Agent skill

Discover API

by rand in rand/cc-polymath

Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

MITAuto-check passedBackend & APIs

Install Discover API

skills CLI
$ npx skills add rand/cc-polymath --skill discover-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rand/cc-polymath discover-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rand/cc-polymath.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/discover-api .claude/skills/discover-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
discover-api
GitHub stars
181
Used in
1 other repo
Token cost
~1.5k tokens
SKILL.md length
624 words
Files
1
Skills in repo
26
Repo updated
First seen
Licence
MIT

At a glance

Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

  • Works in 3 steps: Design phase → Security phase → Production readiness
  • Tasks that involve Authentication
  • SKILL.md covers When This Skill Activates, Available Skills, Common Workflows and Skill Selection Guide, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Discover API is an agent skill from rand/cc-polymath. Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design. Activates for backend API development tasks.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Designed for Claude Code. Compatible with any agent supporting the Agent Skills format.

It sits in Backend & APIs, covering Authentication, GraphQL and REST APIs. It works with GraphQL. The repository describes itself as: Claude Code skills and workflows, optimized for context-efficiency and skill quality. Skills ranging from cloud infrastructure to design to advanced maths. The licence is MIT.

When your agent uses it

  • Tasks that involve Authentication
  • Tasks that involve GraphQL
  • Tasks that involve REST APIs

Example prompts

  • “/discover-api”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code. Compatible with any agent supporting the Agent Skills format.

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Design phase
  2. Security phase
  3. Production readiness

What it can do on your machine

Read from SKILL.md and the folder at commit baa2df1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code. Compatible with any agent supporting the Agent Skills format.

    From compatibility in the SKILL.md frontmatter.

Context cost

Discover API loads about 1.5k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 624 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rand/cc-polymath at commit baa2df1, republished under its MIT licence (© rand). 624 words, ~1,532 tokens.

Download SKILL.mdSave it as .claude/skills/discover-api/SKILL.md (or your agent's skills folder).
name
discover-api
description
Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design. Activates for backend API development tasks.
compatibility
Designed for Claude Code. Compatible with any agent supporting the Agent Skills format.
license
MIT
metadata.author
rand
metadata.version
4.0

API Skills Discovery

Provides automatic access to comprehensive API design, authentication, and implementation skills.

When This Skill Activates

This skill auto-activates when you're working with:

  • REST API design and implementation
  • GraphQL schema design
  • API authentication (JWT, OAuth 2.0, API keys, sessions)
  • API authorization (RBAC, ABAC, permissions)
  • Rate limiting and throttling
  • API versioning strategies
  • Error handling and validation
  • HTTP methods, status codes, endpoints

Available Skills

Quick Reference

The API category contains 8 specialized skills:

  1. rest-api-design - RESTful resource modeling, HTTP semantics, URL conventions
  2. graphql-schema-design - GraphQL types, resolvers, N+1 problem prevention
  3. api-authentication - JWT, OAuth 2.0, API keys, session management
  4. api-authorization - RBAC, ABAC, policy engines, permission systems
  5. api-rate-limiting - Token bucket, sliding window, rate limiting algorithms
  6. api-versioning - API versioning, deprecation, backward compatibility
  7. api-error-handling - RFC 7807 errors, validation, standardized responses
  8. api-design-rules - 35 opinionated rules for API design
Load Full Category Details

For complete descriptions and workflows:

Read ../api/INDEX.md

This loads the full API category index with:

  • Detailed skill descriptions
  • Usage triggers for each skill
  • Common workflow combinations
  • Cross-references to related skills
Load Specific Skills

Load individual skills as needed:

Core API design

Read ../api/rest-api-design.md Read ../api/graphql-schema-design.md

Security and access control

Read ../api/api-authentication.md Read ../api/api-authorization.md

Production hardening

Read ../api/api-rate-limiting.md Read ../api/api-error-handling.md Read ../api/api-versioning.md

Rules and best practices

Read ../api/api-design-rules.md

Common Workflows

New REST API

Sequence: REST design → Authentication → Authorization

Read ../api/rest-api-design.md # Resource modeling, HTTP methods Read ../api/api-authentication.md # User authentication Read ../api/api-authorization.md # Access control

