Agent skill

Route Analysis

by fossasia in fossasia/eventyay-interpretation

A skill your agent uses to analyse, audit, or modify HTTP and WebSocket routes in VoxBento.

Apache-2.0Auto-check passedBackend & APIs

Install Route Analysis

skills CLI
$ npx skills add fossasia/eventyay-interpretation --skill route-analysis -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fossasia/eventyay-interpretation route-analysis --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fossasia/eventyay-interpretation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/route-analysis .claude/skills/route-analysis && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
route-analysis
GitHub stars
1.6k
Token cost
~1.2k tokens
SKILL.md length
418 words
Files
1
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses to analyse, audit, or modify HTTP and WebSocket routes in VoxBento.

  • Works in 6 steps: super_admin — if is_admin=True in user… → event_admin — if user has… → Role from BoothMembership for the… → …
  • Modify HTTP and WebSocket routes in VoxBento
  • SKILL.md covers Route Categories, Auth Patterns, Role Resolution (portal/auth.py) and Redirect Safety, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Route Analysis is an agent skill from fossasia/eventyay-interpretation. Use this skill to analyse, audit, or modify HTTP and WebSocket routes in VoxBento. All routes live in portal/routers/.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Realtime and WebSockets. The repository describes itself as: A plugin for live interpretation of video streams. The licence is Apache-2.0.

When your agent uses it

  • Modify HTTP and WebSocket routes in VoxBento
  • Tasks that involve Realtime and WebSockets

Example prompts

  • “/route-analysis”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. super_admin — if is_admin=True in user token.
  2. event_admin — if user has EventMembership.role == 'event_admin' for the booth's event.
  3. Role from BoothMembership for the specific booth.
  4. Role from EventMembership for the booth's event.
  5. Role embedded in participant session_token — but only if event_slug + language_code match.
  6. Returns None if no applicable role found → 403 on page routes.

What it can do on your machine

Read from SKILL.md and the folder at commit 1ca0139. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Route Analysis loads about 1.2k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 418 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from fossasia/eventyay-interpretation at commit 1ca0139, republished under its Apache-2.0 licence (© fossasia). 418 words, ~1,172 tokens.

Download SKILL.mdSave it as .claude/skills/route-analysis/SKILL.md (or your agent's skills folder).
name
route-analysis
description
Use this skill to analyse, audit, or modify HTTP and WebSocket routes in VoxBento. All routes live in `portal/routers/`.

Skill: Route Analysis

Use this skill to analyse, audit, or modify HTTP and WebSocket routes in VoxBento. All routes live in portal/routers/.


Route Categories

PrefixTypeAuth
/Public pagesNone or cookie-optional
/interpreter/*Booth pagessession_token or user_token cookie
/listener/*Listener pagessession_token or user_token cookie
/join/*Invite redemptionNone (token in path)
/register, /login, /logout, /accountUser authNone / user_token
/api/*REST APIOptional Bearer JWT or ?token=
/admin/*Admin paneladmin_token or user_token with is_admin
/ws/booth/*WebSocket coordinationCookies + optional ?token=
/ws/captions/*Caption WebSocketNone
/static/*Static assetsNone
/healthzHealth checkNone

Auth Patterns

User page routes
python
payload = get_booth_session(request)   # checks session_token then user_token
if payload is None:
    return safe_redirect(url=f'/login?next={path}', ...)
granted_role = await resolve_booth_role(payload, booth_id)
Admin routes
python
@app.get('/admin/...', dependencies=[Depends(require_admin)])

require_admin checks user_token (is_admin=True or event_admin membership) then falls back to admin_token.

API routes (optional auth)
python
_require_access(credentials, token)   # passes if booth_access_token is unset
WebSocket
  • Cookies read at connect time: session_token then user_token.
  • Role resolved via resolve_booth_role(payload, booth_id).
  • Token scope validated: session_token.event_slug + language_code must match the booth.
  • Connection rejected with code 4003 on scope mismatch; 4001 on invalid token.

Role Resolution (portal/auth.py)

resolve_booth_role(payload, booth_id) returns the most privileged applicable role:

  1. super_admin — if is_admin=True in user token.
  2. event_admin — if user has EventMembership.role == 'event_admin' for the booth's event.
  3. Role from BoothMembership for the specific booth.
  4. Role from EventMembership for the booth's event.
  5. Role embedded in participant session_token — but only if event_slug + language_code match.
  6. Returns None if no applicable role found → 403 on page routes.

Redirect Safety

All redirects MUST use safe_redirect(url, status_code):

python
def safe_redirect(url: str, status_code: int) -> RedirectResponse:
    url = url.replace('\\', '').strip()
    parsed = urlparse(url)
    if url and not parsed.netloc and not parsed.scheme and url.startswith('/'):
        return RedirectResponse(url=url, status_code=status_code)
    return RedirectResponse(url='/', status_code=status_code)  # fallback

Never call RedirectResponse(url=user_input) directly.


Show full SKILL.md (184 more words)Show less

Adding a New Route

  1. Add handler to portal/routers/.
  2. Use correct auth pattern (see above).
  3. Use safe_redirect for all redirects.
  4. Return templates.TemplateResponse(request, 'template.html', context) for HTML.
  5. Raise HTTPException for errors — never return raw error strings.
  6. Add test to tests/test_fastapi_app.py.

