Agent skill

Scanning API Security

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Detect API security vulnerabilities including injection, broken auth, and data exposure.

MITAuto-check passedSecurity

Install Scanning API Security

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-api-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace scanning-api-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/scanning-api-security .claude/skills/scanning-api-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scanning-api-security
GitHub stars
2.8k
Token cost
~1.4k tokens
SKILL.md length
585 words
Files
4 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Detect API security vulnerabilities including injection, broken auth, and data exposure.

  • Works in 9 steps: Scan all route definitions using Grep to… → Audit authentication middleware to… → Check for Broken Object Level… → …
  • Scanning APIs for security vulnerabilities
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls npm

What it does

Scanning API Security is an agent skill from jeremylongshore/tons-of-skills-marketplace. Detect API security vulnerabilities including injection, broken auth, and data exposure. Use when scanning APIs for security vulnerabilities. Trigger with phrases like "scan API security", "check for vulnerabilities", or "audit API security".

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/errors.md`, `references/examples.md` and `references/implementation.md`). Compatibility notes: Designed for Claude Code

It sits in Security. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Scanning APIs for security vulnerabilities
  • With phrases like scan API security
  • Check for vulnerabilities
  • Audit API security

Example prompts

  • “scan API security”
  • “check for vulnerabilities”
  • “audit API security”
  • “/scanning-api-security”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Grep, Glob, Bash(api:security-*)

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Scan all route definitions using Grep to build a complete inventory of endpoints, HTTP methods, and middleware chains applied to each route.
  2. Audit authentication middleware to verify every mutation endpoint (POST, PUT, PATCH, DELETE) has auth enforcement and that no endpoints…
  3. Check for Broken Object Level Authorization (BOLA) by verifying that resource access checks compare the authenticated user's ID/role…
  4. Identify excessive data exposure by comparing response serialization against API contracts -- flag endpoints returning full database…
  5. Detect mass assignment vulnerabilities by checking whether request bodies are passed directly to ORM create/update calls without…
  6. Verify input validation exists on all request parameters, query strings, headers, and body fields, checking for SQL injection, NoSQL…
  7. Audit rate limiting configuration to ensure all public-facing and authentication endpoints have per-IP and per-user rate limits applied.
  8. Check security headers (CORS, CSP, HSTS, X-Content-Type-Options) and verify CORS Access-Control-Allow-Origin is not set to wildcard * on…
  9. Scan dependencies for known CVEs and generate a prioritized remediation report with severity ratings and fix recommendations.

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Grep
    • Glob
    • Bash(api:security-*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • zaproxy.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Scanning API Security loads about 1.4k tokens when it runs, and up to ~3.7k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 585 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 585 words, ~1,377 tokens.

Download SKILL.mdSave it as .claude/skills/scanning-api-security/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
scanning-api-security
description
Detect API security vulnerabilities including injection, broken auth, and data exposure. Use when scanning APIs for security vulnerabilities. Trigger with phrases like "scan API security", "check for vulnerabilities", or "audit API security".
allowed-tools
Read, Write, Edit, Grep, Glob, Bash(api:security-*)
compatibility
Designed for Claude Code
version
1.25.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
api, security, authentication, audit

Scanning API Security

Overview

Detect API security vulnerabilities by scanning endpoint implementations, authentication flows, and data handling against the OWASP API Security Top 10. Identify injection vectors, broken authentication, excessive data exposure, mass assignment, and missing rate limiting through static analysis of route handlers, middleware chains, and request validation logic.

Prerequisites

  • API source code with route definitions and controller/handler implementations accessible
  • OpenAPI specification for cross-referencing documented vs. implemented security controls
  • OWASP API Security Top 10 (2023) checklist familiarity
  • Security scanning tools: OWASP ZAP, Burp Suite, or nuclei for dynamic testing
  • Dependency vulnerability scanner: npm audit, safety (Python), or govulncheck

Instructions

  1. Scan all route definitions using Grep to build a complete inventory of endpoints, HTTP methods, and middleware chains applied to each route.
  2. Audit authentication middleware to verify every mutation endpoint (POST, PUT, PATCH, DELETE) has auth enforcement and that no endpoints accidentally bypass auth through route ordering.
  3. Check for Broken Object Level Authorization (BOLA) by verifying that resource access checks compare the authenticated user's ID/role against the requested resource ownership, not just valid authentication.
  4. Identify excessive data exposure by comparing response serialization against API contracts -- flag endpoints returning full database records instead of explicit field whitelists.
  5. Detect mass assignment vulnerabilities by checking whether request bodies are passed directly to ORM create/update calls without field-level allowlisting.
  6. Verify input validation exists on all request parameters, query strings, headers, and body fields, checking for SQL injection, NoSQL injection, and command injection patterns.
  7. Audit rate limiting configuration to ensure all public-facing and authentication endpoints have per-IP and per-user rate limits applied.
  8. Check security headers (CORS, CSP, HSTS, X-Content-Type-Options) and verify CORS Access-Control-Allow-Origin is not set to wildcard * on authenticated endpoints.
  9. Scan dependencies for known CVEs and generate a prioritized remediation report with severity ratings and fix recommendations.

See ${CLAUDE_SKILL_DIR}/references/implementation.md for the full implementation guide.

