skills/engineering-api-documentarian/SKILL.md
Specialize in API documentation — OpenAPI specs, endpoint documentation, request/response examples, error documentation, and authentication docs. Use when: API docs, OpenAPI specs, "document this API/endpoint", generating endpoint reference documentation from code, or when the engineering domain skill's `docs` action routes an api-type request here.
npx skillsauth add mikeparcewski/wicked-garden wicked-garden-engineering-api-documentarianInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
You create comprehensive, accurate API documentation that developers can trust and use effectively.
Focus on API-specific documentation:
Analyze code to find:
Create complete OpenAPI 3.0+ spec:
openapi: 3.0.0
info:
title: User Management API
version: 1.0.0
description: Manage user accounts and authentication
servers:
- url: https://api.example.com/v1
description: Production
paths:
/users/{userId}:
get:
summary: Get user by ID
operationId: getUser
parameters:
- name: userId
in: path
required: true
schema:
type: string
responses:
'200':
description: User found
content:
application/json:
schema:
$ref: '#/components/schemas/User'
example:
id: "123"
email: "[email protected]"
name: "Jane Doe"
'404':
description: User not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
security:
- bearerAuth: []
components:
schemas:
User:
type: object
required:
- id
- email
properties:
id:
type: string
description: Unique user identifier
email:
type: string
format: email
description: User email address
name:
type: string
description: User display name
Error:
type: object
properties:
error:
type: string
message:
type: string
code:
type: string
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
Create detailed endpoint documentation:
## GET /users/{userId}
Retrieve a user by their unique ID.
### Authentication
Requires Bearer token with `users:read` scope.
### Parameters
| Name | Location | Type | Required | Description |
|------|----------|------|----------|-------------|
| userId | path | string | Yes | Unique user identifier |
| fields | query | string | No | Comma-separated fields to include |
### Request Example
\`\`\`bash
curl -X GET "https://api.example.com/v1/users/123" \
-H "Authorization: Bearer YOUR_TOKEN"
\`\`\`
### Response Example
**Success (200)**
\`\`\`json
{
"id": "123",
"email": "[email protected]",
"name": "Jane Doe",
"created_at": "2024-01-15T10:30:00Z"
}
\`\`\`
**Not Found (404)**
\`\`\`json
{
"error": "not_found",
"message": "User not found",
"code": "USER_NOT_FOUND"
}
\`\`\`
### Error Codes
| Code | Description |
|------|-------------|
| USER_NOT_FOUND | No user exists with this ID |
| INVALID_TOKEN | Authentication token is invalid |
| FORBIDDEN | User lacks permission to view this user |
Ensure:
Every endpoint must have:
Document all responses:
Include:
For every schema:
Define reusable components:
components:
schemas:
# Reusable data models
User: {...}
Error: {...}
parameters:
# Reusable parameters
userId:
name: userId
in: path
required: true
schema:
type: string
responses:
# Reusable responses
NotFound:
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
Include version information:
/v1/usersBe explicit about security:
security:
- bearerAuth: []
- apiKey: []
components:
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
description: JWT token from /auth/login
apiKey:
type: apiKey
in: header
name: X-API-Key
description: API key from dashboard
Include helpful metadata:
info:
title: User Management API
version: 1.0.0
description: |
Manage user accounts, authentication, and profiles.
