noir

Installation
SKILL.md

OWASP Noir - API & Attack Surface Scanner

When to Use Noir

Ideal scenarios:

  • API endpoint discovery and inventory
  • Attack surface mapping
  • Shadow API detection
  • Pre-pentest reconnaissance
  • API security assessment preparation
  • Microservices endpoint cataloging
  • REST/GraphQL/WebSocket endpoint discovery
  • Framework-specific route analysis

Complements other tools:

  • Use before manual penetration testing for endpoint discovery
  • Combine with vulnerability scanners (Semgrep, CodeQL) for deeper analysis
Related skills
Installs
7
GitHub Stars
4
First Seen
Feb 19, 2026