All skills
hardw00t avatar

/api-security

@f9bb3b2

Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz endpoints, or find API vulnerabilities.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/api-security

This session only. Nothing lands on disk.

workflowsgrpc_testing.md

≈565 tokens on demand. Your agent reads this file only when SKILL.md points to it.

gRPC Testing Workflow

0 — Tooling

go install github.com/fullstorydev/grpcurl/cmd/grpcurl@latest
go install github.com/fullstorydev/grpcui/cmd/grpcui@latest
# protoc if you have .proto files

1 — Reflection-based discovery

If server reflection is enabled (often is in non-prod, sometimes leaks into prod):

grpcurl -plaintext target:50051 list
grpcurl -plaintext target:50051 list <service>
grpcurl -plaintext target:50051 describe <service>
grpcurl -plaintext target:50051 describe <service>.<Method>
grpcurl -plaintext -d '{"id":"123"}' target:50051 <service>/<Method>

Reflection itself is a finding if exposed externally (API9:2023 — Improper Inventory Management).

2 — No-reflection path

Obtain .proto files from:

  • Mobile app reverse engineering (APK / IPA resources)
  • Public repos / open-source clients
  • Docs / SDKs shipped to users

Then:

grpcurl -plaintext -import-path ./protos -proto user.proto \
        -d '{"id":"123"}' target:50051 user.UserService/GetUser

3 — Auth

  • Metadata-based tokens: -H "authorization: Bearer $TOKEN" or -rpc-header.
  • mTLS: obtain legitimate client cert, then test whether server enforces CN / SAN / OU.
  • API keys in metadata: test scoping, rotation, tenant isolation.

4 — Authorization matrix

Same structure as REST (see methodology/bola_bfla_matrix.md) but issue calls via grpcurl:

  • Unauth vs user-A vs user-B vs admin
  • For every Get*, Update*, Delete* method, iterate resource IDs across tenants.

5 — Input validation

  • Send oversized bytes fields (check API4:2023 resource consumption).
  • Send unexpected oneof combinations.
  • Send negative numbers for counts/sizes.
  • Send deeply nested messages if the schema allows recursion.
  • Send Any type with unexpected packed type URLs.

6 — TLS

# Confirm TLS is actually enforced (fail closed)
grpcurl -plaintext target:50051 list       # should fail if TLS-only
# Cipher / protocol inspection
openssl s_client -connect target:50051 -alpn h2
nmap --script ssl-enum-ciphers -p 50051 target

7 — Reporting

Record per schemas/finding.json with api_type: "grpc", endpoint set to <package>.<service>/<method>, and http_method: "N/A".

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The analyzed skill contains standard penetration testing guides, methodology documents, and common vulnerability checklists for API security auditing. No malicious behavior, prompt injection, or hidden execution channels were detected.

  • Socket16d

    3 alerts: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/api-security