API Audit
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.
$ npx skills add exelearning/exelearning --skill api-v1 -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install exelearning/exelearning api-v1 --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/exelearning/exelearning.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/api-v1 .claude/skills/api-v1 && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "api-v1" agent skill from https://github.com/exelearning/exelearning/tree/main/.agents/skills/api-v1 into .claude/skills/api-v1/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-v1", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/exelearning/exelearning/tree/main/.agents/skills/api-v1Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add exelearning/exelearning --skill api-v1 -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install exelearning/exelearning api-v1 --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/exelearning/exelearning.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/api-v1 .agents/skills/api-v1 && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "api-v1" agent skill from https://github.com/exelearning/exelearning/tree/main/.agents/skills/api-v1 into .agents/skills/api-v1/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-v1", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add exelearning/exelearning --skill api-v1 -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install exelearning/exelearning api-v1 --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/exelearning/exelearning.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/api-v1 .cursor/skills/api-v1 && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "api-v1" agent skill from https://github.com/exelearning/exelearning/tree/main/.agents/skills/api-v1 into .cursor/skills/api-v1/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-v1", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/exelearning/exelearning.git --path .agents/skills/api-v1--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add exelearning/exelearning --skill api-v1 -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install exelearning/exelearning api-v1 --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/exelearning/exelearning.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/api-v1 .gemini/skills/api-v1 && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "api-v1" agent skill from https://github.com/exelearning/exelearning/tree/main/.agents/skills/api-v1 into .gemini/skills/api-v1/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-v1", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install exelearning/exelearning api-v1Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add exelearning/exelearning --skill api-v1 -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/exelearning/exelearning.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/api-v1 .github/skills/api-v1 && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "api-v1" agent skill from https://github.com/exelearning/exelearning/tree/main/.agents/skills/api-v1 into .github/skills/api-v1/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-v1", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add exelearning/exelearning --skill api-v1 -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install exelearning/exelearning api-v1 --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/exelearning/exelearning.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/api-v1 .opencode/skills/api-v1 && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "api-v1" agent skill from https://github.com/exelearning/exelearning/tree/main/.agents/skills/api-v1 into .opencode/skills/api-v1/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-v1", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
api-v1Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.
API V1 is an agent skill from exelearning/exelearning. Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.
Its SKILL.md is about 430 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering REST APIs, Authentication and Authorization and RBAC. The repository describes itself as: eXeLearning is an AGPL-licensed free/libre tool to create and publish open educational resources. The licence is AGPL-3.0.
Read from SKILL.md and the folder at commit 319b5d2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
API V1 loads about 427 tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 185 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from exelearning/exelearning at commit 319b5d2, republished under its AGPL-3.0 licence (© exelearning). 185 words, ~427 tokens.
.claude/skills/api-v1/SKILL.md (or your agent's skills folder).Read src/routes/api/v1/, its types.ts authentication/response helpers, index.ts registration and
Swagger configuration, affected .spec.ts files and doc/development/rest-api.md.
/api/v1/* serves external integrations. Internal public/app/ code uses the existing project APIs
and Yjs/WebSocket flows; do not migrate it to v1 as a convenience.Authorization: Bearer <token> contract of authenticateRequest(). Reuse the real
login harness in projects.spec.ts for authenticated tests rather than inventing createTestJwt()
or setting an unrelated cookie.src/routes/api/v1/index.ts; update both Swagger contracts and
doc/development/rest-api.md when the external API changes.Run bun test src/routes/api/v1/<affected>.spec.ts (or the v1 suite for shared helpers), followed by
verify-change. Assert response data and persisted/synchronized state.
© exelearning, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/api-v1 of exelearning/exelearning.
Open the folder on GitHubat commit 319b5d2
API V1 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| API V1 this skillexelearning/exelearning | 145 | — | ~427 | Automated safety check: Pass | AGPL-3.0 | |
| API Auditbriiirussell/cybersecurity-skills | 412 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Discover APIrand/cc-polymath | 181 | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Project Mapgjovanovicst/golang-auth-api | 129 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Spring Security ConfigurationAmplicode/spring-skills | 126 | — | ~4.3k | Automated safety check: Pass | None | |
| Memstack Security API Auditcwinvestments/memstack | 423 | — | ~3.9k | Automated safety check: Pass | Proprietary |
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
gjovanovicst/golang-auth-api
Complete module inventory of the Auth API project with file paths, dependencies, and architecture overview.
Amplicode/spring-skills
Creates a Spring Security configuration class with authentication, authorization, and HTTP protection setup.
cwinvestments/memstack
A skill your agent uses when the user says 'audit API', 'check API security', 'API routes security', 'endpoint audit', 'check my routes', or needs to verify API route protection.
aiskillstore/marketplace
Design and document RESTful and GraphQL APIs with OpenAPI/Swagger specifications, authentication patterns, versioning strategies, and best practices.
exelearning/exelearning
Write or debug repository Playwright specs, including isolated projects, preview frames and multi-user fixtures.
exelearning/exelearning
Change vanilla JavaScript UI modules in public/app/, including DOM state, events and localization.
exelearning/exelearning
Add or change source-level localized strings using (), c() or the Nunjucks trans filter; not catalog extraction.
exelearning/exelearning
Create or modify an eXeLearning iDevice, including edition/export data, legacy compatibility, assets, TypeScript bundles and teardown.
exelearning/exelearning
Choose and run the appropriate eXeLearning checks for a diff, including the final code gates or guidance-only validation.
exelearning/exelearning
Change eXeLearning shared document mutations, WebSocket rooms, snapshots, reconnects or concurrent editing behavior.
Categories
Add or change external REST API v1 endpoints and their documented authentication/authorization contracts. API V1 is an agent skill from exelearning/exelearning. Add or change external REST API v1 endpoints and their documented authentication/authorization contracts.
API V1 fits situations like: tasks that involve REST APIs; tasks that involve Authentication; tasks that involve Authorization and RBAC.
Run `npx skills add exelearning/exelearning --skill api-v1 -a claude-code`. Or copy the skill folder (.agents/skills/api-v1 in exelearning/exelearning) into .claude/skills/api-v1 in your project. Claude Code loads it when a task matches its description.
Run `npx skills add exelearning/exelearning --skill api-v1 -a codex`. Or copy the skill folder (.agents/skills/api-v1 in exelearning/exelearning) into .agents/skills/api-v1 in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add exelearning/exelearning --skill api-v1 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-v1, .gemini/skills/api-v1, .github/skills/api-v1 and .opencode/skills/api-v1 in your project.
Going by SKILL.md and its folder, API V1 needs the command-line tools its instructions call (bun).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
API V1 is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 427 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with API V1: API Audit (briiirussell/cybersecurity-skills, 412 stars), Discover API (rand/cc-polymath, 181 stars), Project Map (gjovanovicst/golang-auth-api, 129 stars) and Spring Security Configuration (Amplicode/spring-skills, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
exelearning (a GitHub organization) maintains it in exelearning/exelearning, which has 145 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 7, 2026.
Source: exelearning/exelearning on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.