Amazon Elasticache
aws/agent-toolkit-for-aws
Activate when developers have latent caching needs: slow API responses, database read bottlenecks, DynamoDB throttling or cost, RDS/Aurora scaling pressure, Bedrock latency or cost, or adding a…
Create or modify ryOS backend API routes under api/ using the shared apiHandler wrapper, request-auth, Redis, rate limiting, and CORS conventions.
$ npx skills add ryokun6/ryos --skill write-api-route -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ryokun6/ryos write-api-route --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ryokun6/ryos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/write-api-route .claude/skills/write-api-route && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "write-api-route" agent skill from https://github.com/ryokun6/ryos/tree/main/.cursor/skills/write-api-route into .claude/skills/write-api-route/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-api-route", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ryokun6/ryos/tree/main/.cursor/skills/write-api-routeType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ryokun6/ryos --skill write-api-route -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ryokun6/ryos write-api-route --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryokun6/ryos.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.cursor/skills/write-api-route .agents/skills/write-api-route && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "write-api-route" agent skill from https://github.com/ryokun6/ryos/tree/main/.cursor/skills/write-api-route into .agents/skills/write-api-route/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-api-route", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ryokun6/ryos --skill write-api-route -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ryokun6/ryos write-api-route --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryokun6/ryos.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.cursor/skills/write-api-route .cursor/skills/write-api-route && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "write-api-route" agent skill from https://github.com/ryokun6/ryos/tree/main/.cursor/skills/write-api-route into .cursor/skills/write-api-route/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-api-route", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ryokun6/ryos.git --path .cursor/skills/write-api-route--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ryokun6/ryos --skill write-api-route -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ryokun6/ryos write-api-route --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryokun6/ryos.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.cursor/skills/write-api-route .gemini/skills/write-api-route && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "write-api-route" agent skill from https://github.com/ryokun6/ryos/tree/main/.cursor/skills/write-api-route into .gemini/skills/write-api-route/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-api-route", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ryokun6/ryos write-api-routeInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ryokun6/ryos --skill write-api-route -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ryokun6/ryos.git skills-src && mkdir -p .github/skills && cp -r skills-src/.cursor/skills/write-api-route .github/skills/write-api-route && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "write-api-route" agent skill from https://github.com/ryokun6/ryos/tree/main/.cursor/skills/write-api-route into .github/skills/write-api-route/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-api-route", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ryokun6/ryos --skill write-api-route -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ryokun6/ryos write-api-route --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ryokun6/ryos.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.cursor/skills/write-api-route .opencode/skills/write-api-route && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "write-api-route" agent skill from https://github.com/ryokun6/ryos/tree/main/.cursor/skills/write-api-route into .opencode/skills/write-api-route/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "write-api-route", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
write-api-routeCreate or modify ryOS backend API routes under api/ using the shared apiHandler wrapper, request-auth, Redis, rate limiting, and CORS conventions.
Write API Route is an agent skill from ryokun6/ryos. Create or modify ryOS backend API routes under api/ using the shared apiHandler wrapper, request-auth, Redis, rate limiting, and CORS conventions. Use when adding an endpoint, writing a serverless/Bun API handler, wiring auth or rate limits, or working with anything under the api/ directory.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Rate limiting and Serverless. It works with Redis. The repository describes itself as: ryOS, made with Cursor. The licence is AGPL-3.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4a6e61e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Write API Route loads about 2.1k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 492 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ryokun6/ryos at commit 4a6e61e, republished under its AGPL-3.0 licence (© ryokun6). 492 words, ~2,057 tokens.
.claude/skills/write-api-route/SKILL.md (or your agent's skills folder).ryOS API routes are Node-style handlers under api/, served by the standalone Bun server (scripts/api-standalone-server.ts). The canonical reference is docs/8.10-api-design-guide.md — read it for the full contract. This skill is the practical checklist.
- [ ] 1. Pick the path: api/<feature>/index.ts (collection) or api/<feature>/[id].ts (item)
- [ ] 2. Wrap the handler in apiHandler({ methods, auth, ... })
- [ ] 3. Validate input (Zod via bodySchema, or _utils/_validation.ts helpers)
- [ ] 4. Rate-limit public / expensive routes (_utils/_rate-limit.ts)
- [ ] 5. Use shared constants/keys (_utils/constants.ts, REDIS_PREFIXES)
- [ ] 6. Return explicit JSON; errors as { error: "..." }
- [ ] 7. Add structured logs (logger.info / branch decisions)
- [ ] 8. Write/extend an integration test in tests/ (requires `bun run dev:api`)
- [ ] 9. Update the matching docs/8.*.md if the contract changedapi/
├── _utils/ # globally shared helpers (api-handler, redis, request-auth, ...)