Base URL: https://api.example.com/v1
**Rate Limits**: 1000 requests/hour per API key
**Support**: [email protected]
contact:
name: API Support
email: [email protected]
license:
name: MIT
Focus on documenting what the API actually does, not what it should do:
## Endpoints
### Users
- `GET /users` - List all users
- `GET /users/{id}` - Get user by ID
- `POST /users` - Create new user
- `PUT /users/{id}` - Update user
- `DELETE /users/{id}` - Delete user
## Queries
\`\`\`graphql
query GetUser($id: ID!) {
user(id: $id) {
id
email
name
}
}
\`\`\`
## Mutations
\`\`\`graphql
mutation CreateUser($input: CreateUserInput!) {
createUser(input: $input) {
id
email
}
}
\`\`\`
## Events
### Client → Server
\`\`\`json
{"type": "subscribe", "channel": "users.123"}
\`\`\`
### Server → Client
\`\`\`json
{"type": "update", "channel": "users.123", "data": {...}}
\`\`\`
Find API patterns:
docs/api/
├── openapi.yaml # Complete OpenAPI spec
├── README.md # API overview
├── authentication.md # Auth guide
├── endpoints/ # Per-endpoint docs
│ ├── users.md
│ └── posts.md
├── examples/ # Request/response examples
│ ├── create-user.json
│ └── update-profile.json
└── errors.md # Error reference
Publish events for documentation milestones:
[docs:api:generated:success] - API spec created[docs:api:validated:success] - Spec validation passedForked-context worker, reachable two ways:
wicked-garden-engineering-api-documentarian.subagent_type: compat key —
Task(subagent_type="wicked-garden:engineering:api-documentarian") maps to this fork skill.development
Pattern-conformance agent-half: evaluates a produced artifact or diff against a set of architectural/design pattern rules from the conformance-rule store (wicked_governance schema). Returns structured findings with rule ID, severity, and rationale — the deterministic half (mechanical rule recall) is done by the guard pipeline; this is the semantic evaluation step. Triggered by: the guard_pipeline `outgov_pattern` check (session-close), or explicitly by an engineering review when WICKED_OUTGOV_RULES_DIR is populated. NOT a replacement for the full `engineering` review skill — focuses only on conformance to stored Pattern rules; architecture and code-quality checks live in the `engineering` skill. Semantic evaluation reuses `wicked-garden-qe-semantic-reviewer` as the designated agent-half evaluator (per garden#983 spec). This skill is the orchestrating wrapper that loads applicable Pattern rules and delegates the per-rule semantic judgment to qe-semantic-reviewer.
tools
The FOUNDATIONAL domain-model capability: extract a codebase's domain — testable business rules (with confidence + provenance), entities, requirements — as a schema-conformant model on the estate graph. The workers annotate the store; wicked-core reads it and builds the requirements graph, coverage-gating fail-closed. Steers three fork workers. A shared substrate, not a modernization tool. The `modernize` archetype DERIVES from it; build / migrate / review / specify / explore consume the SAME domain model — none OWN it. Understanding a codebase's domain is upstream of almost everything else garden does. Use when: "extract the business rules / domain model from this codebase", "build a requirements graph from the code", "what does this system actually require", "reverse-engineer the domain before we build/port/migrate". Works on ANY codebase (modern or legacy) — the value is the domain model, not the porting. NOT the code transform itself (that is the archetype consuming this model). This skill produces the DOMAIN MODEL, not new code.
development
Domain-graph fork worker for the modernize archetype. Groups the estate's Louvain communities into business domains, attaches each requirement to its cluster (advisory cluster_id provenance), and invokes wicked-core's domain-graph build (which reads the annotated estate store, recomputes coverage fail-closed, and builds the requirements graph) — then validates core's output against the vendored schema. Use when: dispatched by wicked-garden-domain after rule extraction to turn a flat rule set into cluster-keyed domains; "group these into domains", "build the requirements graph", "translate clusters into a domain model". NOT for mining the rules themselves (that is domain-extractor) or threat-modeling (that is domain-coverage).
tools
Rule-extraction fork worker for the FOUNDATIONAL domain-model capability. Mines testable business rules from a codebase — each with a numeric confidence and a provenance{source, ref, source_kinds} — and annotates them into the estate store so wicked-core can build the domain-model requirements graph (coverage-gated). This is a substrate, not a modernization tool: the `modernize` archetype DERIVES from it, and build / migrate / review / specify / explore can consume the same domain model — none OWN it. Use when: dispatched by wicked-garden-domain to mine the business_rules of a codebase (or a module); "extract the domain rules", "what does this system require", building the requirements half of a domain model. NOT for grouping into domains (that is domain-modeler) or judging coverage (that is domain-coverage — a seat-distinct evaluator).