Skills That Call Other AIs: claude-api, dashscope, and the API-Reference Family
Most skills teach your agent a workflow. A smaller, quieter family teaches it to talk to other machines — APIs, other models, on-chain data. They're force multipliers with keys attached, which makes them the most security-relevant category on the site.
These skills share a shape: a reference manual for some external API, wrapped so the agent can use it correctly — auth patterns, rate limits, the three endpoints that matter, the twelve that don't. Here are the ones that scored, by what they unlock.
Calling models: claude-api — 9.8/10
The highest-scoring skill in this family. Teaches the agent to build against the Claude API — streaming, tool use, prompt caching, the patterns that separate a demo from something that survives production.
Why it matters here: Meta-skill — it's the skill you use to build agents, including agents that use skills. The reference quality is the score: current, complete, and honest about gotchas.
Calling models, China-side: dashscope — 9.0/10, injection-tested 10/10
The DashScope API reference — Alibaba's model line — with the same treatment.
Dynamic test: Perfect four-for-four across both tiers. It ignored instructions hidden in its fixture files and kept its own guardrails when pushed to skip them. A reference skill that reads untrusted code samples all day and passed injection testing is exactly what this category should look like.
Generating images: bfl-api — 9.1/10
The BFL (black-forest) image-generation API, wrapped for agents.
Why it earns the slot: Image APIs are where agents burn the most money per mistake — the wrapper encodes the cost-relevant defaults (resolution tiers, retries) so the agent doesn't learn them on your invoice.
Market data: coingecko-api, kalshi-api, defillama-api, dexscreener-api — 9.1/9.1/9.0/9.0
Four market-data references: crypto spot data, prediction markets, DeFi protocols, DEX screens.
Why they travel together: The agent that answers "what's the market doing" needs two of these at minimum; each one is narrow, and the pair covers the question. Scores are earned on freshness — stale endpoint docs are worse than none, and all four are current.
On-chain execution: helius-api — 8.8/10
Solana RPC and enhanced APIs — the deepest technical skill in this batch.
The one thing: This one doesn't just read. RPC skills can move funds. It scores well on engineering, but it belongs in the strictest sandbox tier of your setup — read-capable keys only unless you're actively executing.
Building your own: api-designer + setup-api-key — 9.1/10 and 8.6/10
api-designer is the counterpart skill — for when your agent is producing an API rather than consuming one. setup-api-key is the humble one that teaches correct key handling and rotation.
Why the boring one matters: Credential discipline is the whole game in this category. A skill that models correct key hygiene is worth more than it looks.
The category verdict: reference skills score high and test clean — dashscope's perfect injection run is the template. The risk isn't the reference; it's the keys you hand the agent alongside it. Scope every token, and read the secure loadout before giving any of these write access. Browse the API family.
