Curate a CMS API into 7 Governed Agent Skills with NodeJS
A production CMS is a sprawl of endpoints: content types, entries, media, users, webhooks, plugins, settings, admin routes. Hand an agent all of it and the agent gets worse, not better. The model's tool selection drifts as the list grows, and half the tools are things a publishing assistant should never be able to call. The point of this post is the opposite move. Instead of exposing an API and…
A production content management system (CMS) contains numerous endpoints such as content types, entries, media, users, webhooks, plugins, settings, admin routes. Presenting an LLM with the entire API leads to several issues: the tool selection becomes difficult, response time slows down as the model reasons over a long list, visibility into the agent's capabilities is lost, and dangerous operations can be executed with a single bad call.
The objective of this post is to curate a small, labeled surface of endpoints beforehand using a tool called Skillgate. HazelJS Skillgate achieves this curation from an OpenAPI specification. Skillgate creates a curated set of skills from the CMS's OpenAPI spec, selecting only those endpoints that should be accessible to the agent.
This is done by tagging certain endpoints as 'editorial' and excluding others. The curation process involves mapping each operation in the spec to a skill, with the operation name and description becoming the skill's name and description, the parameters becoming the skill's inputs, the HTTP method determining the class (read or write), and the approval flag being enforced.
Operations without the 'editorial' tag are not considered as skills. After curation, the spec contains 27 endpoints, but after the opt-in editorial filter, Skillgate registered 7 skills. The 7 skills include two read-only ones: listEntries and getEntry, and five write operations flagged for approval: createEntry, updateEntry, publishEntry, scheduleEntry, and unpublishEntry.
In total, 20 endpoints were excluded from becoming skills. The transformation process involves reading the OpenAPI spec, generating skills, and producing a configuration file that contains the baseUrl, headers, and inclusion settings. Skillgate then reads each operation from the spec and generates a corresponding skill, with the operation name, description, parameters, method, class, read-only status, and approval flag.
The result is a curated set of 7 skills that an LLM can use to interact with the CMS, while excluding dangerous operations.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.