Agent skill

Unauthenticated API Endpoint Recon

by uphiago in uphiago/recon-skills

Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

MITAuto-check passedSecurity

Install Unauthenticated API Endpoint Recon

skills CLI
$ npx skills add uphiago/recon-skills --skill api-noauth-hunt -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills api-noauth-hunt --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/api-noauth-hunt .claude/skills/api-noauth-hunt && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-noauth-hunt
GitHub stars
1.3k
Token cost
~2k tokens
SKILL.md length
377 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

  • Works in 4 steps: API Discovery → OpenAPI/Swagger Exploitation → Authorized Synthetic CRUD Validation → …
  • Checking whether a discovered API endpoint enforces authentication
  • SKILL.md covers When to Use, Prerequisites, How to Run and Quick Reference, plus 3 more sections
  • Calls curl, python3 and jq

What it does

This skill is a reconnaissance step for authorized penetration testing or bug-bounty work, used after a port scan or subdomain search turns up an HTTP service that looks like an API — a dedicated subdomain, unusual ports, or endpoints referenced inside JavaScript bundles. Discovery stays read-only by default: it probes a short list of common paths and checks for signals such as an exposed API schema document, an error page leaking internal paths, or data coming back with no authentication header at all.

Any step that would change server state, such as a write test, requires the engagement's scope to explicitly allow write testing and only runs against disposable synthetic records created with authorization right beforehand — the skill is explicit that this guard should not be removed or pointed at a real record. It assumes curl, python3, and jq are already available, along with a target address and a list of common API paths to try.

When your agent uses it

  • Checking whether a discovered API endpoint enforces authentication
  • Investigating an exposed API schema document found during recon
  • Validating an authorization gap on a specific endpoint with written scope permission

Example prompts

  • “Check whether this API subdomain requires authentication on its endpoints.”
  • “Is this exposed API schema leaking endpoints we haven't tested?”
  • “Validate this authorization gap using a synthetic record, scope permits it.”

Requirements

  • curl, python3, and jq
  • nmap, masscan, subfinder, httpx, and nuclei for broader recon
  • Compatibility (from SKILL.md): Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. API Discovery
  2. OpenAPI/Swagger Exploitation
  3. Authorized Synthetic CRUD Validation
  4. Bounded Read Validation

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei

    From compatibility in the SKILL.md frontmatter.

Context cost

Unauthenticated API Endpoint Recon loads about 2k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 377 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 377 words, ~2,044 tokens.

Download SKILL.mdSave it as .claude/skills/api-noauth-hunt/SKILL.md (or your agent's skills folder).
name
api-noauth-hunt
description
Use when an API may expose data or privileged operations without authentication.
compatibility
Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, API, no-auth, data-breach, CRUD
category
recon
related_skills
firebase-supabase-attack, js-secrets-extraction, port-service-discovery, source-leak-hunt

API No-Authentication Validation

Identify API operations that may be reachable without the authentication or authorization required by their data and business function. Discovery is read-only by default. Write validation uses synthetic records and requires explicit authorization immediately before execution.

When to Use

  • Port scan reveals HTTP services on non-standard ports (3000, 5000, 8080-8085, 9000).
  • Target has an API subdomain (api.target.com, backend.target.com).
  • JavaScript bundles reference internal API endpoints.
  • After port-service-discovery finds HTTP on unexpected ports.
  • After firebase-supabase-attack identifies backend APIs.

Prerequisites

  • curl, python3, jq installed.
  • Target URL or IP:port of the suspected API.
  • List of common API paths for fuzzing.

