Saas API Security

Audit SaaS API surface security including rate limiting, CORS configuration, webhook signature verification, GraphQL query depth/complexity, REST API best practices, idempotency keys, request signing, and API key management. Use this skill whenever the user asks about rate limiting, CORS, webhook security, HMAC signatures, GraphQL security, API abuse, throttling, idempotency, replay protection, or "is my API safe". Trigger on phrases like "audit my API", "review my CORS", "webhook security", "rate limit", "GraphQL depth attack", "API abuse", "signature verification". Use this even when only one API surface is mentioned.

hlsitechio e1d2a4d 5 files · 36.0 KB Updated

File contents

hlsitechio/claude-skills-security/tree/main/saas-security-pack/saas-api-security commit e1d2a4d522

Frequently asked questions

npx skillmds@latest add hlsitechio/saas-api-security