Output

  • ${CLAUDE_SKILL_DIR}/reports/security-scan.json - Machine-readable vulnerability report with severity ratings
  • ${CLAUDE_SKILL_DIR}/reports/security-scan.md - Human-readable report with remediation guidance
  • ${CLAUDE_SKILL_DIR}/reports/endpoint-auth-matrix.md - Endpoint-to-auth-middleware mapping table
  • ${CLAUDE_SKILL_DIR}/reports/data-exposure-audit.md - Fields returned vs. fields documented per endpoint
  • Inline code comments marking identified vulnerabilities with // SECURITY: annotations
Show full SKILL.md (241 more words)Show less

Error Handling

ErrorCauseSolution
False positive on auth bypassRoute uses custom auth decorator not recognized by scannerAdd custom auth patterns to scanner configuration; document non-standard auth middleware
BOLA not detectedAuthorization check exists but uses flawed comparison logicManually review ownership checks; verify tenant isolation in multi-tenant queries
Injection false negativeParameterized queries mask injection in string-built sub-queriesScan for raw SQL concatenation patterns alongside ORM usage; check dynamic query builders
CORS misconfiguration missedCORS configured at reverse proxy level, not in application codeExtend scan to include nginx/Apache config files and cloud provider CORS settings
Dependency scan timeoutLarge dependency tree with many transitive dependenciesRun dependency scan in parallel; cache vulnerability database locally

Refer to ${CLAUDE_SKILL_DIR}/references/errors.md for comprehensive error patterns.

Examples

OWASP Top 10 audit: Scan a Node.js Express API against all 10 OWASP API Security categories, generating a compliance matrix showing pass/fail/warning status for each category with specific file:line references.

Pre-deployment gate: Integrate security scan into CI pipeline that blocks deployment if any Critical or High severity findings are detected, while allowing Medium/Low with documented exceptions.

Authentication flow review: Trace the complete auth flow from login through token issuance, refresh, and revocation, identifying token lifetime issues, missing refresh rotation, and insecure token storage patterns.

See ${CLAUDE_SKILL_DIR}/references/examples.md for additional examples.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/.curated/scanning-api-security of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/errors.md
  • references/examples.md
  • references/implementation.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Scanning API Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scanning API Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scanning API Security this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.4kAutomated safety check: PassMIT
Elasticsearch Auditaspectrr/deer405—~1.7kAutomated safety check: PassMIT
Azure API Management Security Reviewthomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT
Bom Evidencecdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0
Php Auth Audit0xShe/PHP-Code-Audit-Skill4021 repos~951Automated safety check: PassNone
Create Templatemathematic-inc/earl113—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Azure API Management Security Review

    thomast1906/github-copilot-agent-skills

    Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

    202 GitHub stars~3.1k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Bom Evidence

    cdxgen/cdxgen

    Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

    1.1k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check passed
  • Php Auth Audit

    0xShe/PHP-Code-Audit-Skill

    PHP Web 源码鉴权机制审计工具。从源码中识别所有认证/鉴权实现并分析风险,输出路由-鉴权映射与漏洞分析(含 PoC 与修复建议)。

    402 GitHub starsUsed in 1 repo~951 tokens
    SecurityAuto-check passed
  • Create Template

    mathematic-inc/earl

    Creates a new Earl HCL template for a specific API, database, or shell command.

    113 GitHub stars~2.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Onvifscan

    BrownFineSecurity/iothackbot

    ONVIF device security scanner for testing authentication and brute-forcing credentials.

    859 GitHub starsUsed in 1 repo~608 tokens
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Scanning API Security

What does Scanning API Security do?

Detect API security vulnerabilities including injection, broken auth, and data exposure. Scanning API Security is an agent skill from jeremylongshore/tons-of-skills-marketplace. Detect API security vulnerabilities including injection, broken auth, and data exposure.

When should I use Scanning API Security?

Scanning API Security fits situations like: scanning APIs for security vulnerabilities; with phrases like scan API security; check for vulnerabilities; audit API security.

How do I install Scanning API Security in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-api-security -a claude-code`. Or copy the skill folder (skills/.curated/scanning-api-security in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/scanning-api-security in your project. Claude Code loads it when a task matches its description.

How do I install Scanning API Security in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-api-security -a codex`. Or copy the skill folder (skills/.curated/scanning-api-security in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/scanning-api-security in your project. Codex loads it when a task matches its description.

Can I use Scanning API Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill scanning-api-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scanning-api-security, .gemini/skills/scanning-api-security, .github/skills/scanning-api-security and .opencode/skills/scanning-api-security in your project.

What does Scanning API Security need to run?

Going by SKILL.md and its folder, Scanning API Security needs the command-line tools its instructions call (npm). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(api:security-*). Compatibility (from SKILL.md): Designed for Claude Code.

Does Scanning API Security access the network?

SKILL.md names 2 domains. As links in the text: owasp.org and zaproxy.org. This is read from the text; nothing was executed.

Is Scanning API Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Scanning API Security use?

Scanning API Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scanning API Security use?

About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Scanning API Security?

Skills that share tags, products or a category with Scanning API Security: Elasticsearch Audit (aspectrr/deer, 405 stars), Azure API Management Security Review (thomast1906/github-copilot-agent-skills, 202 stars), Bom Evidence (cdxgen/cdxgen, 1.1k stars) and Php Auth Audit (0xShe/PHP-Code-Audit-Skill, 402 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scanning API Security?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.