ClaudeSuperPower

api-security

Skill

API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.

Install

git clone https://github.com/transilienceai/communitytools.git ~/.claude/skills/api-security

What is api-security?

API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.

What this can do

Capabilities declared in this component's own frontmatter — not inferred.

Inherit all session tools

Declares no tool restrictions — inherits every session tool

~21 tokens of context used while enabled, before you invoke anything

Documentation

README · ~2 min read

API Security

Test API endpoints for security vulnerabilities across REST, GraphQL, WebSocket, and LLM-integrated APIs.

Techniques

TypeKey Vectors
GraphQLIntrospection, batching attacks, nested query DoS, field suggestion
REST APIBOLA/IDOR, mass assignment, rate limiting, auth bypass, versioning
WebSocketCross-site hijacking, message manipulation, auth flaws
Web-LLMPrompt injection via API, excessive agency, data exfiltration

Workflow

Reviews

Log in to leave a review.

No reviews yet — be the first.

Explore related

Other things in this space — across every part of the ecosystem, not just skills.