api-contract-enforcement
Installation
SKILL.md
API contract enforcement
A public API is a promise. This skill reviews PRs for unannounced changes to that promise — the kind of edit that ships green CI in your repo but breaks every consumer the moment it lands.
What counts as "public API" for this skill
In rough order of consequence:
- HTTP routes and request/response shapes — REST endpoints, JSON-RPC methods, OpenAPI schemas.
- gRPC services and message definitions — protobuf field numbers, deprecated tags, oneof variants.
- GraphQL schemas — types, fields, arguments, directives, enum values.
- SDK exports — anything a package's
index.ts/__init__.py/ package's main entry re-exports. Types AND runtime values. - CLI flags, subcommands, and exit codes — anything documented in
--helpor relied on by scripts. - Database column names, view definitions, materialized views — when the schema is consumed by readers outside the PR's own service.
- Event payload shapes — Kafka topics, webhook bodies, queue messages.
- Configuration file schemas — when a config file is read by code outside the PR's service.
What this skill is not for: internal helper functions, private classes, package-internal modules. Convention says those can change.