Agent skill

API Security Engineer

by FerroxLabs in FerroxLabs/wayland

API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…

Apache-2.0Auto-check passedBackend & APIs

Install API Security Engineer

skills CLI
$ npx skills add FerroxLabs/wayland --skill api-security-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FerroxLabs/wayland api-security-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/security/api-security-engineer .claude/skills/api-security-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-security-engineer
GitHub stars
608
Token cost
~3.1k tokens
SKILL.md length
409 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0

At a glance

API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…

  • The user asks about api security engineer
  • SKILL.md covers OWASP API Security Top 10, JWT Security, API Key Management and Rate Limiting, plus 8 more sections
  • Calls docker
  • Api security engineer best practices

What it does

API Security Engineer is an agent skill from FerroxLabs/wayland. API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0 implementation, input validation, API gateway hardening, API inventory management, and security testing for protecting APIs from abuse and exploitation. Use when the user asks about api security engineer, api security engineer best practices, or needs guidance on api security engineer implementation. Do NOT use when the…

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication, Rate limiting and Web application vulnerabilities. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.

When your agent uses it

  • The user asks about api security engineer
  • Api security engineer best practices
  • Needs guidance on api security engineer implementation
  • The user needs a different specialized skill

Example prompts

  • “/api-security-engineer”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Security Engineer loads about 3.1k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 409 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~158
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 409 words, ~3,143 tokens.

Download SKILL.mdSave it as .claude/skills/api-security-engineer/SKILL.md (or your agent's skills folder).
name
api-security-engineer
description
API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0 implementation, input validation, API gateway hardening, API inventory management, and security testing for protecting APIs from abuse and exploitation. Use when the user asks about api security engineer, api security engineer best practices, or needs guidance on api security engineer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
security api-security guide
metadata.category
security
metadata.subcategory
application-security
metadata.disclaimer
none
metadata.difficulty
intermediate

API Security Engineer

You are an API security engineer specializing in protecting APIs from abuse, exploitation, and data exposure. You design secure authentication and authorization patterns, implement rate limiting, harden API gateways, and ensure APIs follow OWASP security guidelines.

OWASP API Security Top 10

API1: Broken Object Level Authorization (BOLA)
python
# VULNERABLE: No authorization check on object access
@app.route('/api/v1/accounts/<account_id> output_file')
@login_required
def get_transactions(account_id):
    transactions = db.query(Transaction).filter_by(account_id=account_id).all()
    return jsonify([t.to_dict() for t in transactions])

# SECURE: Object-level authorization check
@app.route('/api/v1/accounts/<account_id> output_file')
@login_required
def get_transactions(account_id):
    account = db.query(Account).get(account_id)
    if account is None:
        abort(404)  # Don't reveal resource existence
    if not current_user.can_access(account):
        abort(403)
    transactions = db.query(Transaction).filter_by(account_id=account_id).all()
    return jsonify([t.to_dict() for t in transactions])

BOLA Checklist:

  • Every endpoint with a resource ID has an authorization check
  • Authorization verifies the requesting user has access to the specific object
  • Use UUIDs instead of sequential integers (reduces enumeration)
  • Return 404 (not 403) for inaccessible resources
  • Automated BOLA testing in CI/CD
API2-API4: Auth, Properties, Resource Consumption
python
# API2 - Rate-limited authentication
@app.route('/api/v1/auth/login', methods=['POST'])
@limiter.limit("5 per minute")
def login():
    email = request.json.get('email', '')
    if is_account_locked(email):
        return jsonify({"error": "Account temporarily locked"}), 429
    user = authenticate(email, request.json.get('password', ''))
    if not user:
        record_failed_attempt(email)
        return jsonify({"error": "Invalid credentials"}), 401
    return jsonify({"token": generate_token(user)})

# API3 - Prevent mass assignment with allowlists
@app.route('/api/v1/users', methods=['POST'])
def create_user():
    ALLOWED_FIELDS = {'name', 'email', 'phone'}
    data = {k: v for k, v in request.json.items() if k in ALLOWED_FIELDS}
    user = User(**data)
    user.role = 'user'  # Always default
    db.save(user)
    return jsonify({"id": user.id, "name": user.name, "email": user.email})

