SKILL.md
API HTTP Test
Goal
Use this skill to run real HTTP requests with reusable project configuration and authentication.
Script location
<project-root>/.skills/api-http-test/is config-only and storeshttp.toml.- Helper scripts live in the installed skill directory under
scripts/. - If the current directory is not the target project, set
HTTPPROJECTROOT=/path/to/repo.
First-time setup (required)
- Trigger setup with
/api-http-test install. - The install action must call:
- HTTPPROJECTROOT=/path/to/repo /path/to/api-http-test/scripts/apihttptest.sh install
- This creates
.skills/api-http-test/http.tomlin the target project.
Fast path
- Install/bootstrap profile:
- HTTPPROJECTROOT=/path/to/repo /path/to/api-http-test/scripts/apihttptest.sh install
- Run request:
- HTTPPROJECTROOT=/path/to/repo HTTPPROFILE=local /path/to/api-http-test/scripts/apihttp_test.sh request GET /health
- Run POST with JSON:
- HTTPPROJECTROOT=/path/to/repo HTTPPROFILE=local /path/to/api-http-test/scripts/apihttp_test.sh request POST /auth/login --body '{"username":"demo","password":"demo"}'
Workflow
- Ensure project config exists:
- If .skills/api-http-test/http.toml is missing, run bootstrap (install flow).
- Resolve auth mode:
- Prefer autodetect suggestion during bootstrap. - If unclear, use explicit authmode in TOML (bearer|basic|apikey|none).
- Resolve endpoint from docs when available:
- If <project-root>/docs/ exists and contains OpenAPI YAML files, treat them as source of truth for method/path/params. - Use documented path prefix and required params exactly as defined in YAML. - Only fallback to controller-derived routes when docs are missing or clearly stale.
- Execute request:
- Use runhttp.sh with profile selection (HTTPPROFILE or --profile). - Support custom headers, query params, and raw/body-file payload. - Persist session cookies from Set-Cookie and reuse them automatically on next requests.
- Report outcome:
- Return status, URL, auth mode used, and response body.
Trigger rules (summary)
- If user explicitly asks to initialize config or says install, run bootstrap flow.
- If user asks to run/test an endpoint realistically, use
run_http.sh. - If
docs/OpenAPI YAML exists, read docs first and build the request from documented method/path. - If auth errors occur (401/403), verify profile auth fields and re-run.
- If no profile is specified and multiple are present, ask user which profile to use.
Security guardrails
- Do not commit credentials; ensure
.skills/api-http-test/http.tomlis gitignored. - Do not commit cookie jars; ensure
.skills/api-http-test/.cookies/is gitignored. - Mask secrets in explanations when reporting logs.
- Use project-scoped config only for the target repository.
References
- Usage and examples:
references/http_usage.md - TOML schema:
references/httptomlschema.md