API Testing
petrkindlmann/qa-skills
Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.
Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing.
$ npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install proffesor-for-testing/agentic-qe api-testing-patterns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .claude/skills && cp -r skills-src/assets/skills/api-testing-patterns .claude/skills/api-testing-patterns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "api-testing-patterns" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/api-testing-patterns into .claude/skills/api-testing-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-testing-patterns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/api-testing-patternsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install proffesor-for-testing/agentic-qe api-testing-patterns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .agents/skills && cp -r skills-src/assets/skills/api-testing-patterns .agents/skills/api-testing-patterns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "api-testing-patterns" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/api-testing-patterns into .agents/skills/api-testing-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-testing-patterns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install proffesor-for-testing/agentic-qe api-testing-patterns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/assets/skills/api-testing-patterns .cursor/skills/api-testing-patterns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "api-testing-patterns" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/api-testing-patterns into .cursor/skills/api-testing-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-testing-patterns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/proffesor-for-testing/agentic-qe.git --path assets/skills/api-testing-patterns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install proffesor-for-testing/agentic-qe api-testing-patterns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/assets/skills/api-testing-patterns .gemini/skills/api-testing-patterns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "api-testing-patterns" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/api-testing-patterns into .gemini/skills/api-testing-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-testing-patterns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install proffesor-for-testing/agentic-qe api-testing-patternsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .github/skills && cp -r skills-src/assets/skills/api-testing-patterns .github/skills/api-testing-patterns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "api-testing-patterns" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/api-testing-patterns into .github/skills/api-testing-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-testing-patterns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install proffesor-for-testing/agentic-qe api-testing-patterns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/proffesor-for-testing/agentic-qe.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/assets/skills/api-testing-patterns .opencode/skills/api-testing-patterns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "api-testing-patterns" agent skill from https://github.com/proffesor-for-testing/agentic-qe/tree/main/assets/skills/api-testing-patterns into .opencode/skills/api-testing-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-testing-patterns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
api-testing-patternsComprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing.
API Testing Patterns is an agent skill from proffesor-for-testing/agentic-qe. Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing. Use when testing APIs or designing API test strategies.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts (for example `config.json`, `evals/api-testing-patterns.yaml` and `schemas/output.json`).
It sits in Testing & QA, covering API testing and Integration testing. It works with GraphQL. The repository describes itself as: Agentic QE Fleet is an open-source AI-powered QA/QE platform designed for use with Coding Agents (works best with Claude Code) featuring specialized agents and skills to support… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 829d030. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
API Testing Patterns loads about 2.4k tokens when it runs. Until then it costs about 47 tokens; SKILL.md has 458 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from proffesor-for-testing/agentic-qe at commit 829d030, republished under its MIT licence (© proffesor-for-testing). 458 words, ~2,371 tokens.
.claude/skills/api-testing-patterns/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.<default_to_action> When testing APIs or designing API test strategy:
Quick Pattern Selection:
Critical Success Factors:
| Level | Purpose | Dependencies | Speed |
|---|---|---|---|
| Contract | Provider-consumer agreement | None | Fast |
