Api Security Testing

作者 usestrix469529068290Apache-2.067K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object property level authorization (excessive data exposure and mass assignment), broken function-level authorization, unrestricted resource consumption, SSRF, injection, and auth/token flaws. Every finding comes with a working proof-of-concept request. Use when the user asks to pentest, security-test, audit, or find vulnerabilities in an API, endpoint, or backend service.

仅含说明Security

仅公开文件列表。将技能安装到工作区后即可查看文件内容。

路径大小类型
SKILL.md6.2 KBtext/markdown

来源与署名

来源:usestrix/strix位于skills/api-security-testing提交4695290

许可证: Apache-2.0

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架