Agent skill

Use Yaak

by mountain-loop in mountain-loop/yaak

A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

MITAuto-check passedBackend & APIs

Install Use Yaak

skills CLI
$ npx skills add mountain-loop/yaak --skill use-yaak -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mountain-loop/yaak use-yaak --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mountain-loop/yaak.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates-cli/yaak-cli/skills/use-yaak .claude/skills/use-yaak && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
use-yaak
GitHub stars
19k
Token cost
~1.9k tokens
SKILL.md length
948 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

  • Works in 7 steps: Resolve the workspace before mutating,… → Read the schema rather than guessing… → update takes a JSON merge patch keyed by… → …
  • The user mentions Yaak
  • SKILL.md covers The CLI describes itself, Resource model, Getting oriented and Core workflows, plus 2 more sections
  • Calls npm

What it does

Use Yaak is an agent skill from mountain-loop/yaak. Use when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual testing, configure auth on saved requests, import an OpenAPI spec, a Postman, Insomnia, or Bruno collection, or a cURL command, or run saved requests across environments. Prefer over one-off curl when requests should be saved, reused, shared, or run as a set.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering QA and bug reports, API testing and Realtime and WebSockets. It works with Postman, OpenAPI, gRPC and Tauri. The repository describes itself as: The most intuitive desktop API client. Organize and execute REST, GraphQL, WebSockets, Server Sent Events, and gRPC 🦬. The licence is MIT.

When your agent uses it

  • The user mentions Yaak
  • A Yaak workspace
  • The yaak command
  • Smoke test HTTP/REST endpoints

Example prompts

  • “/use-yaak”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Bash(yaak:*), Bash(which:*), Bash(command:*), Bash(npm:*), Bash(npx:*)

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Resolve the workspace before mutating, and prefer an existing one.
  2. Read the schema rather than guessing field names, auth fields, or body shapes.
  3. update takes a JSON merge patch keyed by id: send only what changes, and
  4. Deletes need --yes in a non-interactive shell. Confirm with the user first.
  5. Never write a real secret into an environment variable on the user's behalf.
  6. Verify what you built by sending it, and report the real HTTP status.
  7. If the CLI warns on stderr that a newer version is available, offer to run

What it can do on your machine

Read from SKILL.md and the folder at commit 919e58f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(yaak:*)
    • Bash(which:*)
    • Bash(command:*)
    • Bash(npm:*)
    • Bash(npx:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Use Yaak loads about 1.9k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 948 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mountain-loop/yaak at commit 919e58f, republished under its MIT licence (© mountain-loop). 948 words, ~1,875 tokens.

Download SKILL.mdSave it as .claude/skills/use-yaak/SKILL.md (or your agent's skills folder).
name
use-yaak
description
Use when the user mentions Yaak, a Yaak workspace, or the `yaak` command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual testing, configure auth on saved requests, import an OpenAPI spec, a Postman, Insomnia, or Bruno collection, or a cURL command, or run saved requests across environments. Prefer over one-off `curl` when requests should be saved, reused, shared, or run as a set.
allowed-tools
Bash(yaak:*), Bash(which:*), Bash(command:*), Bash(npm:*), Bash(npx:*)

Use Yaak

<!--
  Managed by the Yaak CLI. `yaak agent install` replaces this file wholesale on
  every run, so local edits are lost. To add your own guidance, write a separate
  skill or use your tool's project instructions instead.
  yaak-cli-version: __YAAK_CLI_VERSION__
-->

Yaak is a desktop API client. The yaak CLI reads and writes the same local database as the desktop app, so anything you create shows up in the app immediately, and vice versa. There is no server and no sign-in: yaak auth is only for publishing plugins to the Yaak registry.

Two consequences worth holding onto. Requests you create are permanent user data in an app they use, not scratch files, so name them the way the user would and clean up anything created just to test. And because the app is right there, the CLI is usually the wrong place to read a response in detail; it is the right place to build, organize, and run requests.

The CLI describes itself

This skill deliberately does not list fields, body types, auth strategies, or template functions. The user's CLI version and installed plugins decide what exists, so any list written here would eventually be wrong. Ask the CLI:

bash
yaak --help                          # commands, plus agent hints at the bottom
yaak <command> --help                # flags for one command
yaak request schema http --pretty    # full request model, with guidance per field
yaak template-function list [filter] # template functions from installed plugins
yaak template-function show <name>   # one function's arguments

request schema http is generated from the real model and merges in the auth strategies contributed by plugins, so it is the authoritative answer for what a request payload may contain and what each auth strategy needs. workspace, environment, and folder have schema subcommands too.

