Agent skill

API Contract Review

by TencentCloudBase in TencentCloudBase/CloudBase-AI-Toolkit

A skill your agent uses when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes…

MITAuto-check passedBackend & APIs

Install API Contract Review

skills CLI
$ npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill api-contract-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TencentCloudBase/CloudBase-AI-Toolkit api-contract-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TencentCloudBase/CloudBase-AI-Toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-contract-review .claude/skills/api-contract-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-contract-review
GitHub stars
1.1k
Token cost
~1.5k tokens
SKILL.md length
817 words
Files
2 (incl. references)
Skills in repo
49
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes…

  • Works in 4 steps: Scope and evidence → Documentation-first verification → Repository cross-check → …
  • Auditing CloudBase cloud API wrappers
  • SKILL.md covers When to use this skill, Workflow, Routing and Evaluation prompts, plus 1 more section
  • Reaches cloud.tencent.com and docs.cloudbase.net

What it does

API Contract Review is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Use when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes, or missing contract tests, especially during periodic quality review or before preparing corrective PRs.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/review-checklist.md`).

It sits in Backend & APIs, covering API design, Third-party API integration and Integration testing. The repository describes itself as: Backend for AI coding agents on CloudBase — database, auth, functions via Plugin, Skills & MCP. The licence is MIT.

When your agent uses it

  • Auditing CloudBase cloud API wrappers
  • Generated action metadata
  • Related docs for outdated
  • Incorrect action names

Example prompts

  • “/api-contract-review”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Scope and evidence
  2. Documentation-first verification
  3. Repository cross-check
  4. Escalation and follow-through

What it can do on your machine

Read from SKILL.md and the folder at commit ea2c202. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cloud.tencent.com
    • docs.cloudbase.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Contract Review loads about 1.5k tokens when it runs, and up to ~2k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 817 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TencentCloudBase/CloudBase-AI-Toolkit at commit ea2c202, republished under its MIT licence (© TencentCloudBase). 817 words, ~1,539 tokens.

Download SKILL.mdSave it as .claude/skills/api-contract-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
api-contract-review
description
Use when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes, or missing contract tests, especially during periodic quality review or before preparing corrective PRs.
alwaysApply
false

API Contract Review

Review CloudBase cloud API integrations for contract correctness before the repository ships stale, guessed, or undocumented behavior.

When to use this skill

Use this skill when you need to:

  • Review CloudBase cloud API wrappers or MCP tools for outdated or incorrect action or interface names
  • Check whether request parameters, casing, nesting, or request shape drifted away from documentation
  • Audit whether a CloudBase API change is backed by the right contract tests
  • Run a periodic API correctness review before opening corrective PRs
  • Separate confirmed contract bugs from vague "maybe this API changed" speculation

Do NOT use for:

  • General code smell review without a contract-correctness question
  • Regular SDK usage that does not touch CloudBase control-plane or documented API contracts
  • Guessing undocumented behavior from naming intuition
  • Shipping a fix when the documentation still does not support the proposed action or parameter shape

Workflow

Phase 1 — Scope and evidence
  1. Read references/review-checklist.md first.
  2. Identify the review surface:
    • mcp/src/tools/*
    • related tests
    • generated action metadata
    • user-facing docs that describe the same API behavior
  3. Record the exact action, interface, or payload being reviewed before forming conclusions.
Phase 2 — Documentation-first verification

Before judging any implementation, you must read the relevant official documentation first.

Required entry points:

  • CloudBase API overview: https://cloud.tencent.com/document/product/876/34809
  • Dependency-resource API docs when relevant: https://cloud.tencent.com/document/product/876/34808
  • CloudBase Manager SDK docs before approving direct Cloud API usage: https://docs.cloudbase.net/api-reference/manager/node/introduction

Verify the documented contract, not your memory:

  • exact action or interface name
  • required and optional parameters
  • parameter casing and nesting
  • request shape
  • auth model and caller context
  • response shape, task model, and documented limits

If the docs do not clearly support the action, parameter, or behavior, treat the implementation as unverified and stop short of guessing.

Internal parameters

Some parameters are internal to Tencent Cloud and not publicly documented. These parameters are valid but will not appear in the official API documentation.

Known internal parameters:

  • EnvTypes in DescribeEnvs — filters environments by type (e.g., ["weda", "baas"]). This parameter is not in the public documentation but is accepted by the backend.

When you encounter a parameter that:

  1. Does not appear in official documentation
  2. But is confirmed by the team as valid internal behavior

Mark it as an internal parameter in your review report, not as a contract bug.

Internal parameters

Some parameters are internal to Tencent Cloud and not publicly documented. These parameters are valid but will not appear in the official API documentation.

