- Home
- Skills
- Testing & Debugging
- API Contract Tester
Works with the AI tools you already use
API Contract Tester
This skill operates in two high-impact modes: GENERATE: Builds a complete test repository from a spec or description.
$5
API Contract Tester
Example session with this skill installed
Generate tests from our OpenAPI 3.1 spec for an Express + Postgres orders API: POST /orders (body: productId UUID, quantity integer 1 to 100) and GET /orders/{id}, both behind bearer auth, returning 201, 200, 400, 401 and 404. We use Jest + supertest.
- Read your context and instructions
- Compiled the api contract tester
Test suite and coverage matrix for 2 operations, 16 cases across all five test types.
Coverage matrix
| ID | Endpoint | Type | Case | Expect |
|---|---|---|---|---|
| H1 | POST /orders | Happy | Valid body, quantity 5 | 201, matches schema |
| H2 | GET /orders/{id} | Happy | Existing id | 200, matches schema |
| E1 | POST | Edge | quantity 1 | 201 |
| E2 | POST | Edge | quantity 100 | 201 |
| N1 | POST | Negative | quantity 0 | 400 |
| N2 | POST | Negative | quantity 101 | 400 |
| N3 | POST | Negative | quantity "5" (string) | 400 |
| N4 | POST | Negative | productId not a UUID | 400 |
| N5 | POST | Negative | Missing productId | 400 |
| N6 | GET | Negative | Unknown UUID | 404 |
| N7 | GET | Negative | id "abc" | 400 |
| C1 | Both | Contract | Response headers and body match spec | Pass |
| S1 | Both | Security | No token | 401 |
| S2 | Both | Security | Malformed token | 401 |
| S3 | POST | Security | SQL string in productId | 400 |
| S4 | GET | Security | Other user's order id | 404 |
Sample tests
test('N2 rejects quantity above 100', async () => {
const res = await request(app).post('/orders')
.set('Authorization', `Bearer ${token}`)
.send({ productId: uuid(), quantity: 101 });
expect(res.status).toBe(400);
});
Next steps
- Confirm S4: the spec does not say whether cross-user reads return 403 or 404.
- Add jest-openapi so C1 validates every response.
- Seed a fixed order in a test database for H2.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Streamline Your API Reliability
The API Contract Tester is a specialized skill for developers and QA engineers who need to move beyond basic smoke tests. It transforms OpenAPI/Swagger specifications into exhaustive, framework-ready test suites that cover the "dark corners" of your API—validation logic, authz boundaries, and schema conformance.
What it does
This skill operates in two high-impact modes:
- GENERATE: Builds a complete test repository from a spec or description. It goes deep, creating tests for happy paths, negative input validation, schema strictness, authentication/authorization, and defensive security cases.
- AUDIT: Analyzes your existing test suite against your contract to find "silent killers"—untested status codes, response bodies that aren't validated against schemas, and missing edge cases that lead to production outages.
Supported Tools & Frameworks
The skill adapts to your stack, generating idiomatic code for frameworks like Jest/Supertest, Pytest/HTTPX, Playwright API, RestAssured, Vitest, and more. It focuses on REST/JSON architectures where contract drift is the primary risk.
Why use this skill?
Manual test writing often misses the boring but critical negative cases. This skill automates the creation of 4xx and 5xx test scenarios, ensures every documented schema constraint is actually checked, and identifies IDOR vulnerabilities. The output is a runnable, professional-grade test suite with a coverage matrix that maps every endpoint and status code to a specific test ID.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 3 months ago
- Passed all security checks, Safe to install