AgentStack
SKILL verified MIT Self-run

Api Review

skill-muhammedzohaib-patchman-api-review · by MuhammedZohaib

Review an authorized API surface for access control, mass assignment, schema validation, rate limiting, SSRF, error leakage, webhook verification, and unsafe defaults. Use for REST, GraphQL, RPC, and webhook handlers.

No reviews yet
0 installs
13 views
0.0% view→install

Install

$ agentstack add skill-muhammedzohaib-patchman-api-review

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Api Review? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

API Review

Focus

  • route, resolver, and webhook authorization
  • object scoping and tenant filters
  • request validation and mass assignment
  • response leakage and error behavior
  • rate limiting and abuse resistance
  • server-side fetch and callback verification

Output rule

Prioritize externally reachable issues and admin-facing paths first.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.