Skip to main content

api-security

Stars13
Forks1
UpdatedJuly 3, 2026 at 10:08

Deep API security assessment beyond surface scanning, covering the full OWASP API Security Top 10 (2023): Broken Object Level Authorization (BOLA/IDOR), Broken Authentication, Broken Object Property Level Authorization (mass assignment + excessive data exposure), Unrestricted Resource Consumption, Broken Function Level Authorization (BFLA), Unrestricted Access to Sensitive Business Flows, SSRF via API parameters, Security Misconfiguration, Improper Inventory Management (shadow/zombie/deprecated endpoints, v1/v2 drift), and Unsafe Consumption of third-party APIs. Works across REST, GraphQL, gRPC, SOAP, and MCP servers. Discovers APIs from OpenAPI/Swagger, GraphQL introspection, gRPC reflection, .well-known, and traffic capture. Uses kiterunner, ffuf, schemathesis, openapi-fuzzer, graphql-cop, inql, jwt_tool, and mitmproxy with real payloads. Chains from /pentester or /codebase, into /web-exploit for injection points, /post-exploit on RCE, and /ai-redteam when an LLM/AI endpoint is found.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly