Agent skill

API Security Checklist

by revfactory in revfactory/harness-100

Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

Apache-2.0Auto-check passedSecurity

Install API Security Checklist

skills CLI
$ npx skills add revfactory/harness-100 --skill api-security-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 api-security-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/16-fullstack-webapp/.claude/skills/api-security-checklist .claude/skills/api-security-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-security-checklist
GitHub stars
1.3k
Token cost
~1.7k tokens
SKILL.md length
570 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

  • Designing authentication for a new API endpoint
  • SKILL.md covers Target Agent, OWASP API Security Top 10 Check, Authentication Patterns and Authorization Patterns, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Reviewing an API against the OWASP API Security Top 10

What it does

A table maps each OWASP API Security Top 10 risk, such as broken object-level authorization, broken authentication and server-side request forgery, to a check question and a defense, so an agent implementing an endpoint can confirm each one rather than guess. It is explicitly scoped to API design and defense code, not penetration testing or WAF configuration.

Authentication guidance covers JWT settings such as access and refresh token lifetimes, signing algorithm choice, httpOnly cookie storage, and a password policy built on bcrypt or Argon2id with a failed-attempt lockout. Authorization patterns continue into role-based access control for enforcing who can call which endpoint.

When your agent uses it

  • Designing authentication for a new API endpoint
  • Reviewing an API against the OWASP API Security Top 10
  • Setting CORS, CSRF or rate-limiting rules for a backend service

Example prompts

  • “Check our login API against the OWASP API Security Top 10.”
  • “Design JWT authentication with refresh tokens for this service.”
  • “Review this endpoint's CORS and rate-limiting configuration.”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Security Checklist loads about 1.7k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 570 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 570 words, ~1,652 tokens.

Download SKILL.mdSave it as .claude/skills/api-security-checklist/SKILL.md (or your agent's skills folder).
name
api-security-checklist
description
Web app API security checklist. Provides OWASP Top 10-based vulnerability checks, authentication/authorization patterns, input validation, Rate Limiting, CORS, CSRF, and SQL Injection defense as a backend-dev extension skill. Use for requests like 'API security', 'OWASP', 'auth implementation', 'SQL Injection', 'XSS defense', 'CORS configuration', 'security checklist', and other backend security design tasks. However, penetration testing or WAF configuration is outside this skill's scope.

API Security Checklist — Web App API Security Checklist

An OWASP-based security checklist, authentication patterns, and defense code guide that the backend-dev agent uses during API development.

Target Agent

backend-dev — Applies this skill's security checklist directly to API implementation.

OWASP API Security Top 10 Check

RankVulnerabilityCheck ItemDefense
A1BOLA (Broken Object Level Authorization)Can another user's resources be accessed?Verify object ownership at every endpoint
A2Broken AuthenticationWeak passwords, unlimited login attempts?bcrypt hashing, Rate Limit, MFA
A3Broken Object Property Level AuthorizationAre fields that should be hidden exposed?Filter fields via response DTOs
A4Unrestricted Resource ConsumptionCan mass requests crash the server?Rate Limiting, enforce pagination
A5Broken Function Level AuthorizationCan regular users call admin APIs?RBAC middleware
A6Server-Side Request Forgery (SSRF)Can external URL input access internal resources?URL whitelist, block internal IPs
A7Security MisconfigurationDebug mode exposed, default accounts?Separate production config, inspect headers
A8Lack of Protection from Automated ThreatsCan normal APIs be called in abnormal sequences?State machine validation, server-side business rules
A9Improper Asset ManagementUnused APIs, old versions exposed?API inventory, version deprecation policy
A10Unsafe Consumption of APIsAre external API responses blindly trusted?Validate external responses, set timeouts

Authentication Patterns

JWT-Based Authentication
ItemRecommended Setting
Access Token Expiry15-30 minutes
Refresh Token Expiry7-14 days
AlgorithmRS256 (asymmetric) or HS256 (symmetric)
StoragehttpOnly + secure + sameSite cookie
PayloadMinimal info only (userId, role) — no PII
Renewal StrategySilent Refresh or Rotation
Password Policy
  • Minimum 8 characters, recommend uppercase + lowercase + numbers + special chars (show strength rather than enforce)
  • bcrypt (cost factor 12+) or Argon2id
  • Password history (prevent reuse of last 5)
  • Temporary lock after 5 failed login attempts (15 min) or CAPTCHA

Authorization Patterns

RBAC (Role-Based)
Role definitions: admin, manager, user, viewer
Permission mapping:
  admin    → *.* (full access)
  manager  → resource.create, resource.read, resource.update
  user     → resource.create (own), resource.read (own)
  viewer   → resource.read (public)
Middleware Chain
Request → [Rate Limit] → [Auth: JWT verification] → [Authorization: role check] → [Input Validation] → Handler

Input Validation Checklist

Validation ItemMethodTool
Type ValidationSchema validationZod, Joi, class-validator
Length LimitsMin/max lengthSchema min/max
Pattern MatchingEmail, URL, phoneRegex + libraries
Range ValidationNumber range, date rangemin/max values
EnumerationAllowed value listenum type
SQL InjectionParameterized queriesORM (Prisma, TypeORM)
XSSHTML escapingDOMPurify (client), server escape
Path TraversalPath normalizationpath.resolve + whitelist
File UploadType/size validationMIME type + magic number verification
Show full SKILL.md (206 more words)Show less

