Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问clear审计通过

qa-api-testing-contractsQA API 测试 contracts

Agent Skill

用于辅助 API 设计、接口文档、请求响应结构和服务集成说明。它适合让 Agent 梳理 endpoint、生成 OpenAPI 草稿、检查字段命名、整理错误码或辅助前后端联调。使用时需要确认真实业务语义、鉴权方式、分页和错误处理规则;涉及生成接口文档时,应避免凭空补字段,最好从现有代码、schema 或接口样例中提取事实。

总安装

2,424

周安装

101

GitHub Stars

60

下载量

808
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:qa-api-testing-contracts(QA API 测试 contracts)
来源仓库:https://github.com/vasilyu1983/ai-agents-public
仓库路径:skills/qa-api-testing-contracts
安装命令:
npx skills add https://github.com/vasilyu1983/ai-agents-public --skill qa-api-testing-contracts
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/vasilyu1983/ai-agents-public --skill qa-api-testing-contracts

简介

qa-api-testing-contracts 用于辅助 API 设计、接口文档和错误码整理,适合前后端联调支持。

  • 适用于梳理 endpoint、生成 OpenAPI 草稿或检查字段命名。
  • 通过 npx skills add 命令从指定 GitHub 仓库安装使用。
  • 需确认业务语义和鉴权方式,避免凭空补字段。
  • 适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。

SKILL.md

QA API Testing and Contracts

Use this skill to turn an API schema into enforceable checks (lint, diff, contracts, and negative/security cases) and wire them into CI so breaking changes cannot ship silently.

Ask For Inputs

  • API type and canonical schema artifact (OpenAPI 3.1, SDL, proto) and where it lives in-repo.
  • Environments, auth method(s), and how to provision stable test identities/keys.
  • Critical endpoints/operations and business flows (rank by risk and revenue impact).
  • Data constraints (idempotency keys, pagination, ordering), rate limits, and error format (prefer RFC 7807 application/problem+json for REST).
  • Versioning + deprecation policy, consumer inventory, and release cadence.
  • Current test tooling/CI and what “blocking” means for your org.

Outputs (What to Produce)

  • A minimal CI gate set (lint + breaking diff + contract suite) wired to PRs.
  • A coverage map derived from the schema (critical operations first).
  • A negative/security baseline aligned to OWASP API risks.

Quick Start

  1. Lint the schema (syntax + best-practice rules) and fix issues before writing tests.
  2. Add breaking-change checks against the base branch on every PR.
  3. Pick a contract strategy (CDC, schema-driven, or both) and run it in CI against an ephemeral environment.
  4. Add negative/security cases for auth, validation, and error handling.
  5. Make gates explicit (what blocks merge/release) and publish results.

Workflow

1) Establish Contract Artifacts (Source of Truth)

  • REST: single OpenAPI 3.1 file or a compiled artifact; avoid drift across fragments.
  • GraphQL: checked-in SDL (and federation/composition config if relevant).
  • gRPC: checked-in .proto + buf.yaml (or equivalent) with a stable module layout.

2) Validate the Schema (Fast, Deterministic)

  • Run spec linting (Spectral / GraphQL Inspector / buf lint).
  • Enforce a small, explicit ruleset (naming, descriptions, auth annotations, consistent error model).

3) Detect Breaking Changes (PR Gate)

  • REST: OpenAPI diff with a breaking-change policy (remove/rename/type change/requiredness).
  • GraphQL: schema diff with breaking checks (field removals, type changes, non-null tightening).
  • gRPC: buf breaking (do not reuse/renumber fields; avoid changing request/response shapes incompatibly).

4) Execute Contract Tests (CI Gate)

Choose one or combine:

  • CDC (Pact): best when many independent consumers exist and behavior matters beyond schema.
  • Schema-driven (Specmatic): best when schema is the contract and you want fast coverage across operations.
  • Property-based (Schemathesis): best when you want systematic edge cases and server hardening.

5) Add Negative + Security Cases (Minimum Set)

  • AuthN/AuthZ: missing/expired token (401), insufficient scope/role (403), tenant isolation.
  • Validation: missing required fields, invalid types, boundary values, empty strings, large payloads.
  • Error handling: stable error shape, safe messages, correct status codes, correlation IDs.
  • Abuse & limits: rate limiting (429), pagination limits, idempotency replay, retry-safe semantics.

- For GraphQL, also validate operations checks (known/persisted queries) if you have an operation registry (GraphOS/Hive/etc.).

6) Define CI Quality Gates (Merge + Release)

  • Pre-merge: schema lint + breaking-change diff (blocking).
  • Pre-release: contract suite (blocking), plus smoke/functional tests for critical flows.
  • Reporting: publish artifacts (diff report, contract verification, failing cases) and link in PR.

Quality Checks

  • Fail fast: schema violations and breaking changes block merge.
  • Determinism: isolate data, freeze time where needed, avoid shared mutable fixtures.
  • Flake hygiene: separate network instability from contract failures; retry only for known-transient classes.
  • Alignment: contracts reflect versioning/deprecation policy and consumer inventory.
  • Scope control: keep load/resilience tests separate unless explicitly requested.

Use the Bundled Templates

  • Coverage plan: assets/api-test-plan.md
  • Release review: assets/contract-change-checklist.md
  • Tooling map: assets/schema-validation-matrix.md

AI Assistance (Use Carefully)

  • Use AI to draft tests, suggest missing edge cases, and tighten matchers.
  • Treat AI output as untrusted until verified against the schema and real behavior.
  • Avoid uploading sensitive payloads; sanitize examples and logs.
  • For a tool comparison and workflows, read references/ai-contract-testing.md.

Read These When Needed

  • Change safety and CDC patterns: references/contract-testing-patterns.md
  • AI-assisted tooling and decision matrix: references/ai-contract-testing.md
  • API versioning and backward compatibility: references/api-versioning-strategies.md
  • Schema-driven and property-based testing: references/schema-driven-testing.md
  • OWASP API security testing: references/api-security-testing.md
  • Curated authoritative links: data/sources.json

Related Skills

Fact-Checking

  • Use web search/web fetch to verify current external facts, versions, pricing, deadlines, regulations, or platform behavior before final answers.
  • Prefer primary sources; report source links and dates for volatile information.
  • If web access is unavailable, state the limitation and mark guidance as unverified.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

30.09%
按下载量换算243

Cursor

23.7%
按下载量换算191

Antigravity

16.38%
按下载量换算132

OpenCode

13.63%
按下载量换算110

Gemini CLI

8.72%
按下载量换算70

Codex

3.28%
按下载量换算27

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。

来源信息

继续浏览同类 Skills