Agent skill

Corgispec QA API

by ricoyudog in ricoyudog/Coding_Corgi_flow

API walkthrough — endpoint verification with auth pyramid, CRUD coverage, request/response validation, and edge case probing.

MITAuto-check passedTesting & QA

Install Corgispec QA API

skills CLI
$ npx skills add ricoyudog/Coding_Corgi_flow --skill corgispec-qa-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ricoyudog/Coding_Corgi_flow corgispec-qa-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ricoyudog/Coding_Corgi_flow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/atoms/corgispec-qa-api .claude/skills/corgispec-qa-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
corgispec-qa-api
GitHub stars
104
Token cost
~2.6k tokens
SKILL.md length
745 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

API walkthrough — endpoint verification with auth pyramid, CRUD coverage, request/response validation, and edge case probing.

  • Works in 8 steps: Identify endpoints under test → Auth pyramid testing → CRUD coverage per role → …
  • Testing & QA work in your project
  • SKILL.md covers Overview, When to Use, Preconditions and Steps, plus 1 more section
  • Calls curl and python3; needs USER_TOKEN and ADMIN_TOKEN

What it does

Corgispec QA API is an agent skill from ricoyudog/Coding_Corgi_flow. API walkthrough — endpoint verification with auth pyramid, CRUD coverage, request/response validation, and edge case probing.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `skill.meta.json`). Compatibility notes: Requires a running API server or accessible endpoint URL. Works with any HTTP API (REST, GraphQL over HTTP).

It sits in Testing & QA. The repository describes itself as: OpenSpec GitFlow — structured AI engineering workflows with issue tracking. The licence is MIT.

When your agent uses it

  • Testing & QA work in your project

Example prompts

  • “/corgispec-qa-api”

Requirements

  • Python 3
  • A credential in USER_TOKEN
  • A credential in ADMIN_TOKEN
  • Compatibility (from SKILL.md): Requires a running API server or accessible endpoint URL. Works with any HTTP API (REST, GraphQL over HTTP).

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Identify endpoints under test
  2. Auth pyramid testing
  3. CRUD coverage per role
  4. Status code coverage
  5. Response vs spec validation
  6. Boundary and edge case probing
  7. Read qa-testcases.md (if exists)
  8. Generate walkthrough report

What it can do on your machine

Read from SKILL.md and the folder at commit 461555c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • USER_TOKEN
    • ADMIN_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a running API server or accessible endpoint URL. Works with any HTTP API (REST, GraphQL over HTTP).

    From compatibility in the SKILL.md frontmatter.

Context cost

Corgispec QA API loads about 2.6k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 745 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ricoyudog/Coding_Corgi_flow at commit 461555c, republished under its MIT licence (© ricoyudog). 745 words, ~2,620 tokens.

Download SKILL.mdSave it as .claude/skills/corgispec-qa-api/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
corgispec-qa-api
description
API walkthrough — endpoint verification with auth pyramid, CRUD coverage, request/response validation, and edge case probing.
compatibility
Requires a running API server or accessible endpoint URL. Works with any HTTP API (REST, GraphQL over HTTP).
license
MIT
metadata.author
corgispec
metadata.version
1.0
metadata.generatedBy
1.0.0

API endpoint walkthrough with systematic coverage.

Overview

This skill provides a structured approach to manually verifying API endpoints using real HTTP calls (curl/httpie or language-native HTTP clients). It covers:

  • Auth pyramid — escalating from no auth through authenticated, insufficient-permission, and admin roles
  • CRUD coverage — Create, Read, Update, Delete per role
  • Status code coverage — 2xx success, 4xx client errors, 5xx server errors
  • Response vs spec validation — comparing actual responses to documented spec
  • Boundary/edge case probing — empty bodies, large payloads, special characters, malformed input

When to Use

  • After implementing or modifying API endpoints, before marking a Task Group complete
  • During the verify phase to confirm endpoints match their spec
  • When investigating reported API issues with structured reproduction
  • As part of a QA checklist before review

Do not use this skill for unit testing, load testing, or UI testing.

Preconditions

  • API server is running and accessible (local or remote URL known)
  • Endpoint spec exists (in specs/ or documented in design.md/proposal.md)
  • Auth credentials available for each role level (if auth is required)
  • qa-testcases.md exists in the change directory (optional — will be created if missing)

Steps

1. Identify endpoints under test

Read the relevant spec or tasks.md to enumerate all endpoints that need verification:

Endpoint List:
- METHOD /path — purpose
- METHOD /path — purpose

For each endpoint, you will execute the full walkthrough below.

