Agent skill

Implementing API Gateway Security Controls

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Configures API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a centralized security enforcement point, covering authentication enforcement, rate limiting and throttling, request…

Apache-2.0Auto-check passedBackend & APIs

Install Implementing API Gateway Security Controls

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-api-gateway-security-controls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-api-gateway-security-controls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-api-gateway-security-controls .claude/skills/implementing-api-gateway-security-controls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-api-gateway-security-controls
GitHub stars
34k
Token cost
~3.9k tokens
SKILL.md length
609 words
Files
4 (incl. scripts, references)
Skills in repo
639
Repo updated
First seen
Licence
Apache-2.0

At a glance

Configures API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a centralized security enforcement point, covering authentication enforcement, rate limiting and throttling, request…

  • Works in 5 steps: Kong Gateway Security Configuration → AWS API Gateway Security Configuration → Request Validation with OpenAPI Schema → …
  • Securing API traffic at the gateway layer
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls openssl, curl and aws; reaches cognito-idp.us-east-1.amazonaws.com

What it does

Implementing API Gateway Security Controls is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configures API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a centralized security enforcement point, covering authentication enforcement, rate limiting and throttling, request validation, IP allowlisting, TLS termination, and threat protection. Use when securing API traffic at the gateway layer, setting up gateway-level authentication and quota management, or centralizing API protection before requests reach backend services.

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Backend & APIs, covering Microservices and Rate limiting. It works with Amazon Web Services, Azure API Management, Microsoft Azure and OpenAPI. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Securing API traffic at the gateway layer
  • Setting up gateway-level authentication and quota management
  • Centralizing API protection before requests reach backend services

Example prompts

  • “Use the implementing-api-gateway-security-controls skill to configure API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a…”
  • “/implementing-api-gateway-security-controls”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Kong Gateway Security Configuration
  2. AWS API Gateway Security Configuration
  3. Request Validation with OpenAPI Schema
  4. Mutual TLS Configuration
  5. Logging and Monitoring Configuration

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • openssl
    • curl
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cognito-idp.us-east-1.amazonaws.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing API Gateway Security Controls loads about 3.9k tokens when it runs, and up to ~4.3k if it reads all its reference files. Until then it costs about 123 tokens; SKILL.md has 609 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 609 words, ~3,879 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-api-gateway-security-controls/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
implementing-api-gateway-security-controls
description
Configures API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a centralized security enforcement point, covering authentication enforcement, rate limiting and throttling, request validation, IP allowlisting, TLS termination, and threat protection. Use when securing API traffic at the gateway layer, setting up gateway-level authentication and quota management, or centralizing API protection before requests reach backend services.
domain
cybersecurity
subdomain
api-security
tags
api-security, api-gateway, kong, aws-api-gateway, rate-limiting, waf
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, ID.RA-01, PR.DS-10, DE.CM-01
mitre_attack
T1190, T1059.007, T1552.001, T1078.004, T1530

Implementing API Gateway Security Controls

When to Use

  • Deploying a centralized authentication and authorization layer for microservice APIs
  • Implementing rate limiting, throttling, and quota management across all API endpoints
  • Configuring request/response validation against OpenAPI specifications at the gateway level
  • Setting up TLS termination, mutual TLS, and certificate management for API traffic
  • Integrating WAF rules with the API gateway to block injection, XSS, and known attack patterns

Do not use as the sole security layer. API gateways provide defense in depth but backend services must also validate authorization and input.

Prerequisites

  • API gateway platform selected and deployed (Kong, AWS API Gateway, Azure APIM, or Apigee)
  • OpenAPI/Swagger specifications for all backend APIs
  • TLS certificates for the gateway domain
  • Identity provider (IdP) configured for OAuth2/OIDC (Okta, Auth0, Azure AD)
  • Monitoring and logging infrastructure (CloudWatch, Datadog, ELK)
  • Backend service endpoints registered and reachable from the gateway

