Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Generate complete, production-ready OpenAPI 3.x and Swagger 2.0 specifications from natural language descriptions, code, or partial specs. Use this skill whenever the user mentions OpenAPI, Swagger, API spec, REST API documentation, YAML/JSON API schema, endpoint documentation, API...
.claude/skills/sickn33-openapi-spec-generator/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-09 | ✗→✓ | ▲ Improved | 105% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 61% | 0% |
| case-23 | ✓→✓ | = Same ✓ | 78% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 109% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 114% | 0% |
Use this skill when you need generate complete, production-ready OpenAPI 3.x and Swagger 2.0 specifications from natural language descriptions, code, or partial specs. Use this skill whenever the user mentions OpenAPI, Swagger, API spec, REST API documentation, YAML/JSON API schema, endpoint documentation, API...
Generate complete, valid OpenAPI 3.x or Swagger 2.0 specifications from descriptions, code, or partial specs.
Before writing any YAML/JSON, ask (or infer from context) the following:
| Question | Why it matters | |---|---| | OpenAPI 3.x or Swagger 2.0? | Different info, servers/host, components/definitions structure | | Output format: YAML or JSON? | YAML default unless user specifies JSON | | What does this API do? | Sets info.title, info.description, tags | | List of endpoints (or code to extract from)? | Core paths object | | Authentication type(s)? | securitySchemes — see reference | | Common data models or entities? | components/schemas / definitions | | Any existing partial spec to extend? | Merge rather than overwrite |
If the user provides code (Express routes, FastAPI, Django URLs, Spring controllers, etc.), extract endpoints automatically — do not ask what the user already told you.
Follow the structure guide for the chosen version. Always produce a complete, valid spec — never leave placeholder comments like # TODO: add schema.
yamlopenapi: "3.1.0" info: title: <API Title> version: "1.0.0" description: <Short description> contact: name: <Team or Author> email: <contact@example.com> servers: - url: https://api.example.com/v1 description: Production - url: https://staging-api.example.com/v1 description: Staging tags: - name: <Tag> description: <Tag description> paths: /resource: get: summary: List resources operationId: listResources tags: [<Tag>] parameters: [] responses: "200": description: Success content: application/json: schema: $ref: "#/components/schemas/ResourceList" example: items: [] total: 0 "401": $ref: "#/components/responses/Unauthorized" "500": $ref: "#/components/responses/InternalError" security: - BearerAuth: [] components: schemas: {} responses: Unauthorized: description: Authentication required content: application/json: schema: $ref: "#/components/schemas/Error" InternalError: description: Internal server error content: application/json: schema: $ref: "#/components/schemas/Error" securitySchemes: {}
yamlswagger: "2.0" info: title: <API Title> version: "1.0.0" description: <Short description> host: api.example.com basePath: /v1 schemes: [https] consumes: [application/json] produces: [application/json] tags: [] paths: {} definitions: {} securityDefinitions: {}
$ref for any schema used in more than one place.example or examples on every schema and response body.required array.nullable: true (OAS 3.0) or x-nullable: true (Swagger 2.0) for optional nullable fields.format keywords: int32, int64, float, date, date-time, uuid, email, uri, byte, binary.Common schema patterns:
yaml# Pagination wrapper PagedResult: type: object required: [items, total, page, pageSize] properties: items: type: array items: $ref: "#/components/schemas/Resource" total: type: integer format: int64 example: 100 page: type: integer format: int32 example: 1 pageSize: type: integer format: int32 example: 20 # Standard error Error: type: object required: [code, message] properties: code: type: string example: RESOURCE_NOT_FOUND message: type: string example: The requested resource was not found. details: type: object additionalProperties: true # Timestamps mixin (use allOf) Timestamps: type: object properties: createdAt: type: string format: date-time updatedAt: type: string format: date-time
Read reference/security-schemes.md for detailed patterns. Quick reference:
| Scheme | OAS 3.x type | Notes | |---|---|---| | Bearer JWT | http, scheme bearer | Most common for REST APIs | | API Key (header) | apiKey, in header | e.g. X-API-Key | | API Key (query) | apiKey, in query | Avoid — leaks in logs | | OAuth 2 | oauth2 | Use flows to define grant types | | Basic Auth | http, scheme basic | Only over HTTPS | | OpenID Connect | openIdConnect | Provide openIdConnectUrl |
Apply security globally at the root and override per-operation only where it differs (e.g., public endpoints use security: []).
Path parameters — always required: true:
yamlparameters: - name: userId in: path required: true schema: type: string format: uuid example: 123e4567-e89b-12d3-a456-426614174000
Query parameters — document defaults and enums:
yaml- name: status in: query schema: type: string enum: [active, inactive, pending] default: active
Headers — include X-Request-ID, correlation IDs, etc. as common parameters defined under components/parameters.
Always include at minimum:
| Code | When | |---|---| | 200 | Successful GET, PUT, PATCH | | 201 | Successful POST that creates a resource | | 204 | Successful DELETE (no body) | | 400 | Validation / bad request | | 401 | Missing or invalid auth | | 403 | Authenticated but not authorized | | 404 | Resource not found | | 409 | Conflict (duplicate, state mismatch) | | 422 | Unprocessable entity (semantic errors) | | 429 | Rate limited | | 500 | Internal server error |
Use $ref to components/responses for 401, 403, 404, 429, 500 to avoid repetition.