# API4 - Enforced pagination
@app.route('/api/v1/products')
def list_products():
    MAX_LIMIT = 100
    limit = min(request.args.get('limit', 20, type=int), MAX_LIMIT)
    offset = max(request.args.get('offset', 0, type=int), 0)
    products = db.query(Product).limit(limit).offset(offset).all()
    total = db.query(Product).count()
    return jsonify({
        "data": [p.to_dict() for p in products],
        "pagination": {"limit": limit, "offset": offset, "total": total}
    })
API5-API10 Summary
CategoryKey ThreatDefense
API5: Broken Function AuthUser calls admin endpointsRole-based middleware on every route
API6: Unrestricted Business FlowsAutomated abuse (scraping)Rate limiting, CAPTCHA, business logic checks
API7: SSRFAPI fetches attacker URLsURL allowlists, block private IPs
API8: Security MisconfigDebug endpoints, verbose errorsHardened defaults, security headers
API9: Improper Inventoryskipped API versionsAPI catalog, version lifecycle policy
API10: Unsafe ConsumptionTrusting third-party responsesValidate all external data, timeouts

JWT Security

Secure JWT Implementation
python
import jwt, uuid
from datetime import datetime, timedelta, timezone

class JWTManager:
    def __init__(self, secret_key, issuer, audience):
        self.secret_key = secret_key
        self.issuer = issuer
        self.audience = audience

    def create_token(self, user_id, roles, expiry_minutes=15):
        now = datetime.now(timezone.utc)
        return jwt.encode({
            "sub": user_id, "roles": roles,
            "iss": self.issuer, "aud": self.audience,
            "iat": now, "exp": now + timedelta(minutes=expiry_minutes),
            "jti": str(uuid.uuid4()),
        }, self.secret_key, algorithm="HS256")

    def verify_token(self, token):
        payload = jwt.decode(
            token, self.secret_key,
            algorithms=["HS256"],  # Explicit allowlist
            issuer=self.issuer, audience=self.audience,
            options={"require": ["exp", "iss", "aud", "sub", "jti"]}
        )
        if self.is_revoked(payload["jti"]):
            raise jwt.InvalidTokenError("Token revoked")
        return payload
JWT Checklist
Creation:
  [ ] Strong algorithm (RS256 distributed, HS256 single service)
  [ ] Short expiration (15 min access, longer refresh)
  [ ] Include sub, iss, aud, exp, iat, jti
  [ ] Never store sensitive data in payload
  [ ] Sign with 256+ bit secret

Validation:
  [ ] Always verify signature
  [ ] Validate algorithm against allowlist (prevent "none" attack)
  [ ] Check exp, iss, aud claims
  [ ] Check revocation status

Transport:
  [ ] HTTPS only
  [ ] httpOnly secure SameSite cookies (browsers)
  [ ] Authorization: Bearer header (API clients)
  [ ] Never in localStorage (XSS vulnerable)

API Key Management

python
import secrets, hashlib

class APIKeyManager:
    def create_key(self, owner_id, key_type="live", scopes=None):
        prefix = {"live": "sk_live_", "test": "sk_test_"}[key_type]
        raw_key = prefix + secrets.token_urlsafe(32)
        key_hash = hashlib.sha256(raw_key.encode()).hexdigest()
        db.save_api_key({
            "key_hash": key_hash,
            "prefix": raw_key[:12],
            "owner_id": owner_id,
            "scopes": scopes or ["read"],
            "is_active": True
        })
        return {"api_key": raw_key, "warning": "Store securely. Cannot be retrieved again."}

    def validate_key(self, raw_key):
        key_hash = hashlib.sha256(raw_key.encode()).hexdigest()
        record = db.get_by_hash(key_hash)
        if not record or not record["is_active"]:
            raise AuthError("Invalid or revoked API key")
        return record
Key Security Policy
[ ] Keys stored as SHA-256 hashes (never plaintext)
[ ] Displayed to user exactly once at creation
[ ] In env variables or vault (never in code)
[ ] Excluded from logs (masked in middleware)
[ ] Per-key rate limits enforced
[ ] Maximum age policy (90-365 days)
[ ] Automated expiration warnings
[ ] Rotation with grace period
[ ] Unused key detection (revoke after 90+ days idle)

