Skip to main content

api-security-top10

OWASP API Security Top 10 as a dedicated API-only checklist -- BOLA, BFLA, broken object-property-level authz/mass assignment, unrestricted resource consumption, unsafe business-flow access, security misconfiguration, improper inventory management (shadow/zombie APIs), unsafe third-party API consumption, plus GraphQL/gRPC/SOAP/WebSocket coverage. Converted from master-pentest-prompt.md Phase 33. Use on API-only targets (no traditional web UI) as the dedicated checklist -- for mixed web+API targets the vuln-class skills already cover most of this ground per-endpoint.

Jump to install

Source facts

Repository
ankitsingh015/HuntMCP
Last source activity
August 24, 2026 at 12:56
Detected SKILL.md language
English
Stars
4
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.