API Audit
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
$ npx skills add rand/cc-polymath --skill discover-api -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rand/cc-polymath discover-api --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rand/cc-polymath.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/discover-api .claude/skills/discover-api && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "discover-api" agent skill from https://github.com/rand/cc-polymath/tree/main/skills/discover-api into .claude/skills/discover-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "discover-api", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rand/cc-polymath/tree/main/skills/discover-apiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rand/cc-polymath --skill discover-api -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rand/cc-polymath discover-api --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rand/cc-polymath.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/discover-api .agents/skills/discover-api && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "discover-api" agent skill from https://github.com/rand/cc-polymath/tree/main/skills/discover-api into .agents/skills/discover-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "discover-api", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rand/cc-polymath --skill discover-api -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rand/cc-polymath discover-api --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rand/cc-polymath.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/discover-api .cursor/skills/discover-api && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "discover-api" agent skill from https://github.com/rand/cc-polymath/tree/main/skills/discover-api into .cursor/skills/discover-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "discover-api", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rand/cc-polymath.git --path skills/discover-api--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rand/cc-polymath --skill discover-api -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rand/cc-polymath discover-api --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rand/cc-polymath.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/discover-api .gemini/skills/discover-api && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "discover-api" agent skill from https://github.com/rand/cc-polymath/tree/main/skills/discover-api into .gemini/skills/discover-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "discover-api", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rand/cc-polymath discover-apiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rand/cc-polymath --skill discover-api -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rand/cc-polymath.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/discover-api .github/skills/discover-api && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "discover-api" agent skill from https://github.com/rand/cc-polymath/tree/main/skills/discover-api into .github/skills/discover-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "discover-api", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rand/cc-polymath --skill discover-api -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rand/cc-polymath discover-api --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rand/cc-polymath.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/discover-api .opencode/skills/discover-api && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "discover-api" agent skill from https://github.com/rand/cc-polymath/tree/main/skills/discover-api into .opencode/skills/discover-api/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "discover-api", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
discover-apiAutomatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
Discover API is an agent skill from rand/cc-polymath. Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design. Activates for backend API development tasks.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code. Compatible with any agent supporting the Agent Skills format.
It sits in Backend & APIs, covering Authentication, GraphQL and REST APIs. It works with GraphQL. The repository describes itself as: Claude Code skills and workflows, optimized for context-efficiency and skill quality. Skills ranging from cloud infrastructure to design to advanced maths. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit baa2df1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Designed for Claude Code. Compatible with any agent supporting the Agent Skills format.
From compatibility in the SKILL.md frontmatter.
Discover API loads about 1.5k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 624 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rand/cc-polymath at commit baa2df1, republished under its MIT licence (© rand). 624 words, ~1,532 tokens.
.claude/skills/discover-api/SKILL.md (or your agent's skills folder).Provides automatic access to comprehensive API design, authentication, and implementation skills.
This skill auto-activates when you're working with:
The API category contains 8 specialized skills:
For complete descriptions and workflows:
Read ../api/INDEX.md
This loads the full API category index with:
Load individual skills as needed:
Read ../api/rest-api-design.md Read ../api/graphql-schema-design.md
Read ../api/api-authentication.md Read ../api/api-authorization.md
Read ../api/api-rate-limiting.md Read ../api/api-error-handling.md Read ../api/api-versioning.md
Read ../api/api-design-rules.md
Sequence: REST design → Authentication → Authorization
Read ../api/rest-api-design.md # Resource modeling, HTTP methods Read ../api/api-authentication.md # User authentication Read ../api/api-authorization.md # Access control
Sequence: GraphQL schema → Authentication → Authorization
Read ../api/graphql-schema-design.md # Schema design, resolvers Read ../api/api-authentication.md # User authentication Read ../api/api-authorization.md # Field-level permissions
Sequence: Rate limiting → Error handling → Versioning
Read ../api/api-rate-limiting.md # Prevent abuse Read ../api/api-error-handling.md # Standardized errors Read ../api/api-versioning.md # Manage evolution
Full implementation from scratch:
Read ../api/rest-api-design.md
Read ../api/api-authentication.md Read ../api/api-authorization.md Read ../api/api-rate-limiting.md
Read ../api/api-error-handling.md Read ../api/api-versioning.md
Choose REST API skills when:
Choose GraphQL skills when:
Authentication vs Authorization:
Production considerations:
API skills commonly combine with:
Database skills (discover-database):
Testing skills (discover-testing):
Frontend skills (discover-frontend):
Infrastructure skills (discover-infra, discover-cloud):
Read ../api/INDEX.md for full category overviewThis gateway skill (~200 lines, ~2K tokens) enables progressive loading:
Total context: 2K + 3K + skill(s) = 5-10K tokens vs 25K+ for entire index.
