All skills
lassejlv avatar

/minimize-api-responses

@26d2f20
by Lasselassejlv/skills50 stars
1

Minimize API response data while preserving required consumer contracts and enforcing field-level authorization. Use when Codex builds, changes, audits, or reviews REST, GraphQL, RPC, webhook, or server-action endpoints; maps database or domain objects into responses; reduces payloads; prevents excessive data exposure; designs DTOs, serializers, or response schemas; or verifies that each caller receives only the fields it needs and is allowed to access.

Use this Skill: https://skilld.dev/gh/lassejlv/skills/minimize-api-responses

This session only. Nothing lands on disk.

referencesresearch.md

≈606 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Research grounding

These primary sources support the skill's controls. They were checked on 2026-08-16.

OWASP API Security Top 10: API3:2023

Broken Object Property Level Authorization treats excessive data exposure as a property-level authorization failure. Its prevention guidance says to verify access to every exposed property, select specific properties instead of using generic object serialization, validate responses against schemas, and keep returned structures to the functional minimum.

Applied controls:

  • Require both necessity and authorization for each field.
  • Prefer endpoint-specific allowlists and output schemas.
  • Avoid direct model serialization and denylist-only filtering.
  • Keep field selection server-owned even when clients request particular fields.

OWASP Web Security Testing Guide

Testing for Excessive Data Exposure defines the issue as returning more information than the client needs. It recommends comparing raw responses with actual client needs and checking multiple endpoints, privilege levels, nested objects, GraphQL fields, and error output. Its remediation guidance calls for server-side filtering, purpose-specific DTOs or serializer allowlists, field-level access control, restricted schemas, and sanitized errors.

Applied controls:

  • Trace real consumers before deciding that a field is required.
  • Review list, detail, nested, role-specific, and error paths.
  • Test raw response shapes and negative field assertions.
  • Treat UI hiding as presentation only, never as access control.

EU General Data Protection Regulation

GDPR Article 5(1)(c) defines data minimisation for personal data as limiting processing to what is necessary for its purpose. Article 25 requires data protection by design and, by default, processing only the personal data necessary for each specific purpose.

Applied controls when personal data is in scope:

  • Tie each personal-data field to a specific endpoint purpose.
  • Default to omission when that purpose does not require the field.
  • Treat this as engineering guidance, not a substitute for project-specific legal advice.

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill is a security-focused instructional guide for minimizing API responses to prevent excessive data exposure. It does not contain any malicious code, obfuscation, or unauthorized data access patterns.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 26d2f20. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month

README badge

README badge for lassejlv/skills/minimize-api-responses