Agent skill

API Tester

by RightNow-AI in RightNow-AI/openfang

API testing expert for curl, REST, GraphQL, authentication, and debugging

Apache-2.0Auto-check passedBackend & APIs

Install API Tester

skills CLI
$ npx skills add RightNow-AI/openfang --skill api-tester -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RightNow-AI/openfang api-tester --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RightNow-AI/openfang.git skills-src && mkdir -p .claude/skills && cp -r skills-src/crates/openfang-skills/bundled/api-tester .claude/skills/api-tester && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-tester
GitHub stars
18k
Token cost
~807 tokens
SKILL.md length
416 words
Files
1
Skills in repo
68
Repo updated
First seen
Licence
Apache-2.0

At a glance

API testing expert for curl, REST, GraphQL, authentication, and debugging

  • Works in 6 steps: Authentication: Verify that… → Input validation: Send missing required… → Pagination: Test first page, last page,… → …
  • Tasks that involve API testing
  • SKILL.md covers Key Principles, curl Essentials, Testing Methodology and GraphQL Testing, plus 2 more sections
  • Calls curl and jq

What it does

API Tester is an agent skill from RightNow-AI/openfang. API testing expert for curl, REST, GraphQL, authentication, and debugging

Its SKILL.md is about 810 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering API testing, GraphQL and Debugging. It works with GraphQL. The repository describes itself as: Open-source Agent Operating System. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve API testing
  • Tasks that involve GraphQL
  • Tasks that involve Debugging

Example prompts

  • “/api-tester”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Authentication: Verify that unauthenticated requests return 401. Verify expired tokens return 401. Verify wrong roles return 403.
  2. Input validation: Send missing required fields (expect 400), invalid types, empty strings, overly long strings, special characters.
  3. Pagination: Test first page, last page, out-of-range page, zero/negative limits.
  4. Idempotency: Send the same POST/PUT request twice — verify correct behavior.
  5. Rate limiting: Send rapid requests — verify 429 responses and Retry-After headers.
  6. CORS: Check Access-Control-Allow-Origin and preflight OPTIONS responses from a browser context.

What it can do on your machine

Read from SKILL.md and the folder at commit acf2587. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Tester loads about 807 tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 416 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~807

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from RightNow-AI/openfang at commit acf2587, republished under its Apache-2.0 licence (© RightNow-AI). 416 words, ~807 tokens.

Download SKILL.mdSave it as .claude/skills/api-tester/SKILL.md (or your agent's skills folder).
name
api-tester
description
API testing expert for curl, REST, GraphQL, authentication, and debugging

API Testing Expert

You are an API testing specialist. You help users test, debug, and validate REST and GraphQL APIs using curl, httpie, Postman collections, and scripted test suites. You cover authentication, error handling, and edge cases.

Key Principles

  • Always start by reading the API documentation or OpenAPI/Swagger spec before testing.
  • Test the happy path first, then systematically test error cases, edge cases, and boundary conditions.
  • Validate response status codes, headers, body structure, and data types — not just whether the request "works."
  • Keep credentials out of command history and scripts — use environment variables.

curl Essentials

  • GET: curl -s https://api.example.com/users | jq .
  • POST with JSON: curl -s -X POST -H "Content-Type: application/json" -d '{"name":"test"}' https://api.example.com/users
  • Auth header: curl -s -H "Authorization: Bearer $TOKEN" https://api.example.com/me
  • Verbose mode: curl -v to see request/response headers and TLS handshake details.
  • Save response: curl -s -o response.json -w "%{http_code}" https://api.example.com/endpoint
  • Follow redirects: curl -L, timeout: curl --connect-timeout 5 --max-time 30.

Testing Methodology

  1. Authentication: Verify that unauthenticated requests return 401. Verify expired tokens return 401. Verify wrong roles return 403.
  2. Input validation: Send missing required fields (expect 400), invalid types, empty strings, overly long strings, special characters.
  3. Pagination: Test first page, last page, out-of-range page, zero/negative limits.
  4. Idempotency: Send the same POST/PUT request twice — verify correct behavior.
  5. Rate limiting: Send rapid requests — verify 429 responses and Retry-After headers.
  6. CORS: Check Access-Control-Allow-Origin and preflight OPTIONS responses from a browser context.
Show full SKILL.md (179 more words)Show less

GraphQL Testing

  • Use introspection queries ({ __schema { types { name } } }) to discover the schema.
  • Test query depth limits and complexity limits to verify protection against abuse.
  • Test with variables rather than inline values for parameterized queries.
  • Verify that mutations return the updated object and that subscriptions emit events correctly.

Debugging Failed Requests

  • Check the status code first: 4xx means client error, 5xx means server error.
  • Compare request headers with documentation — missing Content-Type or Accept headers are common issues.
  • Use curl -v or --trace to inspect the raw HTTP exchange.
  • Check for API versioning in the URL or headers — you may be hitting the wrong version.
  • Test the same request from a different network to rule out firewall or proxy issues.

Pitfalls to Avoid

  • Never hardcode API keys or tokens in shared scripts — use environment variables or secret managers.
  • Do not test against production APIs with destructive operations (DELETE, bulk updates) without safeguards.
  • Do not trust that a 200 response means success — always validate the response body.
  • Avoid testing only with valid data — the most important tests cover invalid and malicious input.

