API Audit
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-api --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/source/errors/frappe-errors-api .claude/skills/frappe-errors-api && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "frappe-errors-api" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-api into .claude/skills/frappe-errors-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-api", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-apiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-api --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/source/errors/frappe-errors-api .agents/skills/frappe-errors-api && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "frappe-errors-api" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-api into .agents/skills/frappe-errors-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-api", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-api --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/source/errors/frappe-errors-api .cursor/skills/frappe-errors-api && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "frappe-errors-api" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-api into .cursor/skills/frappe-errors-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-api", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git --path skills/source/errors/frappe-errors-api--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-api --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/source/errors/frappe-errors-api .gemini/skills/frappe-errors-api && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "frappe-errors-api" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-api into .gemini/skills/frappe-errors-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-api", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-apiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/source/errors/frappe-errors-api .github/skills/frappe-errors-api && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "frappe-errors-api" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-api into .github/skills/frappe-errors-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-api", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Impertio-Studio/Frappe_Claude_Skill_Package frappe-errors-api --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/source/errors/frappe-errors-api .opencode/skills/frappe-errors-api && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "frappe-errors-api" agent skill from https://github.com/Impertio-Studio/Frappe_Claude_Skill_Package/tree/main/skills/source/errors/frappe-errors-api into .opencode/skills/frappe-errors-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "frappe-errors-api", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
frappe-errors-apiA skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
Frappe Errors API is an agent skill from Impertio-Studio/Frappe_Claude_Skill_Package. Use when debugging or handling API errors in Frappe/ERPNext v14/v15/v16. Prevents silent failures and wrong HTTP status codes in REST endpoints. Covers 401 Unauthorized (wrong token format, expired OAuth), 403 Forbidden (missing @whitelist, allowguest needed), 404 Not Found (wrong endpoint URL), 417 Expectation Failed (validation via frappe.throw), 500 Internal Server Error, CORS issues, CSRF token missing/invalid, rate limit exceeded (429), file upload failures, JSON parse errors in request/response, webhook…
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/anti-patterns.md`, `references/examples.md` and `references/patterns.md`). Compatibility notes: Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16.
It sits in Backend & APIs, covering Rate limiting, REST APIs and Web application vulnerabilities. The repository describes itself as: 60 deterministic Claude AI skills for Frappe Framework & ERPNext v14-v16 development and operations. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 36cfa80. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are python, javascript and json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16.
From compatibility in the SKILL.md frontmatter.
Frappe Errors API loads about 4k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 205 tokens; SKILL.md has 611 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Impertio-Studio/Frappe_Claude_Skill_Package at commit 36cfa80, republished under its MIT licence (© Impertio-Studio). 611 words, ~3,967 tokens.
.claude/skills/frappe-errors-api/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.For API implementation patterns see frappe-core-api. For permission errors see frappe-errors-permissions.
| Code | Frappe Exception | When It Happens | Fix |
|---|---|---|---|
| 200 | — | Success | — |
| 401 | AuthenticationError | Bad/expired token, wrong format | Check Authorization: token key:secret or Bearer access_token |
| 403 | PermissionError | Missing @whitelist, no role, no allow_guest | Add decorator or grant permission |
| 404 | DoesNotExistError | Wrong URL, doc not found, typo in endpoint path | Verify /api/resource/:doctype/:name or /api/method/dotted.path |
| 409 | DuplicateEntryError | Unique constraint violated | Check existing records before insert |
| 417 | ValidationError | frappe.throw() called | Fix validation logic or input data |
| 429 | RateLimitExceededError | Too many requests | Respect Retry-After header; throttle requests |
| 500 | Exception (unhandled) | Unhandled server error | Check Error Log; wrap in try/except |
| 503 | — | Server overloaded / maintenance | Retry with exponential backoff |
Error: HTTP 401 Unauthorized
Cause: Using "Bearer api_key:api_secret" instead of "token api_key:api_secret"Frappe uses TWO authentication formats — NEVER mix them:
| Method | Header Format | When to Use |
|---|---|---|
| API Key/Secret | Authorization: token api_key:api_secret | Server-to-server, scripts |
| OAuth Bearer | Authorization: Bearer access_token | OAuth 2.0 flows |
| Session Cookie | Cookie from /api/method/login | Browser-based apps |
# WRONG — Bearer with API key:secret
headers = {"Authorization": f"Bearer {api_key}:{api_secret}"}
# CORRECT — token keyword for API key:secret
headers = {"Authorization": f"token {api_key}:{api_secret}"}
# CORRECT — Bearer for OAuth access tokens only
headers = {"Authorization": f"Bearer {oauth_access_token}"}Error: HTTP 401 after token was working
Cause: OAuth access_token expired
Fix: Use refresh_token to get new access_tokendef get_fresh_token(settings):
"""ALWAYS implement token refresh for OAuth integrations."""