├── <feature>/
│ ├── index.ts # collection route (GET list / POST create)
│ ├── [id].ts # item route (path param :id)
│ ├── [id]/messages.ts # nested dynamic routes
│ └── _helpers/ # feature-private helpers (_constants.ts, _types.ts, ...)_utils/ = global utilities; feature _helpers/ = domain-specific internals._*.ts / _helpers/ are private modules (not routes).index.ts for collections, [id].ts and nested folders for path params..js extension (e.g. from "../_utils/api-handler.js") — required for Node-style ESM resolution even though the source is .ts.apiHandlerPrefer apiHandler for all new JSON endpoints. It centralizes CORS/preflight, origin allowlisting, method checks, Redis injection, auth resolution, body parsing/validation, analytics, and a 500 fallback.
import { apiHandler } from "../_utils/api-handler.js";
import { z } from "zod";
const bodySchema = z.object({
name: z.string().min(1).max(100),
});
export default apiHandler(
{
methods: ["POST"],
auth: "required", // "none" | "optional" | "required" | "admin"
parseJsonBody: true, // implied when bodySchema is set
bodySchema, // 400 { error: "validation_error", issues } on failure
// allowExpiredAuth: false,
// contentType: "application/json", // pass null to disable the default header
// analytics: true,
},
async ({ req, res, redis, logger, startTime, origin, user, body }) => {
// `user` is the authenticated user (never null when auth: "required"/"admin")
// `body` is the parsed + validated payload (typed from bodySchema)
logger.info("creating thing", { username: user!.username });
// ...business logic against redis...
logger.response(201, Date.now() - startTime);
res.status(201).json({ success: true });
}
);apiHandler passes { req, res, redis, logger, startTime, origin, user, body }:
redis — client from createRedis() (Upstash REST or standard Redis backend).logger — request-scoped logger; request() is already called for you.user — null unless authenticated; guaranteed non-null for auth: "required"/"admin".body — null unless parseJsonBody/bodySchema; typed when bodySchema is set.Auth is unified through _utils/request-auth.ts (resolveRequestAuth). Set auth on apiHandler:
"none" — public."optional" — anonymous allowed, but credentials are validated if present."required" — needs both Authorization: Bearer <token> and X-Username: <username>. Partial creds → 400; bad pair → 401."admin" — required auth AND username === "ryo", else 403.For non-apiHandler routes (e.g. multipart uploads), call resolveRequestAuth() directly to keep behavior aligned.
Apply to public and expensive routes using _utils/_rate-limit.ts:
import * as RateLimit from "../_utils/_rate-limit.js";
import { getClientIp } from "../_utils/_rate-limit.js";
const ip = getClientIp(req);
const key = RateLimit.makeKey(["rl", "feature", "burst", "ip", ip]);
const result = await RateLimit.checkCounterLimit({ key, windowSeconds: 60, limit: 30 });
if (!result.allowed) {
res.setHeader("Retry-After", String(result.resetSeconds));
return res.status(429).json({
error: "rate_limit_exceeded",
limit: result.limit,
retryAfter: result.resetSeconds,
});
}getClientIp respects TRUSTED_PROXY_COUNT when the API sits behind a reverse proxy. Prefer tiers from RATE_LIMIT_TIERS in _utils/constants.ts over magic numbers.
{ success: true }, { data: ... }).400/401/403/404/405/429 with JSON { error: "..." } (extra fields ok if additive).500 { error: "..." } — apiHandler provides this automatically for thrown errors._utils/_sse.ts; set stream headers and emit structured events (start, line, complete, error).| Module | Use |
|---|---|
_utils/_validation.ts | username/room/message validation, profanity filter, HTML escaping |
_utils/_ssrf.ts | validatePublicUrl(), safeFetchWithRedirects() for untrusted URLs |
_utils/_sse.ts | SSE streaming helpers |
_utils/redis.ts | createRedis() client factory |
_utils/storage.ts | S3-compatible object storage adapter |
_utils/constants.ts | REDIS_PREFIXES, TTL, RATE_LIMIT_TIERS, PASSWORD, VALIDATION, TOKEN |
_utils/_logging.ts | initLogger() (only needed for manual handlers) |
Always key Redis entries with REDIS_PREFIXES + shared TTL rather than hardcoding strings.
