Communitygithub.com

curiositech/windags-skills

API gateway and reverse proxy configuration with Kong, Nginx, Traefik, routing, and auth middleware. Activate on: API gateway, reverse proxy, Kong, Nginx, Traefik, load balancer, ingress, auth middleware. NOT for: rate limiting algorithms (use api-rate-limiting-throttling-expert), service mesh (use service-mesh-microservices-expert).

O que é windags-skills?

windags-skills is a Claude Code agent skill that aPI gateway and reverse proxy configuration with Kong, Nginx, Traefik, routing, and auth middleware. Activate on: API gateway, reverse proxy, Kong, Nginx, Traefik, load balancer, ingress, auth middleware. NOT for: rate limiting algorithms (use api-rate-limiting-throttling-expert), service mesh (use service-mesh-microservices-expert).

Funciona com~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/curiositech/windags-skills/tree/HEAD/skills/api-gateway-reverse-proxy-expert

Perguntar na sua IA favorita

Abre um novo chat com esta habilidade de agente já pré-carregada.

Documentação

API Gateway & Reverse Proxy Expert

Configure and optimize API gateways and reverse proxies for routing, authentication, rate limiting, and traffic management.

Decision Points

Authentication Strategy Selection

Traffic Pattern & Requirements
├── Internal services only
│   └── API Key authentication
│       ├── Low complexity, fast validation
│       └── Kong: key-auth plugin, Traefik: forwardAuth
├── Customer-facing API with session needs
│   └── JWT authentication
│       ├── Stateless, includes user claims
│       └── Kong: jwt plugin, Nginx: lua-resty-jwt
├── Enterprise B2B integration
│   └── mTLS authentication
│       ├── Certificate-based, highest security
│       └── Kong: mtls-auth, Nginx: ssl_verify_client
└── Third-party SaaS integration
    └── OAuth2 flow
        ├── Token exchange, delegated auth
        └── Kong: oauth2 plugin, AWS API Gateway: authorizer

Gateway Technology Selection

Requirements → Choice
├── Plugin ecosystem & GUI needed
│   └── Kong Enterprise/OSS
├── Kubernetes-native with auto-discovery
│   └── Traefik v3 or Ingress-NGINX
├── Maximum performance, minimal features
│   └── Nginx or Envoy
└── Cloud-managed, serverless scaling
    └── AWS API Gateway or Azure Application Gateway

Upstream Routing Strategy

Service Architecture → Routing Method
├── Microservices with service discovery
│   └── Dynamic upstream targets
│       ├── Consul/Eureka integration
│       └── Health check based load balancing
├── Static backend services
│   └── Fixed upstream pools
│       ├── Round-robin or least-connections
│       └── Weighted routing for canary deployments
└── Multi-region deployment
    └── Geographic routing
        ├── Latency-based or geo-IP
        └── Fallback to secondary regions

Failure Modes

Gateway Timeout Cascade

Symptom: Slow API responses (>10s) under load
Detection: Response times spike while upstream services report normal latency
Root Cause: Gateway timeout higher than upstream timeout, causing request queuing
Fix: Set gateway read timeout < upstream timeout (gateway: 30s, upstream: 25s)

Authentication Bypass

Symptom: Unauthorized requests reaching backend services
Detection: Backend logs show requests without expected auth headers
Root Cause: Route order allows permissive rules to match before auth rules
Fix: Move auth middleware to global level or ensure specific routes come first in config

Circuit Breaker Thrashing

Symptom: Intermittent 503 errors during traffic spikes
Detection: Circuit breaker opens/closes rapidly (multiple times per minute)
Root Cause: Threshold too sensitive or health check misconfigured
Fix: Tune failure threshold (5+ failures) and recovery time (30s minimum)

SSL Certificate Expiry

Symptom: HTTPS handshake failures, browser certificate warnings
Detection: SSL cert check shows expiry within 30 days
Root Cause: Manual certificate management without renewal automation
Fix: Implement cert-manager (K8s) or ACME client with auto-renewal

