Agent skill

Add API Resource

by wso2 in wso2/agent-manager

Add or change a REST API resource in agent-manager-service (the Go control plane).

Apache-2.0Auto-check passedBackend & APIs

Install Add API Resource

skills CLI
$ npx skills add wso2/agent-manager --skill add-api-resource -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install wso2/agent-manager add-api-resource --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/wso2/agent-manager.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/add-api-resource .claude/skills/add-api-resource && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
add-api-resource
GitHub stars
105
Token cost
~1.1k tokens
SKILL.md length
500 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add or change a REST API resource in agent-manager-service (the Go control plane).

  • Works in 8 steps: Edit the OpenAPI spec —… → make spec (needs Docker) — regenerates… → Add permission(s) in rbac/permissions.go… → …
  • The user asks to add/modify an endpoint
  • SKILL.md covers Steps (do in order), Audit logging, Guardrails and Done checklist
  • Calls make and go

What it does

Add API Resource is an agent skill from wso2/agent-manager. Add or change a REST API resource in agent-manager-service (the Go control plane). Use when the user asks to add/modify an endpoint, resource, route, or API operation in agent-manager-service — anything that touches the OpenAPI spec, controllers, services, repositories, or RBAC. Enforces the spec-first, codegen, and per-route-authz workflow so generated code and permissions stay consistent.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC, OpenAPI specifications and Project scaffolding. It works with OpenAPI. The repository describes itself as: WSO2 AI Agent Manager is an open control plane designed for enterprises to deploy, manage, and govern AI agents at scale. The licence is Apache-2.0.

When your agent uses it

  • The user asks to add/modify an endpoint
  • API operation in agent-manager-service — anything that touches the OpenAPI spec

Example prompts

  • “/add-api-resource”

Requirements

  • Docker

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Edit the OpenAPI spec — agent-manager-service/docs/api_v1_openapi.yaml. Add/modify the path, operation, and schemas. This is the source of…
  2. make spec (needs Docker) — regenerates spec/ from the YAML. The whole spec/ dir is deleted and rebuilt, so never hand-edit a struct there…
  3. Add permission(s) in rbac/permissions.go — name them resource:verb (:create/:read/:update/:delete, or :manage only where peers already do).
  4. Implement controller → service → repository (controllers/ → services/ → repositories/)
  5. Register the route with authz in api/_routes.go using HandleFuncWithValidationAndAuthz(pattern, rbac., ctrl.). Every route declares its…
  6. Grant the permission to at least one role in rbac/predefined_roles.go (PredefinedRolePermissions). An ungranted permission is unreachable.
  7. make codegen — only if you added/changed an interface (regenerates wire DI + mocks; needs moq on PATH). A new repo interface needs a…
  8. Write a service unit test — use the add-service-unit-test skill.

What it can do on your machine

Read from SKILL.md and the folder at commit 6d4af26. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • go

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Add API Resource loads about 1.1k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 500 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from wso2/agent-manager at commit 6d4af26, republished under its Apache-2.0 licence (© wso2). 500 words, ~1,130 tokens.

Download SKILL.mdSave it as .claude/skills/add-api-resource/SKILL.md (or your agent's skills folder).
name
add-api-resource
description
Add or change a REST API resource in agent-manager-service (the Go control plane). Use when the user asks to add/modify an endpoint, resource, route, or API operation in agent-manager-service — anything that touches the OpenAPI spec, controllers, services, repositories, or RBAC. Enforces the spec-first, codegen, and per-route-authz workflow so generated code and permissions stay consistent.

Add/change an API resource (agent-manager-service)

Spec-first, layered, per-route-authz workflow for the Go control plane. The request/response types and mocks are generated — never hand-write them.

Read first: agent-manager-service/AGENTS.md → "Golden path", "Layering", "Permissions (RBAC)", "Code generation". This skill is the executable checklist; that guide has the why.