Workflow

Step 1: Kong Gateway Security Configuration
yaml
# kong.yml - Declarative Kong configuration with security plugins
_format_version: "3.0"

services:
  - name: user-service
    url: http://user-service:8080
    routes:
      - name: user-api
        paths:
          - /api/v1/users
        methods:
          - GET
          - POST
          - PUT
          - PATCH
          - DELETE
        strip_path: false

plugins:
  # 1. Authentication: JWT validation
  - name: jwt
    config:
      uri_param_names:
        - jwt
      header_names:
        - Authorization
      claims_to_verify:
        - exp
      maximum_expiration: 3600  # Max 1 hour token TTL

  # 2. Rate Limiting
  - name: rate-limiting
    config:
      minute: 60
      hour: 1000
      policy: redis
      redis_host: redis
      redis_port: 6379
      fault_tolerant: true
      hide_client_headers: false
      limit_by: credential  # Per-user, not per-IP

  # 3. Request Size Limiting
  - name: request-size-limiting
    config:
      allowed_payload_size: 1  # 1 MB max
      size_unit: megabytes

  # 4. IP Restriction (admin endpoints)
  - name: ip-restriction
    service: admin-service
    config:
      allow:
        - 10.0.0.0/8
        - 172.16.0.0/12

  # 5. Bot Detection
  - name: bot-detection
    config:
      deny:
        - "sqlmap"
        - "nikto"
        - "nmap"
        - "masscan"

  # 6. CORS Configuration
  - name: cors
    config:
      origins:
        - "https://app.example.com"
      methods:
        - GET
        - POST
        - PUT
        - PATCH
        - DELETE
      headers:
        - Authorization
        - Content-Type
      credentials: true
      max_age: 3600

  # 7. Response Transformer - Remove sensitive headers
  - name: response-transformer
    config:
      remove:
        headers:
          - X-Powered-By
          - Server
      add:
        headers:
          - "X-Content-Type-Options: nosniff"
          - "X-Frame-Options: DENY"
          - "Strict-Transport-Security: max-age=31536000; includeSubDomains"
          - "Content-Security-Policy: default-src 'none'"
Step 2: AWS API Gateway Security Configuration
python
import boto3
import json

apigw = boto3.client('apigatewayv2')

# Create API with mutual TLS
api_response = apigw.create_api(
    Name='secure-api',
    ProtocolType='HTTP',
    DisableExecuteApiEndpoint=True,  # Force custom domain
)
api_id = api_response['ApiId']

# Configure authorizer (JWT with Cognito)
authorizer = apigw.create_authorizer(
    ApiId=api_id,
    AuthorizerType='JWT',
    IdentitySource='$request.header.Authorization',
    Name='cognito-jwt-authorizer',
    JwtConfiguration={
        'Audience': ['your-app-client-id'],
        'Issuer': 'https://cognito-idp.us-east-1.amazonaws.com/us-east-1_xxxxx'
    }
)

# Create route with authorizer
apigw.create_route(
    ApiId=api_id,
    RouteKey='GET /api/v1/users',
    AuthorizerId=authorizer['AuthorizerId'],
    AuthorizationType='JWT',
)

# Configure throttling
apigw.create_stage(
    ApiId=api_id,
    StageName='prod',
    DefaultRouteSettings={
        'ThrottlingBurstLimit': 100,
        'ThrottlingRateLimit': 50.0,  # 50 requests per second
    },
    AccessLogSettings={
        'DestinationArn': 'arn:aws:logs:us-east-1:123456789:log-group:api-access-logs',
        'Format': json.dumps({
            'requestId': '$context.requestId',
            'ip': '$context.identity.sourceIp',
            'caller': '$context.identity.caller',
            'user': '$context.identity.user',
            'requestTime': '$context.requestTime',
            'httpMethod': '$context.httpMethod',
            'resourcePath': '$context.resourcePath',
            'status': '$context.status',
            'protocol': '$context.protocol',
            'responseLength': '$context.responseLength'
        })
    }
)

