Urgent.News

What's breaking now, across thousands of outlets.

Tech

Curate a CMS API into 7 Governed Agent Skills with NodeJS

A production CMS is a sprawl of endpoints: content types, entries, media, users, webhooks, plugins, settings, admin routes. Hand an agent all of it and the agent gets worse, not better. The model's tool selection drifts as the list grows, and half the tools are things a publishing assistant should never be able to call. The point of this post is the opposite move. Instead of exposing an API and…

A production content management system (CMS) contains numerous endpoints such as content types, entries, media, users, webhooks, plugins, settings, admin routes. Presenting an LLM with the entire API leads to several issues: the tool selection becomes difficult, response time slows down as the model reasons over a long list, visibility into the agent's capabilities is lost, and dangerous operations can be executed with a single bad call.

The objective of this post is to curate a small, labeled surface of endpoints beforehand using a tool called Skillgate. HazelJS Skillgate achieves this curation from an OpenAPI specification. Skillgate creates a curated set of skills from the CMS's OpenAPI spec, selecting only those endpoints that should be accessible to the agent.

This is done by tagging certain endpoints as 'editorial' and excluding others. The curation process involves mapping each operation in the spec to a skill, with the operation name and description becoming the skill's name and description, the parameters becoming the skill's inputs, the HTTP method determining the class (read or write), and the approval flag being enforced.

Operations without the 'editorial' tag are not considered as skills. After curation, the spec contains 27 endpoints, but after the opt-in editorial filter, Skillgate registered 7 skills. The 7 skills include two read-only ones: listEntries and getEntry, and five write operations flagged for approval: createEntry, updateEntry, publishEntry, scheduleEntry, and unpublishEntry.

In total, 20 endpoints were excluded from becoming skills. The transformation process involves reading the OpenAPI spec, generating skills, and producing a configuration file that contains the baseUrl, headers, and inclusion settings. Skillgate then reads each operation from the spec and generates a corresponding skill, with the operation name, description, parameters, method, class, read-only status, and approval flag.

The result is a curated set of 7 skills that an LLM can use to interact with the CMS, while excluding dangerous operations.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

8051 What does SDCC do part 1 ?

1. Introduction and Problem Statement A good way to learn what a compiler really does when transforming a C source code into a binary is to disassemble the binary and compare it with the C source…

Why recovery readiness has become the new standard for cyber resilience

As outages become more expensive and frequent, recovery readiness is emerging as the true measure of resilience.

  • Over 90% of ransomware attacks attempt to delete or alter backups.
  • Nearly 60% of these attacks successfully compromise backups.
  • Only 1 in 5 organizations have unified backup protection across hybrid environments.

More from Monday 10 August →