forge-apilisted
Install: claude install-skill seroneyemmanuel4-afk/fullstack-forge-skill
# forge-api: API design and implementation
## Purpose
Audit API contracts, boundary validation, authorization, consistency, pagination, errors, and idempotency.
Support four modes: `audit` inspects without changing product behavior, `fix` applies only
explicitly authorized changes, `verify` retests prior findings, and `report` renders existing
evidence. If no mode is supplied, use `audit`.
## Trigger conditions
Use this module when a request names `forge-api`, asks about api design and implementation, or
discovery finds an applicable boundary. Run it from the repository root after project discovery.
## When it applies
- HTTP, GraphQL, RPC, or event-consumed application interfaces
## When it does not apply
- Applications with no machine-consumed interface
Do not silently skip it. Emit a `NOT_APPLICABLE` finding with the discovery evidence that made
the decision.
## Inputs from project discovery
- route inventory
- API specifications
- handlers, middleware, and tests
Prefer `.forge/project-profile.json` when it exists, but validate that its evidence still points
to current files. Read `../fullstack-forge/references/PROTOCOL.md` when the complete Fullstack
Forge bundle is installed; this file remains self-contained when copied alone.
## Inspection procedure
1. Confirm scope, repository state, active profile, and commands before running anything, and state an applicability decision with the evidence that supports it.
2. Enumerate every route from router evidence, w