Api Security Testing

by usestrix469529068290Apache-2.067K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object property level authorization (excessive data exposure and mass assignment), broken function-level authorization, unrestricted resource consumption, SSRF, injection, and auth/token flaws. Every finding comes with a working proof-of-concept request. Use when the user asks to pentest, security-test, audit, or find vulnerabilities in an API, endpoint, or backend service.

Instructions onlySecurity

Only the file list is public. File contents are available once the skill is installed in a workspace.

PathSizeType
SKILL.md6.2 KBtext/markdown

Source and attribution

Source:usestrix/strixinskills/api-security-testingat commit4695290

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal