API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…
Install the "api-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/security/api-security-engineer into .claude/skills/api-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-engineer", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add FerroxLabs/wayland --skill api-security-engineer -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "api-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/security/api-security-engineer into .agents/skills/api-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-engineer", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add FerroxLabs/wayland --skill api-security-engineer -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "api-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/security/api-security-engineer into .cursor/skills/api-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-engineer", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add FerroxLabs/wayland --skill api-security-engineer -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "api-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/security/api-security-engineer into .gemini/skills/api-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-engineer", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add FerroxLabs/wayland --skill api-security-engineer -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "api-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/security/api-security-engineer into .github/skills/api-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-engineer", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add FerroxLabs/wayland --skill api-security-engineer -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "api-security-engineer" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/security/api-security-engineer into .opencode/skills/api-security-engineer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "api-security-engineer", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
api-security-engineer
GitHub stars
608
Token cost
~3.1k tokens
SKILL.md length
409 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0
At a glance
API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…
The user asks about api security engineer
SKILL.md covers OWASP API Security Top 10, JWT Security, API Key Management and Rate Limiting, plus 8 more sections
Calls docker
Api security engineer best practices
What it does
API Security Engineer is an agent skill from FerroxLabs/wayland. API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0 implementation, input validation, API gateway hardening, API inventory management, and security testing for protecting APIs from abuse and exploitation. Use when the user asks about api security engineer, api security engineer best practices, or needs guidance on api security engineer implementation. Do NOT use when the…
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Authentication, Rate limiting and Web application vulnerabilities. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.
When your agent uses it
The user asks about api security engineer
Api security engineer best practices
Needs guidance on api security engineer implementation
The user needs a different specialized skill
Example prompts
“/api-security-engineer”
Requirements
Python 3
Docker
What it can do on your machine
Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
docker
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
API Security Engineer loads about 3.1k tokens when it runs. Until then it costs about 158 tokens; SKILL.md has 409 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~158
When it runs· the whole SKILL.md, loaded when a task matches
~3.1k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/api-security-engineer/SKILL.md (or your agent's skills folder).
name
api-security-engineer
description
API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0 implementation, input validation, API gateway hardening, API inventory management, and security testing for protecting APIs from abuse and exploitation.
Use when the user asks about api security engineer, api security engineer best practices, or needs guidance on api security engineer implementation.
Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
security api-security guide
metadata.category
security
metadata.subcategory
application-security
metadata.disclaimer
none
metadata.difficulty
intermediate
API Security Engineer
You are an API security engineer specializing in protecting APIs from abuse, exploitation, and data exposure. You design secure authentication and authorization patterns, implement rate limiting, harden API gateways, and ensure APIs follow OWASP security guidelines.
OWASP API Security Top 10
API1: Broken Object Level Authorization (BOLA)
python
# VULNERABLE: No authorization check on object access
@app.route('/api/v1/accounts/<account_id> output_file')
@login_required
def get_transactions(account_id):
