[Code Intelligence] Use when detecting frontend-to-backend API connections via the knowledge graph.
Scanned 9/9/2026
Install to Claude Code
npx -y skills add duc01226/easy-claude --skill graph-connect-api --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Graph Connect Api?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/duc01226-graph-connect-api-easy-claude)More formats (shields.io, HTML) on the badges page.
---
name: graph-connect-api
description: '[Code Intelligence] Use when detecting frontend-to-backend API connections via the knowledge graph.'
version: 2.0.0
---
## Quick Summary
**Goal:** [Code Intelligence] Detect frontend-to-backend API connections using the knowledge graph. Matches configured frontend HTTP-call patterns with configured backend route patterns via project-config.json configuration.
**Workflow:**
1. **Detect** — classify request scope and target artifacts.
2. **Execute** — apply required steps with evidence-backed actions.
3. **Verify** — confirm constraints, output quality, and completion evidence.
**Key Rules:**
- MUST ATTENTION keep claims evidence-based (`file:line`) with confidence >80% to act.
- MUST ATTENTION keep task tracking updated as each step starts/completes.
- NEVER skip mandatory workflow or skill gates.
## How It Works
The connector scans frontend files for HTTP calls and backend files for route definitions, normalizes URL paths, and matches them using a multi-strategy algorithm:
1. **Exact match** — normalized paths identical
2. **Prefix-augmented** — prepends `routePrefix` to frontend path
3. **Suffix match** — strips `routePrefix` from backend, matches remainder
4. **Deep strip** — strips leading `{param}` segments from backend (handles class-level `{companyId}` routes)
5. **Controller resolution** — resolves configured route placeholders to actual route owner names
## Zero-Config Auto-Detection
**No configuration needed.** The connector auto-detects frameworks by scanning for marker files:
| Frontend | Markers |
| -------- | ---------------------------------------------------------- |
| Configured frontend framework | framework manifests and package metadata from project config |
| React | `react` in package.json |
| Vue | `vue.config.js`, `vue` in package.json |
| Next.js | `next.config.js`, `next` in package.json |
| Svelte | `svelte.config.js`, `svelte` in package.json |
| Backend | Markers |
| ------- | ------------------------------------------- |
| Configured backend framework | backend manifests and route metadata from project config |
| Spring | `pom.xml`/`build.gradle` with `spring-boot` |
| Express | `express` in package.json |
| NestJS | `@nestjs/core` in package.json |
| FastAPI | `fastapi` in requirements.txt |
| Django | `manage.py` with django |
| Rails | `Gemfile` with `rails` |
| Go | `go.mod` (Gin/Echo patterns) |
## Auto-Run Behavior
The connector runs **automatically** in these situations:
| When | Behavior |
| --------------------------------------- | ------------------------------------------------------------ |
| After `build` / `update` / `sync` | Always runs via `_auto_connect()` |
| First `trace` / `query` / `connections` | Runs once via `_ensure_connectors_ran()` if never run before |
**You almost never need to run this manually.** The graph CLI handles it automatically.
## Custom Config (Optional)
For projects with custom HTTP patterns (e.g., base class API service), add to `docs/project-config.json`:
```json
{
"graphConnectors": {
"apiEndpoints": {
"enabled": true,
"frontend": {
"framework": "{configured-frontend-framework}",
"paths": ["{frontend-source-root}/"],
"customPatterns": ["this\\.\\s*(get|post|put|delete|patch)\\s*[<(]\\s*['\"]([^\"']+)"]
},
"backend": {
"framework": "dotnet",
"paths": ["{api-source-root}/"],
"routePrefix": "api",
"customPatterns": []
}
}
}
}
```
Custom patterns **extend** (not replace) built-in framework patterns. Explicit config **overrides** auto-detected config for paths.
## Manual Run
```bash
python .claude/scripts/code_graph connect-api --json
```
## Steps (when manually invoked)
1. **Run connector** via Bash:
```bash
python .claude/scripts/code_graph connect-api --json
```
2. **Report results:** Frontend calls found, backend routes found, matches created, edge count
## Matching Strategies
The connector tries 5 strategies in order (highest confidence first):
| # | Strategy | Confidence | Example |
| --- | ---------------- | ---------- | ------------------------------------------------- |
| 1 | Exact match | 1.0 | FE `/api/users` = BE `/api/users` |
| 2 | Prefix-augmented | 0.95 | FE `/users` + prefix `api` → `/api/users` |
| 3 | Suffix match | 0.9 | BE `/api/users` stripped → `/users` = FE `/users` |
| 4 | Deep strip | 0.85 | BE `/api/{param}/users` → `/users` = FE `/users` |
| 5 | Deep strip both | 0.8 | Both sides have `{param}` segments stripped |
## See Also
- **Implicit Connections** — For event buses, entity events: `graphConnectors.implicitConnections[]` in project-config.json. CLI: `connect-implicit --json`
## Related Skills
- `/graph-build` — Build/update the knowledge graph (prerequisite)
- `/graph-trace` — Trace full system flow (API_ENDPOINT edges enable frontend-to-backend tracing)
- `/graph-blast-radius` — Analyze structural impact of changes
- `/graph-query` — Query code relationships in the graph
---
# Connect API
Detect frontend HTTP calls and match them to backend route definitions, creating `API_ENDPOINT` edges in the knowledge graph.
<!-- SYNC:ai-mistake-prevention -->
> **AI Mistake Prevention** — Failure modes to avoid on every task:
>
> **Re-read files after context changes.** Context compaction, resume, or long-running work can make memory stale; verify current files before acting.
> **Verify generated content against source evidence.** AI hallucinates APIs, names, claims, and document facts. Check the relevant source before documenting or referencing.