Critical Endpoints Reference

EndpointKey behavior
GET /join/{token}Validates + redeems invite token; sets session_token cookie; redirects to booth or listener
GET /interpreter/{event_slug}/{language_code}Resolves Jitsi URL from DB, relay WHEP, creates MediaMTX path; passes granted_role to template
GET /api/events/{slug}/booths/{lang}/whip-urlValidates event ownership + active-interpreter status before returning WHIP URL
WS /ws/booth/{booth_id}Full WebSocket lifecycle; role never from client; scope validated; disconnect cleans up participant
WS /ws/captions/{booth_id}Open subscription; receives caption + booth:state; used by listener page
POST /admin/.../.../transcription-settingsUpdates DB config; if booth live, stops and restarts transcription worker

Common Route Bugs to Check

  • Missing safe_redirect → open redirect risk.
  • Missing auth dependency on admin route → unauthenticated access.
  • data['role'] used directly from WS message → role injection vulnerability.
  • token path param passed directly to DB query without validation → injection risk (mitigated by redeem_invite_token validation).
  • next_url / next query param used in redirect without safe_redirect → open redirect.

© fossasia, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/route-analysis of fossasia/eventyay-interpretation.

Open the folder on GitHubat commit 1ca0139

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in fossasia/eventyay-interpretation, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Route Analysis next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Route Analysis compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Route Analysis this skillfossasia/eventyay-interpretation1.6k—~1.2kAutomated safety check: PassApache-2.0
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
Gemini Live API Devgoogle-gemini/gemini-skills4.3k—~4.6kAutomated safety check: PassApache-2.0
Broker Integrationmarketcalls/openalgo2.8k—~4.7kAutomated safety check: NotesAGPL-3.0
Trigger.dev Realtimepapermark/papermark9.2k—~1.7kAutomated safety check: PassCustom licence

Similar skills

  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Gemini Live API Dev

    google-gemini/gemini-skills

    Official

    A skill your agent uses when building real-time, bidirectional streaming applications with the Gemini Live API, or migrating legacy Live models (2.0/2.5/3.1) to Gemini 3.8 Live.

    4.3k GitHub stars~4.6k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Broker Integration

    marketcalls/openalgo

    Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.

    2.8k GitHub stars~4.7k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Trigger.dev Realtime

    papermark/papermark

    Shows how to subscribe to Trigger.dev task runs from the backend and from React for progress indicators, live dashboards, AI response streams and approval waits.

    9.2k GitHub stars~1.7k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Spider King

    aoyunyang/spider-king-skill

    Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.

    509 GitHub stars~7.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from fossasia/eventyay-interpretation

All 38 skills in this repo
  • Git Guardrails Claude Code

    fossasia/eventyay-interpretation

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.

    1.6k GitHub starsUsed in 12 repos~578 tokens
    Auto-check passed
  • Diagnosing Bugs

    fossasia/eventyay-interpretation

    Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 32 repos~2.1k tokens
    Auto-check passed
  • Domain Modeling

    fossasia/eventyay-interpretation

    Build and sharpen a project's domain model. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 31 repos~821 tokens
    Auto-check passed
  • Improve

    fossasia/eventyay-interpretation

    Survey any codebase as a senior advisor and produce prioritized, self-contained implementation plans for OTHER models/agents to execute.

    1.6k GitHub starsUsed in 10 repos~3.7k tokens
    Auto-check: warnings
  • Migrate To Shoehorn

    fossasia/eventyay-interpretation

    Migrate test files from as type assertions to @total-typescript/shoehorn.

    1.6k GitHub starsUsed in 12 repos~698 tokens
    Auto-check passed
  • Setup Pre Commit

    fossasia/eventyay-interpretation

    Set up Husky pre-commit hooks with lint-staged (Prettier), type checking, and tests in the current repo.

    1.6k GitHub starsUsed in 12 repos~565 tokens
    Auto-check passed

Categories

Questions about Route Analysis

What does Route Analysis do?

A skill your agent uses to analyse, audit, or modify HTTP and WebSocket routes in VoxBento. Route Analysis is an agent skill from fossasia/eventyay-interpretation. Use this skill to analyse, audit, or modify HTTP and WebSocket routes in VoxBento.

When should I use Route Analysis?

Route Analysis fits situations like: modify HTTP and WebSocket routes in VoxBento; tasks that involve Realtime and WebSockets.

How do I install Route Analysis in Claude Code?

Run `npx skills add fossasia/eventyay-interpretation --skill route-analysis -a claude-code`. Or copy the skill folder (.agents/skills/route-analysis in fossasia/eventyay-interpretation) into .claude/skills/route-analysis in your project. Claude Code loads it when a task matches its description.

How do I install Route Analysis in Codex?

Run `npx skills add fossasia/eventyay-interpretation --skill route-analysis -a codex`. Or copy the skill folder (.agents/skills/route-analysis in fossasia/eventyay-interpretation) into .agents/skills/route-analysis in your project. Codex loads it when a task matches its description.

Can I use Route Analysis in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fossasia/eventyay-interpretation --skill route-analysis -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/route-analysis, .gemini/skills/route-analysis, .github/skills/route-analysis and .opencode/skills/route-analysis in your project.

What does Route Analysis need to run?

SKILL.md names no scripts, command-line tools or credentials: Route Analysis is instructions for the agent only. Our summary lists: Python 3.

Does Route Analysis access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Route Analysis safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Route Analysis use?

Route Analysis is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Route Analysis use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Route Analysis?

Skills that share tags, products or a category with Route Analysis: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Use Yaak (mountain-loop/yaak, 19k stars), Gemini Live API Dev (google-gemini/gemini-skills, 4.3k stars) and Broker Integration (marketcalls/openalgo, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Route Analysis?

fossasia (a GitHub organization) maintains it in fossasia/eventyay-interpretation, which has 1,551 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 5, 2026.

Source: fossasia/eventyay-interpretation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.