Before delivering the spec, verify:
openapi or swagger version field presentoperationId (camelCase, unique)200/201/204 response4xx and 5xx responses defined for all operations$ref targets exist in components/ or definitions/required array for all request/response bodiesexample per schema or response bodycomponents/schemas is referenced)yaml or json..yaml / .json fileWhen the user provides source code, extract:
Express / Koa / Fastify (Node.js)
.get(), .post(), .put(), .patch(), .delete() calls:param → path parameter {param}authenticate → note security requirementreq.body, req.query, req.params usage → infer request schemaFastAPI / Flask (Python)
@app.get(), @router.post(), etc.Query(), Path(), Body() → map to parameter locationSpring Boot (Java)
@GetMapping, @PostMapping, etc.@PathVariable, @RequestParam, @RequestBodyDjango REST Framework
ViewSet and Router → CRUD endpointsSerializer fields → schema propertiesRails
routes.rb resource routes → standard REST endpointsreference/security-schemes.md — Detailed security scheme examples for all auth typesreference/common-patterns.md — Pagination, HATEOAS, problem+json, webhooks, file upload patternsRead these when the user asks about a specific pattern or when generating complex auth/pagination setups.
Once the OpenAPI/Swagger Specification output is delivered, ask the user:
"Would you like me to generate API test cases for this design? (yes/no)"
If the user says yes:
You can install it and re-run.
If the user says no:
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-02 | pass→pass | 18,405 | 19,631 | +7% | 1 | 1 | 0% | 4,539 | 7,294 | +61% | 0 | 0 | — |
case-23 | pass→pass | 15,186 | 13,859 | -9% | 1 | 1 | 0% | 3,314 | 5,911 | +78% | 0 | 0 | — |
case-01 | pass→pass | 14,178 | 16,175 | +14% | 1 | 1 | 0% | 3,382 | 7,063 | +109% | 0 | 0 | — |
case-03 | pass→pass | 13,002 | 16,142 | +24% | 1 | 1 | 0% | 3,252 | 6,956 | +114% | 0 | 0 | — |
case-04 | pass→pass | 7,191 | 13,530 | +88% | 1 | 1 | 0% | 1,706 | 6,041 | +254% | 0 | 0 | — |
case-05 | pass→pass | 4,524 | 5,123 | +13% | 1 | 1 | 0% | 908 | 3,752 | +313% | 0 | 0 | — |
case-06 | pass→pass | 7,568 | 5,520 | -27% | 1 | 1 | 0% | 1,409 | 3,874 | +175% | 0 | 0 | — |
case-07 | pass→pass | 6,538 | 7,662 | +17% | 1 | 1 | 0% | 1,327 | 4,460 | +236% | 0 | 0 | — |
case-08 | pass→pass | 5,891 | 9,747 | +65% | 1 | 1 | 0% | 1,376 | 5,152 | +274% | 0 | 0 | — |
case-09 | fail→pass | 10,543 | 8,102 | -23% | 1 | 1 | 0% | 2,149 | 4,415 | +105% | 0 | 0 | — |
case-10 | pass→pass | 6,434 | 6,916 | +7% | 1 | 1 | 0% | 1,380 | 4,301 | +212% | 0 | 0 | — |
case-11 | pass→pass | 7,307 | 7,067 | -3% | 1 | 1 | 0% | 1,516 | 4,301 | +184% | 0 | 0 | — |
case-12 | pass→pass | 3,348 | 6,357 | +90% | 1 | 1 | 0% | 782 | 4,203 | +437% | 0 | 0 | — |
case-13 | pass→pass | 9,943 | 6,331 | -36% | 1 | 1 | 0% | 2,040 | 3,940 | +93% | 0 | 0 | — |
case-14 | pass→pass | 3,546 | 3,507 | -1% | 1 | 1 | 0% | 691 | 3,372 | +388% | 0 | 0 | — |
case-15 | pass→pass | 6,420 | 5,061 | -21% | 1 | 1 | 0% | 1,064 | 3,631 | +241% | 0 | 0 | — |
case-16 | pass→pass | 4,633 | 4,685 | +1% | 1 | 1 | 0% | 873 | 3,399 | +289% | 0 | 0 | — |
case-17 | pass→pass | 7,167 | 8,293 | +16% | 1 | 1 | 0% | 1,470 | 4,718 | +221% | 0 | 0 | — |
case-18 | pass→pass | 2,790 | 3,805 | +36% | 1 | 1 | 0% | 505 | 3,426 | +578% | 0 | 0 | — |
case-19 | pass→pass | 4,576 | 4,841 | +6% | 1 | 1 | 0% | 913 | 3,567 | +291% | 0 | 0 | — |
case-20 | pass→pass | 5,948 | 4,826 | -19% | 1 | 1 | 0% | 1,143 | 3,717 | +225% | 0 | 0 | — |
case-21 | pass→pass | 4,854 | 8,484 | +75% | 1 | 1 | 0% | 996 | 4,408 | +343% | 0 | 0 | — |
case-22 | pass→pass | 9,542 | 10,706 | +12% | 1 | 1 | 0% | 2,320 | 5,052 | +118% | 0 | 0 | — |
case-24 | pass→pass | 5,426 | 6,640 | +22% | 1 | 1 | 0% | 1,344 | 4,242 | +216% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 24 cases were attempted. The headline lift of +4 percentage points is the difference between those two pass rates over the 24 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.