How to Run

bash
# Quick API test — try common paths without auth
TARGET="https://api.target.com"
for path in "/" "/api" "/api/v1" "/api/users" "/api/health" "/docs" "/swagger.json"; do
  code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 "$TARGET$path")
  echo "HTTP $code: $TARGET$path"
done

Quick Reference

SignalWhat It MeansAction
HTTP 200 on /api/users or /api/clientsPossible unauthenticated data accessValidate one bounded sample
HTTP 2xx on POST without authPossible unauthenticated writeStop and obtain write authorization
OpenAPI/Swagger at /docs, /swagger.jsonFull API map exposedEnumerate all endpoints
Stack trace on errorInternal paths, framework versionMap infrastructure
State change via an unexpected methodPossible method-level authorization gapReproduce with a synthetic record
Login without password validationPossible authentication bypassVerify with an approved test account

Procedure

Phase 1 — API Discovery
bash
TARGET="$1"      # URL or IP:port
OUTDIR="$OUTDIR/api_recon"
mkdir -p "$OUTDIR"

echo "[*] API discovery on $TARGET"

# Common API paths
API_PATHS=(
  "/" "/api" "/api/v1" "/api/v2" "/v1" "/v2"
  "/api/users" "/api/clients" "/api/admin" "/api/health"
  "/api/auth" "/api/login" "/api/register"
  "/api/products" "/api/orders" "/api/contracts"
  "/docs" "/swagger.json" "/swagger.yaml" "/openapi.json"
  "/api-docs" "/swagger-ui.html" "/graphql"
  "/health" "/status" "/version" "/info" "/ping"
  "/actuator" "/actuator/health" "/actuator/info" "/actuator/env"
)

for path in "${API_PATHS[@]}"; do
  code=$(curl -sk -o /tmp/api_probe_$$.tmp -w "%{http_code}" --max-time 5 --connect-timeout 5 "$TARGET$path" 2>/dev/null)

  if [[ "$code" == "200" ]]; then
    body=$(cat /tmp/api_probe_$$.tmp)
    content_type=$(file -b --mime-type /tmp/api_probe_$$.tmp 2>/dev/null)

    # Check if it's JSON (likely API)
    if echo "$body" | python3 -c "import sys,json; json.load(sys.stdin)" 2>/dev/null; then
      record_count=$(echo "$body" | python3 -c "import sys,json; d=json.load(sys.stdin); print(len(d) if isinstance(d,list) else 'object')" 2>/dev/null)
      echo "  [API] $path → HTTP 200 (JSON, ${record_count} records)"
    elif echo "$body" | grep -qi "swagger\|openapi"; then
      echo "  [SWAGGER] $path → HTTP 200 (API documentation)"
    elif echo "$body" | grep -qi "graphql"; then
      echo "  [GRAPHQL] $path → HTTP 200"
    else
      echo "  [HTTP] $path → HTTP 200 (${#body} bytes, $content_type)"
    fi
  elif [[ "$code" == "401" || "$code" == "403" ]]; then
    echo "  [AUTH] $path → HTTP $code (protected)"
  elif [[ "$code" == "500" ]]; then
    echo "  [ERROR] $path → HTTP 500 (potential injection point)"
    cat /tmp/api_probe_$$.tmp | head -5
  elif [[ "$code" != "404" && "$code" != "000" ]]; then
    echo "  [$code] $path"
  fi
done
rm -f /tmp/api_probe_$$.tmp
Phase 2 — OpenAPI/Swagger Exploitation
bash
TARGET="$1"

echo "[*] Extracting API schema..."

# Try multiple Swagger paths
for sw_path in "/swagger.json" "/swagger.yaml" "/openapi.json" "/api/swagger.json" \
  "/api-docs" "/v2/api-docs" "/v3/api-docs"; do
  schema=$(curl -sk --max-time 10 --connect-timeout 10 "$TARGET$sw_path" 2>/dev/null)

  if echo "$schema" | grep -q '"paths"'; then
    echo "[+] Found OpenAPI spec at $sw_path"

    # Extract all endpoints
    echo "$schema" | python3 -c "
import sys, json
spec = json.load(sys.stdin)
paths = spec.get('paths', {})
for path, methods in paths.items():
    for method in methods.keys():
        if method not in ('parameters',):
            print(f'  {method.upper():7s} {path}')
" 2>/dev/null

