Agent skill

API Test Plan

by mohitagw15856 in mohitagw15856/pm-claude-skills

Plan tests for an API endpoint or service — functional, negative, and contract.

MITAuto-check passedBackend & APIs

Install API Test Plan

skills CLI
$ npx skills add mohitagw15856/pm-claude-skills --skill api-test-plan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitagw15856/pm-claude-skills api-test-plan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitagw15856/pm-claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-test-plan .claude/skills/api-test-plan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-test-plan
GitHub stars
1.4k
Token cost
~1.1k tokens
SKILL.md length
509 words
Files
1
Skills in repo
1,322
Repo updated
First seen
Licence
MIT

At a glance

Plan tests for an API endpoint or service — functional, negative, and contract.

  • Asked to test an API
  • SKILL.md covers Working from a brief, Required Inputs, Output Format and Quality Checks, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Write API test cases

What it does

API Test Plan is an agent skill from mohitagw15856/pm-claude-skills. Plan tests for an API endpoint or service — functional, negative, and contract. Use when asked to test an API, write API test cases, plan REST/GraphQL endpoint testing, or validate an API contract. Produces an API test plan — per-endpoint cases (status codes, schema, auth, validation, errors), boundary/negative cases, contract checks, and non-functional notes — so the API is verified beyond the happy 200.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering API testing and REST APIs. It works with GraphQL. The repository describes itself as: 1255 professional Agent Skills for Claude, ChatGPT, Gemini, Cursor & Codex — PRDs, postmortems, leases, medical bills, layoffs, go-bags, new countries. Plain markdown, MIT, in… The licence is MIT.

When your agent uses it

  • Asked to test an API
  • Write API test cases
  • Plan REST/GraphQL endpoint testing
  • Validate an API contract

Example prompts

  • “/api-test-plan”

What it can do on your machine

Read from SKILL.md and the folder at commit 1cbf1f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Test Plan loads about 1.1k tokens when it runs. Until then it costs about 106 tokens; SKILL.md has 509 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitagw15856/pm-claude-skills at commit 1cbf1f0, republished under its MIT licence (© mohitagw15856). 509 words, ~1,079 tokens.

Download SKILL.mdSave it as .claude/skills/api-test-plan/SKILL.md (or your agent's skills folder).
name
api-test-plan
description
Plan tests for an API endpoint or service — functional, negative, and contract. Use when asked to test an API, write API test cases, plan REST/GraphQL endpoint testing, or validate an API contract. Produces an API test plan — per-endpoint cases (status codes, schema, auth, validation, errors), boundary/negative cases, contract checks, and non-functional notes — so the API is verified beyond the happy 200.

API Test Plan Skill

APIs fail in specific, testable ways: wrong status codes, schema drift, missing auth checks, sloppy validation, unhelpful errors. This skill plans the tests that catch them — per endpoint, across the response codes and the error paths, with contract checks so the API keeps its promises to clients. It tests the whole behaviour, not just the happy 200.

Working from a brief

Given an endpoint or an API description, produce the test plan anyway — infer the likely parameters, responses, auth model, and error cases, labelling assumptions. Always include auth, validation, and negative cases. Never hand back a question instead of a plan.

Required Inputs

Ask for these only if they aren't already provided (else infer and label):

  • The API — REST/GraphQL, the endpoints/operations, and what they do.
  • Contract — request/response schemas, parameters, status codes (or an OpenAPI/spec if available).
  • Auth & rules — the auth model (token/scopes/roles), rate limits, and validation rules.
  • Dependencies & data — downstream services, and the data/state needed to test.

Output Format

API Test Plan: [API / endpoint]

Per endpoint, a set of cases grouped by type:

IDEndpointCaseTypeRequestExpected statusExpected body / assertion
API-01POST /ordersvalid createFunctionalvalid payload201body matches schema, id returned
API-02POST /ordersmissing fieldValidationpartial payload400error names the field
API-03POST /ordersno tokenAuthvalid payload, no auth401not created
API-04POST /orderswrong roleAuthzvalid payload, wrong scope403not created
API-05GET /orders/{id}not foundNegativeunknown id404error body

Cover deliberately: happy path (correct status + schema), validation (missing/invalid/extra fields, types, boundaries), auth/authz (no token, expired, wrong scope/role), negative (not found, conflict, bad method), idempotency/concurrency where relevant, and errors (correct codes + helpful, consistent error bodies).

Contract checks — responses conform to the schema; required fields, types, and status codes match the spec; backward compatibility for existing clients.

Non-functional notes — rate limiting, pagination, large payloads, latency expectations, and security basics (no sensitive data leakage, proper status for unauthorised).

Setup — test data, environment, and any mocks/stubs for dependencies.

