api/SKILL.md
--- name: api description: API quality system. 7 modes: score (10-category audit), fix (auto-fix from scorecard), loop (score->fix until target). OWASP API Top 10 mapped. license: Complete terms in LICENSE.txt --- # API Quality System One skill, 7 modes. Score REST/HTTP API quality, fix issues, or run the full loop. ## Modes | Mode | Use When | Workflow | |------|----------|---------| | **score** | Audit API quality | Read routes -> Score 10 categories -> Scorecard | | **fix** | Fix issues f
npx skillsauth add clownnvd/claude-code-skills apiInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
One skill, 7 modes. Score REST/HTTP API quality, fix issues, or run the full loop.
| Mode | Use When | Workflow | |------|----------|---------| | score | Audit API quality | Read routes -> Score 10 categories -> Scorecard | | fix | Fix issues from scorecard | Parse -> Prioritize -> Fix -> Verify -> Re-score | | loop | End-to-end cycle | Score -> Fix -> Re-score until target | | generate | Create new code | Load criteria -> Generate meeting all 10 -> Self-check | | review | Quick 1-2 file check | Read files -> Score applicable categories -> Annotate + fix | | migrate | Framework upgrade | Detect versions -> Map breaking changes -> Migrate -> Verify | | test | Generate test cases | Map categories to assertions -> Generate test files |
Audit any REST/HTTP API codebase across 10 weighted categories (0-100).
When: Before deploying API routes, auditing existing quality, reviewing PR changes, checking OWASP compliance.
Steps: Load references/scoring/scoring-workflow.md
| # | Category | Weight | Criteria Reference |
|---|----------|--------|--------------------|
| 1 | Security | 20% | scoring/criteria/security-auth.md |
| 2 | Auth & AuthZ | 15% | scoring/criteria/security-auth.md |
| 3 | Input Validation | 12% | scoring/criteria/input-errors.md |
| 4 | Error Handling | 10% | scoring/criteria/input-errors.md |
| 5 | Rate Limiting | 10% | scoring/criteria/ratelimit-response-perf.md |
| 6 | Response Design | 8% | scoring/criteria/ratelimit-response-perf.md |
| 7 | Performance | 8% | scoring/criteria/ratelimit-response-perf.md |
| 8 | Observability | 7% | scoring/criteria/observability-docs-testing.md |
| 9 | Documentation & DX | 5% | scoring/criteria/observability-docs-testing.md |
| 10 | Testing | 5% | scoring/criteria/observability-docs-testing.md |
Anti-Bias: Start at 5/10 baseline. Penalize missing checklist items. 9-10 requires evidence.
Grades: A+ (97-100), A (93-96), A- (90-92), B+ (87-89), B (83-86), B- (80-82), C+ (77-79), C (73-76), D (60-72), F (<60)
Take scorecard output and implement all fixes. Prioritize by severity x weight.
When: After scoring, when API is below target.
Steps: Load references/fix/implementation-workflow.md
| Priority | Severity | Score Range | Action | |----------|----------|-------------|--------| | 1 | CRITICAL | 0-3 or security hole | Fix immediately -- blocks deploy | | 2 | HIGH + high weight (>=12%) | 4-5 | Fix next -- moves score most | | 3 | HIGH + low weight (<12%) | 4-5 | Fix after high-weight items | | 4 | MEDIUM | 6-7 | Fix next sprint | | 5 | LOW | 8 | Backlog or skip |
| Scorecard Category | Fix Pattern Reference |
|-------------------|----------------------|
| Security, Auth & AuthZ | fix/fix-patterns/security-auth.md |
| Input Validation, Error Handling | fix/fix-patterns/input-errors.md |
| Rate Limiting, Response Design, Performance | fix/fix-patterns/ratelimit-response-perf.md |
| Observability, Documentation, Testing | fix/fix-patterns/observability-docs-testing.md |
Auto-iterate score->fix until target. Max 5 iterations. Stop on plateau (delta=0 for 2 rounds).
Score Targets: B+ (87) production, A- (90) enterprise, A+ (97) gold standard.
Generate code meeting all 10 categories at 9-10/10. Load references/generate/workflow.md.
Parse request → Load criteria → Generate with all patterns → Self-check → Output (assets/templates/generated-code.md.template)
Quick 1-2 file review. Load references/review/workflow.md.