if is_token_expired(settings.token_expiry):
response = requests.post(f"{settings.base_url}/api/method/frappe.integrations.oauth2.get_token", data={
"grant_type": "refresh_token",
"refresh_token": settings.get_password("refresh_token"),
"client_id": settings.client_id,
})
if response.status_code == 200:
data = response.json()
settings.access_token = data["access_token"]
settings.token_expiry = frappe.utils.add_to_date(None, seconds=data["expires_in"])
settings.save(ignore_permissions=True)
else:
frappe.throw(_("OAuth token refresh failed"), exc=frappe.AuthenticationError)
return settings.access_tokenError: HTTP 403 on /api/method/myapp.api.my_function
Cause: Function exists but lacks @frappe.whitelist() decorator
Fix: Add decorator — without it, NO external call is allowed# WRONG — Callable internally but returns 403 via REST
def my_function(name):
return frappe.get_doc("Item", name)
# CORRECT — Exposed to authenticated users
@frappe.whitelist()
def my_function(name):
return frappe.get_doc("Item", name)
# CORRECT — Exposed to everyone including unauthenticated
@frappe.whitelist(allow_guest=True)
def public_function():
return {"status": "ok"}Error: HTTP 403 for unauthenticated requests
Cause: @frappe.whitelist() without allow_guest=True
Fix: Add allow_guest=True — but ALWAYS validate inputsNEVER use allow_guest=True without input validation — these endpoints are exposed to the internet.
| Wrong URL | Correct URL | Issue |
|---|---|---|
/api/resource/SalesOrder/SO-001 | /api/resource/Sales Order/SO-001 | Space in DocType name |
/api/method/myapp.my_function | /api/method/myapp.api.my_function | Missing module path |
/api/resource/sales_order | /api/resource/Sales Order | Wrong case / underscore |
/api/v2/document/Item/ITEM-001 [v14] | /api/resource/Item/ITEM-001 | v2 API only in v15+ |
# ALWAYS URL-encode DocType names with spaces
import urllib.parse
url = f"/api/resource/{urllib.parse.quote('Sales Order')}/{name}"Every frappe.throw() call returns HTTP 417 by default (unless a specific exception class is provided).
# Returns 417 — generic validation error
frappe.throw(_("Amount must be positive"))
# Returns 417 — with explicit ValidationError type
frappe.throw(_("Amount must be positive"), exc=frappe.ValidationError)
# Returns 403 — PermissionError overrides to 403
frappe.throw(_("Access denied"), exc=frappe.PermissionError)
# Returns 404 — DoesNotExistError overrides to 404
frappe.throw(_("Not found"), exc=frappe.DoesNotExistError)ALWAYS use the specific exception class so clients can handle error types correctly:
# WRONG — all errors look the same to the client
frappe.throw(_("Customer not found")) # 417, generic
# CORRECT — client can distinguish 404 from validation error
frappe.throw(_("Customer not found"), exc=frappe.DoesNotExistError) # 404Error: HTTP 403 "CSRF token missing or invalid"
Cause: POST/PUT/DELETE request without X-Frappe-CSRF-Token headerRules:
X-Frappe-CSRF-Token header for session-based (cookie) auth.Authorization: token ...) does NOT require CSRF token.frappe.csrf_token in JavaScript or embedded as window.CSRF_TOKEN.// Browser-side: ALWAYS include CSRF for session-based requests
fetch("/api/method/myapp.api.update", {
method: "POST",
headers: {
"Content-Type": "application/json",
"X-Frappe-CSRF-Token": frappe.csrf_token
},
body: JSON.stringify({data: "value"})
});Error: "Access-Control-Allow-Origin" header missing
Cause: Cross-origin request not configured in site_config.json// site_config.json — NEVER use "*" in production
{
"allow_cors": "https://your-frontend.example.com"
}For multiple origins [v15+]:
{
"allow_cors": ["https://app1.example.com", "https://app2.example.com"]
}Error: HTTP 429 Too Many Requests
Cause: Exceeded rate limit configured in site_config.json or hooks.py# hooks.py — rate limiting on whitelisted methods [v14+]
rate_limit = {"myapp.api.heavy_endpoint": {"limit": 10, "seconds": 60}}ALWAYS handle 429 in external API calls:
def call_with_rate_limit(url, data):
response = requests.post(url, json=data, timeout=30)
if response.status_code == 429:
wait = int(response.headers.get("Retry-After", 60))
time.sleep(min(wait, 120)) # Cap at 2 minutes
response = requests.post(url, json=data, timeout=30)
response.raise_for_status()
return response.json()Error: HTTP 500 on /api/method/upload_file
Cause: Wrong content type, file too large, or missing file field# CORRECT file upload via REST API
import requests
response = requests.post(
f"{base_url}/api/method/upload_file",
headers={"Authorization": f"token {api_key}:{api_secret}"},
files={"file": ("document.pdf", open("document.pdf", "rb"), "application/pdf")},
data={
"doctype": "Sales Invoice",
"docname": "SINV-001",
"is_private": 1 # 1 = private, 0 = public
},
timeout=60 # ALWAYS set timeout for uploads
