Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    API Contract Tester

    1

    This skill operates in two high-impact modes: GENERATE: Builds a complete test repository from a spec or description.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    API Contract Tester

    API Contract Tester

    Example session with this skill installed

    Generate tests from our OpenAPI 3.1 spec for an Express + Postgres orders API: POST /orders (body: productId UUID, quantity integer 1 to 100) and GET /orders/{id}, both behind bearer auth, returning 201, 200, 400, 401 and 404. We use Jest + supertest.

    • Read your context and instructions
    • Compiled the api contract tester

    Test suite and coverage matrix for 2 operations, 16 cases across all five test types.

    Coverage matrix

    IDEndpointTypeCaseExpect
    H1POST /ordersHappyValid body, quantity 5201, matches schema
    H2GET /orders/{id}HappyExisting id200, matches schema
    E1POSTEdgequantity 1201
    E2POSTEdgequantity 100201
    N1POSTNegativequantity 0400
    N2POSTNegativequantity 101400
    N3POSTNegativequantity "5" (string)400
    N4POSTNegativeproductId not a UUID400
    N5POSTNegativeMissing productId400
    N6GETNegativeUnknown UUID404
    N7GETNegativeid "abc"400
    C1BothContractResponse headers and body match specPass
    S1BothSecurityNo token401
    S2BothSecurityMalformed token401
    S3POSTSecuritySQL string in productId400
    S4GETSecurityOther user's order id404

    Sample tests

    test('N2 rejects quantity above 100', async () => {
      const res = await request(app).post('/orders')
        .set('Authorization', `Bearer ${token}`)
        .send({ productId: uuid(), quantity: 101 });
      expect(res.status).toBe(400);
    });
    

    Next steps

    • Confirm S4: the spec does not say whether cross-user reads return 403 or 404.
    • Add jest-openapi so C1 validates every response.
    • Seed a fixed order in a test database for H2.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Generate framework-ready test suites from OpenAPI or Swagger specs.Audit existing test suites to identify untested paths and schema drift.Create negative test cases for every validation constraint in your API.Verify authorization and IDOR protection across all protected endpoints.Produce a coverage matrix mapping endpoints to specific test IDs.

    About this skill

    Streamline Your API Reliability

    The API Contract Tester is a specialized skill for developers and QA engineers who need to move beyond basic smoke tests. It transforms OpenAPI/Swagger specifications into exhaustive, framework-ready test suites that cover the "dark corners" of your API—validation logic, authz boundaries, and schema conformance.

    What it does

    This skill operates in two high-impact modes:

    • GENERATE: Builds a complete test repository from a spec or description. It goes deep, creating tests for happy paths, negative input validation, schema strictness, authentication/authorization, and defensive security cases.
    • AUDIT: Analyzes your existing test suite against your contract to find "silent killers"—untested status codes, response bodies that aren't validated against schemas, and missing edge cases that lead to production outages.

    Supported Tools & Frameworks

    The skill adapts to your stack, generating idiomatic code for frameworks like Jest/Supertest, Pytest/HTTPX, Playwright API, RestAssured, Vitest, and more. It focuses on REST/JSON architectures where contract drift is the primary risk.

    Why use this skill?

    Manual test writing often misses the boring but critical negative cases. This skill automates the creation of 4xx and 5xx test scenarios, ensures every documented schema constraint is actually checked, and identifies IDOR vulnerabilities. The output is a runnable, professional-grade test suite with a coverage matrix that maps every endpoint and status code to a specific test ID.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    • Passed all security checks, Safe to install

    Listed3 months ago
    Updated10 days ago

    What's inside

    Frequently Asked Questions