API Design Reviewer
Comprehensive analysis and review of REST API designs against conventions, best practices, and industry standards. Helps engineering teams build consistent, maintainable, well-designed APIs through automated linting, breaking-change detection, and design scorecards.
Core Capabilities
- API linting & convention analysis — resource naming (kebab-case URLs, camelCase fields), HTTP method usage, URL structure, status-code compliance, error-format consistency, and documentation coverage.
- Breaking change detection — endpoint removal, response-shape changes, field removal/rename, type changes, new required fields, and status-code changes between two spec versions, with migration guides.
- API design scoring — weighted scorecard across Consistency (30%), Documentation (20%), Security (20%), Usability (15%), and Performance (15%), with letter grades A–F and recommendations.
When to Use
- Designing a new REST API or reviewing an API contract.
- Validating an OpenAPI/Swagger spec against REST conventions.
- Managing API versioning and detecting breaking changes between releases.
- Gating deployments on API design quality in CI.
Clarify First
Before producing the review, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
Tools
| Tool |
Purpose |
Command |
api_linter.py |
Lint an OpenAPI/Swagger JSON spec for REST conventions and best practices |
python scripts/api_linter.py openapi.json --format json |
breaking_change_detector.py |
Detect breaking changes between two spec versions (with migration guides) |
python scripts/breaking_change_detector.py v1.json v2.json --exit-on-breaking |
api_scorecard.py |
Score API design quality across 5 weighted dimensions (A–F grades) |
python scripts/api_scorecard.py openapi.json --min-grade B |
References
Load the reference that matches the task — keep this file lean and pull detail on demand:
- references/rest-design-patterns.md — REST naming/method/URL principles, versioning strategies, pagination patterns, error formats and status codes, auth/RBAC patterns, rate limiting, HATEOAS, idempotency, backward-compatibility rules, OpenAPI validation, performance, and security best practices. Read when designing or reviewing endpoints.
- references/tooling-ci-and-troubleshooting.md — the three tools' features, CI/CD and pre-commit integration, best-practices and anti-pattern checklists, troubleshooting table, success criteria, and full CLI flag references. Read when wiring tools into pipelines or debugging.
- references/rest_design_rules.md — detailed REST design rules reference (resources vs actions, HTTP method semantics with worked examples). Read for an in-depth rules catalog.
- references/api_antipatterns.md — common API anti-patterns (verb-based URLs / RPC trap and more) with bad/good examples and recommended fixes. Read when auditing an existing API for design smells.
Scope & Limitations
This skill covers:
- Linting OpenAPI 3.x and Swagger 2.0 JSON specifications against REST conventions
- Detecting breaking, potentially-breaking, and non-breaking changes between two spec versions
- Scoring API design quality across consistency, documentation, security, usability, and performance
- Generating actionable migration guides when breaking changes are found
This skill does NOT cover:
- Runtime API testing, load testing, or contract testing (see
api-test-suite-builder)
- GraphQL, gRPC, or WebSocket API design review
- Auto-generation of OpenAPI specs from code or server stubs
- Authentication flow implementation or OAuth server configuration (see
senior-security in engineering/)
Integration Points
| Skill |
Integration |
Data Flow |
engineering/api-test-suite-builder |
Generate test cases from linter findings |
Linter issues feed into test plan priorities for endpoint validation |
engineering/changelog-generator |
Document breaking changes in release notes |
Breaking change detector output provides structured change data for changelogs |
engineering/ci-cd-pipeline-builder |
Gate deployments on API quality |
Scorecard grade and linter exit codes integrate as pipeline quality gates |
engineering/senior-backend |
Review API implementation against design |
Scorecard recommendations guide backend refactoring decisions |
engineering/code-reviewer |
Enrich PR reviews with API analysis |
Linter and breaking change reports attach to PR review comments |
engineering/release-manager |
Validate version bumps match change severity |
Breaking change detector severity levels inform semver version decisions |
1---2name: api-design-reviewer3description: Review REST API designs for quality, consistency, and breaking changes. Lints OpenAPI specs, generates scorecards, and detects breaking changes between versions. Use when designing APIs, reviewing contracts, or managing API versioning.4license: MIT + Commons Clause5---6# API Design Reviewer
7
8Comprehensive analysis and review of REST API designs against conventions, best practices, and industry standards. Helps engineering teams build consistent, maintainable, well-designed APIs through automated linting, breaking-change detection, and design scorecards.
9
10## Core Capabilities
11
12- **API linting & convention analysis** — resource naming (kebab-case URLs, camelCase fields), HTTP method usage, URL structure, status-code compliance, error-format consistency, and documentation coverage.