2. Auth pyramid testing

Test each endpoint through four authentication levels in order:

LevelDescriptionExpected Behavior
No authNo token/cookie/key sent401 Unauthorized (or 403)
AuthenticatedValid token, standard roleAccess per role permissions
InsufficientValid token, wrong role/scope403 Forbidden
AdminValid token, admin/superuser roleFull access

For each level, record the request and response:

bash
# Level 1: No auth
curl -s -w "\n%{http_code}" -X GET https://api.example.com/resource

# Level 2: Authenticated (standard user)
curl -s -w "\n%{http_code}" -X GET https://api.example.com/resource \
  -H "Authorization: Bearer $USER_TOKEN"

# Level 3: Insufficient permissions
curl -s -w "\n%{http_code}" -X DELETE https://api.example.com/resource/1 \
  -H "Authorization: Bearer $USER_TOKEN"

# Level 4: Admin
curl -s -w "\n%{http_code}" -X DELETE https://api.example.com/resource/1 \
  -H "Authorization: Bearer $ADMIN_TOKEN"

Record actual status code and body snippet for each level.

3. CRUD coverage per role

For each role that should have access, execute the full CRUD cycle:

OperationMethodPath PatternKey Checks
CreatePOST/resource201 + Location header + body matches input
Read (list)GET/resource200 + array + pagination headers
Read (single)GET/resource/:id200 + correct entity returned
Update (full)PUT/resource/:id200 + all fields updated
Update (partial)PATCH/resource/:id200 + only specified fields changed
DeleteDELETE/resource/:id204 or 200 + subsequent GET returns 404
bash
# Create
curl -s -w "\n%{http_code}" -X POST https://api.example.com/resource \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "test-item", "value": 42}'

# Read back
curl -s -w "\n%{http_code}" -X GET https://api.example.com/resource/$ID \
  -H "Authorization: Bearer $TOKEN"

# Update
curl -s -w "\n%{http_code}" -X PATCH https://api.example.com/resource/$ID \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"value": 99}'

# Delete
curl -s -w "\n%{http_code}" -X DELETE https://api.example.com/resource/$ID \
  -H "Authorization: Bearer $TOKEN"

# Confirm deletion
curl -s -w "\n%{http_code}" -X GET https://api.example.com/resource/$ID \
  -H "Authorization: Bearer $TOKEN"
4. Status code coverage

Ensure the endpoint produces the expected codes across scenarios:

CategoryCodes to CoverHow to Trigger
2xx200, 201, 204Normal CRUD operations
4xx400, 401, 403, 404, 409, 422Bad input, no auth, wrong role, missing resource, conflict, validation failure
5xx500 (if reproducible)Malformed internal state, forced error paths

For each expected error code, craft a request that should trigger it:

bash
# 400 Bad Request — malformed JSON
curl -s -w "\n%{http_code}" -X POST https://api.example.com/resource \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{invalid json'

# 404 Not Found — nonexistent ID
curl -s -w "\n%{http_code}" -X GET https://api.example.com/resource/nonexistent-id \
  -H "Authorization: Bearer $TOKEN"

# 409 Conflict — duplicate creation
curl -s -w "\n%{http_code}" -X POST https://api.example.com/resource \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "already-exists"}'

# 422 Validation — missing required field
curl -s -w "\n%{http_code}" -X POST https://api.example.com/resource \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"value": 42}'
Show full SKILL.md (328 more words)Show less
5. Response vs spec validation

For each endpoint, compare the actual response structure against the spec:

  1. Read the spec (from specs/<capability>/spec.md)
  2. Execute a successful request
  3. Compare:
    • All documented fields are present
    • Field types match (string, number, array, object)
    • Enum values are within documented range
    • Nested objects match documented structure
    • No undocumented fields leak (unless spec allows extension)

Record mismatches in the report as MISMATCH: field X expected type Y, got Z.

6. Boundary and edge case probing

Test these boundary conditions for each endpoint that accepts input:

CaseInputExpected
Empty body{} or no body400 or 422 with clear error message
Large payloadBody > 1MB (or server limit)413 Payload Too Large or graceful rejection
Special characters{"name": "<script>alert(1)</script>"}Stored safely or rejected; never reflected raw
Unicode{"name": "Te\\u00DFt \\u00FC\\u00F1\\u00EF\\u00E7\\u00F6d\\u00E9"}Accepted and stored correctly
Numeric overflow{"count": 99999999999999999}Handled without crash
Null fields{"name": null}Rejected or handled per spec
Extra fields{"name": "x", "unknown": true}Ignored or rejected per API contract
SQL/NoSQL injection{"name": "'; DROP TABLE--"}No error, stored as literal string
Path traversalID = ../../etc/passwd400 or 404, no file access
bash
# Empty body
curl -s -w "\n%{http_code}" -X POST https://api.example.com/resource \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

# Large payload (~2MB)
curl -s -w "\n%{http_code}" -X POST https://api.example.com/resource \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d "{\"name\": \"$(python3 -c "print('A'*2000000)")\"}"

# Special characters
curl -s -w "\n%{http_code}" -X POST https://api.example.com/resource \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "<script>alert(1)</script>"}'
7. Read qa-testcases.md (if exists)

If a qa-testcases.md file exists in the change directory (openspec/changes/<change-name>/qa-testcases.md), read it for additional test scenarios specific to this change.

