All skills
apollographql avatar

/rover

@9ccc6ed official
by Apollo GraphQLapollographql/skills115 stars
13

Guide for using Apollo Rover CLI to manage GraphQL schemas and federation. Use this skill when: (1) publishing or fetching subgraph/graph schemas, (2) composing supergraph schemas locally or via GraphOS, (3) running local supergraph development with rover dev, (4) validating schemas with check and lint commands, (5) configuring Rover authentication and environment, (6) exploring or searching a graph's schema for agent-driven discovery (rover schema describe / rover schema search).

Use this Skill: https://skilld.dev/gh/apollographql/skills/rover

This session only. Nothing lands on disk.

referencesgraphs.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Rover Graph Commands

Commands for managing monograph (non-federated) schemas in Apollo GraphOS.

Note: Use rover subgraph commands for federated graphs. These rover graph commands are for standalone GraphQL APIs without federation.

graph fetch

Download a graph schema from GraphOS.

# Basic fetch
rover graph fetch my-graph@production

# Output to file
rover graph fetch my-graph@production > schema.graphql

# JSON output
rover graph fetch my-graph@production --format json

Options:

Option Description
--format <FORMAT> Output format: plain (default) or json

graph introspect

Extract schema from a running GraphQL server.

# Basic introspection
rover graph introspect http://localhost:4000/graphql

# With authentication header
rover graph introspect http://localhost:4000/graphql \
  --header "Authorization: Bearer token123"

# Multiple headers
rover graph introspect http://localhost:4000/graphql \
  --header "Authorization: Bearer token" \
  --header "X-Tenant-ID: acme"

# Watch mode
rover graph introspect http://localhost:4000/graphql --watch

Options:

Option Description
--header <HEADER> HTTP header(s) to include
--watch Poll endpoint and output changes
--polling-interval <SECONDS> Interval for watch mode (default: 1)

graph publish

Publish a monograph schema to GraphOS.

# From file
rover graph publish my-graph@production \
  --schema ./schema.graphql

# From stdin
cat schema.graphql | rover graph publish my-graph@production --schema -

# From introspection
rover graph publish my-graph@production \
  --schema <(rover graph introspect http://localhost:4000/graphql)

Options:

Option Description
--schema <PATH> Schema file path or - for stdin (required)

graph check

Validate schema changes against GraphOS.

# Basic check
rover graph check my-graph@production \
  --schema ./schema.graphql

# With validation thresholds
rover graph check my-graph@production \
  --schema ./schema.graphql \
  --query-count-threshold 100 \
  --query-count-threshold-percentage 3

Check validates:

  1. Schema validity - Schema is syntactically correct
  2. Operations - Existing client operations still work
  3. Linting - Schema follows GraphOS linting rules

Options:

Option Description
--schema <PATH> Schema file path (required)
--query-count-threshold <N> Min operations for breaking change
--query-count-threshold-percentage <N> Min % of operations
--background Run check in background

Exit codes:

  • 0 - Check passed
  • 1 - Check failed
  • 2 - Check completed with warnings

graph lint

Run GraphOS linting rules against a schema.

# Lint local schema (uses graph for rule configuration)
rover graph lint my-graph@production --schema ./schema.graphql

# Lint without graph reference
rover graph lint --schema ./schema.graphql

graph delete

Delete a graph variant from GraphOS.

# Delete with confirmation
rover graph delete my-graph@staging

# Delete without confirmation
rover graph delete my-graph@staging --confirm

Warning: This deletes the entire variant, not just the schema.

Options:

Option Description
--confirm Skip confirmation prompt

Differences from Subgraph Commands

Aspect rover graph rover subgraph
Use case Monographs Federated subgraphs
Routing URL Not required Required for Router
Composition N/A Composes with other subgraphs
--name flag Not used Required

Migration to Federation

If migrating from a monograph to federation:

# 1. Fetch existing monograph schema
rover graph fetch my-graph@production > schema.graphql

# 2. Add federation directives to schema
# (edit schema.graphql to add @key, extend Query, etc.)

# 3. Publish as first subgraph
rover subgraph publish my-graph@production \
  --name monolith \
  --schema ./schema.graphql \
  --routing-url https://api.example.com/graphql

CI/CD Example

#!/bin/bash
set -e

GRAPH_REF="${APOLLO_GRAPH_REF:-my-graph@production}"
SCHEMA_PATH="./schema.graphql"

# Check schema changes
echo "Checking schema..."
rover graph check "$GRAPH_REF" --schema "$SCHEMA_PATH"

# Publish if check passes
echo "Publishing schema..."
rover graph publish "$GRAPH_REF" --schema "$SCHEMA_PATH"

echo "Schema published successfully!"

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk HIGH
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive guide for the Apollo Rover CLI. It contains installation instructions that involve downloading and executing remote scripts from Apollo's official domain. While these are remote code execution patterns, they are standard for this recognized vendor. The skill is susceptible to indirect prompt injection because it processes external GraphQL schema data without explicit boundary markers or sanitization.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    6/6 files flagged

  • ZeroLeaks5mo

    1 finding · Score: 82/100

Signed by skilld at 9ccc6ed. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
What it can do
Runs commands
compatibility
Node.js v18+, Linux/macOS/Windows
metadata
{
  "author": "apollographql",
  "version": "1.1.2"
}
All 1 allowed tools
Bash(rover:*) Bash(npm:*) Bash(npx:*) Read Write Edit Glob Grep
  • CLI
  • graphql
  • apollo
  • rover
  • federation
  • schema
  • supergraph
  • graphos
  • subgraph

README badge

README badge for apollographql/skills/rover

Manages GraphQL schemas and federation via the Apollo Rover CLI, including publishing subgraphs, composing supergraphs, and validating schemas with check and lint commands. Designed for local schema exploration via piped commands (rover schema describe/search) and GraphOS integration workflows, with built-in support for federated and monograph architectures.

Generated from the current SKILL.md.

Does Rover work with both federated and non-federated GraphQL graphs?
Yes. Use `rover subgraph` commands for federated graphs and `rover graph` commands for monographs (non-federated graphs). Both workflows are supported.
How do I explore a large GraphQL schema without loading the entire SDL into context?
Pipe `rover graph fetch` into `rover schema describe` or `rover schema search` — these commands read the schema via stdin and return only a compact overview or search results, keeping context manageable.
What's the difference between `rover graph fetch` and `rover supergraph fetch`?
`rover graph fetch` returns the API schema (what you can query), while `rover supergraph fetch` returns the composed supergraph SDL with federation internals like `join__` and `link__`. Use the former for schema exploration and the latter for composition/router work.
Can Rover execute GraphQL queries, or does it only manage schemas?
Rover only manages and inspects schemas. To run a generated query, you must send it to the graph's endpoint separately using curl or another HTTP client.
Does this skill require a GraphOS account, or can I use Rover offline?
Most Rover commands (publish, fetch, check) require authentication with a GraphOS API key. Local composition with `rover supergraph compose` and schema exploration of local files work offline.

Generated from the current SKILL.md. These answers refresh after source changes.