Steps (do in order)

  1. Edit the OpenAPI spec — agent-manager-service/docs/api_v1_openapi.yaml. Add/modify the path, operation, and schemas. This is the source of truth for request/response shapes.
  2. make spec (needs Docker) — regenerates spec/ from the YAML. The whole spec/ dir is deleted and rebuilt, so never hand-edit a struct there; your edits would be lost.
  3. Add permission(s) in rbac/permissions.go — name them resource:verb (:create/:read/:update/:delete, or :manage only where peers already do).
  4. Implement controller → service → repository (controllers/ → services/ → repositories/):
    • Controller: HTTP only — parse/validate, map result→status, translate sentinel errors→HTTP.
    • Service: business logic; depend on repo/client interfaces, never concrete types.
    • Repository: persistence only (interface + impl). Add an interface if you introduce a new one.
  5. Register the route with authz in api/<resource>_routes.go using HandleFuncWithValidationAndAuthz(pattern, rbac.<Perm>, ctrl.<Handler>). Every route declares its own permission.
  6. Grant the permission to at least one role in rbac/predefined_roles.go (PredefinedRolePermissions). An ungranted permission is unreachable.
  7. make codegen — only if you added/changed an interface (regenerates wire DI + mocks; needs moq on PATH). A new repo interface needs a //go:generate moq ... directive above its declaration — copy an existing one.
  8. Write a service unit test — use the add-service-unit-test skill.

Audit logging

Step 5 audits the route automatically — a mutating route cannot ship unaudited, and api/audit_coverage_test.go fails the build if one does. Two cases need you:

  • The build says cannot derive an action for audited route, or the route's rbac.Permission does not describe what it does (one permission gating several operations, or naming a different resource). Add one line to actionOverrides in audit/policy.go.
  • The operation touches credentials, privileges, membership, deployment or deletion. The envelope record cannot say what changed, so add a semantic event — use the add-audit-event skill.

Never read a request or response body into a record; pass named fields via audit.Detail, which takes scalars and []string only.

Show full SKILL.md (157 more words)Show less

Guardrails

  • Multi-tenancy: the service must validate the caller's org against the target resource it loads, not just the path (RequireOrgMatch is a first-pass filter, not the enforcement layer).
  • Errors: map gorm.ErrRecordNotFound → the specific utils.ErrXxxNotFound; wrap everything else with %w. Never flatten an unexpected error into not-found; never silently fall back to a default on a real error. Compare with errors.Is.
  • Context: every I/O method takes context.Context first and propagates it.
  • Don't re-fetch a resource already loaded earlier in the request path — pass it down.

Done checklist

  • spec/ regenerated (make spec) and committed if the YAML changed.
  • New permission exists in rbac/permissions.go and is granted in rbac/predefined_roles.go.
  • Route registered with an authz registrar (not plain HandleFuncWithValidation unless deliberate).
  • make codegen run + mocks committed if an interface changed.
  • Service unit test added; make test-unit passes (includes TestEveryMutatingRouteIsAudited).
  • Semantic audit event added if the operation is security-critical (add-audit-event skill).
  • go build -tags=integration ./... compiles.
  • CI lint clean: golangci-lint run --config .github/linters/.golangci.yaml ./...

© wso2, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/add-api-resource of wso2/agent-manager.

Open the folder on GitHubat commit 6d4af26

Compare with similar skills

Add API Resource next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Add API Resource compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Add API Resource this skillwso2/agent-manager105—~1.1kAutomated safety check: PassApache-2.0
API Featuregocronx-team/gocron808—~1.2kAutomated safety check: PassMIT
NestJS ExpertJeffallan/claude-skills12k—~2kAutomated safety check: PassMIT
API DesignWrongStack/WrongStack368—~1.3kAutomated safety check: PassMIT
API Designeraiskillstore/marketplace4301 repos~3.6kAutomated safety check: PassNone
ToolJet Marketplace Plugin BuilderToolJet/ToolJet41k—~2.1kAutomated safety check: PassAGPL-3.0

Similar skills

  • API Feature

    gocronx-team/gocron

    Implement or review an end-to-end gocron HTTP API change. An agent skill from gocronx-team/gocron.

