This skill should be used when the user asks "where is this API endpoint implemented", "find the code for this route", "which file handles this endpoint", "map API findings to code", or needs to correlate OpenAPI spec paths with source code locations. Also use when creating fix plans for code-first API projects (NestJS, Fastify, Express) after running baume-review, or when user mentions "find my NestJS controller", "locate Fastify route handler", "Express route definition".
67
81%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Map Baume review findings to code locations for code-first API projects.
IMPORTANT: If the mcp__baume__baume-correlate tool is available, use it instead of manual correlation. The MCP tool:
baume-reviewUse mcp__baume__baume-correlate with:
- reviewId: {review-id-from-baume-review}
- projectRoot: {absolute-path-to-project}
- specPath: {absolute-path-to-spec} (optional, for context extraction)
- framework: "nestjs" | "fastify" | "express" | "unknown" (optional hint)
- correlationLevel: "minimal" | "moderate" | "thorough" (optional, default: "moderate")The manual process below is a fallback for when MCP tools are not available.
This skill activates when:
baume-review for a code-first projectbaume-review MCP tool or review document)From MCP tool results:
If baume-review was called, use the findings from that response.
From review document:
If working from .baume/reviews/*.md, read the document to get:
spec_path from frontmatterruleId, path, severityParse each finding's path field to extract method and API path:
"GET /users/{id}" → method: GET, path: /users/{id}
"POST /orders" → method: POST, path: /ordersDedupe by method+path (multiple findings may target same endpoint).
Read package.json in project root:
@nestjs/core → NestJS (decorators: @Controller, @Get, @Post)fastify → Fastify (route methods: .get, .post, app.route)express → Express (router methods: router.get, app.get)For each unique operation, spawn a baume-code-locator agent:
Task: baume-code-locator
Prompt: Find the code that implements this API operation:
- method: GET
- path: /users/{id}
- operationId: getUserById (if available from spec)
- framework: nestjs
- rootDir: /projectSpawn up to 5 agents in parallel for efficiency.
For each finding, build this structure:
{
"finding": {
"ruleId": "aip122/plural-resources",
"severity": "warning",
"path": "GET /user/{id}",
"message": "Resource name should be plural",
"suggestion": "Rename to /users/{id}",
"fix": { "type": "rename-path-segment", "..." }
},
"specContext": {
"method": "GET",
"path": "/user/{id}",
"operationId": "getUser",
"summary": "Get a user by ID",
"tags": ["users"]
},
"codeLocations": [
{
"file": "src/users/users.controller.ts",
"line": 42,
"type": "controller",
"confidence": "high",
"snippet": "@Get(':id')\nasync getUser(@Param('id') id: string) { ... }",
"reasoning": "@Get decorator matches, operationId in @ApiOperation"
}
],
"suggestedDiffs": {
"specDiff": "...",
"codeDiffs": [{ "file": "...", "diff": "...", "description": "..." }]
}
}For deterministic fixes, pre-populate code diffs using templates from diff-templates.md.
| fix.type | Code Diff |
|---|---|
rename-path-segment | Update @Controller('user') → @Controller('users') |
rename-parameter | Update @Param name |
change-status-code | Add/update @HttpCode(201) |
remove-request-body | Remove @Body() parameter |
add-parameter | Partial - provide template |
add-schema | No - too complex, guidance only |
Write to .baume/correlations/{date}-{spec-name}.json:
{
"extendedFindings": [
/* ... */
],
"framework": "nestjs",
"generatedAt": "2025-01-15T10:30:00Z",
"reviewPath": ".baume/reviews/...",
"specPath": "openapi.yaml",
"summary": {
"correlated": 6,
"notFound": 2,
"totalFindings": 8
}
}Report results to user:
## Correlation Complete
| Operation | Code Location | Confidence |
| --------------- | ---------------------------------- | ---------- |
| GET /users/{id} | src/users/users.controller.ts:42 | high |
| POST /users | src/users/users.controller.ts:28 | high |
| GET /orders | src/orders/orders.controller.ts:15 | medium |
**Not found:** DELETE /admin/cache, GET /health
Correlation saved to: .baume/correlations/2025-01-15-orders-api.jsonbaume-review: Analyze OpenAPI spec against AIP rules. Returns findings with reviewId.
Call: mcp__baume__baume-review with specPath or specUrl
Returns: { reviewId, findings[], summary, findingsPath, findingsUrl }baume-correlate: Correlate Baume review findings with code locations.
Call: mcp__baume__baume-correlate with reviewId, projectRoot, specPath, framework
Returns: { extendedFindings[], framework, summary, correlationPath }baume-apply-fixes: Apply suggested fixes to spec (after correlation, to fix spec issues).
Call: mcp__baume__baume-apply-fixes with reviewId, specPath/specUrl, writeBack, dryRun
Returns: { summary, downloadUrl, modifiedSpec }baume-code-locator: Find code implementing a single API operation.
| Purpose | Path |
|---|---|
| Review documents | .baume/reviews/*.md |
| Correlation output | .baume/correlations/*.json |
| Code locator agent | plugins/baume/agents/baume-code-locator.md |
| Diff templates | diff-templates.md |
/baume-plan after correlation to create a fix plan/baume-validate to verify fixes against the planbaume-code-locator agent directly for single operation lookupaip-knowledge skill for AIP rule explanations90d0cc6
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.