Agent skill

API Integration

by Hack23 in Hack23/cia

External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

Apache-2.0Auto-check passedBackend & APIs

Install API Integration

skills CLI
$ npx skills add Hack23/cia --skill api-integration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia api-integration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/api-integration .claude/skills/api-integration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-integration
GitHub stars
239
Token cost
~1.9k tokens
SKILL.md length
267 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

  • Tasks that involve Third-party API integration
  • SKILL.md covers Purpose, When to Use, CIA External API Landscape and Retry Logic Pattern, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Rate limiting

What it does

API Integration is an agent skill from Hack23/cia. External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Third-party API integration, Rate limiting and Error handling. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Third-party API integration
  • Tasks that involve Rate limiting
  • Tasks that involve Error handling

Example prompts

  • “/api-integration”

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Integration loads about 1.9k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 267 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 267 words, ~1,861 tokens.

Download SKILL.mdSave it as .claude/skills/api-integration/SKILL.md (or your agent's skills folder).
name
api-integration
description
External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs
license
Apache-2.0

API Integration Skill

Purpose

Provide robust patterns for integrating the CIA platform with external government data APIs, including the Swedish Riksdagen, Election Authority, World Bank, and ESV (Swedish Financial Management Authority). Covers resilience, caching, and error handling.

When to Use

  • ✅ Integrating new external data sources
  • ✅ Improving reliability of existing API connections
  • ✅ Implementing caching for frequently accessed political data
  • ✅ Adding rate limiting to respect API provider constraints
  • ✅ Debugging API integration failures

Do NOT use for:

  • ❌ Internal service-to-service calls (use Spring patterns directly)
  • ❌ Database access patterns (use JPA/Hibernate skill)

CIA External API Landscape

APIBase URLData TypeRate Limit
Riksdagen Open Datadata.riksdagen.seParliament data, votes, documentsBest effort
Swedish Election Authoritydata.val.seElection results, partiesLow volume
World Bank Open Dataapi.worldbank.orgEconomic indicators50 req/sec
ESVwww.esv.seGovernment financesBest effort

Retry Logic Pattern

Exponential Backoff with Jitter
java
@Service
public class ResilientApiClient {

    private static final int MAX_RETRIES = 3;
    private static final long BASE_DELAY_MS = 1000;
    private static final Logger LOG = LoggerFactory.getLogger(ResilientApiClient.class);

    public <T> T executeWithRetry(Supplier<T> apiCall, String operationName) {
        int attempt = 0;
        while (true) {
            try {
                return apiCall.get();
            } catch (Exception e) {
                attempt++;
                if (attempt >= MAX_RETRIES || !isRetryable(e)) {
                    LOG.error("API call failed after {} attempts: {}", attempt, operationName, e);
                    throw new ApiIntegrationException(operationName, e);
                }
                long delay = calculateBackoff(attempt);
                LOG.warn("Retry {}/{} for {} after {}ms", attempt, MAX_RETRIES, operationName, delay);
                try {
                    Thread.sleep(delay);
                } catch (InterruptedException ie) {
                    Thread.currentThread().interrupt();
                    throw new ApiIntegrationException(operationName, ie);
                }
            }
        }
    }

    private long calculateBackoff(int attempt) {
        long exponentialDelay = BASE_DELAY_MS * (1L << (attempt - 1));
        long jitter = ThreadLocalRandom.current().nextLong(0, exponentialDelay / 2);
        return Math.min(exponentialDelay + jitter, 30_000);
    }

    private boolean isRetryable(Exception e) {
        if (e instanceof HttpClientErrorException httpErr) {
            int status = httpErr.getStatusCode().value();
            return status == 429 || status >= 500;
        }
        return e instanceof ResourceAccessException
            || e instanceof SocketTimeoutException;
    }
}

Circuit Breaker Pattern

java
@Component
public class CircuitBreaker {

    private enum State { CLOSED, OPEN, HALF_OPEN }

    private State state = State.CLOSED;
    private int failureCount = 0;
    private long lastFailureTime = 0;

    private static final int FAILURE_THRESHOLD = 5;
    private static final long RECOVERY_TIMEOUT_MS = 60_000;

    public synchronized <T> T execute(Supplier<T> action, Supplier<T> fallback) {
        if (state == State.OPEN) {
            if (System.currentTimeMillis() - lastFailureTime > RECOVERY_TIMEOUT_MS) {
                state = State.HALF_OPEN;
            } else {
                return fallback.get();
            }
        }

        try {
            T result = action.get();
            reset();
            return result;
        } catch (Exception e) {
            recordFailure();
            return fallback.get();
        }
    }

    private synchronized void recordFailure() {
        failureCount++;
        lastFailureTime = System.currentTimeMillis();
        if (failureCount >= FAILURE_THRESHOLD) {
            state = State.OPEN;
        }
    }

    private synchronized void reset() {
        failureCount = 0;
        state = State.CLOSED;
    }
}

Caching Strategy

Spring Cache Configuration
java
@Configuration
@EnableCaching
public class ApiCacheConfig {

    @Bean
    public CacheManager cacheManager() {
        CaffeineCacheManager manager = new CaffeineCacheManager();
        manager.setCaffeine(Caffeine.newBuilder()
            .maximumSize(10_000)
            .expireAfterWrite(Duration.ofHours(1))
            .recordStats());
        return manager;
    }
}

