Agent skill

API Patterns

by vibeeval in vibeeval/vibecosystem

API design, versioning, testing, schema validation, and contract testing patterns for REST and GraphQL APIs.

MITAuto-check passedBackend & APIs

Install API Patterns

skills CLI
$ npx skills add vibeeval/vibecosystem --skill api-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vibeeval/vibecosystem api-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/api-patterns .claude/skills/api-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-patterns
GitHub stars
531
Token cost
~3.9k tokens
SKILL.md length
93 words
Files
1
Skills in repo
144
Repo updated
First seen
Licence
MIT

At a glance

API design, versioning, testing, schema validation, and contract testing patterns for REST and GraphQL APIs.

  • Tasks that involve Forms and validation
  • SKILL.md covers API Versioning, Schema Validation with Zod, Standardized Error Responses and Pagination Patterns, plus 8 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve GraphQL

What it does

API Patterns is an agent skill from vibeeval/vibecosystem. API design, versioning, testing, schema validation, and contract testing patterns for REST and GraphQL APIs.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Forms and validation, GraphQL and API design. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.

When your agent uses it

  • Tasks that involve Forms and validation
  • Tasks that involve GraphQL
  • Tasks that involve API design

Example prompts

  • “/api-patterns”

What it can do on your machine

Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Patterns loads about 3.9k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 93 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 93 words, ~3,888 tokens.

Download SKILL.mdSave it as .claude/skills/api-patterns/SKILL.md (or your agent's skills folder).
name
api-patterns
description
API design, versioning, testing, schema validation, and contract testing patterns for REST and GraphQL APIs.

API Patterns

REST and GraphQL API design patterns for consistent, versioned, and well-tested interfaces.

API Versioning

URL-Based Versioning
typescript
// routes/v1/markets.ts
// routes/v2/markets.ts
// URL: /api/v1/markets, /api/v2/markets

// Express router setup
import { Router } from 'express'

const v1Router = Router()
const v2Router = Router()

app.use('/api/v1', v1Router)
app.use('/api/v2', v2Router)

// Deprecation header middleware
function deprecationWarning(version: string, sunsetDate: string) {
  return (_req: Request, res: Response, next: NextFunction) => {
    res.setHeader('Deprecation', 'true')
    res.setHeader('Sunset', sunsetDate)
    res.setHeader('Link', `</api/v${parseInt(version) + 1}>; rel="successor-version"`)
    next()
  }
}

v1Router.use(deprecationWarning('1', 'Sat, 01 Jan 2027 00:00:00 GMT'))
Header-Based Versioning
typescript
// Accept: application/vnd.api+json;version=2
function versionMiddleware(req: Request, res: Response, next: NextFunction) {
  const accept = req.headers['accept'] || ''
  const match = accept.match(/version=(\d+)/)
  req.apiVersion = match ? parseInt(match[1]) : 1
  next()
}

Schema Validation with Zod

Request + Response Validation
typescript
import { z } from 'zod'

// Request schema
const CreateMarketSchema = z.object({
  name: z.string().min(1).max(200),
  description: z.string().max(2000).optional(),
  category: z.enum(['sports', 'politics', 'crypto', 'tech']),
  closeAt: z.string().datetime(),
  initialLiquidity: z.number().positive().max(1_000_000)
})

// Response schema - strip internal fields
const MarketResponseSchema = z.object({
  id: z.string().uuid(),
  name: z.string(),
  category: z.string(),
  status: z.enum(['open', 'closed', 'resolved']),
  volume: z.number(),
  createdAt: z.string().datetime()
})

type CreateMarketDto = z.infer<typeof CreateMarketSchema>
type MarketResponse = z.infer<typeof MarketResponseSchema>

// Validation middleware
function validate<T>(schema: z.ZodSchema<T>) {
  return (req: Request, res: Response, next: NextFunction) => {
    const result = schema.safeParse(req.body)
    if (!result.success) {
      return res.status(400).json({
        success: false,
        error: 'Validation failed',
        code: 'VALIDATION_ERROR',
        details: result.error.flatten()
      })
    }
    req.validated = result.data
    next()
  }
}

// Usage
router.post('/markets', validate(CreateMarketSchema), async (req, res) => {
  const dto = req.validated as CreateMarketDto
  const market = await marketService.create(dto)
  const response = MarketResponseSchema.parse(market)
  res.status(201).json({ success: true, data: response })
})