New GraphQL API

Sequence: GraphQL schema → Authentication → Authorization

Read ../api/graphql-schema-design.md # Schema design, resolvers Read ../api/api-authentication.md # User authentication Read ../api/api-authorization.md # Field-level permissions

API Hardening

Sequence: Rate limiting → Error handling → Versioning

Read ../api/api-rate-limiting.md # Prevent abuse Read ../api/api-error-handling.md # Standardized errors Read ../api/api-versioning.md # Manage evolution

Complete API Stack

Full implementation from scratch:

1. Design phase

Read ../api/rest-api-design.md

2. Security phase

Read ../api/api-authentication.md Read ../api/api-authorization.md Read ../api/api-rate-limiting.md

3. Production readiness

Read ../api/api-error-handling.md Read ../api/api-versioning.md

Skill Selection Guide

Choose REST API skills when:

  • Building traditional web services
  • Need simple CRUD operations
  • Working with mobile apps or SPAs
  • Require caching and HTTP semantics

Choose GraphQL skills when:

  • Clients need flexible data fetching
  • Reducing over-fetching or under-fetching
  • Building aggregation layers
  • Need strong typing for APIs

Authentication vs Authorization:

  • Authentication (api-authentication.md): Who are you? (Login, JWT, OAuth)
  • Authorization (api-authorization.md): What can you do? (Permissions, RBAC)

Production considerations:

  • Always implement rate limiting for public APIs
  • Use versioning from day one
  • Standardize error responses early
Show full SKILL.md (236 more words)Show less

Integration with Other Skills

API skills commonly combine with:

Database skills (discover-database):

  • API endpoints → Database queries
  • Connection pooling for API servers
  • Query optimization for API performance

Testing skills (discover-testing):

  • Integration tests for API endpoints
  • Contract testing for API consumers
  • Load testing for API performance

Frontend skills (discover-frontend):

  • API client libraries
  • Data fetching patterns
  • Error handling in UI

Infrastructure skills (discover-infra, discover-cloud):

  • API deployment strategies
  • Load balancing and scaling
  • API gateways and proxies

Usage Instructions

  1. Auto-activation: This skill loads automatically when Claude Code detects API-related work
  2. Browse skills: Run Read ../api/INDEX.md for full category overview
  3. Load specific skills: Use bash commands above to load individual skills
  4. Follow workflows: Use recommended sequences for common API patterns
  5. Combine skills: Load multiple skills for comprehensive coverage

Progressive Loading

This gateway skill (~200 lines, ~2K tokens) enables progressive loading:

  • Level 1: Gateway loads automatically (you're here now)
  • Level 2: Load category INDEX.md (~3K tokens) for full overview
  • Level 3: Load specific skills (~2-3K tokens each) as needed

Total context: 2K + 3K + skill(s) = 5-10K tokens vs 25K+ for entire index.

Quick Start Examples

"Design a REST API for a blog": Read ../api/rest-api-design.md

"Add OAuth authentication to my API": Read ../api/api-authentication.md

"Implement role-based access control": Read ../api/api-authorization.md

"Prevent API abuse": Read ../api/api-rate-limiting.md

"Design an API versioning strategy": Read ../api/api-versioning.md

Next Steps: Run Read ../api/INDEX.md to see full category details, or load specific skills using the bash commands above.

© rand, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/discover-api of rand/cc-polymath.

Open the folder on GitHubat commit baa2df1

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in rand/cc-polymath, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Discover API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Discover API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Discover API this skillrand/cc-polymath1811 repos~1.5kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills412—~2.8kAutomated safety check: NotesMIT
API Designeraiskillstore/marketplace4301 repos~3.6kAutomated safety check: PassNone
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT
Domain Webfjrevoredo/mini-diarium3081 repos~1kAutomated safety check: PassMIT
API Connector Builderericrisco/rsc-harness156—~3.6kAutomated safety check: PassMIT

Similar skills

  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    412 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • API Designer

    aiskillstore/marketplace

    Design and document RESTful and GraphQL APIs with OpenAPI/Swagger specifications, authentication patterns, versioning strategies, and best practices.