@Service
public class RiksdagDataService {

    @Cacheable(value = "politicians", key = "#personId")
    public PoliticianData getPolitician(String personId) {
        return riksdagClient.fetchPerson(personId);
    }

    @CacheEvict(value = "politicians", allEntries = true)
    @Scheduled(cron = "0 0 2 * * *") // Refresh at 2 AM daily
    public void evictPoliticianCache() {
        LOG.info("Evicting politician cache for daily refresh");
    }
}
Cache TTL Guidelines
Data TypeTTLReason
Politician profiles24 hoursChanges infrequently
Voting records1 hourUpdated during sessions
Document content7 daysImmutable once published
Election results30 daysUpdated only at elections
Economic indicators24 hoursDaily updates from World Bank

Rate Limiting

java
@Component
public class RateLimiter {

    private final Semaphore semaphore;
    private final ScheduledExecutorService scheduler;

    public RateLimiter(@Value("${api.rate.limit:10}") int maxRequestsPerSecond) {
        this.semaphore = new Semaphore(maxRequestsPerSecond);
        this.scheduler = Executors.newSingleThreadScheduledExecutor();
        this.scheduler.scheduleAtFixedRate(
            () -> semaphore.release(maxRequestsPerSecond - semaphore.availablePermits()),
            1, 1, TimeUnit.SECONDS
        );
    }

    public <T> T throttled(Supplier<T> apiCall) throws InterruptedException {
        semaphore.acquire();
        return apiCall.get();
    }
}

Error Handling

java
public class ApiIntegrationException extends RuntimeException {
    private final String operationName;
    private final int httpStatus;

    public ApiIntegrationException(String operationName, Throwable cause) {
        super("API integration failed: " + operationName, cause);
        this.operationName = operationName;
        this.httpStatus = extractStatus(cause);
    }
}

Security Considerations

  • Never log API keys or tokens — mask sensitive headers in logs
  • Validate all API responses — treat external data as untrusted input
  • Use HTTPS exclusively — reject insecure connections
  • Timeout connections — set connect (5s) and read (30s) timeouts
  • Sanitize data — escape or validate all data before database storage

ISMS Alignment

ControlRequirement
ISO 27001 A.8.24Use of cryptography for API transport
NIST CSF PR.DS-2Data-in-transit protection
CIS Control 12Network infrastructure management

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/api-integration of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

API Integration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Integration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Integration this skillHack23/cia239—~1.9kAutomated safety check: PassApache-2.0
API Integration Specialistaiskillstore/marketplace4302 repos~2.2kAutomated safety check: PassNone
Angular HttpClient StandardsHoangNguyen0403/agent-skills-standard570—~652Automated safety check: PassMIT
Frappe Core APIImpertio-Studio/Frappe_Claude_Skill_Package1871 repos~3.2kAutomated safety check: PassMIT
Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills202—~1.5kAutomated safety check: PassMIT
Bfl APIblack-forest-labs/skills1251 repos~2.5kAutomated safety check: NotesMIT

Similar skills

  • API Integration Specialist

    aiskillstore/marketplace

    Expert in integrating third-party APIs with proper authentication, error handling, rate limiting, and retry logic.

    430 GitHub starsUsed in 2 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Angular HttpClient Standards

    HoangNguyen0403/agent-skills-standard

    Sets rules for Angular HTTP code: functional interceptors, typed requests, services that own every call, and httpResource for reactive data loading in Angular 17+.

    570 GitHub stars~652 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Frappe Core API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.

    187 GitHub starsUsed in 1 repo~3.2k tokens
    Backend & APIsAuto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Bfl API

    black-forest-labs/skills

    BFL FLUX API integration guide covering endpoints, async polling patterns, rate limiting, error handling, webhooks, and regional endpoints with Python and TypeScript code examples.

    125 GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check: notes
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • Business continuity and disaster recovery: 30-day retention, quarterly restore tests, RTO/RPO targets per ISO 27001 A.17

    239 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about API Integration

What does API Integration do?

External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs. API Integration is an agent skill from Hack23/cia.

When should I use API Integration?

API Integration fits situations like: tasks that involve Third-party API integration; tasks that involve Rate limiting; tasks that involve Error handling.

How do I install API Integration in Claude Code?

Run `npx skills add Hack23/cia --skill api-integration -a claude-code`. Or copy the skill folder (.github/skills/api-integration in Hack23/cia) into .claude/skills/api-integration in your project. Claude Code loads it when a task matches its description.

How do I install API Integration in Codex?

Run `npx skills add Hack23/cia --skill api-integration -a codex`. Or copy the skill folder (.github/skills/api-integration in Hack23/cia) into .agents/skills/api-integration in your project. Codex loads it when a task matches its description.

Can I use API Integration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill api-integration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-integration, .gemini/skills/api-integration, .github/skills/api-integration and .opencode/skills/api-integration in your project.

What does API Integration need to run?

SKILL.md names no scripts, command-line tools or credentials: API Integration is instructions for the agent only.

Does API Integration access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Integration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Integration use?

API Integration is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Integration use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Integration?

Skills that share tags, products or a category with API Integration: API Integration Specialist (aiskillstore/marketplace, 430 stars), Angular HttpClient Standards (HoangNguyen0403/agent-skills-standard, 570 stars), Frappe Core API (Impertio-Studio/Frappe_Claude_Skill_Package, 187 stars) and Azure APIM Policy Authoring (thomast1906/github-copilot-agent-skills, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Integration?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.