Standardized Error Responses

typescript
// Always: { success, error, code, details? }
interface ApiError {
  success: false
  error: string
  code: string
  details?: unknown
  requestId?: string
}

interface ApiSuccess<T> {
  success: true
  data: T
  meta?: { total?: number; page?: number; limit?: number }
}

const ERROR_CODES = {
  VALIDATION_ERROR: 400,
  UNAUTHORIZED: 401,
  FORBIDDEN: 403,
  NOT_FOUND: 404,
  CONFLICT: 409,
  RATE_LIMITED: 429,
  INTERNAL: 500
} as const

function apiError(
  res: Response,
  code: keyof typeof ERROR_CODES,
  message: string,
  details?: unknown
): Response {
  return res.status(ERROR_CODES[code]).json({
    success: false,
    error: message,
    code,
    details,
    requestId: res.locals.requestId
  } satisfies ApiError)
}

Pagination Patterns

typescript
interface CursorPage<T> {
  items: T[]
  nextCursor: string | null
  prevCursor: string | null
  hasMore: boolean
}

async function paginateWithCursor<T extends { id: string; createdAt: Date }>(
  query: (cursor: string | null, limit: number) => Promise<T[]>,
  cursor: string | null,
  limit = 20
): Promise<CursorPage<T>> {
  // Fetch one extra to detect hasMore
  const items = await query(cursor, limit + 1)
  const hasMore = items.length > limit
  const page = hasMore ? items.slice(0, limit) : items

  return {
    items: page,
    nextCursor: hasMore ? Buffer.from(page[page.length - 1].id).toString('base64') : null,
    prevCursor: cursor,
    hasMore
  }
}

// GET /api/markets?cursor=<base64>&limit=20
router.get('/markets', async (req, res) => {
  const cursor = req.query.cursor as string | null
  const limit = Math.min(parseInt(req.query.limit as string) || 20, 100)
  const decoded = cursor ? Buffer.from(cursor, 'base64').toString() : null

  const page = await paginateWithCursor(
    (c, l) => db.market.findMany({
      take: l,
      skip: c ? 1 : 0,
      cursor: c ? { id: c } : undefined,
      orderBy: { createdAt: 'desc' }
    }),
    decoded,
    limit
  )

  res.json({ success: true, ...page })
})
Offset Pagination (Simple use cases)
typescript
interface OffsetPage<T> {
  items: T[]
  total: number
  page: number
  limit: number
  totalPages: number
}

// GET /api/markets?page=2&limit=20

Rate Limiting

Token Bucket with Redis
typescript
import Redis from 'ioredis'

const redis = new Redis(process.env.REDIS_URL!)

async function tokenBucket(
  key: string,
  capacity: number,
  refillRate: number   // tokens per second
): Promise<{ allowed: boolean; remaining: number; resetIn: number }> {
  const now = Date.now()
  const bucketKey = `ratelimit:${key}`

  const script = `
    local key = KEYS[1]
    local capacity = tonumber(ARGV[1])
    local refill_rate = tonumber(ARGV[2])
    local now = tonumber(ARGV[3])

    local bucket = redis.call('HMGET', key, 'tokens', 'last_refill')
    local tokens = tonumber(bucket[1]) or capacity
    local last_refill = tonumber(bucket[2]) or now

    local elapsed = (now - last_refill) / 1000
    tokens = math.min(capacity, tokens + elapsed * refill_rate)

    if tokens >= 1 then
      tokens = tokens - 1
      redis.call('HMSET', key, 'tokens', tokens, 'last_refill', now)
      redis.call('EXPIRE', key, math.ceil(capacity / refill_rate) + 1)
      return {1, math.floor(tokens)}
    else
      return {0, 0}
    end
  `

  const [allowed, remaining] = await redis.eval(
    script, 1, bucketKey, capacity, refillRate, now
  ) as [number, number]

  return {
    allowed: allowed === 1,
    remaining,
    resetIn: allowed ? 0 : Math.ceil(1 / refillRate)
  }
}

function rateLimitMiddleware(capacity: number, refillRate: number) {
  return async (req: Request, res: Response, next: NextFunction) => {
    const key = req.user?.id || req.ip || 'anonymous'
    const result = await tokenBucket(key, capacity, refillRate)

    res.setHeader('X-RateLimit-Limit', capacity)
    res.setHeader('X-RateLimit-Remaining', result.remaining)

    if (!result.allowed) {
      res.setHeader('Retry-After', result.resetIn)
      return apiError(res, 'RATE_LIMITED', 'Too many requests')
    }
    next()
  }
}