| Component | API in isolation | Mocked | Fast |
| Integration | Real dependencies | Database, services | Slower |
| Scenario | Must Test | Example |
|---|---|---|
| Auth | 401/403 handling | Expired token, wrong user |
| Input | 400 validation | Missing fields, wrong types |
| Errors | 500 graceful handling | DB down, timeout |
| Idempotency | Duplicate prevention | Same idempotency key |
| Concurrency | Race conditions | Parallel checkout |
qe-api-contract-validator: Validate contracts, detect breaking changesqe-test-generator: Generate tests from OpenAPI specqe-performance-tester: Load test endpointsqe-security-scanner: API security testingPattern: Consumer-Driven Contracts
// Consumer defines expectations
const contract = {
request: { method: 'POST', path: '/orders', body: { productId: 'abc', quantity: 2 } },
response: { status: 201, body: { orderId: 'string', total: 'number' } }
};
// Provider must fulfill
test('order API meets contract', async () => {
const response = await api.post('/orders', { productId: 'abc', quantity: 2 });
expect(response.status).toBe(201);
expect(response.body).toMatchSchema({
orderId: expect.any(String),
total: expect.any(Number)
});
});When: Microservices, distributed systems, third-party integrations
describe('Auth', () => {
it('rejects without token', async () => {
expect((await api.get('/orders')).status).toBe(401);
});
it('rejects expired token', async () => {
const expired = generateExpiredToken();
expect((await api.get('/orders', { headers: { Authorization: `Bearer ${expired}` } })).status).toBe(401);
});
it('blocks cross-user access', async () => {
const userAToken = generateToken({ userId: 'A' });
expect((await api.get('/orders/user-B-order', { headers: { Authorization: `Bearer ${userAToken}` } })).status).toBe(403);
});
});describe('Validation', () => {
it('validates required fields', async () => {
const response = await api.post('/orders', { quantity: 2 }); // Missing productId
expect(response.status).toBe(400);
expect(response.body.errors).toContain('productId is required');
});
it('validates types', async () => {
expect((await api.post('/orders', { productId: 'abc', quantity: 'two' })).status).toBe(400);
});
it('validates ranges', async () => {
expect((await api.post('/orders', { productId: 'abc', quantity: -5 })).status).toBe(400);
});
});it('prevents duplicates with idempotency key', async () => {
const key = 'unique-123';
const data = { productId: 'abc', quantity: 2 };
const r1 = await api.post('/orders', data, { headers: { 'Idempotency-Key': key } });
const r2 = await api.post('/orders', data, { headers: { 'Idempotency-Key': key } });
expect(r1.body.orderId).toBe(r2.body.orderId); // Same order
});it('handles race condition on inventory', async () => {
const promises = Array(10).fill().map(() =>
api.post('/orders', { productId: 'abc', quantity: 1 })
);
const responses = await Promise.all(promises);
const successful = responses.filter(r => r.status === 201);
const inventory = await db.inventory.findById('abc');
expect(inventory.quantity).toBe(initialQuantity - successful.length);
});describe('Product CRUD', () => {
let productId;
it('CREATE', async () => {
const r = await api.post('/products', { name: 'Widget', price: 10 });
expect(r.status).toBe(201);
productId = r.body.id;
});
it('READ', async () => {
const r = await api.get(`/products/${productId}`);
expect(r.body.name).toBe('Widget');
});
it('UPDATE', async () => {
const r = await api.put(`/products/${productId}`, { price: 12 });
expect(r.body.price).toBe(12);
});
it('DELETE', async () => {
expect((await api.delete(`/products/${productId}`)).status).toBe(204);
expect((await api.get(`/products/${productId}`)).status).toBe(404);
});
});// Validate contracts
await Task("Contract Validation", {
spec: 'openapi.yaml',
endpoint: '/orders',
checkBreakingChanges: true
}, "qe-api-contract-validator");
// Generate tests from spec
await Task("Generate API Tests", {
spec: 'openapi.yaml',
coverage: 'comprehensive',
include: ['happy-paths', 'input-validation', 'auth-scenarios', 'error-handling']
}, "qe-test-generator");
// Load test
await Task("API Load Test", {
endpoint: '/orders',
rps: 1000,
duration: '5min'
}, "qe-performance-tester");
// Security scan
await Task("API Security Scan", {
spec: 'openapi.yaml',
checks: ['sql-injection', 'xss', 'broken-auth', 'rate-limiting']
}, "qe-security-scanner");aqe/api-testing/
├── contracts/* - API contract definitions
├── generated-tests/* - Generated test suites
├── validation/* - Contract validation results
└── performance/* - Load test resultsconst apiFleet = await FleetManager.coordinate({
strategy: 'contract-testing',
agents: ['qe-api-contract-validator', 'qe-test-generator', 'qe-test-executor'],
topology: 'mesh'
});
await apiFleet.execute({
services: [
{ name: 'orders-api', consumers: ['checkout-ui', 'admin-api'] },
{ name: 'payment-api', consumers: ['orders-api'] }
]
});API testing = verifying contracts and behavior, not implementation. Focus on what matters to consumers: correct responses, proper error handling, acceptable performance.