transactions = db.query(Transaction).filter_by(account_id=account_id).all()
return jsonify([t.to_dict() for t in transactions])
# SECURE: Object-level authorization check
@app.route('/api/v1/accounts/<account_id> output_file')
@login_required
def get_transactions(account_id):
account = db.query(Account).get(account_id)
if account is None:
abort(404) # Don't reveal resource existence
if not current_user.can_access(account):
abort(403)
transactions = db.query(Transaction).filter_by(account_id=account_id).all()
return jsonify([t.to_dict() for t in transactions])
BOLA Checklist:
Every endpoint with a resource ID has an authorization check
Authorization verifies the requesting user has access to the specific object
Use UUIDs instead of sequential integers (reduces enumeration)
Return 404 (not 403) for inaccessible resources
Automated BOLA testing in CI/CD
API2-API4: Auth, Properties, Resource Consumption
python
# API2 - Rate-limited authentication
@app.route('/api/v1/auth/login', methods=['POST'])
@limiter.limit("5 per minute")
def login():
email = request.json.get('email', '')
if is_account_locked(email):
return jsonify({"error": "Account temporarily locked"}), 429
user = authenticate(email, request.json.get('password', ''))
if not user:
record_failed_attempt(email)
return jsonify({"error": "Invalid credentials"}), 401
return jsonify({"token": generate_token(user)})
# API3 - Prevent mass assignment with allowlists
@app.route('/api/v1/users', methods=['POST'])
def create_user():
ALLOWED_FIELDS = {'name', 'email', 'phone'}
data = {k: v for k, v in request.json.items() if k in ALLOWED_FIELDS}
user = User(**data)
user.role = 'user' # Always default
db.save(user)
return jsonify({"id": user.id, "name": user.name, "email": user.email})
# API4 - Enforced pagination
@app.route('/api/v1/products')
def list_products():
MAX_LIMIT = 100
limit = min(request.args.get('limit', 20, type=int), MAX_LIMIT)
offset = max(request.args.get('offset', 0, type=int), 0)
products = db.query(Product).limit(limit).offset(offset).all()
total = db.query(Product).count()
return jsonify({
"data": [p.to_dict() for p in products],
"pagination": {"limit": limit, "offset": offset, "total": total}
})
Creation:
[ ] Strong algorithm (RS256 distributed, HS256 single service)
[ ] Short expiration (15 min access, longer refresh)
[ ] Include sub, iss, aud, exp, iat, jti
[ ] Never store sensitive data in payload
[ ] Sign with 256+ bit secret
Validation:
[ ] Always verify signature
[ ] Validate algorithm against allowlist (prevent "none" attack)
[ ] Check exp, iss, aud claims
[ ] Check revocation status
Transport:
[ ] HTTPS only
[ ] httpOnly secure SameSite cookies (browsers)
[ ] Authorization: Bearer header (API clients)
[ ] Never in localStorage (XSS vulnerable)
API Key Management
python
import secrets, hashlib
class APIKeyManager:
def create_key(self, owner_id, key_type="live", scopes=None):
prefix = {"live": "sk_live_", "test": "sk_test_"}[key_type]
raw_key = prefix + secrets.token_urlsafe(32)
key_hash = hashlib.sha256(raw_key.encode()).hexdigest()
db.save_api_key({
"key_hash": key_hash,
"prefix": raw_key[:12],
"owner_id": owner_id,
"scopes": scopes or ["read"],
"is_active": True
})
return {"api_key": raw_key, "warning": "Store securely. Cannot be retrieved again."}
def validate_key(self, raw_key):
key_hash = hashlib.sha256(raw_key.encode()).hexdigest()
record = db.get_by_hash(key_hash)
if not record or not record["is_active"]:
raise AuthError("Invalid or revoked API key")
return record
Key Security Policy
[ ] Keys stored as SHA-256 hashes (never plaintext)
[ ] Displayed to user exactly once at creation
[ ] In env variables or vault (never in code)
[ ] Excluded from logs (masked in middleware)
[ ] Per-key rate limits enforced
[ ] Maximum age policy (90-365 days)
[ ] Automated expiration warnings
[ ] Rotation with grace period
[ ] Unused key detection (revoke after 90+ days idle)
Rate Limiting
Multi-Tier Strategy
yaml
global: 10000 req/sec (DDoS protection)
per_ip: 60 req/min (abuse prevention)
per_key:
free: 100 req/hour
basic: 1000 req/hour
pro: 10000 req/hour
per_endpoint:
/auth/login: 5 req/min per IP
/auth/reset: 3 req/hour per IP
/search: 30 req/min per key
/export: 10 req/hour per key
Response Headers
RateLimit-Limit: 100
RateLimit-Remaining: 42
RateLimit-Reset: 1625000000
Retry-After: 30 # Only on 429 responses
Authentication & Authorization:
[ ] All endpoints require authentication
[ ] Object-level authorization on every resource endpoint
[ ] Function-level authorization (admin routes restricted)
[ ] No mass assignment vulnerabilities
Input & Output:
[ ] Strict schema validation (type, length, format)
[ ] Explicit output serialization (no raw object dumps)
[ ] Pagination enforced with maximum
[ ] Error responses don't leak internals
Rate Limiting:
[ ] Global rate limit configured
[ ] Per-client limits enforced
[ ] Auth endpoints strictly limited
[ ] 429 responses include Retry-After
Transport:
[ ] TLS 1.2+ enforced
[ ] HSTS header set
[ ] No sensitive data in URLs
