Agent / universal + product Skills
Combine universal and product Skills to work with APIs.
The universal pontx-hub Skill handles catalog-wide discovery, inspection, and safe calls; product Skills add provider-specific integration flows, best practices, and caveats.
pontx-hub searchpontx-hub previewpontx-hub call@pontx/<api>Install a universal or product Skill
Start with the universal pontx-hub Skill, then add a product Skill when you need a provider's integration flow, best practices, or caveats.
npx skills add https://github.com/pontjs/pontx-hub --skill pontx-hubpnpm add --global @pontx/hub-cli
pontx-hub skill install
pontx-hub skill list
pontx-hub skill install stripe-identityskill install without an argument installs the universal Skill; pass an apiSlug or full Skill name to install a product Skill. Use --output to choose a location and --force to explicitly update an existing Skill.
Universal discovery, product guidance
The universal Skill uses the CLI to find and inspect current data. After an API is selected, a product Skill adds only provider-specific sequencing and risk guidance. You still decide on every live call.
searchFind the right EndpointshowRead parameters and docsproduct SkillAdd product guidancepreviewCheck the full requestconfirmConfirm any data changescallCall after confirmationsdkGenerate application codepontx-hub search "把欧元换算成美元的接口" --locale zh --json
pontx-hub show endpoint:frankfurter/get-latest-rates
pontx-hub frankfurter preview 'Exchange Rates' getLatestRates --base USD
# The Endpoint is called only after you confirm.
pontx-hub frankfurter call 'Exchange Rates' getLatestRates --base USDTwo Skill layers, one PontxSpec
Skills keep only useful workflow guidance. APIs, Endpoints, fields, authentication, and versions are always read from the current PontxSpec for the task.
Product Skills do not copy Endpoint inventories, Schemas, or parameter tables. This keeps provider guidance useful without letting it drift from API metadata.
Boundaries that cannot be bypassed
The Skill can find information and prepare a call, but it never decides to send the request for you.
- ✓Search, explanation, or code generation does not imply execution permission.
- ✓Any operation that may change data must show the full request before you confirm it.
- ✓Credentials come from environment variables, never arguments, logs, or responses.
- ✓Only catalog-approved APIs, Endpoints, and servers can be called.
- ✓Product Skills provide provider integration guidance; the current PontxSpec remains authoritative for API facts.
- ✓Application code uses the published @pontx/<apiSlug> SDK.