apiHandler doesn't fit)Some endpoints (e.g. multipart /api/audio-transcribe) keep explicit handlers. Mirror the shared behavior manually:
import { getEffectiveOrigin, isAllowedOrigin, setCorsHeaders } from "../_utils/_cors.js";
import { initLogger } from "../_utils/_logging.js";
import { resolveRequestAuth } from "../_utils/request-auth.js";
const origin = getEffectiveOrigin(req);
setCorsHeaders(res, origin, { methods: ["POST", "OPTIONS"] });
if (req.method === "OPTIONS") return res.status(204).end();
if (!isAllowedOrigin(origin)) return res.status(403).json({ error: "Unauthorized" });
// method checks → initLogger() + timing logs → resolveRequestAuth() for auth routesAPI integration tests require the standalone server running:
# Terminal 1
bun run dev:api # exports TRUSTED_PROXY_COUNT=1 for spoofed-IP rate-limit tests
# Terminal 2
bun run test:api # or: bun test tests/integration/api/test-<feature>.test.tsUse helpers from tests/helpers/test-utils.ts: fetchWithOrigin, fetchWithAuth, ensureUserAuth, makeRateLimitBypassHeaders (random IP to dodge rate limits). Place new API suites under tests/integration/api/ and append them to API_TEST_FILES in scripts/test-groups.ts, then run bun run test:registration. For pure schema/validation logic, a no-server unit test under tests/unit/ (see the write-tests skill) is often enough.
apiHandler; keep auth semantics via request-auth.bodySchema is preferred).docs/8.*.md whenever a request/response contract changes.© ryokun6, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .cursor/skills/write-api-route of ryokun6/ryos.
Open the folder on GitHubat commit 4a6e61e
Write API Route next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Write API Route this skillryokun6/ryos | 1.3k | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Amazon Elasticacheaws/agent-toolkit-for-aws | 2.8k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| Upstash Ratelimitsickn33/agentic-awesome-skills | 47k | 1 repos | ~1.7k | Automated safety check: Pass | MIT | |
| Upstash Redisgithub/awesome-copilot | 40k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Upstash Ratelimit TSupstash/ratelimit-js | 2k | 1 repos | ~313 | Automated safety check: Pass | MIT | |
| Apikerhodgef/apiker | 127 | — | ~1.4k | Automated safety check: Pass | MIT |
aws/agent-toolkit-for-aws
Activate when developers have latent caching needs: slow API responses, database read bottlenecks, DynamoDB throttling or cost, RDS/Aurora scaling pressure, Bedrock latency or cost, or adding a…
sickn33/agentic-awesome-skills
Add rate limiting to API routes, middleware, and edge functions with @upstash/ratelimit: sliding window, fixed window, and token bucket backed by Upstash Redis.
github/awesome-copilot
Use Redis over HTTP from serverless and edge runtimes with @upstash/redis, and add rate limiting with @upstash/ratelimit.
upstash/ratelimit-js
Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.
hodgef/apiker
Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.
neondatabase/agent-skills
Long-running, serverless Node.js HTTP functions deployed onto your Neon branch, with DATABASEURL injected automatically and compute that runs next to your data.
ryokun6/ryos
Add or modify an AI chat tool ("Ask Ryo" capability) in ryOS.
ryokun6/ryos
Create new applications for ryOS following established patterns and conventions.
ryokun6/ryos
Create or modify ryOS Zustand stores following repo conventions — persist middleware, partialize, versioned migrations, the debounced write-behind storage adapter for large slices, and cloud-sync…
ryokun6/ryos
Cut and publish ryOS Electron desktop releases on GitHub. An agent skill from ryokun6/ryos.
ryokun6/ryos
Localize ryOS apps and components by extracting hardcoded strings, replacing with translation keys, and syncing across languages.
ryokun6/ryos
React performance optimization guidelines from Vercel Engineering (vercel-labs/agent-skills).
Works with
Categories
Create or modify ryOS backend API routes under api/ using the shared apiHandler wrapper, request-auth, Redis, rate limiting, and CORS conventions. Write API Route is an agent skill from ryokun6/ryos. Create or modify ryOS backend API routes under api/ using the shared apiHandler wrapper, request-auth, Redis, rate limiting, and CORS conventions.
Write API Route fits situations like: adding an endpoint; writing a serverless/Bun API handler; working with anything under the api/ directory.
Run `npx skills add ryokun6/ryos --skill write-api-route -a claude-code`. Or copy the skill folder (.cursor/skills/write-api-route in ryokun6/ryos) into .claude/skills/write-api-route in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ryokun6/ryos --skill write-api-route -a codex`. Or copy the skill folder (.cursor/skills/write-api-route in ryokun6/ryos) into .agents/skills/write-api-route in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ryokun6/ryos --skill write-api-route -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/write-api-route, .gemini/skills/write-api-route, .github/skills/write-api-route and .opencode/skills/write-api-route in your project.
Going by SKILL.md and its folder, Write API Route needs the command-line tools its instructions call (bun).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Write API Route is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Write API Route: Amazon Elasticache (aws/agent-toolkit-for-aws, 2.8k stars), Upstash Ratelimit (sickn33/agentic-awesome-skills, 47k stars), Upstash Redis (github/awesome-copilot, 40k stars) and Upstash Ratelimit TS (upstash/ratelimit-js, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ryokun6 (a GitHub user) maintains it in ryokun6/ryos, which has 1,264 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on October 7, 2026.
Source: ryokun6/ryos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.