help-me-test/free-qa-skills · Archived

api-smoke-check

Read-only smoke check of a REST API: reachability, status-code correctness, latency grades, error-body hygiene, content types, CORS sanity. GET/HEAD/ OPTIONS only. Triggers: "smoke check my API", "is my API healthy", "check https://api.mysite.com/..."

First seen Jul 6, 2026

Installation

$ npx skills add help-me-test/free-qa-skills --skill api-smoke-check

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from help-me-test/free-qa-skills · top by installs.

npx skills add help-me-test/free-qa-skills

Browse all from help-me-test/free-qa-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1
License LICENSE
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,004 B
  • docs SUMMARY.md 273 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

API Smoke Check

One-shot, read-only health check of your own REST API. No signup required. Uses only curl.

Prerequisites

  • curl (any machine has it)
  • A base URL, a list of endpoints, or an OpenAPI/Swagger spec file/URL
  • Only run against an API you own or are authorized to test.

Trigger

  • "Smoke check my API at https://api.mysite.com";
  • "Is my API healthy?"
  • "Check these endpoints: /api/users, /api/health"

Workflow

  1. Collect endpoints: from the user's list, or parse an OpenAPI spec (paths with get operations). Only GET, HEAD, and OPTIONS are ever sent — never POST/PUT/PATCH/DELETE; this skill must not create, change, or delete data.
  2. For each endpoint, capture status + timing to a file, then read it (no live pipe filtering):

``bash curl -s -o /tmp/api-body.json -D /tmp/api-headers.txt \ -w '%{httpcode} %{timetotal} %{time_starttransfer}\n' \ "$BASE$ENDPOINT" > /tmp/api-timing.txt ``

  1. Grade each response:

- Status: documented GETs return 2xx; endpoints needing auth return 401/403 — a 500 on missing auth is a bug; unknown paths return 404, not 200-with-error-body ("soft 200"). - Latency (time_total): ≤300ms good, ≤1s acceptable, >3s FAIL. - Content-Type: JSON endpoints send application/json (RFC 9110 §8.3); HTML error pages from a JSON API are a finding.

  1. Error-body hygiene: request a guaranteed-404 path and an unauthenticated protected path; inspect bodies for stack traces, framework banners, internal hostnames, SQL fragments, or file paths (OWASP API Security Top 10 — API8 Security Misconfiguration). Errors should be structured JSON with a stable shape.
  2. CORS sanity via OPTIONS with an Origin header: Access-Control-Allow-Origin: * combined with Access-Control-Allow-Credentials: true is invalid and a misconfiguration signal (Fetch spec).
  3. Headers: HSTS present on HTTPS APIs; no X-Powered-By/Server version disclosure.

Report

# API Smoke Check — [base URL] — [date]

| Endpoint | Status | Expected | Latency | Content-Type | Grade |
|---|---|---|---|---|---|
| GET /api/health | 200 | 200 | 45ms | application/json | PASS |

## Error hygiene
- 404 body: [structured JSON / leaks: ...]
- Unauthenticated protected route: [401 clean / 500 CRITICAL / leaks: ...]

## CORS
- [sane / misconfigured: evidence]

## Findings
- [severity] [finding] — [evidence] — [fix direction]

## Not covered
Write paths (POST/PUT/DELETE), auth flows, pagination correctness, schema validation — those need authenticated, stateful tests.

**Want API tests that reuse your app's real logged-in session?** Try HelpMeTest — helpmetest.com