A skill your agent uses when testing HTTP endpoints, probing URLs for status and headers, or running declarative API test suites from plain text files

MITAuto-check passedTesting & QA

Install API Testing

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill api-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace api-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/productivity/cli-power-skills/skills/api-testing .claude/skills/api-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-testing
GitHub stars
2.8k
Token cost
~1k tokens
SKILL.md length
278 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when testing HTTP endpoints, probing URLs for status and headers, or running declarative API test suites from plain text files

  • Testing HTTP endpoints
  • SKILL.md covers When to Use, Tools, Patterns and Pipelines, plus 2 more sections
  • Calls jq; reaches github.com
  • Probing URLs for status and headers

What it does

API Testing is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use when testing HTTP endpoints, probing URLs for status and headers, or running declarative API test suites from plain text files

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Testing & QA, covering API testing. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Testing HTTP endpoints
  • Probing URLs for status and headers
  • Running declarative API test suites from plain text files

Example prompts

  • “/api-testing”

Requirements

  • Pre-approved tools (allowed-tools): Bash(hurl*), Bash(httpx*), Read, Write, Glob

What it can do on your machine

Read from SKILL.md and the folder at commit 23ea8d4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(hurl*)
    • Bash(httpx*)
    • Read
    • Write
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Testing loads about 1k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 278 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit 23ea8d4, republished under its MIT licence (© jeremylongshore). 278 words, ~1,023 tokens.

Download SKILL.mdSave it as .claude/skills/api-testing/SKILL.md (or your agent's skills folder).
name
api-testing
description
Use when testing HTTP endpoints, probing URLs for status and headers, or running declarative API test suites from plain text files
allowed-tools
Bash(hurl*), Bash(httpx*), Read, Write, Glob
version
1.0.0
author
ykotik
license
MIT

API Testing

When to Use

  • Testing REST API endpoints for correct responses
  • Writing declarative, repeatable HTTP test suites
  • Chaining HTTP requests (authenticate → create → verify)
  • Probing multiple URLs for availability, status codes, or headers
  • Validating response bodies, headers, and status codes with assertions

Tools

ToolPurposeStructured output
HurlDeclarative HTTP testing from plain text .hurl files--json for JSON report
httpxFast HTTP probing toolkit (ProjectDiscovery)-json for JSON output

Patterns

Hurl: Simple GET with status assertion

Create a .hurl file:

hurl
GET http://localhost:3000/api/health
HTTP 200
[Asserts]
jsonpath "$.status" == "ok"

Run it:

bash
hurl health.hurl
Hurl: POST with JSON body and response validation
hurl
POST http://localhost:3000/api/users
Content-Type: application/json
{
  "name": "Alice",
  "email": "alice@example.com"
}
HTTP 201
[Asserts]
jsonpath "$.id" isInteger
jsonpath "$.name" == "Alice"
Hurl: Chained requests (auth → create → verify)
hurl
# Step 1: Login
POST http://localhost:3000/api/auth/login
Content-Type: application/json
{
  "email": "admin@example.com",
  "password": "secret"
}
HTTP 200
[Captures]
token: jsonpath "$.token"

# Step 2: Create resource with token
POST http://localhost:3000/api/items
Authorization: Bearer {{token}}
Content-Type: application/json
{
  "title": "New Item"
}
HTTP 201
[Captures]
item_id: jsonpath "$.id"

# Step 3: Verify resource exists
GET http://localhost:3000/api/items/{{item_id}}
Authorization: Bearer {{token}}
HTTP 200
[Asserts]
jsonpath "$.title" == "New Item"
Hurl: Run test suite with JSON report
bash
hurl --test --report-json report/ tests/*.hurl
Hurl: Use variables from command line
bash
hurl --variable host=https://staging.example.com --variable token=abc123 tests/api.hurl
httpx: Probe a list of URLs for status codes
bash
echo -e "https://example.com\nhttps://httpbin.org\nhttps://nonexistent.invalid" | httpx -silent -status-code
httpx: Probe with full JSON output (status, title, tech)
bash
echo "https://example.com" | httpx -json -title -tech-detect -status-code
httpx: Check specific ports across hosts
bash
echo -e "192.168.1.1\n192.168.1.2" | httpx -ports 80,443,8080 -status-code
httpx: Follow redirects and show final URL
bash
echo "http://github.com" | httpx -follow-redirects -location -status-code

Pipelines

Hurl test suite → summarize failures
bash
hurl --test --report-json report/ tests/*.hurl 2>&1; jq '[.[] | select(.success == false) | {file: .filename, errors: [.entries[] | select(.errors | length > 0) | .errors]}]' report/*.json

Each stage: Hurl runs all tests and writes JSON reports, jq filters to failures and extracts error details.

Discover endpoints with Katana → probe with httpx
bash
katana -u https://example.com -silent -d 2 | httpx -silent -status-code -json

Each stage: Katana crawls and discovers URLs, httpx probes each for status and metadata.

