本文へ移動
cccskills

「api-security」の検索結果

108 件 ・ 関連度順

概要と使いどころ

API Security Testing Workflow workflow skill. Use this skill when the user needs API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.

日本語の概要は準備中です。原文の説明を表示しています。

diegosouzapw/awesome-omni-skills1592026年7月8日 更新

API Security Best Practices workflow skill. Use this skill when the user needs Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.

日本語の概要は準備中です。原文の説明を表示しています。

diegosouzapw/awesome-omni-skills1592026年7月8日 更新

API Security Best Practices workflow skill. Use this skill when the user needs Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.

日本語の概要は準備中です。原文の説明を表示しています。

diegosouzapw/awesome-omni-skills1592026年7月8日 更新

Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Anthropic-Cybersecurity-Skills3.4万2026年8月31日 更新

API Security Testing Workflow workflow skill. Use this skill when the user needs API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.

日本語の概要は準備中です。原文の説明を表示しています。

diegosouzapw/awesome-omni-skills1592026年7月8日 更新

API Security Best Practices workflow skill. Use this skill when the user needs Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.

日本語の概要は準備中です。原文の説明を表示しています。

diegosouzapw/awesome-omni-skills1592026年7月8日 更新

Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.

日本語の概要は準備中です。原文の説明を表示しています。

andycungkrinx91/konoha92026年10月9日 更新

Implement comprehensive API security testing using the 42Crunch platform to perform static audit and dynamic conformance scanning of OpenAPI specifications.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

Uses Postman to perform structured API security testing by building collections that test for OWASP API Security Top 10 vulnerabilities including authentication bypass, authorization flaws, injection, and data exposure. The tester creates environments with multiple user roles, writes test scripts for automated security validation, and integrates Postman with OWASP ZAP and Newman for CI/CD security testing. Activates for requests involving Postman security testing, API security collection, aut...

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

Implement API Security Posture Management to continuously discover, classify, and score APIs based on risk while enforcing security policies across the API lifecycle.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via message flooding, and information leakage through WebSocket frames. The tester intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious payloads, and tests for authorization bypass on WebSocket channels. Activates f...

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.

日本語の概要は準備中です。原文の説明を表示しています。

micsapp/micstec-skills42026年3月20日 更新

Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.

日本語の概要は準備中です。原文の説明を表示しています。

aniket2348823/Vul-Agent22026年6月9日 更新

Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object property level authorization (excessive data exposure and mass assignment), broken function-level authorization, unrestricted resource consumption, SSRF, injection, and auth/token flaws. Every finding comes with a working proof-of-concept request. Use when the user asks to pentest, security-test, audit, or find vulnerabilities in an API, endpoint, or backend service.

日本語の概要は準備中です。原文の説明を表示しています。

usestrix/strix6.8万2026年10月10日 更新

Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities

日本語の概要は準備中です。原文の説明を表示しています。

sickn33/agentic-awesome-skills4.7万2026年10月10日 更新

Authorized security assessment of REST, GraphQL, WebSocket, and SOAP APIs: discovery, authentication and authorization flaws (BOLA/IDOR, JWT/OAuth), rate-limit testing, and a structured multi-phase methodology.

日本語の概要は準備中です。原文の説明を表示しています。

sickn33/agentic-awesome-skills4.7万2026年10月10日 更新

API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.

日本語の概要は準備中です。原文の説明を表示しています。

sickn33/agentic-awesome-skills4.7万2026年10月10日 更新

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

日本語の概要は準備中です。原文の説明を表示しています。

zhaoxuya520/reverse-skill4.1万2026年9月22日 更新

Discover and inventory shadow API endpoints that operate outside documented OpenAPI/Swagger specs, using traffic analysis against API gateways (Kong, AWS API Gateway, Envoy), cloud configuration scanning, and source code repository mining for undocumented routes. Use when assessing API attack surface, auditing for forgotten test environments or deprecated API versions still running, or building an API registration governance policy.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Anthropic-Cybersecurity-Skills3.4万2026年8月31日 更新

Detect and test for OWASP API3:2023 Broken Object Property Level Authorization (BOPLA), covering excessive data exposure in API responses and mass assignment via injected request-body properties. Use when reviewing API responses/requests for over-exposed or over-writable object fields, or building detection rules and test cases for property-level authorization gaps that object-level checks miss.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Anthropic-Cybersecurity-Skills3.4万2026年8月31日 更新

Detect API enumeration attacks (BOLA/IDOR, OWASP API1:2023) by writing SIEM detection rules that flag sequential or UUID identifier iteration, parameter tampering, and mixed 200/401/403 response patterns from API gateway and WAF logs. Use when investigating suspected object-level authorization abuse, building threat-hunting queries for API access-control bypass, or hardening API logging/rate-limiting against enumeration.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Anthropic-Cybersecurity-Skills3.4万2026年8月31日 更新

Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass, credential scanning, and injection attempts. Uses pandas for statistical analysis of request patterns and anomaly detection. Use when investigating API abuse or building API-specific threat detection rules.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Anthropic-Cybersecurity-Skills3.4万2026年8月31日 更新

Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.

日本語の概要は準備中です。原文の説明を表示しています。

SnailSploit/Claude-Red7,4022026年9月20日 更新

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5302026年10月10日 更新