OpenAPI Sec Audit
Installation
SKILL.md
phy-openapi-sec-audit — OpenAPI/Swagger Security Auditor
Scans OpenAPI 3.x and Swagger 2.0 specs for 10 security misconfigurations that API gateways and code review typically miss. Works on local YAML/JSON files, entire directories, or public URLs. Zero external dependencies (only PyYAML for YAML parsing — stdlib JSON always works).
Quick Start
# Single spec file
python openapi_sec_audit.py openapi.yaml
# Remote spec (public URL)
python openapi_sec_audit.py https://petstore3.swagger.io/api/v3/openapi.json
# Scan entire API directory
python openapi_sec_audit.py ./api/ --scan-dir
# CI mode — exit 1 on CRITICAL or HIGH findings
python openapi_sec_audit.py openapi.yaml --ci