api-security-testing
Plan API Security Testing
API reviews can miss authorization flaws, unsafe inputs, weak rate limits, and exposed errors. This skill organizes authorized REST and GraphQL testing into seven focused phases.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "api-security-testing" from https://skillstore.io/skills/sickn33-api-security-testing.md and its manifest at https://skillstore.io/api/skills/sickn33-api-security-testing/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "api-security-testing". Create an authorization test plan for a multi-tenant REST API.
Expected outcome:
- Scope: Verify object, function, role, and tenant boundaries across documented endpoints.
- Method: Compare permitted and denied requests for each role using approved test accounts.
- Evidence: Record request context, expected policy, actual result, impact, and remediation.
Using "api-security-testing". Review the test coverage for a GraphQL endpoint.
Expected outcome:
- Discovery: Inventory queries, mutations, types, and enabled introspection within the approved schema.
- Controls: Check depth, complexity, batching, field suggestions, authentication, authorization, and sanitized errors.
- Quality gate: Document confirmed issues, supporting evidence, severity, and practical remediation.
Security Audit
SafeAll 26 static alerts are false positives caused by inline and fenced Markdown backticks in SKILL.md. The skill contains no executable commands, scripts, prompt injection, or malicious intent.
Risk Factors
⚙️ External commands (26)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-api-security-testing/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-api-security-testing?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-api-security-testing?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-api-security-testing/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-api-security-testing.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
sickn33. (2026). api-security-testing security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-api-security-testing/audits/5BibTeX citation
@techreport{sickn33-sickn33-api-security-testing-2026,
author = {sickn33},
title = {api-security-testing security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/sickn33-api-security-testing/audits/5},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "api-security-testing security audit report (audit version 5)"
version: "unspecified"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/sickn33-api-security-testing/audits/5"
identifiers:
- type: other
value: "skillstore:sickn33-api-security-testing:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Review a New API
Build a pre-release checklist for authentication, authorization, validation, rate limiting, and error handling.
Plan a Security Assessment
Create a phased REST or GraphQL assessment with evidence requirements and quality gates.
Structure Authorized Research
Map approved endpoints and test categories before conducting controlled vulnerability research.
Try These Prompts
Create a security checklist for my [REST or GraphQL] API. Cover authentication, authorization, input validation, rate limiting, errors, HTTPS, CORS, and logging.
Plan authentication and authorization tests for [API]. Include [roles], token lifecycle, object access, function access, privilege changes, and tenant isolation.
Design a test matrix for [endpoints] within [scope]. Include expected results, safe inputs, rate limits, stop conditions, evidence, and remediation fields.
Produce a seven-phase REST and GraphQL security plan for [system]. Prioritize risks, map roles and data flows, define controls, and specify quality gates.
Best Practices
- Confirm written authorization, scope, test accounts, rate limits, and stop conditions before sending requests.
- Start with documented endpoints and low-impact checks, then increase test depth only within approved boundaries.
- Record reproducible evidence and separate confirmed vulnerabilities from observations that require validation.
Avoid
- Do not test production systems without explicit authorization and an approved impact plan.
- Do not treat generic checklists as proof that an API is secure.
- Do not run brute force, resource exhaustion, or injection tests without controlled limits and monitoring.
Frequently Asked Questions
Does this skill run security tools?
Does it support both REST and GraphQL?
What access information should I provide?
Can I use it against a production API?
Does the workflow prove an API is secure?
Which companion skills are referenced?
Developer Details
Author
sickn33License
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/api-security-testingRef
ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006
Maintenance freshness
7/26/2026
Usage
4 downloads · 106 views
File structure
📄 SKILL.md