    430 GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Domain Web

    fjrevoredo/mini-diarium

    A skill your agent uses when building web services. An agent skill from fjrevoredo/mini-diarium.

    308 GitHub starsUsed in 1 repo~1k tokens
    Backend & APIsAuto-check passed
  • API Connector Builder

    ericrisco/rsc-harness

    A skill your agent uses when writing a client for someone else's REST or GraphQL API: auth flow choice and token refresh, pagination to exhaustion, retry-with-jitter on transient failures only…

    156 GitHub stars~3.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Architect

    curiositech/some_claude_skills

    Expert API designer for REST, GraphQL, gRPC architectures. An agent skill from curiositech/some_claude_skills.

    243 GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check passed

More from rand/cc-polymath

All 26 skills in this repo
  • Anti Slop

    rand/cc-polymath

    Comprehensive toolkit for detecting and eliminating "AI slop" - generic, low-quality AI-generated patterns in natural language, code, and design.

    181 GitHub stars~2.9k tokensUpdated 7 mo ago
    Auto-check passed
  • Typed Holes Refactor

    rand/cc-polymath

    Refactor codebases using Design by Typed Holes methodology - iterative, test-driven refactoring with formal hole resolution, constraint propagation, and continuous validation.

    181 GitHub stars~5.6k tokensUpdated 7 mo ago
    Auto-check passed
  • Discover Agentic

    rand/cc-polymath

    Automatically discover agentic workflow skills when building AI agents, implementing tool use patterns, managing context windows, decomposing complex tasks, or designing multi-step autonomous…

    181 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Elegant Design

    rand/cc-polymath

    Create world-class, accessible, responsive interfaces with sophisticated interactive elements including chat, terminals, code display, and streaming content.

    181 GitHub stars~2.7k tokensUpdated 7 mo ago
    Auto-check passed
  • Discover Database

    rand/cc-polymath

    Automatically discover database skills when working with SQL, PostgreSQL, MongoDB, Redis, database schema design, query optimization, migrations, connection pooling, ORMs, or database selection.

    181 GitHub stars~2k tokensUpdated 7 mo ago
    Auto-check passed
  • Discover Frontend

    rand/cc-polymath

    Automatically discover frontend development skills when working with React, Next.js, UI components, state management, data fetching, forms, accessibility, performance optimization, or SEO.

    181 GitHub stars~2.4k tokensUpdated 7 mo ago
    Auto-check passed

Works with

Categories

Questions about Discover API

What does Discover API do?

Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design. Discover API is an agent skill from rand/cc-polymath. Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

When should I use Discover API?

Discover API fits situations like: tasks that involve Authentication; tasks that involve GraphQL; tasks that involve REST APIs.

How do I install Discover API in Claude Code?

Run `npx skills add rand/cc-polymath --skill discover-api -a claude-code`. Or copy the skill folder (skills/discover-api in rand/cc-polymath) into .claude/skills/discover-api in your project. Claude Code loads it when a task matches its description.

How do I install Discover API in Codex?

Run `npx skills add rand/cc-polymath --skill discover-api -a codex`. Or copy the skill folder (skills/discover-api in rand/cc-polymath) into .agents/skills/discover-api in your project. Codex loads it when a task matches its description.

Can I use Discover API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rand/cc-polymath --skill discover-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/discover-api, .gemini/skills/discover-api, .github/skills/discover-api and .opencode/skills/discover-api in your project.

What does Discover API need to run?

SKILL.md names no scripts, command-line tools or credentials: Discover API is instructions for the agent only. Compatibility (from SKILL.md): Designed for Claude Code. Compatible with any agent supporting the Agent Skills format..

Does Discover API access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Discover API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Discover API use?

Discover API is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Discover API use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Discover API?

Skills that share tags, products or a category with Discover API: API Audit (briiirussell/cybersecurity-skills, 412 stars), API Designer (aiskillstore/marketplace, 430 stars), API Designer (Jeffallan/claude-skills, 12k stars) and Domain Web (fjrevoredo/mini-diarium, 308 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Discover API?

rand (a GitHub user) maintains it in rand/cc-polymath, which has 181 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on February 28, 2026.

Source: rand/cc-polymath on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.