)Common upload failures:
Content-Type must be multipart/form-data (set automatically by files= param)Content-Type: application/json for file uploadsmax_file_size in site_config.json (default 10MB)allowed_file_extensions restricts file typesError: "Failed to decode JSON" or unexpected behavior
Cause: API arguments sent as JSON string instead of parsed object@frappe.whitelist()
def update_items(items):
# ALWAYS handle both string and parsed input
if isinstance(items, str):
try:
items = frappe.parse_json(items)
except Exception:
frappe.throw(_("Invalid JSON format"), exc=frappe.ValidationError)
if not isinstance(items, (list, dict)):
frappe.throw(_("Expected list or dict"), exc=frappe.ValidationError)Error: Webhook not firing or returning errors
Cause: Target URL unreachable, wrong format, or timeoutDebug checklist:
# Custom webhook with error handling
@frappe.whitelist(allow_guest=True)
def incoming_webhook():
"""Handle incoming webhook with validation."""
payload = frappe.request.data
signature = frappe.request.headers.get("X-Webhook-Signature")
if not verify_signature(payload, signature):
frappe.local.response["http_status_code"] = 401
return {"error": "Invalid signature"}
try:
data = frappe.parse_json(payload)
except Exception:
frappe.local.response["http_status_code"] = 400
return {"error": "Invalid JSON payload"}
# ALWAYS return 200 quickly to prevent sender retries
frappe.enqueue(process_webhook_data, data=data, queue="short")
return {"status": "accepted"}Error: HTTP 504 Gateway Timeout or connection reset
Cause: Operation takes longer than proxy/server timeout (typically 60s)Fix: Use background jobs for long operations:
@frappe.whitelist()
def start_long_operation(filters):
"""NEVER run long operations synchronously in API calls."""
job_id = frappe.generate_hash(length=10)
frappe.enqueue(
"myapp.tasks.run_long_operation",
queue="long",
timeout=600,
job_id=job_id,
filters=filters
)
return {"status": "queued", "job_id": job_id}
@frappe.whitelist()
def check_job_status(job_id):
"""Poll for job completion."""
from frappe.utils.background_jobs import get_info
jobs = get_info()
for job in jobs:
if job.get("job_id") == job_id:
return {"status": job.get("status", "unknown")}
return {"status": "completed"}@frappe.whitelist()
def safe_api_endpoint(docname, action):
"""ALWAYS follow: validate -> check permission -> execute -> handle errors."""
# 1. Validate input
if not docname:
frappe.throw(_("Document name required"), exc=frappe.ValidationError)
# 2. Check existence
if not frappe.db.exists("My DocType", docname):
frappe.throw(_("Document not found"), exc=frappe.DoesNotExistError)
# 3. Check permission
frappe.has_permission("My DocType", "write", docname, throw=True)
# 4. Execute with error handling
try:
doc = frappe.get_doc("My DocType", docname)
result = doc.run_method(action)
return {"status": "success", "data": result}
except frappe.ValidationError:
raise # Let Frappe handle — returns 417
except frappe.PermissionError:
raise # Let Frappe handle — returns 403
except Exception:
frappe.log_error(frappe.get_traceback(), f"API Error: {docname}")
frappe.throw(_("Operation failed. Please try again."))// ALWAYS handle errors in frappe.call
frappe.call({
method: "myapp.api.safe_api_endpoint",
args: {docname: "DOC-001", action: "approve"},
freeze: true,
freeze_message: __("Processing..."),
callback: function(r) {
if (r.message && r.message.status === "success") {
frappe.show_alert({message: __("Done"), indicator: "green"});
}
},
error: function(r) {
// ALWAYS check exc_type for specific handling
if (r.exc_type === "PermissionError") {
frappe.msgprint(__("You lack permission for this action."));
} else if (r.exc_type === "DoesNotExistError") {
frappe.msgprint(__("Record not found."));
} else if (!r.status) {
frappe.msgprint(__("Network error. Check your connection."));
}
}
});frappe.throw() — enables correct HTTP status codesrequests.get(url, timeout=30)frappe.log_error() then frappe.throw()frappe.call() — silent failures confuse userstoken key:secret vs Bearer oauth_tokensettings.get_password("field") from a DocType| File | Contents |
|---|---|
references/patterns.md | Complete whitelisted method, webhook, external API patterns |
references/examples.md | Full working API module, client integration, external API client |
references/anti-patterns.md | 15 common API error handling mistakes |
frappe-core-api — API implementation patternsfrappe-errors-permissions — Permission error handling (403 deep dive)frappe-syntax-whitelisted — Whitelisted method syntaxfrappe-errors-serverscripts — Server Script error handling© Impertio-Studio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/source/errors/frappe-errors-api of Impertio-Studio/Frappe_Claude_Skill_Package.
