pentest-api-attacker
Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
القائمة
Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
استنادا إلى تصنيف SOC المهني
Plan and orchestrate authorized Nmap host discovery, port and service enumeration, NSE profiling, and reporting artifacts for in-scope targets.
Assess Active Directory identity attack paths including roasting, relay, and delegation abuse.
Test authentication and session management controls for bypass and account takeover scenarios.
Set up authorized C2 simulation workflows and measure defensive detection outcomes.
Assess AWS, Azure, and GCP controls for IAM escalation and cloud service exposure.
Test Docker and Kubernetes security controls for RBAC abuse, breakout, and secret exposure.
| name | pentest-api-attacker |
| description | Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks. |
Enumerate and test API endpoints and business logic attack vectors.
python skills/pentest-api-attacker/scripts/api_attacker.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run
api-endpoints.jsonapi-findings.jsonapi-attack-report.jsonreferences/tools.mdskills/autonomous-pentester/shared/scope_schema.jsonskills/autonomous-pentester/shared/finding_schema.jsonWARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.