Agent skill

API Security Checklist

by revfactory in revfactory/harness-100

웹앱 API 보안 체크리스트. An agent skill from revfactory/harness-100.

Apache-2.0Auto-check passedSecurity

Install API Security Checklist

skills CLI
$ npx skills add revfactory/harness-100 --skill api-security-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 api-security-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ko/16-fullstack-webapp/.claude/skills/api-security-checklist .claude/skills/api-security-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-security-checklist
GitHub stars
1.3k
Token cost
~1.1k tokens
SKILL.md length
522 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

웹앱 API 보안 체크리스트. An agent skill from revfactory/harness-100.

  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers 대상 에이전트, OWASP API Security Top 10 점검, 인증 (Authentication) 패턴 and 인가 (Authorization) 패턴, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

API Security Checklist is an agent skill from revfactory/harness-100. 웹앱 API 보안 체크리스트. OWASP Top 10 기반 취약점 점검, 인증/인가 패턴, 입력 검증, Rate Limiting, CORS, CSRF, SQL Injection 방어를 제공하는 backend-dev 확장 스킬. 'API 보안', 'OWASP', '인증 구현', 'SQL Injection', 'XSS 방어', 'CORS 설정', '보안 체크리스트' 등 백엔드 보안 설계 시 사용한다. 단, 침투 테스트 수행이나 WAF 구성은 이 스킬의 범위가 아니다.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Web application vulnerabilities

Example prompts

  • “API 보안”
  • “SQL Injection”
  • “XSS 방어”
  • “/api-security-checklist”

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

API Security Checklist loads about 1.1k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 522 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 522 words, ~1,083 tokens.

Download SKILL.mdSave it as .claude/skills/api-security-checklist/SKILL.md (or your agent's skills folder).
name
api-security-checklist
description
웹앱 API 보안 체크리스트. OWASP Top 10 기반 취약점 점검, 인증/인가 패턴, 입력 검증, Rate Limiting, CORS, CSRF, SQL Injection 방어를 제공하는 backend-dev 확장 스킬. 'API 보안', 'OWASP', '인증 구현', 'SQL Injection', 'XSS 방어', 'CORS 설정', '보안 체크리스트' 등 백엔드 보안 설계 시 사용한다. 단, 침투 테스트 수행이나 WAF 구성은 이 스킬의 범위가 아니다.

API Security Checklist — 웹앱 API 보안 체크리스트

backend-dev 에이전트가 API 개발 시 활용하는 OWASP 기반 보안 체크리스트, 인증 패턴, 방어 코드 가이드.

대상 에이전트

backend-dev — 이 스킬의 보안 체크리스트를 API 구현에 직접 적용한다.

OWASP API Security Top 10 점검

순위취약점점검 항목방어
A1BOLA (객체 수준 인가 결함)다른 사용자의 리소스 접근 가능?모든 엔드포인트에서 객체 소유권 검증
A2인증 결함약한 비밀번호, 무제한 로그인 시도?bcrypt 해싱, Rate Limit, MFA
A3객체 속성 수준 인가숨겨야 할 필드 노출?응답 DTO로 필드 필터링
A4무제한 리소스 소비대량 요청으로 서버 마비?Rate Limiting, 페이지네이션 강제
A5기능 수준 인가 결함관리자 API를 일반 유저가 호출?RBAC 미들웨어
A6서버 사이드 요청 위조 (SSRF)외부 URL 입력으로 내부 접근?URL 화이트리스트, 내부 IP 차단
A7보안 설정 오류디버그 모드 노출, 기본 계정?프로덕션 설정 분리, 헤더 점검
A8비즈니스 흐름 결함정상 API를 비정상 순서로 호출?상태 머신 검증, 비즈니스 규칙 서버측
A9취약 자산 관리미사용 API, 구버전 노출?API 인벤토리, 버전 폐기 정책
A10안전하지 않은 API 소비외부 API 응답 무조건 신뢰?외부 응답 검증, 타임아웃 설정

인증 (Authentication) 패턴

JWT 기반 인증
항목권장 설정
Access Token 만료15~30분
Refresh Token 만료7~14일
알고리즘RS256 (비대칭) 또는 HS256 (대칭)
저장소httpOnly + secure + sameSite cookie
Payload최소 정보만 (userId, role) — PII 금지
갱신 전략Silent Refresh 또는 Rotation
비밀번호 정책
  • 최소 8자, 대소문자+숫자+특수문자 권장 (강제보다 강도 표시)
  • bcrypt (cost factor 12+) 또는 Argon2id
  • 비밀번호 히스토리 (최근 5개 재사용 금지)
  • 로그인 실패 5회 시 임시 잠금 (15분) 또는 CAPTCHA

인가 (Authorization) 패턴

RBAC (역할 기반)
역할 정의: admin, manager, user, viewer
권한 매핑:
  admin    → *.* (전체)
  manager  → resource.create, resource.read, resource.update
  user     → resource.create (own), resource.read (own)
  viewer   → resource.read (public)
미들웨어 체인
요청 → [Rate Limit] → [인증: JWT 검증] → [인가: 역할 확인] → [입력 검증] → 핸들러