Resource Exhaustion

Symptom: Gateway stops accepting connections, memory/CPU at 100%
Detection: Connection refused errors, gateway health checks failing
Root Cause: No connection limits or memory leaks in plugins
Fix: Set worker_connections (Nginx) or connection pool limits (Kong), restart gateway

Worked Examples

Scenario: E-commerce API Gateway Setup

Context: Deploy Kong for microservices handling orders, inventory, payments with JWT auth

Step 1: Route Definition

# Identify service endpoints first
services:
  - orders: /api/v1/orders/* → http://orders:8080
  - inventory: /api/v1/inventory/* → http://inventory:8080  
  - payments: /api/v1/payments/* → http://payments:8080

Step 2: Apply Decision Tree

  • Traffic pattern: Customer-facing API → JWT authentication
  • Architecture: Microservices → Dynamic upstream targets
  • Requirements: Plugin ecosystem needed → Kong selected

Step 3: Plugin Ordering

# Apply plugins in correct order
plugins:
  1. cors (pre-auth)
  2. jwt (authentication) 
  3. rate-limiting (post-auth)
  4. request-transformer (last)

Expert vs Novice:

  • Novice mistake: Applies rate limiting before authentication (anonymous users consume quota)
  • Expert approach: Auth first, then rate limit per authenticated user
  • Novice mistake: Uses global CORS policy
  • Expert approach: Different CORS per route (orders allows admin origins, payments restricts to frontend only)

Failure Scenario: Canary Deployment Gone Wrong

Situation: Deployed 20% traffic to new orders service version, seeing 500 errors

Detection Process:

  1. Check gateway metrics: 500 rate spike correlates with deployment time
  2. Upstream health checks: New version failing health checks
  3. Gateway logs: Upstream connection timeouts

Rollback Procedure:

# Step 1: Immediate traffic shift
kong:
  routes:
    - service: orders-v1
      weight: 100  # Was 80
    - service: orders-v2  
      weight: 0    # Was 20

# Step 2: Validate rollback
curl -H "Authorization: Bearer $JWT" \
  https://api.company.com/orders/health

# Step 3: Remove failed upstream
kubectl scale deployment orders-v2 --replicas=0

Root Cause Analysis: New version had database connection pool misconfiguration, causing timeouts under load

Quality Gates

  • All routes have explicit path matching (no catch-all /* routes)
  • Authentication middleware configured before business logic plugins
  • Health checks return 2xx for healthy upstreams within 5 seconds
  • Circuit breaker thresholds set: 5 failures in 60s window, 30s recovery
  • TLS certificates auto-renew with 30+ days before expiry
  • Rate limiting applied per authenticated user, not globally
  • CORS policy restricts origins to required domains only
  • Gateway timeout (30s) < upstream timeout (25s) to prevent cascades
  • Access logs include correlation ID for request tracing
  • Gateway deployed with minimum 2 replicas for high availability

NOT-FOR Boundaries

This skill handles: Gateway configuration, routing rules, authentication middleware, reverse proxy setup

NOT for:

  • Rate limiting algorithm design → Use api-rate-limiting-throttling-expert
  • Service mesh data plane configuration → Use service-mesh-microservices-expert
  • API specification and design → Use api-architect
  • Database connection pooling → Use database-performance-expert
  • Container orchestration → Use kubernetes-expert or docker-expert
  • SSL certificate generation → Use security-infrastructure-expert

Delegation Rules:

  • For custom rate limiting algorithms: "I'll configure the rate limiting plugin, but for custom algorithms, use api-rate-limiting-throttling-expert"
  • For service discovery setup: "I'll configure upstream targets, but for service mesh setup, use service-mesh-microservices-expert"

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

curiositech/windags-skills

Expert in 2000s-era music visualization (Milkdrop, AVS, Geiss) and modern WebGL implementations. Specializes in Butterchurn integration, Web Audio API AnalyserNode FFT data, GLSL shaders for audio-reactive visuals, and psychedelic generative art. Activate on "Milkdrop", "music visualization", "WebGL visualizer", "Butterchurn", "audio reactive", "FFT visualization", "spectrum analyzer". NOT for simple bar charts/waveforms (use basic canvas), video editing, or non-audio visuals.

