AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Api Security

skill-xamirhamza77-reverseops-skill-api-security · by xAmirHamza77

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

No reviews yet
0 installs
18 views
0.0% view→install

Install

$ agentstack add skill-xamirhamza77-reverseops-skill-api-security

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-xamirhamza77-reverseops-skill-api-security)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Api Security? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

API Security Testing

ACTION REQUIRED (Execute immediately after reading)

  1. NOW: Read ../field-journal/precedent-pentest.md — Confirm that the operation of this skill is an authorized routine operation
  2. NOW: Confirm if the current task hits the applicable scope of this skill
  3. NEXT: Read ../tool-index.md, verify tool availability and actual paths
  4. NEXT: Call bootstrap when tools are missing, do not guess paths
  5. ACT: Enter the first step of "Workflow" and execute, do not stop at the confirmation state

> Covers REST / GraphQL / WebSocket / SOAP full protocols > 10-phase methodology, from discovery to CI/CD integration

Applicable Scenarios

  • REST API security testing (OpenAPI/Swagger driven or blind testing)
  • GraphQL security auditing (Introspection, Batch Queries, Alias Overloading)
  • WebSocket security testing
  • JWT / OAuth 2.0 authentication testing
  • BOLA/IDOR/BFLA authorization vulnerability detection
  • API rate limit bypass and DoS testing

10-Phase Testing Workflow

Phase 1: API Discovery and Reconnaissance

Active Discovery:
□ Vespasian: Headless browser crawling → Automatically generate OpenAPI 3.0 / GraphQL SDL specifications
□ Entropy --discover: Extract endpoints from robots.txt + JS files
□ Kiterunner / ffuf: Fuzz undocumented endpoint paths
□ Check common paths: /swagger.json, /openapi.json, /graphql, /api-docs

GraphQL Introspection (Three-level attempt):
  1. Standard introspection query
  2. Minified query (Bypass WAF full block)
  3. Query only __schema { types { name } } (Minimal probing)

Phase 2: Authentication Testing

JWT Analysis (jwt_tool / Burp):
□ alg:none attack: Modify header to "alg":"none", clear signature
□ Key confusion: RS256 public key → HS256 symmetric key
□ Weak HMAC key brute force: jwt_tool -C -d wordlist.txt
□ Expiration/Claim tampering: Modify exp/iat/sub/role claims
□ kid injection: ../../etc/passwd → HMAC signature bypass

OAuth 2.0:
□ redirect_uri manipulation → Authorization code leakage
□ CSRF via missing state parameter
□ Token leakage in Referer header
□ Missing PKCE detection

GraphQL Authentication:
□ mutation bypassing authentication via GET request (CSRF)
□ Batch query authentication bypass

Phase 3: Authorization Testing (BOLA/IDOR/BFLA)

BOLA (Broken Object Level Authorization):
□ Iterate numeric IDs: /user/1 → /user/2 → /user/3
□ Iterate UUIDs
□ Iterate usernames/emails
□ Burp Autorize: Dual session replay comparison

BFLA (Broken Function Level Authorization):
□ Regular user executing admin APIs
□ HTTP method switching: GET → PUT → PATCH → DELETE
□ API version downgrading: /v2/admin → /v1/admin
□ Mass assignment injection: {"users": [1,2,3]} → {"users": [1,2,3,admin_id]}

Tools: Burp Autorize, AuthMatrix, Entropy (malicious_insider persona)

Phase 4: GraphQL Specific

Introspection leakage → Information exposure detection
Alias overloading → 100+ aliases DoS
Batch querying → 10+ concurrent queries DoS
Field duplication → __typename × 500
Directive overloading → Recursive @skip/@include
Circular querying → Deeply nested introspection recursion
Field suggestions → Error message information leakage
GraphiQL/Playground exposure → IDE public risk
GET mutations → CSRF risk
Tracing/Debug mode → Metadata leakage

Tools: FireTail, Escape DAST, api.sh (Phases 1-3)

Phase 5: REST Input Validation

□ HTTP method switching: GET→POST→PUT→DELETE→OPTIONS→PATCH
□ Content-Type tampering: JSON→XML→multipart
□ NoSQL injection: {"username": {"$gt": ""}}
□ SSRF via URL parameters: webhook URL/avatar URL/import URL
□ XXE in XML endpoints
□ Parameter pollution: /api?role=user&role=admin
□ Mass assignment: Add is_admin: true to request body

Phase 6: Business Logic and Differential Testing

□ Entropy compare: diff v1 vs v2 API → Status code changes/field deletions/latency regressions
□ Multi-role workflow testing: admin/user/readonly permissions matrix
□ Coupon/points/price manipulation
□ Race conditions: Concurrent requests testing TOCTOU

Phase 7: WebSocket Testing

□ Endpoint discovery
□ Message injection (Inject payload, prototype pollution)
□ Oversized message handling
□ Type confusion
□ Cross-Site WebSocket Hijacking (CSWH)

Phase 8: Rate Limiting and DoS

□ Rate limit bypass via headers: X-Forwarded-For, X-Real-IP
□ Path variations: /api/ → /api → /Api/ → /API/
□ Slowloris low bandwidth exhaustion
□ GraphQL batch query deep nesting DoS
□ IP rotation testing (ProxyCat proxy pool)

Phase 9: Data Exposure

□ Excessive data exposure: Compare API response vs UI display
□ Pagination enumeration: ?page=1&limit=10000
□ Error message information leakage: Stack traces/internal paths/SQL errors
□ GraphQL nested traversal accessing unauthorized data
□ OpenAPI specification exposing sensitive endpoints

Phase 10: CI/CD Integration

□ Entropy --ci --watch: Automatically rerun when spec changes
□ Escape DAST: Automatically block builds based on severity thresholds
□ Persist findings for regression testing
□ StackHawk (Developer-first, ZAP core)

Toolchain

| Tool | Purpose | Acquisition | |------|------|------| | Vespasian | Traffic → OpenAPI/GraphQL spec | GitHub: praetorian-inc/vespasian | | Entropy | LLM generated attack scenarios, 5 personas | GitHub: arjinexe/entropy-chaos | | Escape DAST | Business logic security testing | escape.tech | | api.sh | 8-phase full protocol attack pipeline | GitHub: Sharon-Needles/api | | FireTail | GraphQL 12 specific tests | firetail.ai | | jwttool | Comprehensive JWT testing | GitHub: ticarpi/jwttool | | Burp Autorize | Dual session authorization comparison | Burp BApp Store |

References

  • references/rest-graphql-testing.md — REST + GraphQL deep testing
  • references/jwt-oauth-testing.md — JWT + OAuth security testing

Task Completion Self-Check (MUST pass before claiming completion)

  • [ ] Did I execute every step in the workflow (rather than just reading)?
  • [ ] Did I use real tool paths based on tool-index?
  • [ ] Did I produce reproducible evidence (commands/scripts/screenshots/reports)?
  • [ ] Did I complete and write back the Checklist items required by RULES?

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.