The file format expected:

markdown
# QA Test Cases: <change-name>

## Endpoint: METHOD /path

### Happy Path
- [ ] Description of test — expected result

### Error Cases
- [ ] Description of test — expected result

### Edge Cases
- [ ] Description of test — expected result

Execute every unchecked item. Mark items as [x] when they pass, or annotate with [FAIL] and the actual result.

8. Generate walkthrough report

Produce a structured report summarizing all findings:

markdown
# API Walkthrough Report

**Date**: <today>
**Change**: <change-name>
**Server**: <base URL>
**Endpoints tested**: N

## Summary

| Endpoint | Auth | CRUD | Status Codes | Spec Match | Edge Cases | Result |
|----------|------|------|--------------|------------|------------|--------|
| GET /resource | PASS | PASS | PASS | PASS | PASS | OK |
| POST /resource | PASS | PASS | PASS | FAIL | PASS | ISSUES |

## Issues Found

### Issue 1: <endpoint> — <summary>
- **Severity**: critical | high | medium | low
- **Request**: <curl command>
- **Expected**: <what spec says>
- **Actual**: <what happened>
- **Evidence**: <response body snippet>

## Coverage Matrix

| Test Category | Executed | Passed | Failed | Skipped |
|---------------|----------|--------|--------|---------|
| Auth pyramid | N | N | N | N |
| CRUD ops | N | N | N | N |
| Status codes | N | N | N | N |
| Spec validation | N | N | N | N |
| Boundary tests | N | N | N | N |
| qa-testcases.md | N | N | N | N |

## Verdict

**PASS** — All endpoints conform to spec, auth is enforced, edge cases handled.
or
**FAIL** — N issues found. See Issues Found above.

Common Mistakes

  • Running tests against a stale/stopped server (verify connectivity first)
  • Skipping the "no auth" test (assumes auth is enforced — verify it)
  • Not recording the actual response body (makes debugging impossible later)
  • Testing only happy paths (the auth pyramid and edge cases catch real bugs)
  • Forgetting to compare response structure against spec (drift accumulates silently)
  • Using hardcoded IDs that no longer exist (create fresh test data in step 3)
  • Not cleaning up test data after the walkthrough (leaves garbage in the database)

© ricoyudog, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/atoms/corgispec-qa-api of ricoyudog/Coding_Corgi_flow.

  • SKILL.md
  • skill.meta.json

Open the folder on GitHubat commit 461555c

Compare with similar skills

Corgispec QA API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Corgispec QA API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Corgispec QA API this skillricoyudog/Coding_Corgi_flow104—~2.6kAutomated safety check: PassMIT
Web Application Testinganthropics/skills180k51 repos~966Automated safety check: PassApache-2.0
Diagnosing Bugsfossasia/eventyay-interpretation1.6k32 repos~2.1kAutomated safety check: PassApache-2.0
TDDpietheinstrengholt/rssmonster56430 repos~906Automated safety check: PassMIT
TDD WorkflowhellangleZ/burn-in-cceverywhere-ralph11211 repos~2.4kAutomated safety check: PassNone
TDDsanity-io/sanity6.4k20 repos~1kAutomated safety check: PassMIT

Similar skills

  • Web Application Testing

    anthropics/skills

    Official

    Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.

    180k GitHub starsUsed in 51 repos~966 tokens
    Testing & QAAuto-check passed
  • Diagnosing Bugs

    fossasia/eventyay-interpretation

    Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 32 repos~2.1k tokens
    Testing & QAAuto-check passed
  • TDD

    pietheinstrengholt/rssmonster

    Test-driven development. An agent skill from pietheinstrengholt/rssmonster.

    564 GitHub starsUsed in 30 repos~906 tokens
    Testing & QAAuto-check passed
  • TDD Workflow

    hellangleZ/burn-in-cceverywhere-ralph

    A skill your agent uses when writing new features, fixing bugs, or refactoring code.

