Agent skill

API Testing

by fugazi in fugazi/test-automation-skills-agents

Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java).

MITAuto-check passedTesting & QA

Install API Testing

skills CLI
$ npx skills add fugazi/test-automation-skills-agents --skill api-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install fugazi/test-automation-skills-agents api-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/fugazi/test-automation-skills-agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-testing .claude/skills/api-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-testing
GitHub stars
247
Token cost
~1.5k tokens
SKILL.md length
452 words
Files
10 (incl. scripts, references)
Skills in repo
10
Repo updated
First seen
Licence
MIT

At a glance

Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java).

  • Works in 5 steps: Schema validation on every response —… → Test all HTTP status codes — happy path… → Auth testing is mandatory — verify… → …
  • Standalone API tests covering schemas
  • SKILL.md covers When to Use This Skill, Prerequisites, Core Principles and Quick Reference — Playwright, plus 7 more sections
  • Runs Shell, TypeScript and Java scripts from its folder

What it does

API Testing is an agent skill from fugazi/test-automation-skills-agents. Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java). Use for standalone API tests covering schemas, auth, status/error handling, pagination, idempotency, rate limits, or contract checks; not for browser E2E specs. Keywords: REST, GraphQL, API contract, schema validation, REST Assured.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `references/contract-testing.md`, `references/playwright-api-testing.md` and `references/rest-api-patterns.md`).

It sits in Testing & QA, covering API testing, GraphQL and Browser testing. It works with GraphQL, Playwright, Java and TypeScript. The repository describes itself as: A practical library of agents, instructions, and skills designed specifically for QA Automation Engineers, focusing on production-oriented solutions. The licence is MIT.

When your agent uses it

  • Standalone API tests covering schemas
  • Status/error handling
  • Contract checks
  • Not for browser E2E specs

Example prompts

  • “/api-testing”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Schema validation on every response — never trust an unvalidated response
  2. Test all HTTP status codes — happy path AND error states
  3. Auth testing is mandatory — verify 401/403 for protected endpoints
  4. Data-driven — test with valid, invalid, boundary, and empty values
  5. Stateless where possible — each test cleans up or uses unique data

What it can do on your machine

Read from SKILL.md and the folder at commit 65a72d5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell, TypeScript and Java), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Testing loads about 1.5k tokens when it runs, and up to ~6.1k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 452 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from fugazi/test-automation-skills-agents at commit 65a72d5, republished under its MIT licence (© fugazi). 452 words, ~1,491 tokens.

Download SKILL.mdSave it as .claude/skills/api-testing/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
api-testing
description
Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java). Use for standalone API tests covering schemas, auth, status/error handling, pagination, idempotency, rate limits, or contract checks; not for browser E2E specs. Keywords: REST, GraphQL, API contract, schema validation, REST Assured.
license
Complete terms in LICENSE.txt

API Testing (Playwright + REST Assured)

Comprehensive API testing skill covering both Playwright TypeScript (request fixture, Supertest, Zod) and Java (REST Assured, AssertJ, JSON Schema Validator).

When to Use This Skill

  • Create API tests for REST or GraphQL endpoints
  • Validate request/response schemas (Zod, JSON Schema)
  • Test authentication flows (OAuth2, JWT, API keys, Bearer tokens)
  • Verify error handling (400, 401, 403, 404, 409, 422, 500)
  • Test pagination, filtering, sorting edge cases
  • Validate idempotency for PUT/DELETE operations
  • Contract testing between services
  • Rate limiting validation
Do NOT Use For
  • Browser-driven UI flows (use playwright-e2e-testing for Playwright specs, or webapp-selenium-testing for Selenium)
  • Live interactive browser sessions or snapshots (use playwright-cli)
  • Visual/layout regression (out of scope — no DOM)
  • End-to-end journeys that must drive a real browser across pages

Prerequisites

StackRequirements
TypeScriptNode.js 18+, @playwright/test or supertest, zod
JavaJava 21+, REST Assured 5.x, AssertJ, Jackson, json-schema-validator

Core Principles

  1. Schema validation on every response — never trust an unvalidated response
  2. Test all HTTP status codes — happy path AND error states
  3. Auth testing is mandatory — verify 401/403 for protected endpoints
  4. Data-driven — test with valid, invalid, boundary, and empty values
  5. Stateless where possible — each test cleans up or uses unique data

