Api Security Testing

usestrix/strix/skills/api-security-testing

作者 usestrix469529068290Apache-2.067K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object property level authorization (excessive data exposure and mass assignment), broken function-level authorization, unrestricted resource consumption, SSRF, injection, and auth/token flaws. Every finding comes with a working proof-of-concept request. Use when the user asks to pentest, security-test, audit, or find vulnerabilities in an API, endpoint, or backend service.

僅含說明Security

僅公開檔案列表。將技能安裝到工作區後即可檢視檔案內容。

路徑大小類型
SKILL.md6.2 KBtext/markdown

來源與署名

來源:usestrix/strix位於skills/api-security-testing提交4695290

授權條款: Apache-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架