"Design a REST API for a blog": Read ../api/rest-api-design.md
"Add OAuth authentication to my API": Read ../api/api-authentication.md
"Implement role-based access control": Read ../api/api-authorization.md
"Prevent API abuse": Read ../api/api-rate-limiting.md
"Design an API versioning strategy": Read ../api/api-versioning.md
Next Steps: Run Read ../api/INDEX.md to see full category details, or load specific skills using the bash commands above.
© rand, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/discover-api of rand/cc-polymath.
Open the folder on GitHubat commit baa2df1
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in rand/cc-polymath, which our catalogue first saw on October 7, 2026.
Discover API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Discover API this skillrand/cc-polymath | 181 | 1 repos | ~1.5k | Automated safety check: Pass | MIT | |
| API Auditbriiirussell/cybersecurity-skills | 412 | — | ~2.8k | Automated safety check: Notes | MIT | |
| API Designeraiskillstore/marketplace | 430 | 1 repos | ~3.6k | Automated safety check: Pass | None | |
| API DesignerJeffallan/claude-skills | 12k | 2 repos | ~2k | Automated safety check: Pass | MIT | |
| Domain Webfjrevoredo/mini-diarium | 308 | 1 repos | ~1k | Automated safety check: Pass | MIT | |
| API Connector Builderericrisco/rsc-harness | 156 | — | ~3.6k | Automated safety check: Pass | MIT |
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
aiskillstore/marketplace
Design and document RESTful and GraphQL APIs with OpenAPI/Swagger specifications, authentication patterns, versioning strategies, and best practices.
Jeffallan/claude-skills
Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.
fjrevoredo/mini-diarium
A skill your agent uses when building web services. An agent skill from fjrevoredo/mini-diarium.
ericrisco/rsc-harness
A skill your agent uses when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only…
curiositech/some_claude_skills
Expert API designer for REST, GraphQL, gRPC architectures. An agent skill from curiositech/some_claude_skills.
rand/cc-polymath
Comprehensive toolkit for detecting and eliminating "AI slop" - generic, low-quality AI-generated patterns in natural language, code, and design.
rand/cc-polymath
Refactor codebases using Design by Typed Holes methodology - iterative, test-driven refactoring with formal hole resolution, constraint propagation, and continuous validation.
rand/cc-polymath
Automatically discover agentic workflow skills when building AI agents, implementing tool use patterns, managing context windows, decomposing complex tasks, or designing multi-step autonomous…
rand/cc-polymath
Create world-class, accessible, responsive interfaces with sophisticated interactive elements including chat, terminals, code display, and streaming content.
rand/cc-polymath
Automatically discover database skills when working with SQL, PostgreSQL, MongoDB, Redis, database schema design, query optimization, migrations, connection pooling, ORMs, or database selection.
rand/cc-polymath
Automatically discover frontend development skills when working with React, Next.js, UI components, state management, data fetching, forms, accessibility, performance optimization, or SEO.
Works with
Categories
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design. Discover API is an agent skill from rand/cc-polymath. Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.
Discover API fits situations like: tasks that involve Authentication; tasks that involve GraphQL; tasks that involve REST APIs.
Run `npx skills add rand/cc-polymath --skill discover-api -a claude-code`. Or copy the skill folder (skills/discover-api in rand/cc-polymath) into .claude/skills/discover-api in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rand/cc-polymath --skill discover-api -a codex`. Or copy the skill folder (skills/discover-api in rand/cc-polymath) into .agents/skills/discover-api in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rand/cc-polymath --skill discover-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/discover-api, .gemini/skills/discover-api, .github/skills/discover-api and .opencode/skills/discover-api in your project.
SKILL.md names no scripts, command-line tools or credentials: Discover API is instructions for the agent only. Compatibility (from SKILL.md): Designed for Claude Code. Compatible with any agent supporting the Agent Skills format..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Discover API is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Discover API: API Audit (briiirussell/cybersecurity-skills, 412 stars), API Designer (aiskillstore/marketplace, 430 stars), API Designer (Jeffallan/claude-skills, 12k stars) and Domain Web (fjrevoredo/mini-diarium, 308 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rand (a GitHub user) maintains it in rand/cc-polymath, which has 181 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on February 28, 2026.
Source: rand/cc-polymath on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.