API Endpoint Testing

typescript
import { describe, it, expect, beforeAll, afterAll } from 'vitest'
import supertest from 'supertest'
import { app } from '../app'
import { db } from '../db'

const request = supertest(app)

describe('POST /api/v1/markets', () => {
  let authToken: string

  beforeAll(async () => {
    authToken = await getTestToken()
  })

  it('creates a market with valid payload', async () => {
    const payload = {
      name: 'Will BTC reach 100k?',
      category: 'crypto',
      closeAt: new Date(Date.now() + 86400000).toISOString(),
      initialLiquidity: 1000
    }

    const res = await request
      .post('/api/v1/markets')
      .set('Authorization', `Bearer ${authToken}`)
      .send(payload)
      .expect(201)

    expect(res.body.success).toBe(true)
    expect(res.body.data).toMatchObject({
      id: expect.any(String),
      name: payload.name,
      status: 'open'
    })
  })

  it('rejects invalid payload with 400', async () => {
    const res = await request
      .post('/api/v1/markets')
      .set('Authorization', `Bearer ${authToken}`)
      .send({ name: '' })   // invalid
      .expect(400)

    expect(res.body.success).toBe(false)
    expect(res.body.code).toBe('VALIDATION_ERROR')
  })

  it('returns 401 without auth token', async () => {
    const res = await request.post('/api/v1/markets').send({}).expect(401)
    expect(res.body.code).toBe('UNAUTHORIZED')
  })
})

Breaking Change Detection Checklist

Before releasing a new API version, verify:

BREAKING changes (require version bump):
  [ ] Removed a field from response
  [ ] Changed field type (string → number)
  [ ] Renamed a field
  [ ] Changed HTTP method
  [ ] Removed an endpoint
  [ ] Changed required → optional (ok) vs optional → required (breaking)
  [ ] Changed error codes/format

NON-BREAKING changes (safe to ship):
  [ ] Added new optional fields to response
  [ ] Added new optional query parameters
  [ ] Added new endpoints
  [ ] Added new enum values (check client handling)
  [ ] Relaxed validation rules

OpenAPI Spec Generation

typescript
// Use zod-to-openapi or tsoa
import { extendZodWithOpenApi } from 'zod-to-openapi'
import { z } from 'zod'

extendZodWithOpenApi(z)

const MarketSchema = z.object({
  id: z.string().uuid().openapi({ example: 'abc-123' }),
  name: z.string().openapi({ example: 'Will BTC hit 100k?' }),
  status: z.enum(['open', 'closed', 'resolved'])
}).openapi('Market')

// Auto-generate spec at /api/docs.json

Plan-Based Authorization

Tier-Aware Middleware
typescript
enum PlanTier {
  FREE = 'free',
  PRO = 'pro',
  ENTERPRISE = 'enterprise'
}

interface PlanLimits {
  tier: PlanTier
  rateLimit: number          // requests per minute
  maxItems: number           // max resources
  features: Set<string>      // enabled features
}

const PLAN_LIMITS: Record<PlanTier, PlanLimits> = {
  [PlanTier.FREE]:       { tier: PlanTier.FREE, rateLimit: 60, maxItems: 100, features: new Set(['read']) },
  [PlanTier.PRO]:        { tier: PlanTier.PRO, rateLimit: 600, maxItems: 10_000, features: new Set(['read', 'write', 'export']) },
  [PlanTier.ENTERPRISE]: { tier: PlanTier.ENTERPRISE, rateLimit: 6000, maxItems: Infinity, features: new Set(['read', 'write', 'export', 'audit', 'sso']) },
}

function requireFeature(feature: string) {
  return (req: Request, res: Response, next: NextFunction) => {
    const plan = PLAN_LIMITS[req.user.planTier as PlanTier]
    if (!plan.features.has(feature)) {
      return apiError(res, 'FORBIDDEN', `Feature "${feature}" requires ${PlanTier.PRO} plan or higher`)
    }
    next()
  }
}

function requireQuota(countFn: (userId: string) => Promise<number>) {
  return async (req: Request, res: Response, next: NextFunction) => {
    const plan = PLAN_LIMITS[req.user.planTier as PlanTier]
    const current = await countFn(req.user.id)
    if (current >= plan.maxItems) {
      return apiError(res, 'FORBIDDEN', `Plan limit reached (${plan.maxItems} items). Upgrade to increase.`)
    }
    next()
  }
}