HTTP Security Headers

HeaderValuePurpose
Strict-Transport-Securitymax-age=31536000; includeSubDomainsForce HTTPS
X-Content-Type-OptionsnosniffPrevent MIME sniffing
X-Frame-OptionsDENY or SAMEORIGINPrevent clickjacking
Content-Security-Policydefault-src 'self'Prevent XSS
X-XSS-Protection0 (replaced by CSP)Legacy
Referrer-Policystrict-origin-when-cross-originLimit referrer info
Permissions-Policycamera=(), microphone=()Restrict browser features

CORS Configuration Guide

EnvironmentSetting
Developmentorigin: 'http://localhost:3000'
Productionorigin: ['https://example.com'] — specify domains
Forbiddenorigin: '*' + credentials: true — security risk

Required settings:

  • methods: Allow only necessary methods
  • allowedHeaders: Only necessary headers
  • credentials: Set to true only when cookies are needed
  • maxAge: Preflight caching (86400 seconds)

Rate Limiting Strategy

TargetLimitImplementation
Auth endpoints5 req/min/IPIP-based
General API100 req/min/userToken-based
File upload10 req/hour/userToken-based
Unauthenticated API30 req/min/IPIP-based
Response Headers
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 95
X-RateLimit-Reset: 1609459200
Retry-After: 60 (on 429 response)

Error Response Security

Production Error Response Rules
  • Never expose internal implementation details (stack traces, SQL queries)
  • Use consistent error format
  • Prevent enumeration attacks: On login failure, show "Email or password is incorrect" (don't reveal which one is wrong)
Error Response Format
json
{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "Input is invalid",
    "details": [
      {"field": "email", "message": "Please enter a valid email"}
    ]
  }
}

Sensitive Data Handling

Data TypeStorageTransmissionLogging
Passwordsbcrypt hash onlyHTTPS onlyNever
API KeysEnvironment variablesHeader (Authorization)Masked (first 4 chars only)
PIIEncrypted (AES-256)HTTPS onlyMasked
Credit CardsTokenized (delegate to payment provider)Payment provider SDKNever
Sessions/TokenshttpOnly cookieHTTPS onlyNever

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/16-fullstack-webapp/.claude/skills/api-security-checklist of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

API Security Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Security Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Security Checklist this skillrevfactory/harness-1001.3k—~1.7kAutomated safety check: PassApache-2.0
Secure Code GuardianJeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Hunt APIEncod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT
Cloudflare Workers Securitysecondsky/claude-skills227—~1.9kAutomated safety check: PassMIT
API Security EngineerFerroxLabs/wayland608—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Secure Code Guardian

    Jeffallan/claude-skills

    Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.

    12k GitHub stars~1.8k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Hunt API

    Encod3d-Sec/TORCH

    API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

    329 GitHub stars~1.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Cloudflare Workers Security

    secondsky/claude-skills

    Cloudflare Workers security with authentication, CORS, rate limiting, input validation.

    227 GitHub stars~1.9k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • API Security Engineer

    FerroxLabs/wayland

    API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…

    608 GitHub stars~3.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    412 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • Audit Checklist Engine

    revfactory/harness-100

    A systematic checklist generation engine for compliance audits.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about API Security Checklist

What does API Security Checklist do?

Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design. A table maps each OWASP API Security Top 10 risk, such as broken object-level authorization, broken authentication and server-side request forgery, to a check question and a defense, so an agent implementing an endpoint can confirm each one rather than guess. It is explicitly scoped to API design and defense code, not penetration testing or WAF configuration.

When should I use API Security Checklist?

API Security Checklist fits situations like: designing authentication for a new API endpoint; reviewing an API against the OWASP API Security Top 10; setting CORS, CSRF or rate-limiting rules for a backend service.

How do I install API Security Checklist in Claude Code?

Run `npx skills add revfactory/harness-100 --skill api-security-checklist -a claude-code`. Or copy the skill folder (en/16-fullstack-webapp/.claude/skills/api-security-checklist in revfactory/harness-100) into .claude/skills/api-security-checklist in your project. Claude Code loads it when a task matches its description.

How do I install API Security Checklist in Codex?

Run `npx skills add revfactory/harness-100 --skill api-security-checklist -a codex`. Or copy the skill folder (en/16-fullstack-webapp/.claude/skills/api-security-checklist in revfactory/harness-100) into .agents/skills/api-security-checklist in your project. Codex loads it when a task matches its description.

Can I use API Security Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill api-security-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-security-checklist, .gemini/skills/api-security-checklist, .github/skills/api-security-checklist and .opencode/skills/api-security-checklist in your project.

What does API Security Checklist need to run?

SKILL.md names no scripts, command-line tools or credentials: API Security Checklist is instructions for the agent only.

Does API Security Checklist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Security Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Security Checklist use?

API Security Checklist is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Security Checklist use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Security Checklist?

Skills that share tags, products or a category with API Security Checklist: Secure Code Guardian (Jeffallan/claude-skills, 12k stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Hunt API (Encod3d-Sec/TORCH, 329 stars) and Cloudflare Workers Security (secondsky/claude-skills, 227 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Security Checklist?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.