Agent skill

Endpoint Validator

by notque in notque/vexjoy-agent

Deterministic API endpoint validation with pass/fail reporting.

MITAuto-check: notesBackend & APIs

Install Endpoint Validator

skills CLI
$ npx skills add notque/vexjoy-agent --skill endpoint-validator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install notque/vexjoy-agent endpoint-validator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/notque/vexjoy-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/infrastructure/endpoint-validator .claude/skills/endpoint-validator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
endpoint-validator
GitHub stars
435
Token cost
~1.1k tokens
SKILL.md length
354 words
Files
4 (incl. references)
Skills in repo
61
Repo updated
First seen
Licence
MIT

At a glance

Deterministic API endpoint validation with pass/fail reporting.

  • Works in 3 steps: DISCOVER → VALIDATE → REPORT
  • Tasks that involve REST APIs
  • SKILL.md covers Deep References, Instructions, Error Handling and CI Integration
  • Calls curl and jq

What it does

Endpoint Validator is an agent skill from notque/vexjoy-agent. Deterministic API endpoint validation with pass/fail reporting.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/auth-endpoint-patterns.md`, `references/endpoint-config-preferred-patterns.md` and `references/security-headers.md`).

It sits in Backend & APIs, covering REST APIs. The repository describes itself as: VexJoy AI Agent with Jev Intelligent Routing - /do routes plain-English requests to the right specialist agent and gates the work with reviews, tests, and a learning loop. The licence is MIT.

When your agent uses it

  • Tasks that involve REST APIs

Example prompts

  • “/endpoint-validator”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, Write, Glob, Edit

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. DISCOVER
  2. VALIDATE
  3. REPORT

What it can do on your machine

Read from SKILL.md and the folder at commit 5218674. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Glob
    • Edit

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Endpoint Validator loads about 1.1k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 21 tokens; SKILL.md has 354 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Glob, Edit

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from notque/vexjoy-agent at commit 5218674, republished under its MIT licence (© notque). 354 words, ~1,072 tokens.

Download SKILL.mdSave it as .claude/skills/endpoint-validator/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
endpoint-validator
description
Deterministic API endpoint validation with pass/fail reporting.
allowed-tools
Bash, Read, Write, Glob, Edit
promoted_to
deploy
user-invocable
false
routing.triggers
validate endpoints, smoke test API, health check endpoints, test endpoint, check API, smoke test
routing.category
infrastructure
routing.not_for
process/service uptime or daemon liveness (use service-health-check); only HTTP/API endpoint request validation
routing.pairs_with
assessment, testing

Endpoint Validator Skill

Deterministic HTTP endpoint validation: discover config, test each endpoint against expectations, report pass/fail with CI-compatible exit codes.

Deep References

Load on demand when the signal matches.

SignalReferenceContent
Security header WARNs, HSTS/CSP/X-Framereferences/security-headers.mdHeader checks, required values, remediation
Config errors, hardcoded IPs, timeoutsreferences/endpoint-config-preferred-patterns.mdConfiguration failure modes and fixes
401/403 failures, auth patternsreferences/auth-endpoint-patterns.mdBearer, API-key, cookie auth validation

Instructions

Phase 1: DISCOVER

Read repository CLAUDE.md for base URL conventions or env var names.

Search for endpoint config in order: endpoints.json in project root, tests/endpoints.json, inline specification from user. Prefer version-controlled config over ad-hoc lists.

Config shape:

json
{
  "base_url": "http://localhost:8000",
  "endpoints": [
    {"path": "/health", "expect_status": 200},
    {"path": "/api/v1/users", "expect_key": "data", "timeout": 10},
    {"path": "/api/v1/search?q=test", "max_time": 2.0}
  ]
}

Endpoint fields: path (required), expect_status (default 200), expect_key (top-level JSON key), timeout (default 5s), max_time (SLOW threshold), method (default GET), headers (per-endpoint).

Rules:

  • Warn before POST/PUT/DELETE against production base URLs.
  • Use hostnames or ${ENV_VAR} in base_url, not hardcoded IPs.
  • Confirm base URL reachable before the full suite.

Gate: config parsed, base URL reachable, at least one endpoint defined.

Phase 2: VALIDATE

Execute, do not reason. Run the request. Paste the exit code and output.

Test endpoints sequentially. For each:

  1. Send request with configured method and timeout.
  2. Check status code against expect_status. Mismatch -> FAIL.
  3. If expect_key set, parse JSON and check key exists. Missing/invalid -> FAIL.
  4. If max_time set and elapsed exceeds it -> SLOW.
  5. On non-localhost URLs, check security headers (HSTS, CSP, X-Content-Type-Options, X-Frame-Options). Missing -> WARN (not FAIL). Skip HSTS on HTTP-only base URLs. Skip X-Frame-Options if CSP has frame-ancestors.
Show full SKILL.md (110 more words)Show less

Failure handling: connection refused -> FAIL "Connection refused"; timeout -> FAIL "Timeout after Ns"; invalid JSON on expect_key -> FAIL "Invalid JSON response".

Gate: all endpoints tested, each has PASS/FAIL/SLOW verdict.