Read files → Score applicable categories → Annotate line numbers → Suggest fixes (assets/templates/review-report.md.template)
Upgrade code for framework changes. Load references/migrate/workflow.md.
Detect versions → Map breaking changes → Apply migrations → Verify (assets/templates/migration-report.md.template)
Generate tests from scoring criteria. Load references/test/workflow.md.
Map categories to assertions → Generate tests → Output suite (assets/templates/test-suite.md.template)
| OWASP Risk | Covered By | |---|---| | API1: BOLA | Auth & AuthZ | | API2: Broken Auth | Security, Auth & AuthZ | | API3: BOPLA | Auth & AuthZ, Input Validation | | API4: Resource Consumption | Rate Limiting, Performance | | API5: BFLA | Auth & AuthZ | | API6: Sensitive Flows | Security, Rate Limiting | | API7: SSRF | Security, Input Validation | | API8: Misconfiguration | Security, Error Handling, Observability | | API9: Inventory Mgmt | Observability, Documentation | | API10: Unsafe API Consumption | Rate Limiting, Input Validation |
| Stack | Additional Reference |
|-------|---------------------|
| Next.js App Router | references/nextjs-patterns.md -- two-layer auth, security headers, webhook patterns, response helpers |
references/scoring/overview.md -- Scoring system, grade scale, quality gates, OWASP mappingreferences/scoring/best-practices.md -- Do/Don't for security, validation, errors, rate limiting, auth, observability, testingreferences/scoring/scoring-workflow.md -- 6-step audit process, category mapping, issue formatreferences/scoring/criteria/ -- 4 files: security-auth, input-errors, ratelimit-response-perf, observability-docs-testingreferences/nextjs-patterns.md -- Next.js App Router scoring adjustments, anti-pattern penaltiesreferences/fix/overview.md -- How fix works, priority order, score targets, integration with scoringreferences/fix/best-practices.md -- Fix discipline, safe vs dangerous changes, test guidelines, common mistakesreferences/fix/implementation-workflow.md -- 6-step process, priority matrix, which refs to loadreferences/fix/verification.md -- Post-fix checklist, re-scoring protocol, comparison template, loop modereferences/fix/fix-patterns/ -- 4 files: security-auth, input-errors, ratelimit-response-perf, observability-docs-testingassets/templates/scorecard.md.templateassets/templates/fix-report.md.templateassets/templates/generated-code.md.templateassets/templates/review-report.md.templateassets/templates/migration-report.md.templateassets/templates/test-suite.md.template
Fill {{VARIABLE}} placeholders with actual values.tools
Zustand v5 state management for Next.js 16. Store patterns, middleware (persist/immer/devtools), SSR hydration, CV editor multi-step wizard, 20 documented errors. Triggers: zustand, store, state management, useState replacement, global state, persist, immer.
development
React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.
development
Ultimate UI/UX design intelligence with real app flow knowledge. 93 styles, 121 palettes, 81 font pairings, 35 charts, 79 components, 62 animations, 65 WCAG criteria, 46 responsive patterns, 46 dark mode rules, 60 design tokens, 13 stacks. PLUS: Claude.ai full UI blueprint (19 flows, all screens), PageFlows app patterns. Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check, clone, recreate, rebuild. Styles: glassmorphism, brutalism, neumorphism, bento, dark mode, view transitions, scroll-driven, container queries, AI-native, liquid glass, neo-minimalism, mesh gradient, geometric abstraction. Topics: color, accessibility, animation, layout, typography, spacing, shadow, gradient, responsive, dark mode, WCAG 2.2, design tokens, components, spring physics, kinetic typography, container queries, popover API, semantic tokens. Apps: claude.ai, ChatGPT-style, AI chat UI, SaaS dashboard.
development
--- name: ui description: UI quality system. 4 modes: research (design brief), score (10-category audit), fix (auto-fix from scorecard), pipeline (end-to-end chain). license: Complete terms in LICENSE.txt --- # UI Quality System One skill, 4 modes. Research real products, score UI quality, fix issues, or run the full pipeline. ## Modes | Mode | Use When | Workflow | |------|----------|---------| | **research** | Before building any page | Extract tokens → Search → Fetch → Design Brief | | **