skills/legal/api-constraints-exhibit/SKILL.md
Extracts technical API constraints from OpenAPI/Swagger specs and developer docs into a contract-ready API Access & Constraints Schedule with source traceability, risk flags, and change-control language. Use when drafting legal exhibits or schedules covering API access scope, rate limits, authentication, data fields, or deprecation terms for MSAs, SOWs, or order forms.
npx skillsauth add casemark/skills api-constraints-exhibitInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Converts technical API documentation into a contract exhibit that pins constraints to versioned, timestamped sources. Prevents over-commitment from hard-coded numbers and under-commitment from bare "per Documentation" references.
[BRACKETED] placeholdersGather before drafting (skip only if user says "use defaults"):
Defaults (apply and label if user doesn't specify):
| Parameter | Default | |---|---| | Exhibit type | API Access & Constraints Schedule | | API scope | Single API, current GA version | | Posture | Provider (outbound) | | Commitment level | Descriptive/as-is | | Categories | Auth, rate limits, data fields | | Output mode | Full Package |
Record deviations in the Risk/Gap Log.
Lock every source with version and retrieval timestamp:
| ID | Source Type | URL/File | Version/Commit | Retrieved (UTC) | Owner | |---|---|---|---|---|---| | S-1 | OpenAPI spec | | | | Eng | | S-2 | Auth docs | | | | Eng | | S-3 | Rate limits | | | | Eng/Support | | S-4 | Changelog | | | | PM | | S-5 | Error codes | | | | Eng |
Checklist:
servers[].url and environment labels capturedcomponents.securitySchemes and operation-level security identified| Spec Element | Example | Legal Significance |
|---|---|---|
| info.version | v2.1.0 | Versioning & sunset terms |
| servers[].url | https://api.example.com | Data residency |
| paths.{path}.{method} | GET /v1/widgets | Scope of access grant |
| components.securitySchemes | OAuth2 client credentials | Security obligations |
| Rate limit docs | 1000/min | Usage caps / SLA |
API Constraints:
| Method | Path | Summary | Auth Type/Scopes | Rate Limit | Key Fields | Errors | |---|---|---|---|---|---|---|
Data Field Inventory:
| Schema | Field | Type | Required | Classification | |---|---|---|---|---|
Auth Profile:
| Category | Details | |---|---| | Methods | API key, OAuth2, mTLS, JWT | | Credential placement | Header, query, cookie | | Scopes/roles | (list) | | Token lifecycle | Expiry, refresh, rotation |
Rate Limit Profile:
| Dimension | Limit | Burst | Headers | Enforcement | Tiering | |---|---|---|---|---|---|
Produce exhibit with these sections:
Every numeric limit, auth requirement, and scope boundary must have a row:
| Exhibit Section | Statement | Source ID | Spec Path/Anchor | Confidence | Notes | |---|---|---|---|---|---|
| ID | Issue | Impact | Proposed Fix | Owner | Status | |---|---|---|---|---|---|
Ask after delivering the draft:
[BRACKETED] placeholders clearly marked[VERIFY] for legal/engineering reviewRequired disclaimer on every output:
THIS EXHIBIT IS A DRAFTING AID AND REQUIRES REVIEW BY QUALIFIED LEGAL COUNSEL AND ENGINEERING BEFORE INCORPORATION INTO ANY AGREEMENT. IT DOES NOT CONSTITUTE LEGAL ADVICE.
Key changes from the original:
tags field: Not part of the required frontmatter spectools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.