Phase 3: REPORT

Format:

ENDPOINT VALIDATION REPORT
==========================
Base URL: http://localhost:8000
  /api/health                    200 OK      45ms
  /api/products                  500 FAIL   "Internal Server Error"
  /api/slow                      200 SLOW   3.2s > 2.0s threshold

SUMMARY: Passed 13/15 (86.7%), Failed 1, Slow 1

Exit 0 if all passed. Exit 1 if any failed.

Error Handling

ErrorCauseFix
Base URL unreachableWrong port or service downss -tlnp to confirm port
All endpoints timeoutWrong host or proxy issuecurl -v a single endpoint
JSON parse failure on expect_keyNon-JSON response (HTML/XML)Remove expect_key or check Content-Type
FAIL on intentional 404Default expect_status is 200Set "expect_status": 404
401 on auth endpointMissing/expired credentialsAdd auth header; see references/auth-endpoint-patterns.md

CI Integration

bash
# Pre-deployment gate with curl
jq -r '.endpoints[].path' endpoints.json | while read path; do
  curl -sf "http://localhost:8000$path" > /dev/null || { echo "FAIL: $path"; exit 1; }
done

© notque, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/infrastructure/endpoint-validator of notque/vexjoy-agent.

  • SKILL.md
  • references/auth-endpoint-patterns.md
  • references/endpoint-config-preferred-patterns.md
  • references/security-headers.md

Open the folder on GitHubat commit 5218674

Compare with similar skills

Endpoint Validator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Endpoint Validator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Endpoint Validator this skillnotque/vexjoy-agent435—~1.1kAutomated safety check: NotesMIT
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Paperclippaperclipai/paperclip98k—~9.6kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works15817 repos~4kAutomated safety check: PassAGPL-3.0
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT

Similar skills

  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Paperclip

    paperclipai/paperclip

    Interact with the Paperclip control plane API for task coordination and governance.

    98k GitHub stars~9.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 17 repos~4k tokens
    Backend & APIsAuto-check passed
  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Covers the RuView `wifi-densepose` command line binary, its Axum REST API and the WebAssembly builds for browsers and ESP32, for embedding or scripting RuView.

    97k GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check: notes

More from notque/vexjoy-agent

All 61 skills in this repo
  • Game Asset Generator

    notque/vexjoy-agent

    Deterministic palette/matrix pixel art (not AI). An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2.3k tokensUpdated 4 days ago
    Auto-check: notes
  • PR Workflow

    notque/vexjoy-agent

    Pull request lifecycle: commit, codex review, sync, review, fix, status, cleanup, and PR mining.

    435 GitHub stars~2.8k tokensUpdated 4 days ago
    Auto-check: notes
  • Architecture Deepening

    notque/vexjoy-agent

    Improve architecture across modules by deepening interfaces.

    435 GitHub stars~3.3k tokensUpdated 4 days ago
    Auto-check: notes
  • Code Quality

    notque/vexjoy-agent

    Code quality: cleanup, linting, formatting, quality gates. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~1.5k tokensUpdated 4 days ago
    Auto-check: notes
  • Codebase Analyzer

    notque/vexjoy-agent

    Statistical rule discovery from Go codebase patterns. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check: notes
  • Comment Quality

    notque/vexjoy-agent

    Review and fix temporal references in code comments. An agent skill from notque/vexjoy-agent.

    435 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check: notes

Categories

Questions about Endpoint Validator

What does Endpoint Validator do?

Deterministic API endpoint validation with pass/fail reporting. Endpoint Validator is an agent skill from notque/vexjoy-agent. Deterministic API endpoint validation with pass/fail reporting.

When should I use Endpoint Validator?

Endpoint Validator fits situations like: tasks that involve REST APIs.

How do I install Endpoint Validator in Claude Code?

Run `npx skills add notque/vexjoy-agent --skill endpoint-validator -a claude-code`. Or copy the skill folder (skills/infrastructure/endpoint-validator in notque/vexjoy-agent) into .claude/skills/endpoint-validator in your project. Claude Code loads it when a task matches its description.

How do I install Endpoint Validator in Codex?

Run `npx skills add notque/vexjoy-agent --skill endpoint-validator -a codex`. Or copy the skill folder (skills/infrastructure/endpoint-validator in notque/vexjoy-agent) into .agents/skills/endpoint-validator in your project. Codex loads it when a task matches its description.

Can I use Endpoint Validator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add notque/vexjoy-agent --skill endpoint-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/endpoint-validator, .gemini/skills/endpoint-validator, .github/skills/endpoint-validator and .opencode/skills/endpoint-validator in your project.

What does Endpoint Validator need to run?

Going by SKILL.md and its folder, Endpoint Validator needs the command-line tools its instructions call (curl and jq). Its frontmatter pre-approves these tools: Bash, Read, Write, Glob, Edit.

Does Endpoint Validator access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Endpoint Validator safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Endpoint Validator use?

Endpoint Validator is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Endpoint Validator use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.2k tokens, read only when the agent opens those files.

What are the alternatives to Endpoint Validator?

Skills that share tags, products or a category with Endpoint Validator: API Designer (Jeffallan/claude-skills, 12k stars), Paperclip (paperclipai/paperclip, 98k stars), Nodejs Backend Patterns (ever-works/ever-works, 158 stars) and OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Endpoint Validator?

notque (a GitHub user) maintains it in notque/vexjoy-agent, which has 435 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 3, 2026.

Source: notque/vexjoy-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.