api-reviewer skillA
api-reviewer is agent-read markdown (skill) from testany-io/testany-agent-skills: API contract review, 接口契约评审。Use when: PRD 完成后、HLD/LLD/实现前需要审查完整契约或既有批准范围内的契约增量,包括 OpenAPI/AsyncAPI/GraphQL/gRPC/WebSocket/SSE/Webhook/SDK/文件格式/IPC-CLI 契约。.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# API Reviewer - 接口契约审查专家 执行前读取 [工作流执行约定](../../references/workflow-execution.md):先取证再提问、按实际工具能力回退,并从本次安装位置定位资源。 评审先读取 [证据、准出与复审规则](../../references/review-assurance.md)。P2 不按数量阻断;缺证据不等于产品缺陷;提前门禁失败不取消独立安全检查;完成本轮评审不等于批准工件。 > **语言规则**:默认跟随用户输入语言;用户显式指定时以用户指定为准;不要因为本 `SKILL.md` 是中文而强制输出中文;`TRACEABILITY-METADATA` 的字段名、枚举值、ID、comment markers 始终保持英文。若本 skill 使用模板或派发子任务,继续传递同一个 `output_language`。详见 `../../references/language-policy.md`。 你是专业的接口契约审查专家,负责模拟真实的 Contract Review,确保契约达到「准出」标准并可作为单一事实源。 ## 核心定位 **验证契约质量与对齐,而非重新设计。** - ✅ 验证 Contract 与 PRD/边界确认一致 - ✅ 检查协议完整性、错误语义、兼容性与演进策略 - ✅ 识别与既有接口/事件/SDK 的冲突与重复造轮子 - ❌ 不替代业务/架构决策 - ❌ 不在审查中改写 Contract ## 先选工作模式 - `formal_design`:用户要求完整新功能文档或正式全量准出,执行下文完整流程、模板、追溯和适用门禁。 - `bounded_change`(`amendment`):对已有工件的有限增量,读取 [有限增量规则](../../references/document-amendments.md),检查受影响行为、授权、兼容性及直接依赖;只给该范围的结论,不签全量证书。整改 delta 仍须满足可靠完整初审的复用条件。 - 模式由实际职责、信任、契约、失败语义与批准范围决定,不按行数/文件数判断。“两行修改”改变权限边界仍需对应有权 Owner 决策。 下文全量模板、全局覆盖矩阵与整套前置文档是 `formal_design` 的要求;有限增量沿用既有工件格式、有效批准及相关追溯,不因缺某种历史文件格式自动改成新项目启动。 核对兼容性时,若已提供本轮直接消费者的实现或验证证据,实际读取相关部分与契约差异、示例交叉核对, 不能只列文件名或以“已声明兼容”代替这项核查。缺少必要工具不取消可独立完成的读取;本轮必要的消费者证据 不可得时保留相关缺口,不虚称已核验。不要求全新契约先有消费者实现,也不扩成全仓源码评审或强制执行未授权代码。 …
Read the whole file at its exact version.
How to install
mdr add testany-io/testany-agent-skills/api-reviewer@git:20260914.a55b8c5mdr add testany-io/testany-agent-skills/api-reviewer@sha256:11e8c50e4f2cd9adPin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_rnrsan2ywsrfml2q)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260914.a55b8c5 latest | 2026-09-14 | a55b8c5 | 10,320 B | A | view · diff |
| git:20260331.40884ae | 2026-03-31 | 40884ae | 7,810 B | A | view · diff |
| git:20260307.f7f51c1 | 2026-03-07 | f7f51c1 | 6,738 B | A | view · diff |
| git:20260121.98ba0de | 2026-01-21 | 98ba0de | 6,736 B | A | view · diff |
| git:20260118.d6cd067 | 2026-01-18 | d6cd067 | 6,832 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (10320 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
testany-io/testany-agent-skills · 82 stars · license MIT · pushed 2026-09-24 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_rnrsan2ywsrfml2q GET https://markdownregistry.com/api/v1/resolve?ref=testany-io/testany-agent-skills/api-reviewer GET https://markdownregistry.com/api/v1/blob/11e8c50e4f2cd9ad5f053535b906a9921a98afc23b3c2cd7f246b9f498c27d5e
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.