Integrations & APIs
Integration agent skills teach AI agents to work with specific external services and APIs: third-party platforms, webhooks, MCP servers, and data syncs. Instead of re-explaining an API every session, install the skill and the agent knows the endpoints and conventions.
-
mouadja02 Bundle M And A AdvisorTriggers on keywords M&A, due diligence, post-merger integration, synergy
-
mouadja02 Skill Github Cache HygieneGitHub quota/cache hygiene: answer reads from cache first, spend live API calls only for freshness or writes.
-
mouadja02 Bundle AI Code MigratorAutomate large-scale codebase migrations using AI — framework upgrades, language conversions, API modernization, and dependency swaps
-
mouadja02 Skill Typespec API OperationsAdd GET, POST, PATCH, and DELETE operations to a TypeSpec API plugin with proper routing, parameters, and adaptive cards
-
mouadja02 Skill Declarative AgentsComplete development kit for Microsoft 365 Copilot declarative agents with three comprehensive workflows (basic, advanced, validation), TypeSpec support, and Microsoft 365 Agents Toolkit integration
-
mouadja02 Bundle Framework Fastapi ExpertUse when the user asks to work on a Python FastAPI project. Triggers on keywords Python, FastAPI, Pydantic, SQLAlchemy.
-
mouadja02 Bundle Stripe Integration ExpertImplement production-grade Stripe integrations
-
mouadja02 Skill Typespec Create API PluginGenerate a TypeSpec API plugin with REST operations, authentication, and Adaptive Cards for Microsoft 365 Copilot
-
mouadja02 Skill Openapi To Application CodeGenerate a complete, production-ready application from an OpenAPI specification
-
mouadja02 Bundle Python Pypi Package BuilderBuild, test, lint, version, publish Python library to PyPI — all build tool flavors
-
mouadja02 Bundle Copilot Usage MetricsRetrieve and display GitHub Copilot usage metrics for organizations and enterprises using the GitHub CLI and REST API.
-
mouadja02 Skill Transloadit Media ProcessingProcess media files (video, audio, images, documents) using Transloadit
-
openclaw-commons Skill Hasura GRAPHQLHasura Graphql
-
killvxk Bundle Detecting Shadow API Endpoints通过流量分析、代码扫描和API发现平台,发现和清点在已记录规范之外运行的影子API(Shadow API)端点。
-
killvxk Bundle Exploiting Idor Vulnerabilities通过操纵 API 请求和 URL 中的对象标识符,识别并利用不安全的直接对象引用(IDOR)漏洞以访问未授权资源。
-
killvxk Bundle Performing Osint With Spiderfoot使用 SpiderFoot REST API 和 CLI 自动化 OSINT 收集,用于目标画像、基于模块的侦察,以及跨 200+ 数据源的结构化结果分析
-
killvxk Bundle Deploying Ransomware Canary Files使用 Python watchdog 库在关键目录中部署并监控勒索软件诱饵文件(Canary File),实现实时文件系统事件检测。 将策略性命名的诱饵文件(模拟高价值目标,如财务记录、凭据、数据库导出)放置在勒索软件通常优先枚举的 目录中,监控对诱饵文件的任何读取、修改、重命名或删除操作,并在检测到交互时通过 Email、Slack Webhook 或 Syslog 触发即时告警,在完整加密开始前提供早期预警。
-
killvxk Bundle Detecting API Enumeration Attacks通过监控顺序标识符访问模式和授权失败,检测和防止API枚举攻击,包括BOLA(越权对象访问)和IDOR(不安全的直接对象引用)利用。
-
killvxk Bundle Exploiting OAUTH Misconfiguration在安全评估期间识别并利用 OAuth 2.0 和 OpenID Connect 错误配置,包括重定向 URI 操纵、令牌泄漏和授权码窃取。
-
killvxk Bundle Hunting For Dns Based Persistence使用被动 DNS 数据库、SecurityTrails API 和 DNS 审计日志分析,狩猎 DNS 劫持、悬空 CNAME 记录、通配符 DNS 滥用和未授权区域修改等 DNS 持久化机制。
-
killvxk Bundle Testing Mobile API Authentication测试移动应用 API 的认证与授权机制,识别认证失效、不安全的令牌管理、会话固定、 权限提升和 IDOR 漏洞。适用于对移动应用后端进行 API 安全评估、测试 JWT 实现、 评估 OAuth 流程或评估会话管理的场景。适合涉及移动 API 认证测试、令牌安全评估、 OAuth 移动端流程测试或 API 授权绕过的相关请求。
-
killvxk Bundle Detecting Email Account Compromise通过分析收件箱规则创建、可疑登录位置、邮件转发规则和异常 API 访问模式,检测受攻陷的 O365 和 Google Workspace 邮件账号。
-
killvxk Bundle Performing API Fuzzing With Restler使用 Microsoft RESTler 执行有状态 REST API 模糊测试(Fuzzing),通过自动生成并执行测试序列来 覆盖 API 端点,发现请求间的生产者-消费者依赖关系,并找出安全性和可靠性缺陷。 测试人员将 OpenAPI 规范编译为 RESTler 模糊测试语法,配置认证,运行 test/fuzz-lean/fuzz 模式,并分析结果以发现 500 错误、认证绕过、资源泄漏和载荷注入漏洞。 当请求涉及 API 模糊测试、RESTler 测试、有状态 API 测试或自动化 API 安全扫描时触发。
-
killvxk Bundle Testing For Sensitive Data Exposure在安全评估中识别敏感数据暴露漏洞,包括 API 密钥泄露、响应中的 PII、不安全存储以及未受保护的数据传输。
-
killvxk Bundle Testing Oauth2 Implementation Flaws测试 OAuth 2.0 和 OpenID Connect 实现中的安全缺陷,包括授权码拦截、重定向 URI 操控、OAuth 流程中的 CSRF、令牌泄露、权限范围(scope)提升以及 PKCE 绕过。测试人员对授权服务器、客户端应用及令牌处理进行评估,发现可导致账户接管或未授权访问的常见错误配置。适用于 OAuth 安全测试、OIDC 漏洞评估、OAuth2 重定向绕过或授权码流程测试相关请求。
-
openclaw-commons Skill API DevApi Dev
-
openclaw-commons Skill Hug APIHug Api
-
openclaw-commons Skill API DocsApi Docs
-
caishengold Bundle Technical Writing当需要编写技术文档、API文档、操作手册时使用。
-
mouadja02 Skill Xurlxurl X/Twitter API CLI: install, auth, app choice, shortcuts, raw endpoints.