    808 GitHub stars~1.2k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • NestJS Expert

    Jeffallan/claude-skills

    Scaffolds NestJS modules, controllers, services, DTOs and guards for TypeScript backends, with validation, JWT and Passport auth, Swagger docs and unit and E2E tests.

    12k GitHub stars~2k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • API Design

    WrongStack/WrongStack

    A skill your agent uses when designing, implementing, or reviewing an HTTP API — endpoints, request and response shapes, errors, pagination, versioning, and authorization.

    368 GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • API Designer

    aiskillstore/marketplace

    Design and document RESTful and GraphQL APIs with OpenAPI/Swagger specifications, authentication patterns, versioning strategies, and best practices.

    430 GitHub starsUsed in 1 repo~3.6k tokens
    Backend & APIsAuto-check passed
  • Turns an API description, such as an OpenAPI file or a Postman collection, into a connector plugin for ToolJet's marketplace and checks it with the repo's validator.

    41k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed

More from wso2/agent-manager

  • Add Audit Event

    wso2/agent-manager

    Add a semantic audit event to agent-manager-service (the Go control plane).

    105 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Add Console API Feature

    wso2/agent-manager

    Add an API-backed feature to the console (React/TypeScript web UI).

    105 GitHub stars~761 tokensUpdated today
    Auto-check passed
  • Add Evaluator

    wso2/agent-manager

    Add a new evaluator to the amp-evaluation Python library. An agent skill from wso2/agent-manager.

    105 GitHub stars~710 tokensUpdated today
    Auto-check passed
  • Add Service Unit Test

    wso2/agent-manager

    Write a service-layer unit test in agent-manager-service (the Go control plane).

    105 GitHub stars~997 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Add API Resource

What does Add API Resource do?

Add or change a REST API resource in agent-manager-service (the Go control plane). Add API Resource is an agent skill from wso2/agent-manager. Add or change a REST API resource in agent-manager-service (the Go control plane).

When should I use Add API Resource?

Add API Resource fits situations like: the user asks to add/modify an endpoint; API operation in agent-manager-service — anything that touches the OpenAPI spec.

How do I install Add API Resource in Claude Code?

Run `npx skills add wso2/agent-manager --skill add-api-resource -a claude-code`. Or copy the skill folder (.claude/skills/add-api-resource in wso2/agent-manager) into .claude/skills/add-api-resource in your project. Claude Code loads it when a task matches its description.

How do I install Add API Resource in Codex?

Run `npx skills add wso2/agent-manager --skill add-api-resource -a codex`. Or copy the skill folder (.claude/skills/add-api-resource in wso2/agent-manager) into .agents/skills/add-api-resource in your project. Codex loads it when a task matches its description.

Can I use Add API Resource in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wso2/agent-manager --skill add-api-resource -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/add-api-resource, .gemini/skills/add-api-resource, .github/skills/add-api-resource and .opencode/skills/add-api-resource in your project.

What does Add API Resource need to run?

Going by SKILL.md and its folder, Add API Resource needs the command-line tools its instructions call (make and go). Our summary lists: Docker.

Does Add API Resource access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Add API Resource safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Add API Resource use?

Add API Resource is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Add API Resource use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Add API Resource?

Skills that share tags, products or a category with Add API Resource: API Feature (gocronx-team/gocron, 808 stars), NestJS Expert (Jeffallan/claude-skills, 12k stars), API Design (WrongStack/WrongStack, 368 stars) and API Designer (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Add API Resource?

wso2 (a GitHub organization) maintains it in wso2/agent-manager, which has 105 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 7, 2026.

Source: wso2/agent-manager on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.