Known internal parameters:

  • EnvTypes in DescribeEnvs — filters environments by type (e.g., ["weda", "baas"]). This parameter is not in the public documentation but is accepted by the backend.

When you encounter a parameter that:

  1. Does not appear in official documentation
  2. But is confirmed by the team as valid internal behavior

Mark it as an internal parameter in your review report, not as a contract bug.

Show full SKILL.md (353 more words)Show less
Phase 3 — Repository cross-check
  1. Compare implementation, tests, generated metadata, and user-facing docs against the documented contract.
  2. Mark each mismatch as one of:
    • outdated action or interface name
    • wrong parameter mapping
    • wrong parameter casing or nesting
    • undocumented request shape
    • missing contract test
    • stale public documentation
  3. Prefer nearby targeted tests over broad assumptions.
Phase 4 — Escalation and follow-through
  1. If the contract bug is confirmed and the fix is low-risk, prepare the code, test, and doc updates needed for a focused PR.
  2. Any change to a CloudBase cloud API wrapper or call is incomplete without tests that would fail on the previous wrong contract.
  3. If the issue is serious but still ambiguous, write a report and open an issue instead of shipping a guessed fix.
  4. Route broad code hygiene findings to codebase-audit. Route open-PR repair work to pr-review-fix after the contract finding is confirmed.

Routing

TaskRead
Review CloudBase API contract correctnessreferences/review-checklist.md
Run a broad code audit after contract reviewcodebase-audit
Repair an already-open PR after confirming the contract fixpr-review-fix

Evaluation prompts

Should-trigger
  1. Audit mcp/src/tools for CloudBase API actions whose parameter casing or nesting no longer matches the official docs.
  2. Review this MCP tool and tell me whether it guessed a CloudBase action name instead of proving it from documentation.
  3. Help me prepare a corrective PR for a documented CloudBase API mismatch and make sure the tests would fail on the old payload.
Should-not-trigger
  1. Review this React component for accessibility issues.
  2. Help me polish the README introduction copy.
  3. Fix an open PR that only has lint failures and no API contract question.

Minimum self-check

  • Did I read the relevant official docs before judging the code?
  • Can I point to the exact documented action or interface name?
  • Did I verify parameter casing, nesting, and request shape instead of inferring them?
  • Did I identify the nearest tests that should prove the contract?
  • If I recommend a fix, did I require targeted tests and a focused PR path?
  • If the docs were still unclear, did I stop at report or issue instead of guessing?

© TencentCloudBase, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/api-contract-review of TencentCloudBase/CloudBase-AI-Toolkit.

  • SKILL.md
  • references/review-checklist.md

Open the folder on GitHubat commit ea2c202

Compare with similar skills

API Contract Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Contract Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Contract Review this skillTencentCloudBase/CloudBase-AI-Toolkit1.1k—~1.5kAutomated safety check: PassMIT
Eval IntegrationIbrahim-3d/orchestrator-supaconductor380—~1.8kAutomated safety check: PassAGPL-3.0
Build MCP Serveranthropics/claude-plugins-official37k1 repos~3kAutomated safety check: PassApache-2.0
API Designs-morgan-jeffries/apple-mail-fast-mcp104—~876Automated safety check: PassMIT
Contract Testingproffesor-for-testing/agentic-qe494—~1.8kAutomated safety check: PassMIT
MCP API Key AuthenticationYourdaylight/stock_datasource188—~1.2kAutomated safety check: PassMIT

Similar skills

  • Eval Integration

    Ibrahim-3d/orchestrator-supaconductor

    Specialized integration evaluator for the Evaluate-Loop. An agent skill from Ibrahim-3d/orchestrator-supaconductor.

    380 GitHub stars~1.8k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Build MCP Server

    anthropics/claude-plugins-official

    Official

    Entry point for building an MCP server: asks about the use case, picks a deployment model and tool-design pattern, then hands off to more specialized skills.

    37k GitHub starsUsed in 1 repo~3k tokens
    Agent WorkflowsAuto-check passed
  • API Design

    s-morgan-jeffries/apple-mail-fast-mcp

    Use BEFORE adding any new tool, parameter, or endpoint to the Apple Mail MCP server.

    104 GitHub stars~876 tokensUpdated 28 days ago
    Backend & APIsAuto-check passed
  • Contract Testing

    proffesor-for-testing/agentic-qe

    Consumer-driven contract testing for microservices using Pact, schema validation, API versioning, and backward compatibility testing.

    494 GitHub stars~1.8k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • MCP API Key Authentication

    Yourdaylight/stock_datasource

    Sets up and troubleshoots MCP API key authentication for a stock data service, covering key creation, client configuration and per-tool usage statistics.