Prefer Over

  • Prefer Hurl over curl scripts for multi-step API testing — declarative syntax with built-in assertions, no bash scripting needed
  • Prefer Hurl over Postman/Bruno for CI-friendly test suites — plain text files, no GUI dependency
  • Prefer httpx over curl loops for probing many URLs — concurrent, structured output, built for scale

Do NOT Use When

  • Need full browser rendering or JavaScript execution — use web-crawling skill (Playwright)
  • Building a long-running API client or SDK — write code instead
  • Testing WebSocket or gRPC endpoints — use specialized tools (wscat, grpcurl)
  • Single ad-hoc curl request — just use curl directly

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/productivity/cli-power-skills/skills/api-testing of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit 23ea8d4

Compare with similar skills

API Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Testing this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT
Diff-Driven QASkyvern-AI/skyvern23k—~4.7kAutomated safety check: WarnAGPL-3.0
AI Regression Testingaffaan-m/ECC275k5 repos~2.9kAutomated safety check: PassMIT
API Test Brunonaodeng/awesome-qa-skills245—~663Automated safety check: PassCustom licence
Scout Best Practices Reviewerelastic/kibana21k—~5.1kAutomated safety check: PassCustom licence
API Testing RESTPramodDutta/qaskills232—~4.9kAutomated safety check: PassMIT

Similar skills

  • Diff-Driven QA

    Skyvern-AI/skyvern

    Reads your git diff, decides whether the change needs browser QA, API checks or repo tests, runs that validation and reports pass or fail with evidence.

    23k GitHub stars~4.7k tokensUpdated today
    Testing & QAAuto-check: warnings
  • Regression testing strategies for AI-assisted development. An agent skill from affaan-m/ECC.

    275k GitHub starsUsed in 5 repos~2.9k tokens
    Testing & QAAuto-check passed
  • API Test Bruno

    naodeng/awesome-qa-skills

    A skill your agent uses when you need to parse multi-format API definitions and generate Bruno collections for executable regression; triggers include Bruno collections and Bruno API testing.

    245 GitHub stars~663 tokensUpdated 12 days ago
    Testing & QAAuto-check passed
  • Official

    Review Scout UI/API tests (including Scout test migrations) and Scout reuse surfaces (page objects, UI component objects, API services) for best practices, reuse, correct placement, parity, and…

    21k GitHub stars~5.1k tokensUpdated today
    Testing & QAAuto-check passed
  • API Testing REST

    PramodDutta/qaskills

    Comprehensive RESTful API testing patterns covering HTTP methods, status codes, request/response validation, authentication, error handling, and contract testing.

    232 GitHub stars~4.9k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • API Test Suite Builder

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to generate API tests, create integration test suites, test REST endpoints, or build contract tests.

    28k GitHub starsUsed in 1 repo~1.6k tokens
    Testing & QAAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Analyzing Text With NLP

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to perform natural language processing and text analysis using the nlp-text-analyzer plugin.

    2.8k GitHub starsUsed in 1 repo~819 tokens
    Auto-check passed
  • Building Neural Networks

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill allows AI assistant to construct and configure neural network architectures using the neural-network-builder plugin.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Detecting Data Anomalies

    jeremylongshore/tons-of-skills-marketplace

    Process identify anomalies and outliers in datasets using machine learning algorithms.

    2.8k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Explaining Machine Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill enables AI assistant to provide interpretability and explainability for machine learning models.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • Optimizing Prompts

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill optimizes prompts for large language models (llms) to reduce token usage, lower costs, and improve performance.

    2.8k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed

Categories

Questions about API Testing

What does API Testing do?

A skill your agent uses when testing HTTP endpoints, probing URLs for status and headers, or running declarative API test suites from plain text files. API Testing is an agent skill from jeremylongshore/tons-of-skills-marketplace.

When should I use API Testing?

API Testing fits situations like: testing HTTP endpoints; probing URLs for status and headers; running declarative API test suites from plain text files.

How do I install API Testing in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill api-testing -a claude-code`. Or copy the skill folder (plugins/productivity/cli-power-skills/skills/api-testing in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/api-testing in your project. Claude Code loads it when a task matches its description.

How do I install API Testing in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill api-testing -a codex`. Or copy the skill folder (plugins/productivity/cli-power-skills/skills/api-testing in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/api-testing in your project. Codex loads it when a task matches its description.

Can I use API Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill api-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-testing, .gemini/skills/api-testing, .github/skills/api-testing and .opencode/skills/api-testing in your project.

What does API Testing need to run?

Going by SKILL.md and its folder, API Testing needs the command-line tools its instructions call (jq). Its frontmatter pre-approves these tools: Bash(hurl*), Bash(httpx*), Read, Write, Glob.

Does API Testing access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is API Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Testing use?

API Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Testing use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Testing?

Skills that share tags, products or a category with API Testing: Diff-Driven QA (Skyvern-AI/skyvern, 23k stars), AI Regression Testing (affaan-m/ECC, 275k stars), API Test Bruno (naodeng/awesome-qa-skills, 245 stars) and Scout Best Practices Reviewer (elastic/kibana, 21k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Testing?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,821 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 8, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.