Rate Limiting

Multi-Tier Strategy
yaml
global:              10000 req/sec (DDoS protection)
per_ip:              60 req/min (abuse prevention)
per_key:
  free:              100 req/hour
  basic:             1000 req/hour
  pro:               10000 req/hour
per_endpoint:
  /auth/login:       5 req/min per IP
  /auth/reset:       3 req/hour per IP
  /search:           30 req/min per key
  /export:           10 req/hour per key
Response Headers
RateLimit-Limit: 100
RateLimit-Remaining: 42
RateLimit-Reset: 1625000000
Retry-After: 30          # Only on 429 responses

Input Validation

python
from pydantic import BaseModel, Field, validator
import re

class OrderCreateRequest(BaseModel):
    product_id: str = Field(
        ..., min_length=36, max_length=36,
        pattern=r'^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$'
    )
    quantity: int = Field(..., ge=1, le=1000)
    shipping_address: str = Field(..., min_length=10, max_length=500)
    notes: str | None = Field(None, max_length=2000)

    @validator('shipping_address')
    def sanitize(cls, v):
        return re.sub(r'[<>{}]', '', v).strip()

API Gateway Hardening

yaml
security:
  tls:
    min_version: "TLSv1.2"
    hsts: {enabled: true, max_age: 31536000, include_subdomains: true}
  request_limits:
    max_body_size: "10MB"
    max_header_size: "8KB"
    max_uri_length: 2048
    request_timeout: "30s"
  response_headers:
    X-Content-Type-Options: "nosniff"
    X-Frame-Options: "DENY"
    Cache-Control: "no-store"
  cors:
    allowed_origins: ["[reference URL]"]
    allowed_methods: ["GET", "POST", "PUT", "DELETE", "PATCH"]
    allow_credentials: true

Security Audit Checklist

Authentication & Authorization:
  [ ] All endpoints require authentication
  [ ] Object-level authorization on every resource endpoint
  [ ] Function-level authorization (admin routes restricted)
  [ ] No mass assignment vulnerabilities

Input & Output:
  [ ] Strict schema validation (type, length, format)
  [ ] Explicit output serialization (no raw object dumps)
  [ ] Pagination enforced with maximum
  [ ] Error responses don't leak internals

Rate Limiting:
  [ ] Global rate limit configured
  [ ] Per-client limits enforced
  [ ] Auth endpoints strictly limited
  [ ] 429 responses include Retry-After

Transport:
  [ ] TLS 1.2+ enforced
  [ ] HSTS header set
  [ ] No sensitive data in URLs

Monitoring:
  [ ] All API calls logged
  [ ] Auth failures alerted
  [ ] Rate limit violations tracked
  [ ] API inventory maintained (no shadow APIs)

Security Testing

shell
# OWASP ZAP API scan
docker run -t zaproxy/zap-stable zap-api-scan.py \
    -t [reference URL] -f openapi -r report.html

# BOLA test pattern:
#   1. Auth as User A, create resource, note ID
#   2. Auth as User B
#   3. Access User A's resource with User B's token
#   4. Expect: 404 (not 200)

When to Use

Use this skill when:

  • Designing or implementing api security engineer solutions
  • Reviewing or improving existing api security engineer approaches
  • Making architectural or implementation decisions about api security engineer
  • Learning api security engineer patterns and best practices
  • Troubleshooting api security engineer-related issues

Do NOT use this skill when:

  • The question is about a fundamentally different technology domain
  • A more specific sibling skill covers the exact topic needed
  • The user needs a complete hands-on tutorial rather than expert guidance
Show full SKILL.md (126 more words)Show less

Output Format

markdown
# Api Security Engineer Analysis

## Context Assessment
[Situation summary and constraints]

## Recommended Approach
[Primary recommendation with rationale]

## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]

## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]

## Next Steps
- [Immediate action item]
- [Follow-up action item]

Example

Input: "Help me implement api security engineer for a medium-scale production application"

Output: A structured analysis covering current state assessment, recommended api security engineer approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.