curiositech/windags-skills

Expert legal research agent for finding and scraping expungement data state by state. Knows authoritative sources, URL patterns, Firecrawl configuration, and 2026 legal landscape.

curiositech/windags-skills

Expert in 3D computer vision labeling tools, workflows, and AI-assisted annotation for LiDAR, point clouds, and sensor fusion. Covers SAM4D/Point-SAM, human-in-the-loop architectures, and vertical-specific training strategies. Activate on '3D labeling', 'point cloud annotation', 'LiDAR labeling', 'SAM 3D', 'SAM4D', 'sensor fusion annotation', '3D bounding box', 'semantic segmentation point cloud'. NOT for 2D image labeling (use clip-aware-embeddings), general ML training (use ml-engineer), video annotation without 3D (use computer-vision-pipeline), or VLM prompt engineering (use prompt-engineer).

curiositech/windags-skills

Implement WCAG 2.2 AA/AAA compliance with automated testing, keyboard navigation, screen reader support, and focus management. Activate on: accessibility audit, WCAG compliance, keyboard navigation, screen reader, aria attributes, axe-core, focus trap. NOT for: design-level accessibility review (use design-accessibility-auditor), color contrast only (use css-in-js-architect).

curiositech/windags-skills

Time-blind friendly planning, executive function support, and daily structure for ADHD brains. Specializes in realistic time estimation, dopamine-aware task design, and building systems that actually work for neurodivergent minds.

curiositech/windags-skills

Designs digital experiences for ADHD brains using neuroscience research and UX principles. Expert in reducing cognitive load, time blindness solutions, dopamine-driven engagement, and compassionate design patterns. Activate on 'ADHD design', 'cognitive load', 'accessibility', 'neurodivergent UX', 'time blindness', 'dopamine-driven', 'executive function'. NOT for general accessibility (WCAG only), neurotypical UX design, or simple UI styling without ADHD context.

curiositech/windags-skills

>- Apply crisis decision-making research to agent routing, uncertainty triage, and coordination failure analysis in time-pressured systems. Use when diagnosing handoff failures, analytical paralysis, or expert judgment under incomplete information. NOT for routine coding, simple CRUD design, or static single-agent tasks with complete information.

curiositech/windags-skills

Extend and modify the admin dashboard, developer portal, and operations console. Use when adding new admin tabs, metrics, monitoring features, or internal tools. Activates for dashboard development, analytics, user management, and internal tooling.

curiositech/windags-skills

Conversation patterns and interaction protocols for multi-agent systems. Covers request/response, pub/sub, blackboard, delegation chains, debate, critique, consensus, fan-out/fan-in, supervisor-worker, and peer negotiation. Deep analysis of AutoGen conversation patterns, CrewAI delegation, LangGraph state passing, and FIPA-ACL performatives. Teaches how to design what agents say to each other and in what order. Activate on: "agent conversation", "agent protocol", "multi-agent debate", "agent delegation", "supervisor worker pattern", "agent voting", "consensus protocol", "fan-out fan-in", "agent negotiation", "blackboard pattern", "agent dialogue", "conversation topology", "agent handoff". NOT for: wire format or serialization (use agent-interchange-formats), orchestration infrastructure (use agentic-infrastructure-2026), single agent behavior (use agentic-patterns).

curiositech/windags-skills

Meta-agent for creating new custom agents, skills, and MCP integrations. Expert in agent design, MCP development, skill architecture, and rapid prototyping. Activate on 'create agent', 'new skill', 'MCP server', 'custom tool', 'agent design'. NOT for using existing agents (invoke them directly), general coding (use language-specific skills), or infrastructure setup (use deployment-engineer).

curiositech/windags-skills

AI-powered calendar management and agent-based scheduling coordination. Covers calendar APIs (Google Calendar, CalDAV/iCal), AI scheduling assistants (Reclaim, Clockwise, Motion, Cal.com), building custom calendar agents with MCP, multi-calendar merging, timezone management, focus block protection, meeting fatigue detection, and agent-to-agent meeting negotiation protocols. Activate on: "calendar agent", "AI scheduling", "calendar coordination", "meeting scheduling", "calendar API", "focus time protection", "calendar optimization", "Google Calendar MCP", "Reclaim", "Clockwise", "Motion", "Cal.com", "smart scheduling", "calendar-aware agent", "timezone scheduling", "agent negotiation meetings". NOT for: manual calendar UI component design (use form-validation-architect), project management scheduling or Gantt charts (use project-management-guru-adhd), general time-tracking or pomodoro apps (use adhd-daily-planner for time-awareness), building the agent itself from scratch (use agent-creator).

curiositech/windags-skills

Build and adopt production AI agent infrastructure in 2026. Covers framework selection (LangGraph, CrewAI, AutoGen, MCP), orchestration patterns, evaluation, observability, memory systems, and tool use. Also covers the SOCIAL dimension: how to sell agent infrastructure internally, change management, measuring ROI, building trust in autonomous systems, and scaling adoption across teams. Activate on: "agent infrastructure", "agent framework comparison", "which agent framework", "sell AI tools internally", "agent adoption", "agent observability", "agent evaluation", "MCP architecture", "agentic mesh", "enterprise AI agents", "AI change management", "agent ROI". NOT for: building specific agents (use ai-engineer), designing agent behavior patterns (use agentic-patterns), prompt tuning (use prompt-engineer).

curiositech/windags-skills

Fundamental patterns for effective agentic behavior. Teaches decomposition, tool orchestration, error recovery, context management, quality self-assessment, and knowing when to stop. Model-agnostic principles that make any agent more effective regardless of domain. Activate on: "how should I structure this agent", "agentic workflow", "agent patterns", "multi-step task", "tool orchestration", "/agentic-patterns", "decompose this", "agent best practices", "chain of actions", "when should the agent stop", "agent loop design". NOT for: creating agent infrastructure (use agent-creator), building DAGs (use windags-architect), specific tool implementation.

curiositech/windags-skills

Automated discovery and matching of agent skills for dynamic task routing and capability assessment

curiositech/windags-skills

Cryptographic security for agentic systems — zero-trust agent networking, signed message envelopes (JWS/JWE), capability-based security (ocaps), Merkle tree audit trails, WASM sandboxing, and formal verification. Covers CLI dev tool security, mTLS between agents, permission boundaries (least privilege for AI agents), and supply chain security for skills/plugins. Activate on: "agent security", "zero trust agents", "secure agent communication", "capability-based security", "ocap", "signed messages between agents", "agent audit trail", "sandbox agent execution", "agent permissions", "mTLS agents", "cryptographic verification", "agent supply chain", "OWASP agentic", "prove agent did X", "tamper-proof agent logs". NOT for: application-level SAST scanning (use security-auditor), network firewall rules (use infrastructure), SOC2/HIPAA compliance (organizational), or prompt injection defense (use prompt-engineer).

curiositech/windags-skills

Data structures and serialization formats for agent-to-agent communication. Covers message envelopes, structured output schemas, capability declarations, task handoff payloads, error/retry signaling, and context windows as data structures. Deep comparison of A2A protocol, MCP, OpenAI function calling, and LangChain message types. Teaches when to use rigid schemas vs free-form with validation, typed vs untyped, streaming vs batch. Activate on: "agent message format", "agent communication schema", "agent-to-agent protocol", "A2A protocol", "MCP message format", "structured output for agents", "agent interop", "interchange format", "agent serialization", "task handoff format", "capability declaration". NOT for: what agents say to each other (use agent-conversation-protocols), orchestration topology (use multi-agent-coordination), building agent infrastructure (use agentic-infrastructure-2026).

curiositech/windags-skills

Logic-based agent programming language implementing BDI architecture for practical autonomous agent development

curiositech/windags-skills

>- Design AgentSpeak(L)-style BDI agents with context-guarded plans, selection functions, and intention stacks. Use for interruptible autonomy, agent policy, and multi-agent orchestration in dynamic environments. NOT for simple rule engines, static planners, or centralized workflows.

curiositech/windags-skills

Foundational concurrent computation model where actors communicate exclusively through asynchronous message passing

curiositech/windags-skills

license: Apache-2.0 NOT for unrelated tasks outside this domain.

Habilidades Relacionadas