API Security

Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz endpoints, or find API vulnerabilities.

hardw00t Updated

File contents

hardw00t/ai-security-arsenal/tree/main/skills/api-security commit 6fcb4c590d

Frequently asked questions

npx skillmds@latest add hardw00t/api-security