With Agents: Agents automate contract validation, generate comprehensive test suites from specs, and monitor production APIs for drift. Use agents to maintain API quality at scale.
© proffesor-for-testing, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts) in assets/skills/api-testing-patterns of proffesor-for-testing/agentic-qe.
Open the folder on GitHubat commit 829d030
API Testing Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| API Testing Patterns this skillproffesor-for-testing/agentic-qe | 494 | — | ~2.4k | Automated safety check: Pass | MIT | |
| API Testingpetrkindlmann/qa-skills | 165 | — | ~2.7k | Automated safety check: Pass | MIT | |
| API Testingcosmicstack-labs/mercury-agent-skills | 476 | — | ~449 | Automated safety check: Pass | MIT | |
| Integration Tests for pRESTprest/prest | 4.6k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Reasoning Serialization Teststailcallhq/forgecode | 7.6k | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| Syncable Entity Integration Teststwentyhq/twenty | 58k | — | ~3.4k | Automated safety check: Pass | Custom licence |
petrkindlmann/qa-skills
Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.
cosmicstack-labs/mercury-agent-skills
REST and GraphQL testing, Postman/Insomnia patterns, contract testing, schema validation, and monitoring
prest/prest
Guides writing and reviewing pREST Docker-based integration tests so every HTTP request is explained by step comments or table-driven descriptions.
tailcallhq/forgecode
Checks that ReasoningConfig fields are serialized into the right provider-specific JSON for OpenRouter, Anthropic, GitHub Copilot and Codex requests.
twentyhq/twenty
Step-by-step guide to writing the mandatory integration tests for syncable metadata entities in Twenty's server, covering failures and CRUD success cases.
fugazi/test-automation-skills-agents
Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java).
proffesor-for-testing/agentic-qe
Consumer-driven contract testing for microservices using Pact, schema validation, API versioning, and backward compatibility testing.
proffesor-for-testing/agentic-qe
Test quality validation through mutation testing, assessing test suite effectiveness by introducing code mutations and measuring kill rate.
proffesor-for-testing/agentic-qe
Profiles application performance under load using k6, Artillery, or JMeter to measure latency, throughput, and error rates.
proffesor-for-testing/agentic-qe
Conduct context-driven code reviews focusing on quality, testability, and maintainability.
proffesor-for-testing/agentic-qe
Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology.
proffesor-for-testing/agentic-qe
Database schema validation, data integrity testing, migration testing, transaction isolation, and query performance.
Works with
Categories
Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing. API Testing Patterns is an agent skill from proffesor-for-testing/agentic-qe. Comprehensive API testing patterns including contract testing, REST/GraphQL testing, and integration testing.
API Testing Patterns fits situations like: designing API test strategies; tasks that involve API testing; tasks that involve Integration testing.
Run `npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a claude-code`. Or copy the skill folder (assets/skills/api-testing-patterns in proffesor-for-testing/agentic-qe) into .claude/skills/api-testing-patterns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a codex`. Or copy the skill folder (assets/skills/api-testing-patterns in proffesor-for-testing/agentic-qe) into .agents/skills/api-testing-patterns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add proffesor-for-testing/agentic-qe --skill api-testing-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-testing-patterns, .gemini/skills/api-testing-patterns, .github/skills/api-testing-patterns and .opencode/skills/api-testing-patterns in your project.
SKILL.md names no scripts, command-line tools or credentials: API Testing Patterns is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
API Testing Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with API Testing Patterns: API Testing (petrkindlmann/qa-skills, 165 stars), API Testing (cosmicstack-labs/mercury-agent-skills, 476 stars), Integration Tests for pREST (prest/prest, 4.6k stars) and Reasoning Serialization Tests (tailcallhq/forgecode, 7.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
proffesor-for-testing (a GitHub user) maintains it in proffesor-for-testing/agentic-qe, which has 494 GitHub stars. The repository holds 95 skills in this directory. The repository was last updated on October 4, 2026.
Source: proffesor-for-testing/agentic-qe on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.