Read the relevant schema before writing a JSON payload you are not certain of. That is faster than a failed send, and it stays correct as Yaak changes.

Resource model

  • Workspace (wk_…) is the top-level container.
  • Folder (fl_…) groups requests and can nest. Folders carry headers and authentication that child requests inherit, which is the usual way to apply one token to a whole group.
  • Request (rq_…) is a single HTTP, gRPC, or WebSocket request. The CLI can currently only create and send HTTP ones.
  • Environment (ev_…) holds variables. Each workspace has a base environment plus any number of sub-environments; a sub-environment overrides base variables of the same name and is chosen per send with -e.
  • Cookie jar (cj_…) stores cookies per workspace. The oldest is used by default, so this normally needs no attention.

IDs are prefix-typed, so you can always tell what an ID refers to. Commands that take a workspace ID infer it when exactly one workspace exists.

Getting oriented

bash
yaak --version || npm install -g @yaakapp/cli
yaak workspace list

Pick the workspace matching the user's project before changing anything, and create one only when nothing fits.

Skill freshness

The CLI writes this skill, so an upgraded CLI can leave it behind. That failure is silent: nothing errors, the skill just stops mentioning things the CLI can now do. Check once per session, alongside the commands above:

bash
yaak --help 2>&1 | grep -A2 "Agent tooling:"

If it reports the skill is out of date, run yaak agent install and tell the user to restart their coding tool. This session keeps running on the old copy until they do, so finish the current request either way. Check once and do not re-run it after acting.

When the CLI and this skill disagree, the CLI is right.

Show full SKILL.md (463 more words)Show less

Core workflows

Start from a spec when one exists. yaak import <path> auto-detects OpenAPI, Swagger, Postman, Insomnia, Bruno, cURL, and Yaak exports, and beats authoring requests by hand every time. Bruno collections can also be imported from a ZIP or directory.

Make the host swappable. Put the base URL in a base-environment variable, reference it as ${[ base_url ]}, then add a sub-environment per deployment target. Now yaak -e ev_staging send <wk_id> runs everything against staging.

Chain instead of shell-plumbing. A request can read another request's response directly, and Yaak sends the dependency first if it needs to:

${[ response.body.path(request='rq_login', path='$.token') ]}

Run yaak template-function show response.body.path for its arguments, including how to control when the upstream request re-sends. Chain when a request genuinely depends on another's response; to merely run requests in order, yaak send <fl_id> already does that.

Run a set. yaak send accepts a folder or workspace ID, with --fail-fast and --parallel. Workspace and request IDs survive an export/import, so a committed yaak export plus --data-dir ./.yaak gives a runnable suite in CI.

Reading results

A plain send writes only the response body to stdout. Yaak also stores every response, so the reliable way to see what happened is to ask afterwards rather than to parse the send output:

bash
yaak response show rq_abc123     # latest response for a request, as JSON
yaak response list rq_abc123     # its history, newest first
yaak response body rq_abc123     # just the body

response show gives status, reason, timing, headers, the final URL, and any transport error. Pass a response ID for a specific one.

-v on a send prints the same information prefixed *, >, and <, with the body after the last < header line:

bash
yaak -v request send rq_abc123 2>&1 | grep '^< HTTP'

That works, but response show is still better when you need to act on the result, since it gives you fields rather than text to parse.

Exit code 1 means the send did not complete: an unresolved template variable, an unreachable host, a TLS failure. HTTP error statuses are not failures. Like curl, a 404 or 500 exits 0, and a folder of requests that all return 500 reports success. Never tell the user an API is healthy based on a clean exit; check the status.

Execution rules

  1. Resolve the workspace before mutating, and prefer an existing one.
  2. Read the schema rather than guessing field names, auth fields, or body shapes.
  3. update takes a JSON merge patch keyed by id: send only what changes, and note that arrays are replaced wholesale, not merged.
  4. Deletes need --yes in a non-interactive shell. Confirm with the user first.
  5. Never write a real secret into an environment variable on the user's behalf. Reference one and let them fill in the value.
  6. Verify what you built by sending it, and report the real HTTP status.
  7. If the CLI warns on stderr that a newer version is available, offer to run the upgrade command it prints, then re-run yaak agent install so this skill updates too.

© mountain-loop, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates-cli/yaak-cli/skills/use-yaak of mountain-loop/yaak.