    188 GitHub stars~1.2k tokensUpdated 29 days ago
    Backend & APIsAuto-check passed
  • Contract First

    qshanx/docs-governance

    分前端/后端(或多个服务)多端开发的项目,用 CONTRACT.md 指向的唯一机器契约,各端只照它各做各的,防止字段漂移导致集成时白屏。支持单会话多 agent 和多终端各自跑两种模式。只要项目有前后端/多服务、接口字段老对不上、各端联调卡住、某端改了字段忘了通知别人、或前端为渲染一个页面要调一堆接口拼数据,就用这个…

    130 GitHub stars~1.2k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed

More from TencentCloudBase/CloudBase-AI-Toolkit

All 49 skills in this repo
  • AI Model Nodejs

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.

    1.1k GitHub starsUsed in 3 repos~5k tokens
    Auto-check passed
  • HTTP API Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    CloudBase official HTTP API client guide. An agent skill from TencentCloudBase/CloudBase-AI-Toolkit.

    1.1k GitHub starsUsed in 3 repos~2.1k tokens
    Auto-check passed
  • Cloud API Recipe Authoring

    TencentCloudBase/CloudBase-AI-Toolkit

    Author or revise a cloud-api-operations recipe (config/source/skills/cloud-api-operations/references/recipes/).

    1.1k GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Manage Local Skills

    TencentCloudBase/CloudBase-AI-Toolkit

    Analyze, standardize, validate, and sync locally maintained skills into agent skill directories with a skills CLI-aligned workflow.

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Cloudbase Agent Python

    TencentCloudBase/CloudBase-AI-Toolkit

    Build production-ready AI agent backends using the CloudBase Agent Python SDK — create agents with LangGraph/CrewAI/LlamaIndex, serve them via FastAPI with AG-UI protocol streaming +…

    1.1k GitHub starsUsed in 2 repos~2.9k tokens
    Auto-check: notes
  • Cloudbase

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses when you develop, design, build, deploy, debug, migrate, or troubleshoot CloudBase (腾讯云开发, 云开发, TCB, 微信云开发) projects — Web, 微信小程序, 小程序, uni-app, mobile (iOS, Android…

    1.1k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed

Categories

Questions about API Contract Review

What does API Contract Review do?

A skill your agent uses when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes…. API Contract Review is an agent skill from TencentCloudBase/CloudBase-AI-Toolkit. Use when auditing CloudBase cloud API wrappers, MCP tools, generated action metadata, or related docs for outdated or incorrect action names, parameters, casing, request shapes, or missing contract tests, especially during periodic quality review or before preparing corrective PRs.

When should I use API Contract Review?

API Contract Review fits situations like: auditing CloudBase cloud API wrappers; generated action metadata; related docs for outdated; incorrect action names.

How do I install API Contract Review in Claude Code?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill api-contract-review -a claude-code`. Or copy the skill folder (skills/api-contract-review in TencentCloudBase/CloudBase-AI-Toolkit) into .claude/skills/api-contract-review in your project. Claude Code loads it when a task matches its description.

How do I install API Contract Review in Codex?

Run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill api-contract-review -a codex`. Or copy the skill folder (skills/api-contract-review in TencentCloudBase/CloudBase-AI-Toolkit) into .agents/skills/api-contract-review in your project. Codex loads it when a task matches its description.

Can I use API Contract Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TencentCloudBase/CloudBase-AI-Toolkit --skill api-contract-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-contract-review, .gemini/skills/api-contract-review, .github/skills/api-contract-review and .opencode/skills/api-contract-review in your project.

What does API Contract Review need to run?

SKILL.md names no scripts, command-line tools or credentials: API Contract Review is instructions for the agent only.

Does API Contract Review access the network?

SKILL.md names 2 domains. In commands or code: cloud.tencent.com and docs.cloudbase.net; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is API Contract Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Contract Review use?

API Contract Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Contract Review use?

About 1.5k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 434 tokens, read only when the agent opens those files.

What are the alternatives to API Contract Review?

Skills that share tags, products or a category with API Contract Review: Eval Integration (Ibrahim-3d/orchestrator-supaconductor, 380 stars), Build MCP Server (anthropics/claude-plugins-official, 37k stars), API Design (s-morgan-jeffries/apple-mail-fast-mcp, 104 stars) and Contract Testing (proffesor-for-testing/agentic-qe, 494 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Contract Review?

TencentCloudBase (a GitHub organization) maintains it in TencentCloudBase/CloudBase-AI-Toolkit, which has 1,132 GitHub stars. The repository holds 49 skills in this directory. The repository was last updated on October 6, 2026.

Source: TencentCloudBase/CloudBase-AI-Toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.