© RightNow-AI, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in crates/openfang-skills/bundled/api-tester of RightNow-AI/openfang.

Open the folder on GitHubat commit acf2587

Compare with similar skills

API Tester next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Tester compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Tester this skillRightNow-AI/openfang18k—~807Automated safety check: PassApache-2.0
API Testingpetrkindlmann/qa-skills165—~2.7kAutomated safety check: PassMIT
Cdrf Expertvintasoftware/django-ai-plugins151—~859Automated safety check: PassNone
QA Find Bugs MCPbex-co/beancount-io295—~3kAutomated safety check: PassMIT
API Testingcosmicstack-labs/mercury-agent-skills476—~449Automated safety check: PassMIT
Shopify Common Errorsjeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT

Similar skills

  • API Testing

    petrkindlmann/qa-skills

    Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.

    165 GitHub stars~2.7k tokensUpdated 4 mo ago
    Testing & QAAuto-check passed
  • Cdrf Expert

    vintasoftware/django-ai-plugins

    Expert guidance for Django REST Framework class-based views using Classy DRF (https://www.cdrf.co).

    151 GitHub stars~859 tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • QA Find Bugs MCP

    bex-co/beancount-io

    Hunt bugs in the Beancount.io remote MCP server by driving the real POST /api-gateway/mcp endpoint with JSON-RPC and real MCP clients, checking transport, discovery, credential boundaries, tool and…

    295 GitHub stars~3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • API Testing

    cosmicstack-labs/mercury-agent-skills

    REST and GraphQL testing, Postman/Insomnia patterns, contract testing, schema validation, and monitoring

    476 GitHub stars~449 tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Shopify Common Errors

    jeremylongshore/tons-of-skills-marketplace

    Diagnose and fix common Shopify API errors including 401, 403, 422, 429, and GraphQL errors.

    2.8k GitHub stars~1k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Testing

    fugazi/test-automation-skills-agents

    Test REST and GraphQL endpoint contracts using Playwright request fixture (TypeScript) or REST Assured (Java).

    247 GitHub stars~1.5k tokensUpdated 5 days ago
    Testing & QAAuto-check passed

More from RightNow-AI/openfang

All 68 skills in this repo
  • Reference of CSS selectors, step-by-step web workflows and error recovery tactics for an agent that browses, fills forms and compares prices on live sites.

    18k GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Reference knowledge for open-source intelligence collection: the collection cycle, source reliability tiers, search query patterns and entity extraction.

    18k GitHub stars~2.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Lead Generation Research Guide

    RightNow-AI/openfang

    Reference knowledge for AI lead generation: building an ideal customer profile, researching prospects on the web, enriching lead records and finding email formats.

    18k GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Video Clipping Reference

    RightNow-AI/openfang

    Command reference for cutting clips from online video: yt-dlp downloads, whisper transcription, SRT subtitle files and ffmpeg processing, with Windows, macOS and Linux differences.

    18k GitHub stars~4.1k tokensUpdated 3 mo ago
    Auto-check: warnings
  • Forecasting Expert Knowledge

    RightNow-AI/openfang

    Reference knowledge for AI forecasting: superforecasting principles, a signal taxonomy, confidence calibration rules and reasoning chains for making and tracking predictions.

    18k GitHub stars~2.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Deep Research Methodology

    RightNow-AI/openfang

    Reference knowledge for AI deep research: a five-phase process, strategies by question type, CRAAP source scoring, cross-referencing, synthesis and citation formats.

    18k GitHub stars~2.6k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Questions about API Tester

What does API Tester do?

API testing expert for curl, REST, GraphQL, authentication, and debugging. API Tester is an agent skill from RightNow-AI/openfang.

When should I use API Tester?

API Tester fits situations like: tasks that involve API testing; tasks that involve GraphQL; tasks that involve Debugging.

How do I install API Tester in Claude Code?

Run `npx skills add RightNow-AI/openfang --skill api-tester -a claude-code`. Or copy the skill folder (crates/openfang-skills/bundled/api-tester in RightNow-AI/openfang) into .claude/skills/api-tester in your project. Claude Code loads it when a task matches its description.

How do I install API Tester in Codex?

Run `npx skills add RightNow-AI/openfang --skill api-tester -a codex`. Or copy the skill folder (crates/openfang-skills/bundled/api-tester in RightNow-AI/openfang) into .agents/skills/api-tester in your project. Codex loads it when a task matches its description.

Can I use API Tester in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RightNow-AI/openfang --skill api-tester -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-tester, .gemini/skills/api-tester, .github/skills/api-tester and .opencode/skills/api-tester in your project.

What does API Tester need to run?

Going by SKILL.md and its folder, API Tester needs the command-line tools its instructions call (curl and jq).

Does API Tester access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is API Tester safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Tester use?

API Tester is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Tester use?

About 807 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Tester?

Skills that share tags, products or a category with API Tester: API Testing (petrkindlmann/qa-skills, 165 stars), Cdrf Expert (vintasoftware/django-ai-plugins, 151 stars), QA Find Bugs MCP (bex-co/beancount-io, 295 stars) and API Testing (cosmicstack-labs/mercury-agent-skills, 476 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Tester?

RightNow-AI (a GitHub organization) maintains it in RightNow-AI/openfang, which has 18,213 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on July 2, 2026.

Source: RightNow-AI/openfang on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.