    112 GitHub starsUsed in 11 repos~2.4k tokens
    Testing & QAAuto-check passed
  • TDD

    sanity-io/sanity

    Official

    Test-driven development with red-green-refactor loop. An agent skill from sanity-io/sanity.

    6.4k GitHub starsUsed in 20 repos~1k tokens
    Testing & QAAuto-check passed
  • Context Driven Development

    Ibrahim-3d/orchestrator-supaconductor

    A skill your agent uses when working with Conductor's context-driven development methodology, managing project context artifacts, or understanding the relationship between product.md, tech-stack.md…

    380 GitHub starsUsed in 9 repos~2.9k tokens
    Testing & QAAuto-check passed

More from ricoyudog/Coding_Corgi_flow

All 18 skills in this repo
  • Corgispec Propose

    ricoyudog/Coding_Corgi_flow

    Create or complete one RFC-first CorgiSpec planning package from an accepted unbound RFC Slice or a closed maintenance exemption.

    104 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Update

    ricoyudog/Coding_Corgi_flow

    Reconcile an existing CorgiSpec planning package after intent, requirements, scenarios, design, or task sequencing changes.

    104 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Ask

    ricoyudog/Coding_Corgi_flow

    Answer pending Obsidian questions from CorgiSpec Memory/Wiki with early-stop retrieval, source citations, and a strict file budget.

    104 GitHub stars~689 tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Install

    ricoyudog/Coding_Corgi_flow

    A skill your agent uses when installing, updating, or verifying this repo's project-local Corgi GitFlow assets in a target project.

    104 GitHub stars~4.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Lint

    ricoyudog/Coding_Corgi_flow

    Validate CorgiSpec v4 Memory/Wiki structure, freshness, source integrity, delivery extraction, bridge drift, and legacy preservation.

    104 GitHub stars~987 tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Rfc

    ricoyudog/Coding_Corgi_flow

    Guide a human-authored CorgiSpec RFC through isolated draft creation, validation, explicit interactive approval, merge effectiveness, collision renumbering, and amendments.

    104 GitHub stars~777 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Corgispec QA API

What does Corgispec QA API do?

API walkthrough — endpoint verification with auth pyramid, CRUD coverage, request/response validation, and edge case probing. Corgispec QA API is an agent skill from ricoyudog/Coding_Corgi_flow. API walkthrough — endpoint verification with auth pyramid, CRUD coverage, request/response validation, and edge case probing.

When should I use Corgispec QA API?

Corgispec QA API fits situations like: testing & QA work in your project.

How do I install Corgispec QA API in Claude Code?

Run `npx skills add ricoyudog/Coding_Corgi_flow --skill corgispec-qa-api -a claude-code`. Or copy the skill folder (.claude/skills/atoms/corgispec-qa-api in ricoyudog/Coding_Corgi_flow) into .claude/skills/corgispec-qa-api in your project. Claude Code loads it when a task matches its description.

How do I install Corgispec QA API in Codex?

Run `npx skills add ricoyudog/Coding_Corgi_flow --skill corgispec-qa-api -a codex`. Or copy the skill folder (.claude/skills/atoms/corgispec-qa-api in ricoyudog/Coding_Corgi_flow) into .agents/skills/corgispec-qa-api in your project. Codex loads it when a task matches its description.

Can I use Corgispec QA API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ricoyudog/Coding_Corgi_flow --skill corgispec-qa-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/corgispec-qa-api, .gemini/skills/corgispec-qa-api, .github/skills/corgispec-qa-api and .opencode/skills/corgispec-qa-api in your project.

What does Corgispec QA API need to run?

Going by SKILL.md and its folder, Corgispec QA API needs the command-line tools its instructions call (curl and python3) and credentials named USER_TOKEN and ADMIN_TOKEN. Our summary lists: Python 3; A credential in USER_TOKEN; A credential in ADMIN_TOKEN. Compatibility (from SKILL.md): Requires a running API server or accessible endpoint URL. Works with any HTTP API (REST, GraphQL over HTTP)..

Does Corgispec QA API access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Corgispec QA API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Corgispec QA API use?

Corgispec QA API is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Corgispec QA API use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Corgispec QA API?

Skills that share tags, products or a category with Corgispec QA API: Web Application Testing (anthropics/skills, 180k stars), Diagnosing Bugs (fossasia/eventyay-interpretation, 1.6k stars), TDD (pietheinstrengholt/rssmonster, 564 stars) and TDD Workflow (hellangleZ/burn-in-cceverywhere-ralph, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Corgispec QA API?

ricoyudog (a GitHub user) maintains it in ricoyudog/Coding_Corgi_flow, which has 104 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on August 19, 2026.

Source: ricoyudog/Coding_Corgi_flow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.