    # Save for later use
    echo "$schema" > /tmp/openapi_$$.json
    echo "[+] Schema saved to /tmp/openapi_$$.json"
    break
  fi
done
Phase 3 — Authorized Synthetic CRUD Validation

This phase changes server state. Run it only when the scope explicitly permits write testing and the endpoint stores disposable synthetic records. The guard below is deliberate: do not remove it or substitute an existing object ID.

bash
TARGET="$1"
ENDPOINT="$2"  # approved test collection
OUTPUT_DIR="${OUTPUT_DIR:-./output}"
PROBE_ID="noauth-test-$(date +%s)"

if [[ "${I_HAVE_EXPLICIT_WRITE_AUTHORIZATION:-no}" != "yes" ]]; then
  echo "Refusing state-changing validation without explicit authorization." >&2
  exit 1
fi

mkdir -p "$OUTPUT_DIR/api-validation"

create_body=$(curl -sk --max-time 10 --connect-timeout 5 \
  -X POST "$TARGET$ENDPOINT" \
  -H "Content-Type: application/json" \
  -d "{\"name\":\"$PROBE_ID\",\"test_record\":true}")
printf '%s\n' "$create_body" \
  > "$OUTPUT_DIR/api-validation/create-response.json"

created_id=$(printf '%s' "$create_body" | jq -r '.id // .uuid // empty')
if [[ -z "$created_id" ]]; then
  echo "Create response did not expose a disposable object ID; stop here." >&2
  exit 1
fi

curl -sk --max-time 10 --connect-timeout 5 \
  "$TARGET$ENDPOINT/$created_id" \
  -o "$OUTPUT_DIR/api-validation/read-response.json"

curl -sk --max-time 10 --connect-timeout 5 \
  -X PATCH "$TARGET$ENDPOINT/$created_id" \
  -H "Content-Type: application/json" \
  -d '{"validation_state":"updated"}' \
  -o "$OUTPUT_DIR/api-validation/update-response.json"

curl -sk --max-time 10 --connect-timeout 5 \
  -X DELETE "$TARGET$ENDPOINT/$created_id" \
  -o "$OUTPUT_DIR/api-validation/delete-response.txt"
Show full SKILL.md (139 more words)Show less
Phase 4 — Bounded Read Validation
bash
TARGET="$1"
ENDPOINT="$2"  # confirmed no-auth endpoint
OUTPUT_DIR="${OUTPUT_DIR:-./output}"

mkdir -p "$OUTPUT_DIR/api-validation"
curl --max-time 15 --connect-timeout 5 -sk \
  "$TARGET$ENDPOINT?page=1&limit=2" \
  -o "$OUTPUT_DIR/api-validation/bounded-sample.json"

jq 'if type == "array" then .[:2] else . end' \
  "$OUTPUT_DIR/api-validation/bounded-sample.json"

Pitfalls

  • HTTP 200 ≠ API. Some services return HTML on unexpected paths. Verify JSON content type.
  • Pagination can turn validation into collection. Request the smallest page that proves the access-control failure. Do not enumerate the dataset.
  • POST, PATCH, PUT, and DELETE change state. Require explicit authorization and operate only on a synthetic object created for the test.
  • Authentication tests can lock accounts or trigger alerts. Use approved test identities and the agreed request rate.

Verification

  • Confirm that the same operation succeeds without authentication and is rejected by the expected negative control.
  • For reads, retain only the minimum sanitized sample needed to demonstrate the protected data class.
  • For writes, record creation, retrieval, update, deletion, and cleanup of the same synthetic object.
  • Document the URL, method, expected policy, observed behavior, identity, timestamp, control result, and testing limit.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/api-noauth-hunt of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

Unauthenticated API Endpoint Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Unauthenticated API Endpoint Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Unauthenticated API Endpoint Recon this skilluphiago/recon-skills1.3k—~2kAutomated safety check: PassMIT
Security Reviewjewbetcha/opentrace11617 repos~3.1kAutomated safety check: NotesMIT
API Security Checklistrevfactory/harness-1001.3k—~1.7kAutomated safety check: PassApache-2.0
Secure Code GuardianJeffallan/claude-skills12k—~1.8kAutomated safety check: PassMIT
Exploiting Prototype Pollution In Javascriptmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Defending Applicationstelagod/code-abyss244—~777Automated safety check: PassMIT