Quick Reference — Playwright

typescript
import { test, expect } from "@playwright/test";

test("GET /api/users returns 200 with valid schema", async ({ request }) => {
  const response = await request.get("/api/users");
  expect(response.ok()).toBeTruthy();
  const body = await response.json();
  expect(body).toMatchObject({ data: expect.any(Array) });
});

Quick Reference — REST Assured

java
import static io.restassured.RestAssured.*;
import static org.hamcrest.Matchers.*;

import java.util.List;

import org.junit.jupiter.api.DisplayName;
import org.junit.jupiter.api.Test;

@Test
@DisplayName("GET /api/users returns 200 with valid schema")
void getUsers() {
    String token = "test-token";

    given()
        .header("Authorization", "Bearer " + token)
    .when()
        .get("/api/users")
    .then()
        .statusCode(200)
        .body("data", is(instanceOf(List.class)))
        .body("data.size()", greaterThan(0));
}

Red Flags

Stop and reconsider if you see any of these in generated API tests:

  • Assertions only on status code with no body/schema validation — an unvalidated response hides contract drift.
  • Hardcoded secrets/tokens committed to the test file — read from env or a secrets manager.
  • Tests sharing mutable state with no cleanup — flaky and order-dependent.
  • Skipping auth tests (no 401/403 assertions on protected endpoints) — security regression risk.
  • No coverage of error states (only happy-path 200s) — error handling is untested.

Show full SKILL.md (170 more words)Show less

References

DocumentContent
REST API PatternsCRUD, pagination, filtering, error patterns
Playwright API TestingRequest fixture, Supertest, TypeScript patterns
REST Assured TestingREST Assured, AssertJ, Java patterns
Schema ValidationZod (TS), JSON Schema (Java), strict vs loose
Contract TestingRequest/response contracts, idempotency, versioning

Templates

Scripts

Troubleshooting

IssueSolution
401 on authenticated endpointsVerify token is fresh; check expiry; re-authenticate
Flaky API testsAdd retry logic; check for rate limiting; use unique test data
Schema validation too strictUse .passthrough() (Zod) or additionalProperties: true for flexible fields
Timeout on slow endpointsIncrease timeout in request options; check for server load

Verification

  • Schema validation in place — Every response validated against a schema (Zod or JSON Schema)
  • Authentication tested — 401 returned for protected endpoints without valid credentials
  • Idempotency verified — PUT/DELETE produce same result when called multiple times
  • Edge cases covered — Empty payloads, invalid types, boundary values, SQL injection attempts

© fugazi, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in skills/api-testing of fugazi/test-automation-skills-agents.

  • SKILL.md
  • LICENSE.txt
  • references/contract-testing.md
  • references/playwright-api-testing.md
  • references/rest-api-patterns.md
  • references/rest-assured-testing.md
  • references/schema-validation.md
  • scripts/api-health-check.sh
  • templates/playwright-api-spec.ts
  • templates/rest-assured-test.java

Open the folder on GitHubat commit 65a72d5

Compare with similar skills

API Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Testing this skillfugazi/test-automation-skills-agents247—~1.5kAutomated safety check: PassMIT
API Testingpetrkindlmann/qa-skills163—~2.7kAutomated safety check: PassMIT
Common Tasksidavidov13/agentic-playwright223—~2.5kAutomated safety check: PassMIT
Data Strategyidavidov13/agentic-playwright223—~3.4kAutomated safety check: PassMIT
Type Safetyidavidov13/agentic-playwright223—~3.5kAutomated safety check: PassMIT
API Testingidavidov13/agentic-playwright223—~5.7kAutomated safety check: PassMIT

Similar skills

  • API Testing

    petrkindlmann/qa-skills

    Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.

    163 GitHub stars~2.7k tokensUpdated 3 mo ago
    Testing & QAAuto-check passed
  • Common Tasks

    idavidov13/agentic-playwright

    Copy-paste AI prompt templates for common Playwright scaffold development tasks — adding page objects, functional/E2E/API tests, Zod schemas, factories, fixtures, and components.

