Graphql Expert

SkillMedia

GraphQL API design and implementation. Use when building GraphQL APIs, designing schemas, implementing resolvers, or optimizing GraphQL performance.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Graphql Expert skill

What this skill tells your AI

The instructions your AI receives, as published by travisjneuman/.claude in skills/graphql-expert/SKILL.md and read by ahel’s review.

apollo caching

When reviewing or writing code, apply these guidelines:

  • Utilize Apollo Client's caching capabilities

apollo custom hooks

When reviewing or writing code, apply these guidelines:

  • Implement custom hooks for Apollo operations

apollo devtools

When reviewing or writing code, apply these guidelines:

  • Use Apollo Client DevTools for debugging

apollo provider setup

When reviewing or writing code, apply these guidelines:

  • Use Apollo Provider at the root of your app

graphql apollo client usage

When reviewing or writing code, apply these guidelines:

  • Use Apollo Client for state management and data fetching
  • Implement query components for data fetching
  • Utilize mutations for data modifications
  • Use fragments for reusable query parts
  • Implement proper error handling and loading states

graphql error boundaries

When reviewing or writing code, apply these guidelines:

  • Implement proper error boundaries for GraphQL errors

graphql naming conventions

When reviewing or writing code, apply these guidelines:

  • Follow naming conventions for queries, mutations, and fragments

graphql typescript integration

When reviewing or writing code, apply these guidelines:

  • Use TypeScript for type safety with GraphQL operations

Iron Laws

  1. ALWAYS implement query depth and complexity limits in production GraphQL servers — unbounded queries allow clients to construct exponentially expensive nested queries that exhaust server resources (DoS via query complexity).
  2. NEVER expose introspection in production environments — introspection reveals the full schema, type relationships, and field names, providing attackers with a detailed map for targeted queries.
  3. ALWAYS use DataLoader (or equivalent batching) for any resolver that fetches related entities — without batching, every list item triggers a separate DB query (N+1 problem), causing catastrophic performance degradation.
  4. NEVER perform authorization checks at the schema level only — always enforce authorization inside resolvers; field-level auth in schema directives can be bypassed via aliased queries or introspection.
  5. ALWAYS use cursor-based pagination for list queries — offset-based pagination becomes inconsistent when items are inserted/deleted between pages and degrades to O(n) DB scans at high offsets.

Anti-Patterns

Anti-PatternWhy It FailsCorrect Approach
No query depth/complexity limitsSingle deeply-nested query can DoS the serverConfigure graphql-depth-limit and graphql-query-complexity middleware
Introspection enabled in productionExposes full schema to attackers; aids targeted exploitationDisable via introspection: false in Apollo Server config for production
N+1 resolver queriesEach list item triggers separate DB query; 100 users = 100 queriesUse DataLoader to batch and deduplicate DB fetches per request
Authorization only in schema directivesDirectives can be bypassed by aliasing fields or crafting custom queriesCheck permissions inside every resolver; use context for user/role
Offset-based paginationInconsistent pages when data changes; O(n) scan at large offsetsUse cursor-based pagination with first, after, and opaque cursor tokens

Consolidated Skills

This expert skill consolidates 1 individual skills:

  • graphql-expert

Memory Protocol (MANDATORY)

Before starting:

cat .claude/context/memory/learnings.md

After completing: Record any new patterns or exceptions discovered.

ASSUME INTERRUPTION: Your context may reset. If it's not in memory, it didn't happen.

Signals

GitHub stars
97
Forks
22
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
graphql-expert
Source
github.com/travisjneuman/.claude