Monitoring:
[ ] All API calls logged
[ ] Auth failures alerted
[ ] Rate limit violations tracked
[ ] API inventory maintained (no shadow APIs)
Security Testing
shell
# OWASP ZAP API scan
docker run -t zaproxy/zap-stable zap-api-scan.py \
-t [reference URL] -f openapi -r report.html
# BOLA test pattern:
# 1. Auth as User A, create resource, note ID
# 2. Auth as User B
# 3. Access User A's resource with User B's token
# 4. Expect: 404 (not 200)
When to Use
Use this skill when:
Designing or implementing api security engineer solutions
Reviewing or improving existing api security engineer approaches
Making architectural or implementation decisions about api security engineer
Learning api security engineer patterns and best practices
Troubleshooting api security engineer-related issues
Do NOT use this skill when:
The question is about a fundamentally different technology domain
A more specific sibling skill covers the exact topic needed
The user needs a complete hands-on tutorial rather than expert guidance
Show full SKILL.md (126 more words)Show less
Output Format
markdown
# Api Security Engineer Analysis
## Context Assessment
[Situation summary and constraints]
## Recommended Approach
[Primary recommendation with rationale]
## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]
## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]
## Next Steps
- [Immediate action item]
- [Follow-up action item]
Example
Input: "Help me implement api security engineer for a medium-scale production application"
Output: A structured analysis covering current state assessment, recommended api security engineer approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.
Edge Cases
Legacy system integration: When api security engineer must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities
API Security Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
API Security Engineer compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
API Security Engineer this skillFerroxLabs/wayland
A skill your agent uses when writing code that processes user input, manages authentication or authorization, constructs database queries, handles file operations, interacts with external data…
Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.
End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.
Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…
API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…. API Security Engineer is an agent skill from FerroxLabs/wayland.0 implementation, input validation, API gateway hardening, API inventory management, and security testing for protecting APIs from abuse and exploitation.
When should I use API Security Engineer?
API Security Engineer fits situations like: the user asks about api security engineer; api security engineer best practices; needs guidance on api security engineer implementation; the user needs a different specialized skill.
How do I install API Security Engineer in Claude Code?
Run `npx skills add FerroxLabs/wayland --skill api-security-engineer -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/security/api-security-engineer in FerroxLabs/wayland) into .claude/skills/api-security-engineer in your project. Claude Code loads it when a task matches its description.
How do I install API Security Engineer in Codex?
Run `npx skills add FerroxLabs/wayland --skill api-security-engineer -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/security/api-security-engineer in FerroxLabs/wayland) into .agents/skills/api-security-engineer in your project. Codex loads it when a task matches its description.
Can I use API Security Engineer in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill api-security-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-security-engineer, .gemini/skills/api-security-engineer, .github/skills/api-security-engineer and .opencode/skills/api-security-engineer in your project.
What does API Security Engineer need to run?
Going by SKILL.md and its folder, API Security Engineer needs the command-line tools its instructions call (docker). Our summary lists: Python 3; Docker.
Does API Security Engineer access the network?
SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Is API Security Engineer safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does API Security Engineer use?
API Security Engineer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does API Security Engineer use?
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to API Security Engineer?
Skills that share tags, products or a category with API Security Engineer: API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Auth Bypass (NeoTheCapt/RedteamAgent, 140 stars), Security Protocol (NoobyGains/godmode, 107 stars) and Supercheck Security Auth (supercheck-io/supercheck, 215 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains API Security Engineer?
FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.
Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.