All skills
davila7 avatar

/api-patterns

@1deb97c

API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination.

Use this Skill: https://skilld.dev/gh/davila7/claude-code-templates/api-patterns

This session only. Nothing lands on disk.

auth.md

≈144 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Authentication Patterns

Choose auth pattern based on use case.

Selection Guide

Pattern Best For
JWT Stateless, microservices
Session Traditional web, simple
OAuth 2.0 Third-party integration
API Keys Server-to-server, public APIs
Passkey Modern passwordless (2025+)

JWT Principles

Important:
├── Always verify signature
├── Check expiration
├── Include minimal claims
├── Use short expiry + refresh tokens
└── Never store sensitive data in JWT

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides comprehensive API design and security documentation along with a Python-based endpoint validator. It is generally well-constructed but contains a potential surface for indirect prompt injection because the validation script analyzes untrusted project files.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    10/12 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 1deb97c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 13 hours ago.

Activeupdated 8 months ago
What it can do
Reads files Edits files
All 5 allowed tools
ReadWriteEditGlobGrep

README badge

README badge for davila7/claude-code-templates/api-patterns