Agent skill

API V1

by exelearning in exelearning/exelearning

Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.

AGPL-3.0Auto-check passedBackend & APIs

Install API V1

skills CLI
$ npx skills add exelearning/exelearning --skill api-v1 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install exelearning/exelearning api-v1 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/exelearning/exelearning.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/api-v1 .claude/skills/api-v1 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-v1
GitHub stars
145
Token cost
~427 tokens
SKILL.md length
185 words
Files
1
Skills in repo
17
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.

  • Tasks that involve REST APIs
  • Calls bun
  • Tasks that involve Authentication
  • Tasks that involve Authorization and RBAC

What it does

API V1 is an agent skill from exelearning/exelearning. Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.

Its SKILL.md is about 430 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs, Authentication and Authorization and RBAC. The repository describes itself as: eXeLearning is an AGPL-licensed free/libre tool to create and publish open educational resources. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve REST APIs
  • Tasks that involve Authentication
  • Tasks that involve Authorization and RBAC

Example prompts

  • “/api-v1”

What it can do on your machine

Read from SKILL.md and the folder at commit 319b5d2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API V1 loads about 427 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 185 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~427

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from exelearning/exelearning at commit 319b5d2, republished under its AGPL-3.0 licence (© exelearning). 185 words, ~427 tokens.

Download SKILL.mdSave it as .claude/skills/api-v1/SKILL.md (or your agent's skills folder).
name
api-v1
description
Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.

External REST API v1

Read src/routes/api/v1/, its types.ts authentication/response helpers, index.ts registration and Swagger configuration, affected .spec.ts files and doc/development/rest-api.md.

  • /api/v1/* serves external integrations. Internal public/app/ code uses the existing project APIs and Yjs/WebSocket flows; do not migrate it to v1 as a convenience.
  • Preserve the JWT Authorization: Bearer <token> contract of authenticateRequest(). Reuse the real login harness in projects.spec.ts for authenticated tests rather than inventing createTestJwt() or setting an unrelated cookie.
  • Authentication does not grant project access or admin rights. Cover the endpoint's actual owner, collaborator and administrator rules, including a different user's resource and denied mutations.
  • Keep success/error envelopes, status codes, validation and pagination consistent with neighboring endpoints. Test invalid input and service failures as well as 200/401/403 paths where applicable.
  • Preserve Yjs mutation/broadcast and persistence behavior for project content changes; a successful REST response must not leave connected editors or the next reload with stale content.
  • Register new routes in src/routes/api/v1/index.ts; update both Swagger contracts and doc/development/rest-api.md when the external API changes.

Run bun test src/routes/api/v1/<affected>.spec.ts (or the v1 suite for shared helpers), followed by verify-change. Assert response data and persisted/synchronized state.

© exelearning, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/api-v1 of exelearning/exelearning.

Open the folder on GitHubat commit 319b5d2

Compare with similar skills

API V1 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API V1 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API V1 this skillexelearning/exelearning145—~427Automated safety check: PassAGPL-3.0
API Auditbriiirussell/cybersecurity-skills412—~2.8kAutomated safety check: NotesMIT
Discover APIrand/cc-polymath1811 repos~1.5kAutomated safety check: PassMIT
Project Mapgjovanovicst/golang-auth-api129—~2.6kAutomated safety check: PassMIT
Spring Security ConfigurationAmplicode/spring-skills126—~4.3kAutomated safety check: PassNone
Memstack Security API Auditcwinvestments/memstack423—~3.9kAutomated safety check: PassProprietary

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    412 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • Project Map

    gjovanovicst/golang-auth-api

    Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.

    129 GitHub stars~2.6k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Spring Security Configuration

    Amplicode/spring-skills

    Creates a Spring Security configuration class with authentication, authorization, and HTTP protection setup.

    126 GitHub stars~4.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Memstack Security API Audit

    cwinvestments/memstack

    A skill your agent uses when the user says 'audit API', 'check API security', 'API routes security', 'endpoint audit', 'check my routes', or needs to verify API route protection.

    423 GitHub stars~3.9k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • API Designer

    aiskillstore/marketplace

    Design and document RESTful and GraphQL APIs with OpenAPI/Swagger specifications, authentication patterns, versioning strategies, and best practices.

    430 GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed

More from exelearning/exelearning

All 17 skills in this repo
  • E2E Test

    exelearning/exelearning

    Write or debug repository Playwright specs, including isolated projects, preview frames and multi-user fixtures.

    145 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Frontend Module

    exelearning/exelearning

    Change vanilla JavaScript UI modules in public/app/, including DOM state, events and localization.

    145 GitHub stars~867 tokensUpdated today
    Auto-check passed
  • I18n

    exelearning/exelearning

    Add or change source-level localized strings using (), c() or the Nunjucks trans filter; not catalog extraction.

    145 GitHub stars~812 tokensUpdated today
    Auto-check passed
  • Idevice

    exelearning/exelearning

    Create or modify an eXeLearning iDevice, including edition/export data, legacy compatibility, assets, TypeScript bundles and teardown.

    145 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Verify Change

    exelearning/exelearning

    Choose and run the appropriate eXeLearning checks for a diff, including the final code gates or guidance-only validation.

    145 GitHub stars~676 tokensUpdated today
    Auto-check passed
  • Websocket Yjs

    exelearning/exelearning

    Change eXeLearning shared document mutations, WebSocket rooms, snapshots, reconnects or concurrent editing behavior.

    145 GitHub stars~759 tokensUpdated today
    Auto-check passed

Categories

Questions about API V1

What does API V1 do?

Add or change external REST API v1 endpoints and their documented authentication/authorization contracts. API V1 is an agent skill from exelearning/exelearning. Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.

When should I use API V1?

API V1 fits situations like: tasks that involve REST APIs; tasks that involve Authentication; tasks that involve Authorization and RBAC.

How do I install API V1 in Claude Code?

Run `npx skills add exelearning/exelearning --skill api-v1 -a claude-code`. Or copy the skill folder (.agents/skills/api-v1 in exelearning/exelearning) into .claude/skills/api-v1 in your project. Claude Code loads it when a task matches its description.

How do I install API V1 in Codex?

Run `npx skills add exelearning/exelearning --skill api-v1 -a codex`. Or copy the skill folder (.agents/skills/api-v1 in exelearning/exelearning) into .agents/skills/api-v1 in your project. Codex loads it when a task matches its description.

Can I use API V1 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add exelearning/exelearning --skill api-v1 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-v1, .gemini/skills/api-v1, .github/skills/api-v1 and .opencode/skills/api-v1 in your project.

What does API V1 need to run?

Going by SKILL.md and its folder, API V1 needs the command-line tools its instructions call (bun).

Does API V1 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API V1 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API V1 use?

API V1 is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API V1 use?

About 427 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API V1?

Skills that share tags, products or a category with API V1: API Audit (briiirussell/cybersecurity-skills, 412 stars), Discover API (rand/cc-polymath, 181 stars), Project Map (gjovanovicst/golang-auth-api, 129 stars) and Spring Security Configuration (Amplicode/spring-skills, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API V1?

exelearning (a GitHub organization) maintains it in exelearning/exelearning, which has 145 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.

Source: exelearning/exelearning on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.