Similar skills

  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 17 repos~3.1k tokens
    SecurityAuto-check: notes
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Secure Code Guardian

    Jeffallan/claude-skills

    Guides secure implementation of authentication, authorization, input validation and security headers, with password hashing, parameterized queries and OWASP Top 10 checks.

    12k GitHub stars~1.8k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Exploiting Prototype Pollution In Javascript

    mukul975/Anthropic-Cybersecurity-Skills

    Detects and exploits JavaScript prototype pollution vulnerabilities in client-side and server-side (Node.js) applications to achieve XSS, RCE, or authentication bypass through property injection…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Defending Applications

    telagod/code-abyss

    Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

    244 GitHub stars~777 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Token Storage Security

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based…

    74k GitHub stars~604 tokensUpdated yesterday
    SecurityAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Asn Infrastructure Mapping

    uphiago/recon-skills

    Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.

    1.3k GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Unauthenticated API Endpoint Recon

What does Unauthenticated API Endpoint Recon do?

Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing. This skill is a reconnaissance step for authorized penetration testing or bug-bounty work, used after a port scan or subdomain search turns up an HTTP service that looks like an API — a dedicated subdomain, unusual ports, or endpoints referenced inside JavaScript bundles. Discovery stays read-only by default: it probes a short list of common paths and checks for signals such as an exposed API schema document, an error page leaking internal paths, or data coming back with no authentication header at all.

When should I use Unauthenticated API Endpoint Recon?

Unauthenticated API Endpoint Recon fits situations like: checking whether a discovered API endpoint enforces authentication; investigating an exposed API schema document found during recon; validating an authorization gap on a specific endpoint with written scope permission.

How do I install Unauthenticated API Endpoint Recon in Claude Code?

Run `npx skills add uphiago/recon-skills --skill api-noauth-hunt -a claude-code`. Or copy the skill folder (recon/api-noauth-hunt in uphiago/recon-skills) into .claude/skills/api-noauth-hunt in your project. Claude Code loads it when a task matches its description.

How do I install Unauthenticated API Endpoint Recon in Codex?

Run `npx skills add uphiago/recon-skills --skill api-noauth-hunt -a codex`. Or copy the skill folder (recon/api-noauth-hunt in uphiago/recon-skills) into .agents/skills/api-noauth-hunt in your project. Codex loads it when a task matches its description.

Can I use Unauthenticated API Endpoint Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill api-noauth-hunt -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-noauth-hunt, .gemini/skills/api-noauth-hunt, .github/skills/api-noauth-hunt and .opencode/skills/api-noauth-hunt in your project.

What does Unauthenticated API Endpoint Recon need to run?

Going by SKILL.md and its folder, Unauthenticated API Endpoint Recon needs the command-line tools its instructions call (curl, python3 and jq). Our summary lists: curl, python3, and jq; nmap, masscan, subfinder, httpx, and nuclei for broader recon. Compatibility (from SKILL.md): Requires curl, nmap, python3, masscan, subfinder, httpx, nuclei.

Does Unauthenticated API Endpoint Recon access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Unauthenticated API Endpoint Recon safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Unauthenticated API Endpoint Recon use?

Unauthenticated API Endpoint Recon is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Unauthenticated API Endpoint Recon use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Unauthenticated API Endpoint Recon?

Skills that share tags, products or a category with Unauthenticated API Endpoint Recon: Security Review (jewbetcha/opentrace, 116 stars), API Security Checklist (revfactory/harness-100, 1.3k stars), Secure Code Guardian (Jeffallan/claude-skills, 12k stars) and Exploiting Prototype Pollution In Javascript (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Unauthenticated API Endpoint Recon?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.