// Usage
router.post('/exports', requireFeature('export'), async (req, res) => { /* ... */ })
router.post('/projects', requireQuota(countUserProjects), async (req, res) => { /* ... */ })

Serverless Rate Limiting

Sliding Window without Redis
typescript
// In-memory sliding window — single-instance only
// WARNING: Resets on cold start (serverless). For production multi-instance,
// use Redis/Upstash. Add MAX_ENTRIES cap to prevent memory exhaustion from IP flooding.
const windows = new Map<string, number[]>()

function slidingWindowRateLimit(
  key: string,
  maxRequests: number,
  windowMs: number
): { allowed: boolean; remaining: number; retryAfter: number } {
  const now = Date.now()
  const windowStart = now - windowMs

  // Get or create timestamps array
  const timestamps = windows.get(key) ?? []
  const valid = timestamps.filter(t => t > windowStart)

  if (valid.length >= maxRequests) {
    const oldestInWindow = valid[0]
    const retryAfter = Math.ceil((oldestInWindow + windowMs - now) / 1000)
    return { allowed: false, remaining: 0, retryAfter }
  }

  valid.push(now)
  windows.set(key, valid)
  return { allowed: true, remaining: maxRequests - valid.length, retryAfter: 0 }
}

// Cleanup stale entries periodically
setInterval(() => {
  const cutoff = Date.now() - 60_000
  for (const [key, timestamps] of windows) {
    const valid = timestamps.filter(t => t > cutoff)
    if (valid.length === 0) windows.delete(key)
    else windows.set(key, valid)
  }
}, 60_000)

API Key Authentication

typescript
import { randomBytes, createHash, timingSafeEqual } from 'crypto'

// SECURITY: For in-memory secret comparison, always use timingSafeEqual
// DB lookups by hash are safe (constant-time at DB level)

// Generate: give raw key to user, store hash
function generateApiKey(prefix: string): { raw: string; hash: string } {
  const raw = `${prefix}_${randomBytes(24).toString('base64url')}`
  const hash = createHash('sha256').update(raw).digest('hex')
  return { raw, hash }
}

// Verify: hash incoming key, compare with stored hash
async function verifyApiKey(rawKey: string): Promise<ApiKeyRecord | null> {
  const hash = createHash('sha256').update(rawKey).digest('hex')
  return db.apiKey.findFirst({
    where: { hash, revokedAt: null, expiresAt: { gt: new Date() } }
  })
}

// Middleware
async function apiKeyAuth(req: Request, res: Response, next: NextFunction) {
  const key = req.headers['x-api-key'] as string
  if (!key) return apiError(res, 'UNAUTHORIZED', 'API key required')

  const record = await verifyApiKey(key)
  if (!record) return apiError(res, 'UNAUTHORIZED', 'Invalid or expired API key')

  // Scope check
  if (!record.scopes.includes(req.method.toLowerCase())) {
    return apiError(res, 'FORBIDDEN', 'API key lacks required scope')
  }

  req.user = { id: record.ownerId, keyId: record.id }
  next()
}

Usage Metering and Quota Management

typescript
interface UsageRecord {
  tenantId: string
  metric: string      // 'api_calls' | 'storage_bytes' | 'ai_tokens'
  value: number
  period: string      // '2026-03' (monthly bucket)
}

async function trackUsage(tenantId: string, metric: string, increment: number): Promise<void> {
  const period = new Date().toISOString().slice(0, 7) // YYYY-MM
  await db.usage.upsert({
    where: { tenantId_metric_period: { tenantId, metric, period } },
    update: { value: { increment } },
    create: { tenantId, metric, period, value: increment }
  })
}

async function checkQuota(tenantId: string, metric: string, limit: number): Promise<boolean> {
  const period = new Date().toISOString().slice(0, 7)
  const usage = await db.usage.findUnique({
    where: { tenantId_metric_period: { tenantId, metric, period } }
  })
  return (usage?.value ?? 0) < limit
}

// Middleware
function meteringMiddleware(metric: string, increment = 1) {
  return async (req: Request, res: Response, next: NextFunction) => {
    const plan = PLAN_LIMITS[req.user.planTier as PlanTier]
    const withinQuota = await checkQuota(req.user.tenantId, metric, plan.rateLimit * 60 * 24)
    if (!withinQuota) {
      return apiError(res, 'RATE_LIMITED', `Monthly ${metric} quota exceeded. Upgrade plan.`)
    }
    await trackUsage(req.user.tenantId, metric, increment)
    next()
  }
}

Remember: Consistent versioning and validation contracts make APIs maintainable across client teams and breaking-change deployments.

© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/api-patterns of vibeeval/vibecosystem.

Open the folder on GitHubat commit 3b763b1

Compare with similar skills

API Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Patterns this skillvibeeval/vibecosystem531—~3.9kAutomated safety check: PassMIT
Contract Testingproffesor-for-testing/agentic-qe494—~1.8kAutomated safety check: PassMIT
Qe Contract Testingproffesor-for-testing/agentic-qe494—~1.2kAutomated safety check: PassMIT
API Testingpetrkindlmann/qa-skills163—~2.7kAutomated safety check: PassMIT
API Testingcosmicstack-labs/mercury-agent-skills476—~449Automated safety check: PassMIT
API DesignerJeffallan/claude-skills12k2 repos~2kAutomated safety check: PassMIT

Similar skills

  • Contract Testing

    proffesor-for-testing/agentic-qe

    Consumer-driven contract testing for microservices using Pact, schema validation, API versioning, and backward compatibility testing.

    494 GitHub stars~1.8k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Qe Contract Testing

    proffesor-for-testing/agentic-qe

    Consumer-driven contract testing for APIs including REST, GraphQL, and event-driven systems with schema validation.

    494 GitHub stars~1.2k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • API Testing

    petrkindlmann/qa-skills

    Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.

    163 GitHub stars~2.7k tokensUpdated 3 mo ago
    Testing & QAAuto-check passed
  • API Testing

    cosmicstack-labs/mercury-agent-skills

    REST and GraphQL testing, Postman/Insomnia patterns, contract testing, schema validation, and monitoring

    476 GitHub stars~449 tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 17 repos~4k tokens
    Backend & APIsAuto-check passed

More from vibeeval/vibecosystem

All 144 skills in this repo
  • Agent Benchmark

    vibeeval/vibecosystem

    Framework for measuring and tracking agent response quality over time.

    531 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Differential Review

    vibeeval/vibecosystem

    Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Factcheck Guard

    vibeeval/vibecosystem

    A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.

    531 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    531 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Notepad System

    vibeeval/vibecosystem

    A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.

    531 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about API Patterns

What does API Patterns do?

API design, versioning, testing, schema validation, and contract testing patterns for REST and GraphQL APIs. API Patterns is an agent skill from vibeeval/vibecosystem. API design, versioning, testing, schema validation, and contract testing patterns for REST and GraphQL APIs.

When should I use API Patterns?

API Patterns fits situations like: tasks that involve Forms and validation; tasks that involve GraphQL; tasks that involve API design.

How do I install API Patterns in Claude Code?

Run `npx skills add vibeeval/vibecosystem --skill api-patterns -a claude-code`. Or copy the skill folder (skills/api-patterns in vibeeval/vibecosystem) into .claude/skills/api-patterns in your project. Claude Code loads it when a task matches its description.

How do I install API Patterns in Codex?

Run `npx skills add vibeeval/vibecosystem --skill api-patterns -a codex`. Or copy the skill folder (skills/api-patterns in vibeeval/vibecosystem) into .agents/skills/api-patterns in your project. Codex loads it when a task matches its description.

Can I use API Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill api-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-patterns, .gemini/skills/api-patterns, .github/skills/api-patterns and .opencode/skills/api-patterns in your project.

What does API Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: API Patterns is instructions for the agent only.

Does API Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Patterns use?

API Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Patterns use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Patterns?

Skills that share tags, products or a category with API Patterns: Contract Testing (proffesor-for-testing/agentic-qe, 494 stars), Qe Contract Testing (proffesor-for-testing/agentic-qe, 494 stars), API Testing (petrkindlmann/qa-skills, 163 stars) and API Testing (cosmicstack-labs/mercury-agent-skills, 476 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Patterns?

vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 144 skills in this directory. The repository was last updated on August 8, 2026.

Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.