Endpoint Pentest

Authorized, conservative security assessment of the HTTP/API endpoints beside an MCP server. Covers route discovery, OpenAPI/Swagger leakage, auth bypass, IDOR/BOLA, broken function-level authorization, mass assignment, excessive data exposure, SSRF, injection, file upload, webhook signature bypass, CORS, CSRF, rate limiting, and error/debug leakage. Safe-by-default and read-only. Use when testing REST/HTTP APIs in an authorized environment.

rwcod b428460 4 files · 6.4 KB Updated

File contents

rwcod/mcp-remote-oauth-pentest-kit/tree/main/skills/endpoint-pentest commit b428460dde

Frequently asked questions

npx skillmds@latest add rwcod/endpoint-pentest