Show full SKILL.md (173 more words)Show less

Quality Checks

  • Each endpoint is tested beyond 200 — error codes (4xx/5xx) and their bodies are asserted
  • Auth and authorization cases are included (no token, expired, wrong scope/role)
  • Validation/boundary/negative cases cover missing, invalid, and extra inputs
  • Responses are checked against the schema/contract, incl. backward compatibility
  • Status codes match the spec and are used correctly (e.g. 401 vs. 403, 400 vs. 422)
  • Non-functional aspects (rate limits, pagination, data leakage) are noted

Anti-Patterns

  • Do not test only the happy 200 — most API bugs are in validation, auth, and error paths
  • Do not ignore the response schema — a 200 with the wrong body still breaks clients
  • Do not skip authz (role/scope) testing — "logged in" isn't "allowed"
  • Do not assert only status codes — check the body/contract too
  • Do not overlook error-body quality and correct status semantics (401 vs 403, 400 vs 404)

Based On

API testing practice — contract/schema validation, status-code correctness, auth/authz coverage, and negative/boundary testing beyond the happy path.

Example Trigger Phrases

  • "Test an API."
  • "Write API test cases."
  • "Plan REST/GraphQL endpoint testing."
  • "Validate an API contract."

© mohitagw15856, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/api-test-plan of mohitagw15856/pm-claude-skills.

Open the folder on GitHubat commit 1cbf1f0

Compare with similar skills

API Test Plan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Test Plan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Test Plan this skillmohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMIT
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
API TesterRightNow-AI/openfang18k—~807Automated safety check: PassApache-2.0
API Recon And Docsyaklang/hack-skills2.4k—~456Automated safety check: PassMIT
Webui Connection Infolablup/backend.ai-webui133—~556Automated safety check: NotesLGPL-3.0
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT

Similar skills

  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • API Tester

    RightNow-AI/openfang

    API testing expert for curl, REST, GraphQL, authentication, and debugging

    18k GitHub stars~807 tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 25 days ago
    Backend & APIsAuto-check passed
  • Webui Connection Info

    lablup/backend.ai-webui

    Find the WebUI dev server address and the Backend.AI API endpoint and test account to use.

    133 GitHub stars~556 tokensUpdated today
    Backend & APIsAuto-check: notes
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed

More from mohitagw15856/pm-claude-skills

All 1,322 skills in this repo
  • Exit Waterfall

    mohitagw15856/pm-claude-skills

    Compute who gets what at each exit price from a cap table — liquidation preferences, conversion points, and where the founders' share collapses.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Feature Prioritisation

    mohitagw15856/pm-claude-skills

    Apply prioritisation frameworks (RICE, MoSCoW, Kano, ICE, Opportunity Scoring) to rank features and backlog items.

    1.4k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Freelance Rate

    mohitagw15856/pm-claude-skills

    Derive a freelance day/hourly rate backwards from target income, honest billable utilization, overhead, and the self-employment tax premium — the arithmetic that proves a rate is not salary÷2000.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Offer Comparison

    mohitagw15856/pm-claude-skills

    Compare two or more job offers as total-comp curves over four years — vesting cliffs, bonuses, 401(k) match, and the crossover year computed, not vibed.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Refinance Breakeven

    mohitagw15856/pm-claude-skills

    Compute the month a refinance actually starts saving money — payment delta, breakeven month, and total interest on both paths including the term-reset trap.

    1.4k GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Rent Vs Buy

    mohitagw15856/pm-claude-skills

    Model rent-vs-buy honestly — year-by-year net position for both paths including the assumption everyone drops (the renter invests the difference), with a breakeven horizon instead of a verdict.

    1.4k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about API Test Plan

What does API Test Plan do?

Plan tests for an API endpoint or service — functional, negative, and contract. API Test Plan is an agent skill from mohitagw15856/pm-claude-skills. Plan tests for an API endpoint or service — functional, negative, and contract.

When should I use API Test Plan?

API Test Plan fits situations like: asked to test an API; write API test cases; plan REST/GraphQL endpoint testing; validate an API contract.

How do I install API Test Plan in Claude Code?

Run `npx skills add mohitagw15856/pm-claude-skills --skill api-test-plan -a claude-code`. Or copy the skill folder (skills/api-test-plan in mohitagw15856/pm-claude-skills) into .claude/skills/api-test-plan in your project. Claude Code loads it when a task matches its description.

How do I install API Test Plan in Codex?

Run `npx skills add mohitagw15856/pm-claude-skills --skill api-test-plan -a codex`. Or copy the skill folder (skills/api-test-plan in mohitagw15856/pm-claude-skills) into .agents/skills/api-test-plan in your project. Codex loads it when a task matches its description.

Can I use API Test Plan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitagw15856/pm-claude-skills --skill api-test-plan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-test-plan, .gemini/skills/api-test-plan, .github/skills/api-test-plan and .opencode/skills/api-test-plan in your project.

What does API Test Plan need to run?

SKILL.md names no scripts, command-line tools or credentials: API Test Plan is instructions for the agent only.

Does API Test Plan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Test Plan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Test Plan use?

API Test Plan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Test Plan use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Test Plan?

Skills that share tags, products or a category with API Test Plan: Use Yaak (mountain-loop/yaak, 19k stars), API Tester (RightNow-AI/openfang, 18k stars), API Recon And Docs (yaklang/hack-skills, 2.4k stars) and Webui Connection Info (lablup/backend.ai-webui, 133 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Test Plan?

mohitagw15856 (a GitHub user) maintains it in mohitagw15856/pm-claude-skills, which has 1,431 GitHub stars. The repository holds 1,322 skills in this directory. The repository was last updated on October 7, 2026.

Source: mohitagw15856/pm-claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.