/rsc-harness) into .agents/skills/api-connector-builder in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill api-connector-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-connector-builder, .gemini/skills/api-connector-builder, .github/skills/api-connector-builder and .opencode/skills/api-connector-builder in your project.
Going by SKILL.md and its folder, API Connector Builder needs a shell for the scripts in its folder and credentials named VENDOR_API_TOKEN. Our summary lists: Python 3; Node.js; A Bash shell; A credential in VENDOR_API_TOKEN.
SKILL.md names 1 domain. In commands or code: api.vendor.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
API Connector Builder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with API Connector Builder: Discover API (rand/cc-polymath, 181 stars), Shopify API (Microck/ordinary-claude-skills, 401 stars), API Forge (EliasOulkadi/shokunin, 114 stars) and Saleor GraphQL API Change Checklist (saleor/saleor, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.