skills/skills.volces.com/OpenAPI Sec Audit

OpenAPI Sec Audit

Installation
SKILL.md

phy-openapi-sec-audit — OpenAPI/Swagger Security Auditor

Scans OpenAPI 3.x and Swagger 2.0 specs for 10 security misconfigurations that API gateways and code review typically miss. Works on local YAML/JSON files, entire directories, or public URLs. Zero external dependencies (only PyYAML for YAML parsing — stdlib JSON always works).

Quick Start

# Single spec file
python openapi_sec_audit.py openapi.yaml

# Remote spec (public URL)
python openapi_sec_audit.py https://petstore3.swagger.io/api/v3/openapi.json

# Scan entire API directory
python openapi_sec_audit.py ./api/ --scan-dir

# CI mode — exit 1 on CRITICAL or HIGH findings
python openapi_sec_audit.py openapi.yaml --ci
Installs
4
First Seen
Apr 22, 2026
OpenAPI Sec Audit from skills.volces.com