    223 GitHub stars~2.5k tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • Data Strategy

    idavidov13/agentic-playwright

    Test data strategy for the Playwright scaffold — Faker + Zod factories for dynamic happy-path data, static TS files (.ts with as const exports — never .json) for domain-specific curated invalid…

    223 GitHub stars~3.4k tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • Type Safety

    idavidov13/agentic-playwright

    TypeScript type safety conventions for the Playwright scaffold — the "no any" rule, Zod 4 schema patterns (z.strictObject, top-level validators like z.uuid / z.email / z.url / z.int / z.enum)…

    223 GitHub stars~3.5k tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • API Testing

    idavidov13/agentic-playwright

    API testing patterns for Playwright -- apiRequest fixture usage, Zod response schema creation and validation, test.step wrapping for multi-call tests, per-field negative/validation testing, path…

    223 GitHub stars~5.7k tokensUpdated 6 days ago
    Testing & QAAuto-check passed
  • Official

    A skill your agent uses when writing Playwright tests, fixing flaky tests, debugging failures, implementing Page Object Model, configuring CI/CD, optimizing performance, mocking APIs, handling…

    6.4k GitHub starsUsed in 7 repos~6.4k tokens
    Testing & QAAuto-check passed

More from fugazi/test-automation-skills-agents

All 10 skills in this repo
  • Accessibility Selenium Testing

    fugazi/test-automation-skills-agents

    Accessibility testing toolkit using Selenium WebDriver 4+ with Java 21+ and axe-core engine.

    247 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • QA Manual Istqb

    fugazi/test-automation-skills-agents

    Create QA artifacts from requirements: test plans, test conditions/cases, bug reports, regression suites, traceability, and exploratory charters.

    247 GitHub stars~3.6k tokensUpdated 4 days ago
    Auto-check passed
  • Webapp Selenium Testing

    fugazi/test-automation-skills-agents

    Author and maintain versioned Selenium WebDriver tests with Java and JUnit 5.

    247 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check passed
  • A11y Playwright Testing

    fugazi/test-automation-skills-agents

    Accessibility testing for web applications using Playwright (@playwright/test), TypeScript, and axe-core.

    247 GitHub stars~3.2k tokensUpdated 4 days ago
    Auto-check passed
  • Grill Me QA

    fugazi/test-automation-skills-agents

    A guided interview to challenge and validate QA automation plans, test strategies, and framework designs before implementation.

    247 GitHub stars~3.9k tokensUpdated 4 days ago
    Auto-check passed
  • Playwright CLI

    fugazi/test-automation-skills-agents

    Drive a live browser from the CLI with playwright-cli to navigate, interact, snapshot, and capture evidence.

    247 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about API Testing

What does API Testing do?

Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java). API Testing is an agent skill from fugazi/test-automation-skills-agents. Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java).

When should I use API Testing?

API Testing fits situations like: standalone API tests covering schemas; status/error handling; contract checks; not for browser E2E specs.

How do I install API Testing in Claude Code?

Run `npx skills add fugazi/test-automation-skills-agents --skill api-testing -a claude-code`. Or copy the skill folder (skills/api-testing in fugazi/test-automation-skills-agents) into .claude/skills/api-testing in your project. Claude Code loads it when a task matches its description.

How do I install API Testing in Codex?

Run `npx skills add fugazi/test-automation-skills-agents --skill api-testing -a codex`. Or copy the skill folder (skills/api-testing in fugazi/test-automation-skills-agents) into .agents/skills/api-testing in your project. Codex loads it when a task matches its description.

Can I use API Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fugazi/test-automation-skills-agents --skill api-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-testing, .gemini/skills/api-testing, .github/skills/api-testing and .opencode/skills/api-testing in your project.

What does API Testing need to run?

Going by SKILL.md and its folder, API Testing needs a shell, TypeScript and Java for the scripts in its folder. Our summary lists: Node.js; A Bash shell.

Does API Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does API Testing use?

API Testing is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Testing use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.

What are the alternatives to API Testing?

Skills that share tags, products or a category with API Testing: API Testing (petrkindlmann/qa-skills, 163 stars), Common Tasks (idavidov13/agentic-playwright, 223 stars), Data Strategy (idavidov13/agentic-playwright, 223 stars) and Type Safety (idavidov13/agentic-playwright, 223 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Testing?

fugazi (a GitHub user) maintains it in fugazi/test-automation-skills-agents, which has 247 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 3, 2026.

Source: fugazi/test-automation-skills-agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.