Agent skill

API Contract Testing

by makifbaysal in makifbaysal/tasktrooper

A skill your agent uses when a task adds or changes an HTTP endpoint, its request/response shape, status codes, auth or error format - the request matrix, curl templates and what counts as a…

Apache-2.0Auto-check passedBackend & APIs

Install API Contract Testing

skills CLI
$ npx skills add makifbaysal/tasktrooper --skill api-contract-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install makifbaysal/tasktrooper api-contract-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/agents/qa-agent/skills/api-contract-testing .claude/skills/api-contract-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-contract-testing
GitHub stars
109
Used in
1 other repo
Token cost
~771 tokens
SKILL.md length
331 words
Files
1
Skills in repo
99
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when a task adds or changes an HTTP endpoint, its request/response shape, status codes, auth or error format - the request matrix, curl templates and what counts as a…

  • Changes an HTTP endpoint
  • SKILL.md covers Contract source, Request template, Per changed endpoint, the matrix and Compatibility, plus 4 more sections
  • Calls curl, jq and uvx
  • Its request/response shape

What it does

API Contract Testing is an agent skill from makifbaysal/tasktrooper. Use when a task adds or changes an HTTP endpoint, its request/response shape, status codes, auth or error format - the request matrix, curl templates and what counts as a contract break

Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering API design. It works with OpenAPI. The repository describes itself as: Local-first agent platform: board + role agents + agent CLI runs (Claude Code, Cursor, Antigravity, OpenCode) or local and API models (Ollama, LM Studio), all on your own Mac. The licence is Apache-2.0.

When your agent uses it

  • Changes an HTTP endpoint
  • Its request/response shape
  • Error format - the request matrix
  • Curl templates and what counts as a contract break

Example prompts

  • “/api-contract-testing”

What it can do on your machine

Read from SKILL.md and the folder at commit 09f6258. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • uvx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl and uvx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Contract Testing loads about 771 tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 331 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~771

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from makifbaysal/tasktrooper at commit 09f6258, republished under its Apache-2.0 licence (© makifbaysal). 331 words, ~771 tokens.

Download SKILL.mdSave it as .claude/skills/api-contract-testing/SKILL.md (or your agent's skills folder).
name
api-contract-testing
description
Use when a task adds or changes an HTTP endpoint, its request/response shape, status codes, auth or error format - the request matrix, curl templates and what counts as a contract break
category
qa

API Contract Testing

Contract source

The task, its acceptance criteria and the spec document first; then the repo's OpenAPI file or README API docs (the named boot-docs exception). Never the handler source — a contract derived from the implementation only proves the implementation matches itself.

Request template

bash
curl -sS -D "$QA/h.txt" -o "$QA/b.json" -w '%{http_code} %{time_total}s\n' -X POST "$BASE/api/tasks" -H "Authorization: Bearer $TOKEN" -H 'Content-Type: application/json' -d '{"title":"qa-T-12 a"}'; jq . "$QA/b.json"  # no jq (stock Windows, some Linux): read_file the body instead

Per changed endpoint, the matrix

One case each, mapped to the category enum:

CaseCategory
2xx happy pathhappy_path
400/422 for invalid body, with the error payload shapenegative
401 no tokenauth
403 other user's resource (BOLA: create as A, read/update/delete as B)auth
404 unknown idnegative
409 duplicate where uniqueness is impliednegative
405 wrong methodnegative
extra unknown/privileged field ignored, e.g. "role":"admin" (mass assignment)auth
pagination edges (limit 0, max, max+1)boundary
idempotency: PUT/DELETE twice, POST with Idempotency-Key twice when claimednegative
content-type (missing, wrong)negative

Compatibility

Existing fields keep their name, type and nullability. A removed or renamed field is a break unless the task explicitly asks for it. Compare against the OpenAPI file, or a request to the same endpoint on stage/the default branch.

Side effects

Verify them the same way backend-manual-testing does — a 2xx with the wrong DB row or missed outbound call is a FAIL, not a pass with a note.

Optional depth: schema fuzzing

Local boot only, and only when the repo ships an OpenAPI file:

bash
uvx schemathesis run <openapi> --url <base> -H "Authorization: Bearer $TOKEN" --include-path-regex '<changed path>' --checks not_a_server_error,status_code_conformance,response_schema_conformance --max-examples 20 --max-failures 5

Scope it to the changed paths with --include-path-regex. Never run it against stage or anything shared — it generates many writes.

Worked Example

"POST /tasks title ≤120 chars": happy path (120 chars, 201); empty title (422); 121 chars (422); no auth (401); another user's project (403); duplicate title where unique (409 or 201 per spec); wrong Content-Type (415/400); unknown field is_admin:true ignored (201, field absent from response) — 8 cases, each with its expected code recorded before running it.

Red Flags

  • Asserting only the status code and never the body shape.
  • Testing authz with the same user for both sides of a BOLA case.
  • Fuzzing a shared environment (stage, a shared database).

© makifbaysal, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in catalog/agents/qa-agent/skills/api-contract-testing of makifbaysal/tasktrooper.

Open the folder on GitHubat commit 09f6258

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in makifbaysal/tasktrooper, which our catalogue first saw on October 7, 2026.