입력 검증 체크리스트

검증 항목방법도구
타입 검증스키마 검증Zod, Joi, class-validator
길이 제한최소/최대 길이스키마에 min/max
패턴 매칭이메일, URL, 전화번호정규식 + 라이브러리
범위 검증숫자 범위, 날짜 범위min/max 값
열거형허용된 값 목록enum 타입
SQL Injection파라미터화 쿼리ORM (Prisma, TypeORM)
XSSHTML 이스케이핑DOMPurify (클라이언트), 서버 이스케이프
Path Traversal경로 정규화path.resolve + 화이트리스트
파일 업로드타입/크기 검증MIME 타입 + 매직넘버 검증
Show full SKILL.md (191 more words)Show less

HTTP 보안 헤더

헤더값목적
Strict-Transport-Securitymax-age=31536000; includeSubDomainsHTTPS 강제
X-Content-Type-OptionsnosniffMIME 스니핑 방지
X-Frame-OptionsDENY 또는 SAMEORIGIN클릭재킹 방지
Content-Security-Policydefault-src 'self'XSS 방지
X-XSS-Protection0 (CSP로 대체)레거시
Referrer-Policystrict-origin-when-cross-origin리퍼러 정보 제한
Permissions-Policycamera=(), microphone=()브라우저 기능 제한

CORS 설정 가이드

환경설정
개발origin: 'http://localhost:3000'
프로덕션origin: ['https://example.com'] — 도메인 명시
금지origin: '*' + credentials: true — 보안 위험

필수 설정:

  • methods: 필요한 메서드만 허용
  • allowedHeaders: 필요한 헤더만
  • credentials: 쿠키 필요 시에만 true
  • maxAge: 프리플라이트 캐싱 (86400초)

Rate Limiting 전략

대상제한구현
인증 엔드포인트5회/분/IPIP 기반
API 일반100회/분/사용자토큰 기반
파일 업로드10회/시간/사용자토큰 기반
비인증 API30회/분/IPIP 기반
응답 헤더
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 95
X-RateLimit-Reset: 1609459200
Retry-After: 60 (429 응답 시)

에러 응답 보안

프로덕션 에러 응답 규칙
  • 내부 구현 세부사항 절대 노출 금지 (스택 트레이스, SQL 쿼리)
  • 일관된 에러 형식 사용
  • 열거 공격 방지: 로그인 실패 시 "이메일 또는 비밀번호가 올바르지 않습니다" (어느 것이 틀렸는지 X)
에러 응답 형식
json
{
  "error": {
    "code": "VALIDATION_ERROR",
    "message": "입력값이 올바르지 않습니다",
    "details": [
      {"field": "email", "message": "유효한 이메일을 입력하세요"}
    ]
  }
}

민감 데이터 처리

데이터 유형저장전송로깅
비밀번호bcrypt 해시만HTTPS only절대 금지
API Key환경변수헤더 (Authorization)마스킹 (앞4자리만)
개인정보 (PII)암호화 (AES-256)HTTPS only마스킹
신용카드토큰화 (PG사 위임)PG사 SDK절대 금지
세션/토큰httpOnly cookieHTTPS only절대 금지

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ko/16-fullstack-webapp/.claude/skills/api-security-checklist of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

API Security Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

API Security Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
API Security Checklist this skillrevfactory/harness-1001.3k—~1.1kAutomated safety check: PassApache-2.0
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11617 repos~3.1kAutomated safety check: NotesMIT
Strix Code Vulnerability Scanusestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 17 repos~3.1k tokens
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    67k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about API Security Checklist

What does API Security Checklist do?

웹앱 API 보안 체크리스트. An agent skill from revfactory/harness-100. API Security Checklist is an agent skill from revfactory/harness-100. 웹앱 API 보안 체크리스트.

When should I use API Security Checklist?

API Security Checklist fits situations like: tasks that involve Web application vulnerabilities.

How do I install API Security Checklist in Claude Code?

Run `npx skills add revfactory/harness-100 --skill api-security-checklist -a claude-code`. Or copy the skill folder (ko/16-fullstack-webapp/.claude/skills/api-security-checklist in revfactory/harness-100) into .claude/skills/api-security-checklist in your project. Claude Code loads it when a task matches its description.

How do I install API Security Checklist in Codex?

Run `npx skills add revfactory/harness-100 --skill api-security-checklist -a codex`. Or copy the skill folder (ko/16-fullstack-webapp/.claude/skills/api-security-checklist in revfactory/harness-100) into .agents/skills/api-security-checklist in your project. Codex loads it when a task matches its description.

Can I use API Security Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill api-security-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-security-checklist, .gemini/skills/api-security-checklist, .github/skills/api-security-checklist and .opencode/skills/api-security-checklist in your project.

What does API Security Checklist need to run?

SKILL.md names no scripts, command-line tools or credentials: API Security Checklist is instructions for the agent only.

Does API Security Checklist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is API Security Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does API Security Checklist use?

API Security Checklist is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does API Security Checklist use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to API Security Checklist?

Skills that share tags, products or a category with API Security Checklist: Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Strix Code Vulnerability Scan (usestrix/strix, 67k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains API Security Checklist?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.