Review API Contracts — Security skill for Claude Code
Audit API boundary code for contract drift: response envelope consistency, error response shapes, HTTP status-code semantics, and frontend/backend type agreement.
How to install Review API Contracts
Installs to ~/.claude/commands/sourjya-kiro-rails-review-api-contracts.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/sourjya/kiro-rails/HEAD/.claude/commands/review-api-contracts.md -o ~/.claude/commands/sourjya-kiro-rails-review-api-contracts.md Restart Claude Code, or start a new session, for it to be picked up.
What Review API Contracts does
description: "Audit API boundary code for contract drift: response envelope consistency, error response shapes, HTTP status-code semantics, and frontend/backend type agreement."
Before scanning, read `docs/decisions/` ADRs and any API design docs if they exist. Use documented contract decisions (intentional envelope exceptions, versioning strategy) to distinguish intentional design from accidental inconsistency.
Act as a principal-level API architect and backend engineer performing a
Alternatives in Security
- Skill Audit — Audit codebases for quality, consistency, and broken patterns — use for pre-release or tech debt review 2.8k ★
- Sanyuan Skills — Expert code review skill: SOLID, security, performance, error handling, boundary conditions 2.7k ★
- Query Token Audit — Audit token security to detect scams, honeypots, and malicious contracts across BSC, Base, Solana, and Ethereu 483 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
API Contract Review
API platform contract review. Invokes api-platform-reviewer to audit rate-limit design, OAuth scope hygiene, w
Audit MCP Error Semantics
Catch Resend-class bug (isError: false on HTTP 4xx/5xx) across all MCP server tool handlers
Adversarial Audit Engine
Cross-model audit engine for documents and technical artifacts: hallucination gate on verbatim quotes, claim v
TypeScript Senior Review
Claude Code plugin: senior TypeScript developer code reviewer. Reviews your TS code across 18 angles — quality
Audit Mirage Analyze
Phases 2-3 and 7 of auditing-green-mirage: systematic line-by-line audit, the Green Mirage Patterns, named ass
QA Lab
Two-agent QA and application security assessment workspace. Two AI coding agents from two providers run indepe
Related Agents
API Contract Tester
Use to verify HTTP/API contracts - request and response schemas, status codes, error shapes, versioning and ba
API Contract Auditor
Internal dynos-work agent. Audits API, event, RPC, and schema contracts for compatibility, error semantics, an
Rondoflow Reviewer
Reviews a RondoFlow code change against this project's specific conventions and security rules (child_process