Compare with similar skills

API Contract Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Contract Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Contract Testing this skillmakifbaysal/tasktrooper1091 repos~771Automated safety check: PassApache-2.0
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Pangolin CRUD Endpointsfosrl/pangolin23k—~461Automated safety check: PassCustom licence
Old Coder API DesignAmazingAng/old-coder7491 repos~3.4kAutomated safety check: PassMIT
Designing APIsCloudAI-X/claude-workflow-v21.4k2 repos~1.2kAutomated safety check: PassMIT
API Surface Reviewpolarsource/polar10k—~1.3kAutomated safety check: PassMIT

Similar skills

  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Use whenever asked to add, create, or scaffold a CRUD endpoint, router, or entity in this repo's server (create/list/get/update/delete handlers, new…

    23k GitHub stars~461 tokensUpdated today
    Backend & APIsAuto-check passed
  • Old Coder API Design

    AmazingAng/old-coder

    Reviews or designs an HTTP/JSON API's endpoints, auth, pagination, versioning and deprecations, guarding against inventing a bespoke interface or silently breaking consumers.

    749 GitHub starsUsed in 1 repo~3.4k tokens
    Backend & APIsAuto-check passed
  • Designing APIs

    CloudAI-X/claude-workflow-v2

    Designs REST and GraphQL APIs including endpoints, error handling, versioning, and documentation.

    1.4k GitHub starsUsed in 2 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • API Surface Review

    polarsource/polar

    Review changes to Polar's API contract — Pydantic schemas, FastAPI endpoints, OpenAPI output and the generated SDKs.

    10k GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • API Contract

    ChenyCHENYU/Robot_Admin

    A skill your agent uses when: generating TypeScript API layer (type definitions + request functions) from page-spec JSON or Swagger/OpenAPI docs.

    1k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from makifbaysal/tasktrooper

All 99 skills in this repo
  • Acceptance Criteria Gwt

    makifbaysal/tasktrooper

    A skill your agent uses when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases

    109 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Check

    makifbaysal/tasktrooper

    A skill your agent uses when a task changes any screen, form, dialog, menu or control - Lighthouse/axe scan of the changed screens, a keyboard walk, and the thresholds that fail a task

    109 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Analiz Gate

    makifbaysal/tasktrooper

    A skill your agent uses when deciding whether a request needs an analiz task before implementation - the conditions that require the architect's analysis versus going straight to implementation

    109 GitHub stars~641 tokensUpdated yesterday
    Auto-check passed
  • Analiz HTML Report

    makifbaysal/tasktrooper

    A skill your agent uses when you write or revise the analiz deliverable - the ONE self-contained HTML report (spec and plan as sections) a human reviews passage by passage

    109 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed
  • Analiz Human Review Gate

    makifbaysal/tasktrooper

    A skill your agent uses when you finish an analiz report - the human must approve the analysis before any implementation task is created, via the analizreview column

    109 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Android Compose Patterns

    makifbaysal/tasktrooper

    A skill your agent uses when building native Android with Jetpack Compose - stateless composables, state hoisting, ViewModel-owned state, edge-to-edge, predictive back, adaptive layout, atomic…

    109 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about API Contract Testing

What does API Contract Testing do?

A skill your agent uses when a task adds or changes an HTTP endpoint, its request/response shape, status codes, auth or error format - the request matrix, curl templates and what counts as a…. API Contract Testing is an agent skill from makifbaysal/tasktrooper.

When should I use API Contract Testing?

API Contract Testing fits situations like: changes an HTTP endpoint; its request/response shape; error format - the request matrix; curl templates and what counts as a contract break.

How do I install API Contract Testing in Claude Code?

Run `npx skills add makifbaysal/tasktrooper --skill api-contract-testing -a claude-code`. Or copy the skill folder (catalog/agents/qa-agent/skills/api-contract-testing in makifbaysal/tasktrooper) into .claude/skills/api-contract-testing in your project. Claude Code loads it when a task matches its description.

How do I install API Contract Testing in Codex?

Run `npx skills add makifbaysal/tasktrooper --skill api-contract-testing -a codex`. Or copy the skill folder (catalog/agents/qa-agent/skills/api-contract-testing in makifbaysal/tasktrooper) into .agents/skills/api-contract-testing in your project. Codex loads it when a task matches its description.

Can I use API Contract Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add makifbaysal/tasktrooper --skill api-contract-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-contract-testing, .gemini/skills/api-contract-testing, .github/skills/api-contract-testing and .opencode/skills/api-contract-testing in your project.

What does API Contract Testing need to run?

Going by SKILL.md and its folder, API Contract Testing needs the command-line tools its instructions call (curl, jq and uvx).

Does API Contract Testing access the network?

SKILL.md contains no URLs. Its commands use curl and uvx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is API Contract Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Contract Testing use?

API Contract Testing is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Contract Testing use?

About 771 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Contract Testing?

Skills that share tags, products or a category with API Contract Testing: API Designer (Jeffallan/claude-skills, 12k stars), Pangolin CRUD Endpoints (fosrl/pangolin, 23k stars), Old Coder API Design (AmazingAng/old-coder, 749 stars) and Designing APIs (CloudAI-X/claude-workflow-v2, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Contract Testing?

makifbaysal (a GitHub user) maintains it in makifbaysal/tasktrooper, which has 109 GitHub stars. The repository holds 99 skills in this directory. The repository was last updated on October 7, 2026.

Source: makifbaysal/tasktrooper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.