Open the folder on GitHubat commit 36cfa80
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Impertio-Studio/Frappe_Claude_Skill_Package, which our catalogue first saw on October 7, 2026.
Frappe Errors API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Frappe Errors API this skillImpertio-Studio/Frappe_Claude_Skill_Package | 187 | 1 repos | ~4k | Automated safety check: Pass | MIT | |
| API Auditbriiirussell/cybersecurity-skills | 412 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Apikerhodgef/apiker | 127 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Discover APIrand/cc-polymath | 181 | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Laravel Securityaffaan-m/ECC | 274k | 3 repos | ~2k | Automated safety check: Pass | MIT | |
| Web Ssrfs0ld13rr/pentestcode | 817 | — | ~660 | Automated safety check: Warn | MIT |
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
hodgef/apiker
Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.
rand/cc-polymath
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
affaan-m/ECC
Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
s0ld13rr/pentestcode
Server-Side Request Forgery detection→internal-access→proof for web apps.
Microck/ordinary-claude-skills
Complete API integration guide for Shopify including GraphQL Admin API, REST Admin API, Storefront API, Ajax API, OAuth authentication, rate limiting, and webhooks.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when receiving vague or unclear ERPNext/Frappe development requests that need interpretation.
Impertio-Studio/Frappe_Claude_Skill_Package
Deploy HTML/CSS websites to ERPNext/Frappe (v15/v16) as Web Pages via the REST API.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building ERPNext/Frappe API integrations (v14/v15/v16) including REST API, RPC API, authentication, webhooks, and rate limiting.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when implementing hooks.py configurations in a Frappe custom app.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when building API endpoints with @frappe.whitelist() in Frappe.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when creating Frappe Whitelisted Methods (Python API endpoints) for v14/v15/v16.
Categories
A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16. Frappe Errors API is an agent skill from Impertio-Studio/Frappe_Claude_Skill_Package. Use when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.
Frappe Errors API fits situations like: handling API errors in Frappe/ERPNext v14/v15/v16; tasks that involve Rate limiting; tasks that involve REST APIs.
Run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a claude-code`. Or copy the skill folder (skills/source/errors/frappe-errors-api in Impertio-Studio/Frappe_Claude_Skill_Package) into .claude/skills/frappe-errors-api in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a codex`. Or copy the skill folder (skills/source/errors/frappe-errors-api in Impertio-Studio/Frappe_Claude_Skill_Package) into .agents/skills/frappe-errors-api in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Impertio-Studio/Frappe_Claude_Skill_Package --skill frappe-errors-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/frappe-errors-api, .gemini/skills/frappe-errors-api, .github/skills/frappe-errors-api and .opencode/skills/frappe-errors-api in your project.
SKILL.md names no scripts, command-line tools or credentials: Frappe Errors API is instructions for the agent only. Our summary lists: Python 3; A credential in CSRF_TOKEN. Compatibility (from SKILL.md): Claude Code, Claude.ai Projects, Claude API. Frappe v14-v16..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Frappe Errors API is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Frappe Errors API: API Audit (briiirussell/cybersecurity-skills, 412 stars), Apiker (hodgef/apiker, 127 stars), Discover API (rand/cc-polymath, 181 stars) and Laravel Security (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Impertio-Studio (a GitHub organization) maintains it in Impertio-Studio/Frappe_Claude_Skill_Package, which has 187 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on September 17, 2026.
Source: Impertio-Studio/Frappe_Claude_Skill_Package on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.