13- **Breaking change detection** — endpoint removal, response-shape changes, field removal/rename, type changes, new required fields, and status-code changes between two spec versions, with migration guides.
14- **API design scoring** — weighted scorecard across Consistency (30%), Documentation (20%), Security (20%), Usability (15%), and Performance (15%), with letter grades A–F and recommendations.
15
16## When to Use
17
18- Designing a new REST API or reviewing an API contract.
19- Validating an OpenAPI/Swagger spec against REST conventions.
20- Managing API versioning and detecting breaking changes between releases.
21- Gating deployments on API design quality in CI.
22
23## Clarify First
24
25Before producing the review, confirm these inputs. If any is unknown or vague, ASK — do not assume:
26
27- [ ] **Which output** — lint report, design scorecard, or breaking-change detection (selects `api_linter.py`, `api_scorecard.py`, or `breaking_change_detector.py`)
28- [ ] **Spec file(s)** — the OpenAPI/Swagger JSON, or the two versions to diff (the input the tools parse)
29- [ ] **Quality bar / CI gate** — minimum grade or fail-on-breaking (sets `--min-grade` / `--exit-on-breaking` and how strict the verdict is)
30
31Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
32
33## Tools
34
35| Tool | Purpose | Command |
36|------|---------|---------|
37| `api_linter.py` | Lint an OpenAPI/Swagger JSON spec for REST conventions and best practices | `python scripts/api_linter.py openapi.json --format json` |
38| `breaking_change_detector.py` | Detect breaking changes between two spec versions (with migration guides) | `python scripts/breaking_change_detector.py v1.json v2.json --exit-on-breaking` |
39| `api_scorecard.py` | Score API design quality across 5 weighted dimensions (A–F grades) | `python scripts/api_scorecard.py openapi.json --min-grade B` |
40
41## References
42
43Load the reference that matches the task — keep this file lean and pull detail on demand:
44
45- **[references/rest-design-patterns.md](references/rest-design-patterns.md)** — REST naming/method/URL principles, versioning strategies, pagination patterns, error formats and status codes, auth/RBAC patterns, rate limiting, HATEOAS, idempotency, backward-compatibility rules, OpenAPI validation, performance, and security best practices. Read when designing or reviewing endpoints.
46- **[references/tooling-ci-and-troubleshooting.md](references/tooling-ci-and-troubleshooting.md)** — the three tools' features, CI/CD and pre-commit integration, best-practices and anti-pattern checklists, troubleshooting table, success criteria, and full CLI flag references. Read when wiring tools into pipelines or debugging.
47- **[references/rest_design_rules.md](references/rest_design_rules.md)** — detailed REST design rules reference (resources vs actions, HTTP method semantics with worked examples). Read for an in-depth rules catalog.
48- **[references/api_antipatterns.md](references/api_antipatterns.md)** — common API anti-patterns (verb-based URLs / RPC trap and more) with bad/good examples and recommended fixes. Read when auditing an existing API for design smells.
49
50## Scope & Limitations
51
52**This skill covers:**
53- Linting OpenAPI 3.x and Swagger 2.0 JSON specifications against REST conventions
54- Detecting breaking, potentially-breaking, and non-breaking changes between two spec versions
55- Scoring API design quality across consistency, documentation, security, usability, and performance
56- Generating actionable migration guides when breaking changes are found
57
58**This skill does NOT cover:**
59- Runtime API testing, load testing, or contract testing (see `api-test-suite-builder`)
60- GraphQL, gRPC, or WebSocket API design review
61- Auto-generation of OpenAPI specs from code or server stubs
62- Authentication flow implementation or OAuth server configuration (see `senior-security` in engineering/)
63
64## Integration Points
65
66| Skill | Integration | Data Flow |
67|-------|-------------|-----------|
68| `engineering/api-test-suite-builder` | Generate test cases from linter findings | Linter issues feed into test plan priorities for endpoint validation |
69| `engineering/changelog-generator` | Document breaking changes in release notes | Breaking change detector output provides structured change data for changelogs |
70| `engineering/ci-cd-pipeline-builder` | Gate deployments on API quality | Scorecard grade and linter exit codes integrate as pipeline quality gates |
71| `engineering/senior-backend` | Review API implementation against design | Scorecard recommendations guide backend refactoring decisions |
72| `engineering/code-reviewer` | Enrich PR reviews with API analysis | Linter and breaking change reports attach to PR review comments |
73| `engineering/release-manager` | Validate version bumps match change severity | Breaking change detector severity levels inform semver version decisions |