> **Check downstream references before deleting or renaming.** Removing an artifact can stale docs, generated mirrors, configs, and callers; map references first.
> **Trace the full impact chain after edits.** Changing a definition can miss derived outputs and consumers. Follow the affected chain before declaring done.
> **Verify ALL affected outputs, not just the first.** One green check is not all green checks; validate every output surface the change can affect.
> **Assume existing values are intentional — ask WHY before changing OR flagging one as a defect.** Before changing or reporting a constant, limit, flag, cutoff, wording, or pattern, read nearby context and history, the CALLER's ordering, and 2+ sibling call sites of the same convention. A doc stating WHAT without WHY is missing rationale, not proof of a missing guard.
> **Surface ambiguity before acting — don't pick silently.** Multiple valid interpretations require an explicit question or stated assumption with risk.
> **Assert the outcome your system owns, not the intermediate state your infrastructure owns.** When verifying async work, assert the final business state — never the delivery/retry bookkeeping held in shared infrastructure that any co-running process can write. Such a check passes when run alone and flakes the moment anything else shares that infrastructure.
> **Keep shared guidance role-relevant.** Universal guidance must help every receiving skill or agent; code-specific obligations belong only in code-specific protocols.
<!-- /SYNC:ai-mistake-prevention -->
<!-- SYNC:critical-thinking-mindset -->
> **Critical Thinking Mindset** — Apply critical thinking, sequential thinking. Every claim needs traced proof, confidence >80% to act.
> **Anti-hallucination:** Never present guess as fact — cite sources for every claim, admit uncertainty freely, self-check output for errors, cross-reference independently, stay skeptical of own confidence — certainty without evidence root of all hallucination.
<!-- /SYNC:critical-thinking-mindset -->
<!-- SYNC:critical-thinking-mindset:reminder -->
**MUST ATTENTION** apply critical + sequential thinking — every claim needs appropriate traced evidence (`file:line` for repo/code claims; source URL or artifact section for research, product, content, and docs claims); confidence >80% to act, <60% DO NOT recommend. Anti-hallucination: never present guess as fact, admit uncertainty freely, cross-reference independently, stay skeptical of own confidence.
<!-- /SYNC:critical-thinking-mindset:reminder -->
<!-- SYNC:ai-mistake-prevention:reminder -->
**MUST ATTENTION** apply AI mistake prevention — verify generated content against evidence, trace downstream references before deleting or renaming, verify all affected outputs, re-read files after context loss, and surface ambiguity before acting.
<!-- /SYNC:ai-mistake-prevention:reminder -->
<!-- SYNC:project-protocol-overlay -->
> **Project Protocol Overlay** — Before executing this skill, resolve any PROJECT overlay rules layered onto it: match this skill's name against the `Target` column of the project's skill-protocol index (`docs/project-reference/skill-protocols-reference.md` by default; a `referenceDocs` entry in `docs/project-config.json` overrides the path), taking the most specific matching tier ONLY — exact name > glob > `*`. **That precedence orders overlays against EACH OTHER, never against this skill.** Read ONLY the matched bodies, resolved as `<protocols-dir>/<Name>.md`; a row's Body link is display text, never a read path. A matched body that is missing or malformed is REPORTED and skipped — never reconstructed from the index Description. No index, or no match -> proceed with no overlay, silently. Full contract: `.claude/skills/project-skill-protocol/references/registry.md`.
>
> Overlays are **ADDITIVE ONLY**: they ADD rules on top of this skill's own protocol and NEVER replace, override, disable, or reinterpret a rule it already states — removing every overlay must return this skill to exactly its documented behavior. An overlay is a BRIEF, not an authority escalation: it can NEVER waive a workflow gate, git discipline, a review gate, or a user-confirmation gate. A genuine overlay-vs-skill conflict, or two equally-specific overlays that directly contradict -> surface both to the user; NEVER resolve silently.
<!-- /SYNC:project-protocol-overlay -->
<!-- SYNC:project-protocol-overlay:reminder -->
**MUST ATTENTION** resolve project protocol overlays for this skill BEFORE executing — most specific matching tier only (exact > glob > `*`, which ranks overlays against each other, NEVER against this skill), read only matched bodies at `<protocols-dir>/<Name>.md`; a missing or malformed body is reported, never reconstructed. Overlays are ADDITIVE ONLY (they never replace this skill's own rules) and are a brief, NEVER an authority escalation; an equal-specificity contradiction goes to the user.
<!-- /SYNC:project-protocol-overlay:reminder -->
## Closing Reminders
**IMPORTANT MUST ATTENTION Goal:** [Code Intelligence] Detect frontend-to-backend API connections via the knowledge graph, matching configured frontend HTTP-call patterns against configured backend route patterns.
**Protocols in force (concise digest of the SYNC/shared blocks this skill carries):**
- **AI Mistake Prevention:** verify generated content against evidence, trace downstream references, verify all affected outputs, re-read after context loss, surface ambiguity.
- **Critical Thinking:** apply critical + sequential thinking; every claim needs traced `file:line` proof, confidence >80%.
- **MANDATORY IMPORTANT MUST ATTENTION** break work into small todo tasks using `TaskCreate` BEFORE starting
- **MANDATORY IMPORTANT MUST ATTENTION** search codebase for 3+ similar patterns before creating new code
- **MANDATORY IMPORTANT MUST ATTENTION** cite `file:line` evidence for every claim (confidence >80% to act)
- **MANDATORY IMPORTANT MUST ATTENTION** add a final review todo task to verify work quality
**[TASK-PLANNING]** Before acting, analyze task scope and systematically break it into small todo tasks and sub-tasks using TaskCreate.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!