From ai-security-skills
Performs API security review against OWASP API Top 10 (2023). Audits OpenAPI/Swagger specs, REST/GraphQL/gRPC implementations, auth mechanisms, rate limiting, SSRF, and gateways with attack scenarios.
npx claudepluginhub cmaenner/agent-security-playbookThis skill uses the workspace's default tool permissions.
Perform comprehensive API security assessment following `plays/tier1-code-analysis/api-security-review.md`.
<!-- AUTO-GENERATED by export-plugins.py — DO NOT EDIT -->
Identifies OWASP API Security Top 10 (2023) vulnerabilities like BOLA in REST, GraphQL, gRPC APIs during audits, with code examples and detection patterns for Express, Flask, Spring Boot, Go.
Assesses REST and GraphQL API endpoints against OWASP API Security Top 10 risks using ffuf fuzzing, Burp Suite, Postman collections, and manual curl tests. For authorized pen testing before production.
Share bugs, ideas, or general feedback.
Perform comprehensive API security assessment following plays/tier1-code-analysis/api-security-review.md.
Discovery & Reconnaissance
Authentication Deep Dive
Assess All 10 OWASP API Risks with attack scenarios:
Automated Testing
API Gateway & Infrastructure Review
Comprehensive API security report including: