Agent Skills
› vudovn/ag-kit
› api-patterns
api-patterns
GitHub提供API设计原则与决策指南,涵盖REST/GraphQL/tRPC选型、响应格式、版本控制及安全防护。旨在指导开发者根据上下文选择合适模式,避免反模式,确保API设计的规范性与安全性。
Trigger Scenarios
需要设计或重构API接口
在REST、GraphQL和tRPC之间进行技术选型
制定API版本管理策略
规划API认证与安全机制
Install
npx skills add vudovn/ag-kit --skill api-patterns -g -y
SKILL.md
Frontmatter
{
"name": "api-patterns",
"version": "1.0.0",
"description": "API design principles and decision-making. REST vs GraphQL vs tRPC selection, response formats, versioning, pagination.",
"when_to_use": "When designing REST\/GraphQL\/tRPC APIs, defining response formats, versioning, pagination, or API authentication. NOT for UI\/frontend work.",
"allowed-tools": "Read, Write, Edit, Glob, Grep"
}
API Patterns
API design principles and decision-making. Learn to THINK, not copy fixed patterns.
🎯 Selective Reading Rule
Read ONLY files relevant to the request! Check the content map, find what you need.
📑 Content Map
| File | Description | When to Read |
|---|---|---|
api-style.md |
REST vs GraphQL vs tRPC decision tree | Choosing API type |
rest.md |
Resource naming, HTTP methods, status codes | Designing REST API |
response.md |
Envelope pattern, error format, pagination | Response structure |
graphql.md |
Schema design, when to use, security | Considering GraphQL |
trpc.md |
TypeScript monorepo, type safety | TS fullstack projects |
versioning.md |
URI/Header/Query versioning | API evolution planning |
auth.md |
JWT, OAuth, Passkey, API Keys | Auth pattern selection |
rate-limiting.md |
Token bucket, sliding window | API protection |
documentation.md |
OpenAPI/Swagger best practices | Documentation |
security-testing.md |
OWASP API Top 10, auth/authz testing | Security audits |
🔗 Related Skills
| Need | Skill |
|---|---|
| API implementation | @[skills/nodejs-best-practices] |
| Data structure | @[skills/database-design] |
| Security details | @[skills/vulnerability-scanner] |
✅ Decision Checklist
Before designing an API:
- Asked user about API consumers?
- Chosen API style for THIS context? (REST/GraphQL/tRPC)
- Defined consistent response format?
- Planned versioning strategy?
- Considered authentication needs?
- Planned rate limiting?
- Documentation approach defined?
❌ Anti-Patterns
DON'T:
- Default to REST for everything
- Use verbs in REST endpoints (/getUsers)
- Return inconsistent response formats
- Expose internal errors to clients
- Skip rate limiting
DO:
- Choose API style based on context
- Ask about client requirements
- Document thoroughly
- Use appropriate status codes
Script
| Script | Purpose | Command |
|---|---|---|
scripts/api_validator.py |
API endpoint validation | python scripts/api_validator.py <project_path> |
Version History
- 211561c Current 2026-08-20 11:37