# WAF association
waf = boto3.client('wafv2')
web_acl = waf.create_web_acl(
    Name='api-security-acl',
    Scope='REGIONAL',
    DefaultAction={'Allow': {}},
    Rules=[
        {
            'Name': 'AWS-AWSManagedRulesSQLiRuleSet',
            'Priority': 1,
            'Statement': {
                'ManagedRuleGroupStatement': {
                    'VendorName': 'AWS',
                    'Name': 'AWSManagedRulesSQLiRuleSet'
                }
            },
            'OverrideAction': {'None': {}},
            'VisibilityConfig': {
                'SampledRequestsEnabled': True,
                'CloudWatchMetricsEnabled': True,
                'MetricName': 'SQLiRuleSet'
            }
        },
        {
            'Name': 'RateLimit',
            'Priority': 2,
            'Statement': {
                'RateBasedStatement': {
                    'Limit': 2000,
                    'AggregateKeyType': 'IP'
                }
            },
            'Action': {'Block': {}},
            'VisibilityConfig': {
                'SampledRequestsEnabled': True,
                'CloudWatchMetricsEnabled': True,
                'MetricName': 'RateLimitRule'
            }
        },
    ],
    VisibilityConfig={
        'SampledRequestsEnabled': True,
        'CloudWatchMetricsEnabled': True,
        'MetricName': 'ApiSecurityACL'
    }
)
Step 3: Request Validation with OpenAPI Schema
yaml
# Kong OAS Validation Plugin configuration
plugins:
  - name: oas-validation
    config:
      api_spec: |
        openapi: "3.0.3"
        info:
          title: Secure API
          version: "1.0"
        paths:
          /api/v1/users:
            post:
              requestBody:
                required: true
                content:
                  application/json:
                    schema:
                      type: object
                      required: [name, email]
                      properties:
                        name:
                          type: string
                          maxLength: 100
                          pattern: "^[a-zA-Z ]+$"
                        email:
                          type: string
                          format: email
                          maxLength: 255
                      additionalProperties: false  # Block mass assignment
              responses:
                '201':
                  description: User created
      validate_request_body: true
      validate_request_header_params: true
      validate_request_query_params: true
      validate_request_uri_params: true
      verbose_response: false  # Do not expose schema details in errors
Step 4: Mutual TLS Configuration
bash
# Generate CA and client certificates for mTLS
# 1. Create CA
openssl genrsa -out ca.key 4096
openssl req -new -x509 -key ca.key -out ca.crt -days 365 \
    -subj "/CN=API Gateway CA/O=Example Corp"

# 2. Create client certificate
openssl genrsa -out client.key 2048
openssl req -new -key client.key -out client.csr \
    -subj "/CN=api-client/O=Example Corp"
openssl x509 -req -in client.csr -CA ca.crt -CAkey ca.key \
    -CAcreateserial -out client.crt -days 365

# Kong mTLS configuration
# Upload CA certificate to Kong
curl -X POST http://kong-admin:8001/ca_certificates \
    -F "cert=@ca.crt"

# Enable mTLS plugin
curl -X POST http://kong-admin:8001/services/user-service/plugins \
    --data "name=mtls-auth" \
    --data "config.ca_certificates[]=$(cat ca_cert_id)" \
    --data "config.revocation_check_mode=SKIP" \
    --data "config.authenticated_group_by=CN"
Step 5: Logging and Monitoring Configuration
python
# CloudWatch monitoring for API security events
import boto3

cloudwatch = boto3.client('cloudwatch')
logs = boto3.client('logs')

# Create metric filters for security events
security_filters = [
    {
        'name': 'UnauthorizedAccess',
        'pattern': '{ $.status = 401 || $.status = 403 }',
        'metric': 'UnauthorizedAccessCount'
    },
    {
        'name': 'RateLimitHits',
        'pattern': '{ $.status = 429 }',
        'metric': 'RateLimitHitCount'
    },
    {
        'name': 'ServerErrors',
        'pattern': '{ $.status >= 500 }',
        'metric': 'ServerErrorCount'
    },
    {
        'name': 'LargeResponses',
        'pattern': '{ $.responseLength > 1000000 }',
        'metric': 'LargeResponseCount'
    },
]

for sf in security_filters:
    logs.put_metric_filter(
        logGroupName='api-access-logs',
        filterName=sf['name'],
        filterPattern=sf['pattern'],
        metricTransformations=[{
            'metricName': sf['metric'],
            'metricNamespace': 'APISecurityMetrics',
            'metricValue': '1',
            'defaultValue': 0
        }]
    )

