Need an API test plan, API cases, or API risk analysis.
The request involves REST, GraphQL, SOAP, gRPC, WebSocket, or mixed API behavior.
Workflow
Read and follow the main prompt listed under Progressive disclosure (coverage, structure, quality bar).
Add only project context that changes the result: scope, environment, constraints, risks, dependencies, expected deliverable.
If input is incomplete, return a usable first draft and explicitly mark assumptions and gaps.
Default to Markdown; switch formats only when the user asks.
Core Constraints
Prioritize by risk / business impact — do not treat everything equally.
Separate confirmed facts from current assumptions.
Do not invent endpoints, fields, environments, or root causes the user did not provide.
Keep output executable: concrete scenarios, clear priority, clear next steps.
Progressive Disclosure
Before producing output, read and follow prompts/api-testing.md (minimum coverage, output structure, quality bar).
When Excel/CSV/JSON/Word is requested: read output-formats.md and honor the format.
When a ready-made template fits: use matching files under output-templates/.
For deep framework/troubleshoot/schema notes: read only the relevant file(s) under references/, do not load the whole directory.
For format conversion or helper checks: prefer existing scripts/ over reinventing.
For evaluating/regressing this skill: use evals/ with skill-up.
Pre-delivery Checklist
[ ] Followed the main prompt's output structure
[ ] Minimum coverage focus: endpoints or business flows in scope, priority and risk level, positive scenarios, negative scenarios, boundary scenarios, auth and permission checks, request and response validation, error handling, ... (details in main prompt)
[ ] Covered the minimum checklist, or explained omissions
[ ] High-risk items have explicit priority
[ ] Did not invent details the user did not provide
[ ] Assumptions and gaps are marked
Common Pitfalls
Do not pretend completeness when scope/context is missing.
Do not treat every item as equally important.
Do not skip assumptions and information gaps.
Do not dump generic theory unrelated to the current toolchain.
How to use it
Copy the folder
Take naodeng/api-testing from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
Check the name does not clash
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.