@monadworks/agentify
AYour API has new users it doesn't know about yet — AI agents.
Install
agr install @monadworks/agentify --target claudeWrites 1 file into .claude/skills/, pinned to git-6bb2965e.
- .claude/skills/agentify/AGENTS.md
Document
AGENTS.md
Agentify is an Agent Interface Compiler that transforms OpenAPI specifications into multiple agent-consumable formats (MCP Server, Skills, CLAUDE.md, .cursorrules, AGENTS.md, llms.txt, A2A Card).
Build & Run
npm install
npm run build # Build with tsup
npm run dev # Dev mode with tsx
npm test # Run tests with Vitest
npm run lint # TypeScript type check
Architecture
- Parser (
src/parser/): OpenAPI spec parsing + input sanitization - Generator (
src/generator/): Pluggable emitters for each output format - Security (
src/security/): Generated code scanning for dangerous patterns - IR (
src/types.ts): Canonical intermediate representation (AgentifyIR) - CLI (
src/cli.ts): Commander.js CLI entry point
Code Conventions
- TypeScript strict mode (all strict flags enabled)
- Immutable data patterns — never mutate objects, always spread
- Small files: 200-400 lines typical, 800 max
- Emitter interface: implement
emit(ir, options) => EmitterResult - All OpenAPI spec fields must pass through sanitizer before use
- Generated code must pass security scanner before output
Testing
- Framework: Vitest
- Coverage target: 80%+
- Test files:
test/*.test.ts - Integration tests use live Petstore API
Security
- Input sanitization blocks: eval, exec, Function constructor, require/import in descriptions
- Handlebars template injection prevention
- Prompt injection pattern detection
- Generated code scanner checks for critical patterns before writing files
Repository README
Describes MonadWorks/agentify as a whole, which may contain artifacts other than this one. Where this artifact had no useful description of its own, its summary was taken from here.
Your API has new users it doesn't know about yet — AI agents.
Claude Code reads CLAUDE.md. Cursor reads .cursorrules. Codex and Copilot read AGENTS.md. And if you want your API callable as a tool, you need an MCP server. That's a lot of files to write and keep in sync with your API spec.
Agentify reads your OpenAPI spec and writes them all.
npx agentify-cli transform https://petstore.swagger.io/v2/swagger.json
What You Get
One command generates up to 9 formats from a single OpenAPI spec:
| Format | Used by |
|---|---|
| MCP Server | Claude, ChatGPT, Copilot (with Dockerfile) |
| CLAUDE.md | Claude Code |
| AGENTS.md | Codex, Copilot, Cursor, Gemini CLI |
| .cursorrules | Cursor IDE |
| Skills | Agent platforms |
| llms.txt | LLM search engines |
| GEMINI.md | Gemini CLI |
| A2A Card | Google Agent-to-Agent protocol |
| CLI | A standalone command-line tool that makes real API calls |
Quick Start
# Transform any OpenAPI spec (Swagger 2.0 or OpenAPI 3.x)
npx agentify-cli transform https://petstore.swagger.io/v2/swagger.json
# Pick specific formats
npx agentify-cli transform ./my-api.yaml -f mcp claude.md agents.md
# Generate a standalone CLI tool
npx agentify-cli transform ./my-api.yaml -f cli -o my-api-cli
# Custom output directory and project name
npx agentify-cli transform https://api.example.com/openapi.json -o ./output -n my-project
Example output:
Agentify v0.4.1
Agent Interface Compiler
+-- 20 endpoints detected -> SMALL API strategy
+-- 3 domains identified (pet, store, user)
+-- Auth: apiKey (SWAGGER_PETSTORE_API_KEY)
+-- Strategy: Direct tool mapping — one tool per endpoint
> Generated mcp + claude.md + agents.md + cursorrules + llms.txt + gemini.md + skills + a2a (15 files)
> Output: ./swagger-petstore-mcp-server
> Security scan: PASSED
Tested on Real APIs
Agentify handles APIs of any size — from 13-endpoint apps to 1,000+ endpoint platforms.
| API | Endpoints | Domains | TypeScript | Server starts |
|---|---|---|---|---|
| Notion | 13 | 5 | PASS | PASS |
| Petstore (Swagger 2.0) | 20 | 3 | PASS | PASS |
| httpbin (non-compliant spec) | 73 | 11 | PASS | PASS |
| Slack Web API | 174 | 55 | PASS | PASS |
| Stripe | 452 | 1 | PASS | PASS |
| GitHub REST API | 1,093 | 43 | PASS | PASS |
Every generated MCP server compiles with zero TypeScript errors and starts immediately. Non-compliant specs (like httpbin) are auto-normalized with warnings instead of rejected. The GitHub REST API — 1,093 endpoints across 43 domains — produces a working server with 1,093 tools.
How It Works
OpenAPI Spec (URL or file)
|
v
PARSE ──> SANITIZE ──> ANALYZE ──> COMPILE ──> EMIT ──> SCAN ──> OUTPUT
| | | | |
Strip unsafe Detect Build IR Run Security
patterns domains, (typed) emitters scan all
auth, generated
API scale code
Agentify parses your spec into an intermediate representation (AgentifyIR), then runs pluggable emitters to produce each output format. Every generated artifact goes through a security scan before being written to disk.
Security built in:
- Input sanitization (blocks
eval,exec,Functionconstructor injection) - Prompt injection pattern detection
- Generated code scanning
Contributing
New emitters are welcome. Each one implements a simple interface:
import type { Emitter, AgentifyIR, EmitterOptions, EmitterResult } from "../types";
export class MyFormatEmitter implements Emitter {
readonly name = "my-format";
readonly format = "my-format";
async emit(ir: AgentifyIR, options: EmitterOptions): Promise<EmitterResult> {
// Generate output files from the IR
return { format: this.format, filesWritten: [...], warnings: [] };
}
}
agentify/
+-- src/
| +-- cli.ts # CLI entry point
| +-- parser/ # OpenAPI parsing + sanitization
| +-- generator/ # Pluggable emitters for each format
| +-- security/ # Input sanitization + output scanning
| +-- types.ts # AgentifyIR type definitions
+-- test/ # Vitest test suite (136 tests)
Status
This is early. It works on Swagger 2.0 and OpenAPI 3.x specs, handles auth detection, domain grouping, and API scale analysis. If you try it and something breaks, open an issue — that helps a lot.
- OpenAPI parser, MCP emitter, security scanner, CLI
- 9 output formats: MCP, CLAUDE.md, AGENTS.md, .cursorrules, Skills, llms.txt, GEMINI.md, A2A, CLI
- Capability graph and semantic grouping
- Web UI and one-click deploy
- Custom emitter plugins
License
Trustgrade A
- passBody integrity
Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.
- passType matchnot applicable to this artifact type
Whether the artifact is really the kind of thing its metadata claims it is.
- passFreshness
How long since the source repository was last pushed to.
- passPrompt injection
Scans the artifact's own text for instructions aimed at your agent rather than at you.
- passLicense
Whether the source repository declares an SPDX license permissive enough to redistribute.
How the grade is calculated
Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:
- Aevery check passed
- Bone warning
- Ctwo warnings
- Dprompt injection or body integrity failed, or three warnings
- Fone of those failed, and something else is wrong
These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.
Versions
git-6bb2965e72bb2026-08-04