# Create alarm for unusual 401/403 spike
cloudwatch.put_metric_alarm(
    AlarmName='API-UnauthorizedAccessSpike',
    MetricName='UnauthorizedAccessCount',
    Namespace='APISecurityMetrics',
    Statistic='Sum',
    Period=300,  # 5 minutes
    EvaluationPeriods=1,
    Threshold=100,
    ComparisonOperator='GreaterThanThreshold',
    AlarmActions=['arn:aws:sns:us-east-1:123456789:security-alerts'],
    AlarmDescription='More than 100 unauthorized access attempts in 5 minutes'
)

Key Concepts

TermDefinition
API GatewayCentralized entry point for all API traffic that enforces authentication, authorization, rate limiting, and request validation before routing to backend services
Rate LimitingControlling the number of API requests per client within a time window to prevent abuse and ensure fair resource allocation
Request ValidationVerifying that incoming API requests conform to the expected schema (data types, required fields, value ranges) before forwarding to backend services
Mutual TLS (mTLS)Two-way TLS authentication where both the client and server present certificates, providing strong identity verification for API-to-API communication
WAF IntegrationWeb Application Firewall rules applied at the API gateway to block common attack patterns (SQLi, XSS, path traversal)
OAuth2/OIDCToken-based authentication protocols where the gateway validates JWT tokens against an identity provider before allowing access

Tools & Systems

  • Kong Gateway: Open-source API gateway with extensive plugin ecosystem for security, rate limiting, and authentication
  • AWS API Gateway: Managed API gateway service with built-in throttling, WAF integration, and Lambda authorizers
  • Azure API Management: Enterprise API gateway with policy-based security, developer portal, and Azure AD integration
  • Apigee (Google Cloud): API management platform with threat protection, quota management, and API analytics
  • Envoy Proxy: High-performance proxy used as API gateway in service mesh architectures with extensive filter chain
Show full SKILL.md (228 more words)Show less

Common Scenarios

Scenario: Securing a Microservice API with Kong Gateway

Context: A company is migrating from a monolithic API to microservices. Each microservice has its own REST API. The security team needs to implement centralized authentication, rate limiting, and request validation without modifying each service.

Approach:

  1. Deploy Kong Gateway as the single entry point, routing traffic to 8 backend microservices
  2. Configure JWT validation plugin to verify tokens against the company's Keycloak IdP
  3. Apply rate limiting: 60 requests/minute for regular users, 300/minute for premium users, identified by JWT claims
  4. Enable OAS validation plugin to reject requests that do not match the OpenAPI spec (blocks mass assignment and injection)
  5. Configure mTLS for service-to-service communication behind the gateway
  6. Set up response transformer to remove Server and X-Powered-By headers and add security headers
  7. Integrate with AWS WAF for SQL injection and XSS protection rules
  8. Configure access logging to CloudWatch with security metric filters and alerting

Pitfalls:

  • Relying solely on the gateway for authorization when backend services also need to verify permissions
  • Not configuring rate limiting per authenticated user (per-IP only allows attackers to bypass with IP rotation)
  • Using verbose error responses from the gateway that reveal internal service architecture
  • Not testing the gateway configuration with security tools after deployment
  • Missing mutual TLS between the gateway and backend services, allowing direct backend access

Output Format

## API Gateway Security Configuration Report

**Gateway**: Kong 3.5 (Kubernetes deployment)
**Backend Services**: 8 microservices
**Date**: 2024-12-15

### Security Controls Implemented

| Control | Plugin/Feature | Configuration |
|---------|---------------|---------------|
| Authentication | JWT Plugin | Cognito IdP, 1-hour max TTL |
| Rate Limiting | Rate Limiting Plugin | 60 req/min (user), Redis-backed |
| Request Validation | OAS Validation | Strict mode, no additional properties |
| TLS | Kong TLS | TLS 1.3 only, HSTS enabled |
| mTLS | mTLS Auth Plugin | Client cert required for admin APIs |
| WAF | AWS WAF | SQLi, XSS, rate-based rules |
| Headers | Response Transformer | Server header removed, security headers added |
| Logging | HTTP Log Plugin | CloudWatch, security metric filters |

### Verification Results

- JWT validation: Expired/invalid tokens correctly rejected (tested 50 payloads)
- Rate limiting: Enforced at 60 req/min, 429 returned with Retry-After header
- Request validation: Malformed requests rejected with 400 (tested 30 invalid payloads)
- mTLS: Requests without client certificate rejected with 401
- WAF: SQL injection payloads blocked (tested top 100 SQLi patterns)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/implementing-api-gateway-security-controls of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing API Gateway Security Controls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing API Gateway Security Controls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing API Gateway Security Controls this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.9kAutomated safety check: PassApache-2.0
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Azure Aigatewaymicrosoft/GitHub-Copilot-for-Azure2552 repos~1.3kAutomated safety check: PassMIT
API Gatewayitsmostafa/aws-agent-skills1.2k1 repos~2.2kAutomated safety check: PassMIT
Azure Mgmt Apimanagement Pymicrosoft/skills3.1k6 repos~2.2kAutomated safety check: PassMIT
API Security ReviewOWASP/secure-agent-playbook186—~744Automated safety check: PassCC-BY-4.0

Similar skills

  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Azure Aigateway

    microsoft/GitHub-Copilot-for-Azure

    Official

    Configure Azure API Management as an AI Gateway for AI models, MCP tools, and agents.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    Backend & APIsAuto-check passed
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Backend & APIsAuto-check passed
  • Official

    Azure API Management SDK for Python. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 6 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    186 GitHub stars~744 tokensUpdated 12 days ago
    Backend & APIsAuto-check passed
  • Ak Cloud Deploy

    yaalalabs/agent-kernel

    Deploy an Agent Kernel project to AWS, Azure, or GCP using Terraform modules, or to any Kubernetes cluster (on-prem, baremetal, EKS) using the official Helm chart.

    191 GitHub stars~14k tokensUpdated today
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 639 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Implementing API Gateway Security Controls

What does Implementing API Gateway Security Controls do?

Configures API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a centralized security enforcement point, covering authentication enforcement, rate limiting and throttling, request…. Implementing API Gateway Security Controls is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Configures API gateways such as Kong, AWS API Gateway, Azure APIM, or Apigee as a centralized security enforcement point, covering authentication enforcement, rate limiting and throttling, request validation, IP allowlisting, TLS termination, and threat protection.

When should I use Implementing API Gateway Security Controls?

Implementing API Gateway Security Controls fits situations like: securing API traffic at the gateway layer; setting up gateway-level authentication and quota management; centralizing API protection before requests reach backend services.

How do I install Implementing API Gateway Security Controls in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-api-gateway-security-controls -a claude-code`. Or copy the skill folder (skills/implementing-api-gateway-security-controls in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-api-gateway-security-controls in your project. Claude Code loads it when a task matches its description.

How do I install Implementing API Gateway Security Controls in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-api-gateway-security-controls -a codex`. Or copy the skill folder (skills/implementing-api-gateway-security-controls in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-api-gateway-security-controls in your project. Codex loads it when a task matches its description.

Can I use Implementing API Gateway Security Controls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-api-gateway-security-controls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-api-gateway-security-controls, .gemini/skills/implementing-api-gateway-security-controls, .github/skills/implementing-api-gateway-security-controls and .opencode/skills/implementing-api-gateway-security-controls in your project.

What does Implementing API Gateway Security Controls need to run?

Going by SKILL.md and its folder, Implementing API Gateway Security Controls needs Python for the scripts in its folder and the command-line tools its instructions call (openssl, curl and aws). Our summary lists: Python 3.

Does Implementing API Gateway Security Controls access the network?

SKILL.md names 1 domain. In commands or code: cognito-idp.us-east-1.amazonaws.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Implementing API Gateway Security Controls safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing API Gateway Security Controls use?

Implementing API Gateway Security Controls is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing API Gateway Security Controls use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 410 tokens, read only when the agent opens those files.

What are the alternatives to Implementing API Gateway Security Controls?

Skills that share tags, products or a category with Implementing API Gateway Security Controls: API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Azure Aigateway (microsoft/GitHub-Copilot-for-Azure, 255 stars), API Gateway (itsmostafa/aws-agent-skills, 1.2k stars) and Azure Mgmt Apimanagement Py (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing API Gateway Security Controls?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,870 GitHub stars. The repository holds 639 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.