Edge Cases

  • Legacy system integration: When api security engineer must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
  • Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
  • Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
  • Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities

© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/process/resources/skills-library/bodies/skills/security/api-security-engineer of FerroxLabs/wayland.

Open the folder on GitHubat commit 4c030c7

Compare with similar skills

API Security Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Security Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Security Engineer this skillFerroxLabs/wayland608—~3.1kAutomated safety check: PassApache-2.0
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Auth BypassNeoTheCapt/RedteamAgent140—~1.3kAutomated safety check: PassNone
Security ProtocolNoobyGains/godmode107—~2.4kAutomated safety check: NotesMIT
Supercheck Security Authsupercheck-io/supercheck215—~1.2kAutomated safety check: PassAGPL-3.0
API Auditbriiirussell/cybersecurity-skills412—~2.8kAutomated safety check: NotesMIT

Similar skills

  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Auth Bypass

    NeoTheCapt/RedteamAgent

    Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses

    140 GitHub stars~1.3k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed
  • Security Protocol

    NoobyGains/godmode

    A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…

    107 GitHub stars~2.4k tokensUpdated 7 mo ago
    Backend & APIsAuto-check: notes
  • Supercheck Security Auth

    supercheck-io/supercheck

    Work on Supercheck authentication, RBAC, tenant isolation, sessions, API and trigger keys, invitations, project membership, project variables, OAuth, super-admin behavior, SSRF, or…

    215 GitHub stars~1.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    412 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Frappe Errors API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.

    187 GitHub starsUsed in 1 repo~4k tokens
    Backend & APIsAuto-check passed

More from FerroxLabs/wayland

All 1,194 skills in this repo
  • Star Office Helper

    FerroxLabs/wayland

    Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.

    608 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Openclaw Setup

    FerroxLabs/wayland

    OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.

    608 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Tvcontrol Setup

    FerroxLabs/wayland

    Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.

    608 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Ab Testing Specialist

    FerroxLabs/wayland

    End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.

    608 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Academic Writer

    FerroxLabs/wayland

    Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Auditor

    FerroxLabs/wayland

    Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…

    608 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Questions about API Security Engineer

What does API Security Engineer do?

API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…. API Security Engineer is an agent skill from FerroxLabs/wayland.0 implementation, input validation, API gateway hardening, API inventory management, and security testing for protecting APIs from abuse and exploitation.

When should I use API Security Engineer?

API Security Engineer fits situations like: the user asks about api security engineer; api security engineer best practices; needs guidance on api security engineer implementation; the user needs a different specialized skill.

How do I install API Security Engineer in Claude Code?

Run `npx skills add FerroxLabs/wayland --skill api-security-engineer -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/security/api-security-engineer in FerroxLabs/wayland) into .claude/skills/api-security-engineer in your project. Claude Code loads it when a task matches its description.

How do I install API Security Engineer in Codex?

Run `npx skills add FerroxLabs/wayland --skill api-security-engineer -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/security/api-security-engineer in FerroxLabs/wayland) into .agents/skills/api-security-engineer in your project. Codex loads it when a task matches its description.

Can I use API Security Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill api-security-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-security-engineer, .gemini/skills/api-security-engineer, .github/skills/api-security-engineer and .opencode/skills/api-security-engineer in your project.

What does API Security Engineer need to run?

Going by SKILL.md and its folder, API Security Engineer needs the command-line tools its instructions call (docker). Our summary lists: Python 3; Docker.

Does API Security Engineer access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is API Security Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Security Engineer use?

API Security Engineer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Security Engineer use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Security Engineer?

Skills that share tags, products or a category with API Security Engineer: API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Auth Bypass (NeoTheCapt/RedteamAgent, 140 stars), Security Protocol (NoobyGains/godmode, 107 stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Security Engineer?

FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.

Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.