api-security

Installation
SKILL.md

API Security

Test API endpoints for security vulnerabilities across REST, GraphQL, WebSocket, and LLM-integrated APIs.

Techniques

Type Key Vectors
GraphQL Introspection, batching attacks, nested query DoS, field suggestion
REST API BOLA/IDOR, mass assignment, rate limiting, auth bypass, versioning
WebSocket Cross-site hijacking, message manipulation, auth flaws
Web-LLM Prompt injection via API, excessive agency, data exfiltration

Workflow

  1. Discover API endpoints and documentation (Swagger, GraphQL schema)
  2. Map authentication and authorization mechanisms
  3. Test per API type using appropriate techniques
  4. Validate data exposure and access control flaws
Related skills
Installs
36
GitHub Stars
258
First Seen
Mar 21, 2026