Open the folder on GitHubat commit 919e58f

Compare with similar skills

Use Yaak next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Use Yaak compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Use Yaak this skillmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
Dotnet Webapidotnet/skills5.6k2 repos~5.5kAutomated safety check: PassMIT
API Architectcuriositech/some_claude_skills2431 repos~1.4kAutomated safety check: PassMIT
API ForgeEliasOulkadi/shokunin114—~2.9kAutomated safety check: PassMIT
API Protocol Securityzhaji2333/CkSKILLS113—~520Automated safety check: PassMIT
System Design CommunicationHoangNguyen0403/agent-skills-standard571—~894Automated safety check: PassMIT

Similar skills

  • Dotnet Webapi

    dotnet/skills

    Official

    Guides creation and modification of ASP.NET Core Web API endpoints with correct HTTP semantics, OpenAPI metadata, and error handling.

    5.6k GitHub starsUsed in 2 repos~5.5k tokens
    Backend & APIsAuto-check passed
  • API Architect

    curiositech/some_claude_skills

    Expert API designer for REST, GraphQL, gRPC architectures. An agent skill from curiositech/some_claude_skills.

    243 GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check passed
  • API Forge

    EliasOulkadi/shokunin

    Design REST/GraphQL APIs with OpenAPI 3.1, error handling, pagination, rate limiting, webhooks, and idempotency.

    114 GitHub stars~2.9k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • API Protocol Security

    zhaji2333/CkSKILLS

    当目标存在REST/GraphQL/gRPC/WebSocket接口、Swagger/OpenAPI文档、调试端点(actuator/console)、旧版本API、内部接口、微服务网关,或需要测试HTTP走私、DoS、速率限制时调用。负责API全方法测试、BOLA越权、GraphQL深度攻击、协议层漏洞挖掘。

    113 GitHub stars~520 tokensUpdated 23 days ago
    Backend & APIsAuto-check passed
  • System Design Communication

    HoangNguyen0403/agent-skills-standard

    Select how services talk: REST, gRPC, GraphQL, WebSocket, SSE, or webhook per hop, sync versus async per flow, service discovery mode, and DNS/edge routing.

    571 GitHub stars~894 tokensUpdated today
    Backend & APIsAuto-check passed
  • Dev Rules

    rust-dd/tako

    General coding-style rules to apply to every project. An agent skill from rust-dd/tako.

    162 GitHub stars~810 tokensUpdated 6 days ago
    Backend & APIsAuto-check passed

More from mountain-loop/yaak

  • Yaak Changelog

    mountain-loop/yaak

    Create or edit Yaak changelogs. An agent skill from mountain-loop/yaak.

    19k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Generate Yaak release notes from git history and PR metadata, including feedback links and full changelog compare links.

    19k GitHub stars~548 tokensUpdated yesterday
    Auto-check passed

Questions about Use Yaak

What does Use Yaak do?

A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…. Use Yaak is an agent skill from mountain-loop/yaak. Use when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual testing, configure auth on saved requests, import an OpenAPI spec, a Postman, Insomnia, or Bruno collection, or a cURL command, or run saved requests across environments.

When should I use Use Yaak?

Use Yaak fits situations like: the user mentions Yaak; A Yaak workspace; the yaak command; smoke test HTTP/REST endpoints.

How do I install Use Yaak in Claude Code?

Run `npx skills add mountain-loop/yaak --skill use-yaak -a claude-code`. Or copy the skill folder (crates-cli/yaak-cli/skills/use-yaak in mountain-loop/yaak) into .claude/skills/use-yaak in your project. Claude Code loads it when a task matches its description.

How do I install Use Yaak in Codex?

Run `npx skills add mountain-loop/yaak --skill use-yaak -a codex`. Or copy the skill folder (crates-cli/yaak-cli/skills/use-yaak in mountain-loop/yaak) into .agents/skills/use-yaak in your project. Codex loads it when a task matches its description.

Can I use Use Yaak in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mountain-loop/yaak --skill use-yaak -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/use-yaak, .gemini/skills/use-yaak, .github/skills/use-yaak and .opencode/skills/use-yaak in your project.

What does Use Yaak need to run?

Going by SKILL.md and its folder, Use Yaak needs the command-line tools its instructions call (npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(yaak:*), Bash(which:*), Bash(command:*), Bash(npm:*), Bash(npx:*).

Does Use Yaak access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Use Yaak safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Use Yaak use?

Use Yaak is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Use Yaak use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Use Yaak?

Skills that share tags, products or a category with Use Yaak: Dotnet Webapi (dotnet/skills, 5.6k stars), API Architect (curiositech/some_claude_skills, 243 stars), API Forge (EliasOulkadi/shokunin, 114 stars) and API Protocol Security (zhaji2333/CkSKILLS, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Use Yaak?

mountain-loop (a GitHub organization) maintains it in mountain-loop/yaak, which has 19,297 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: mountain-loop/yaak on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.