-
vincentchuwaichow Bundle Salesforce Apex Test Runner SkillExecutes Apex tests against a connected SANDBOX org via sf apex run test, parses results and coverage delta, identifies failures with stack traces, and suggests fixes. T1 read-only runtime (sandbox-only). Production org targets are HARD REFUSED before any API call. TRIGGER when: user wants to run Apex tests, execute a test class, check test coverage, diagnose test failures, or validate coverage before deployment. Trigger phrases: run apex tests, execute test class, test my changes, check test coverage, why is my test failing. DO NOT TRIGGER when: user needs to generate test classes (use salesforce-apex-test-generator-skill), debug without running tests (use salesforce-apex-log-analyzer-skill), static code review of test code (use salesforce-apex-lwc-code-review-skill), or user needs a deployment (use salesforce-deployment-validator-skill).
-
vincentchuwaichow Bundle D365 Live Record Field Update GuardMutating-runtime live-guard for updating one or more named fields on a single Dataverse row identified by table and record GUID, via the Dataverse Web API PATCH (data plane). Strictly scoped — one record, named fields only. Requires explicit written human approval token referencing the exact target, proposed change, and blast-radius. PREFLIGHT performs a dry-run diff before any write. Fully reversible — prior field values are captured and the inverse PATCH is the rollback. Gate-only; never auto-dispatched. Phase B mutating-runtime.
-
vincentchuwaichow Bundle Salesforce Integration Review SkillSalesforce Integration Review Skill
-
vincentchuwaichow Bundle Snowflake Live Auth Network Policy GuardApproval-gated live guard for exactly one Snowflake network-policy or authentication-policy change. Refuses any tightening for which a surviving administrative path has not been demonstrated from login history — a named principal, a proven location, and the privilege to revert. Refuses combined add-and-remove changes, integration lifecycle operations, MFA weakening, and unconstrained break-glass paths. Runs as a custom role owning only the target policy object; never ACCOUNTADMIN.
-
vincentchuwaichow Bundle Typescript Node Execution CompatibilityUse this skill to statically review whether TypeScript code runs on the stated target Node version and is type-checked somewhere before production: type-stripping limits, runtime-unsupported syntax, proof of a separate `tsc --noEmit` gate, `paths`-alias and import-extension requirements, and Node version/API gating. Reads source, the run command, CI configuration, and every `tsconfig.json` only; it never executes code and never assumes a Node version.
-
vincentchuwaichow Bundle Netsuite Sandbox Nonproduction Governance SkillStatic-review flashlight for NetSuite sandbox, Release Preview, and non-production environment governance. Enforces the confirmed isolation facts: OAuth 2.0 authorized apps and client credentials flow setup in production are NOT copied to sandbox or Release Preview (and are cleared on each sandbox refresh); TBA tokens created in production are NOT copied to sandbox or Release Preview. Enforces that sandbox success does not equal production readiness without explicit re-authorization. TRIGGER when: user asks about sandbox governance, OAuth app re-authorization after sandbox refresh, TBA token management across environments, Release Preview usage policies, environment isolation between production and sandbox, sandbox-to-production promotion readiness, or sandbox refresh impact on integration testing. Trigger phrases: sandbox refresh, OAuth re-authorize sandbox, Release Preview isolation, sandbox governance, non-production environment, sandbox success production readiness, TBA token sandbox. DO NOT TRIGGER when:
Frequently asked questions
What are Integrations & APIs agent skills?
Integration agent skills teach AI agents to work with specific external services and APIs: third-party platforms, webhooks, MCP servers, and data syncs. Instead of re-explaining an API every session, install the skill and the agent knows the endpoints and conventions.
Which Integrations & APIs skills are most installed?
Popular Integrations & APIs skills on SkillMD right now include framework-fastapi-expert, performing-api-fuzzing-with-restler, api-dev. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Integrations & APIs skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.