
from antigravity-awesome-workspace-skill9
A comprehensive security testing framework for REST and GraphQL APIs, covering auth, rate limiting, and input validation.
This skill provides a structured, multi-phase workflow for auditing the security of REST and GraphQL APIs. It transforms the agent from a general assistant into a security researcher capable of systematic vulnerability discovery.
Activate this skill when tasked with API security audits, bug bounty hunting on API endpoints, or validating the security posture of a new API deployment.
Designed for agents capable of invoking other specialized security skills (e.g., Codex, Claude Code) to perform the actual fuzzing and scanning.
API security testing workflow skill that provides a phased checklist for REST/GraphQL security testing. No bundled scripts — purely instructional markdown. The skill delegates all actual work to other referenced skills (api-fuzzing-bug-bounty, broken-authentication, etc.) making it a meta-workflow rather than a standalone tool. Checklist items are generic and lack concrete methodology or tool-specific guidance.
Safe skill — no security concerns. Main issue is it adds little standalone value beyond being a structured checklist. References to external skills (@api-fuzzing-bug-bounty, @idor-testing, etc.) have no guarantees those skills exist or are compatible.