Loading skill
Install any skill in seconds. Free to start, no credit card required.
Get Started Free →API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | -22% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 10% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 6% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 0% | 0% |
| case-16 | ✗→✓ | ▲ Improved | -54% | 0% |
Specialized workflow for testing REST and GraphQL API security including authentication, authorization, rate limiting, input validation, and API-specific vulnerabilities.
Use this workflow when:
api-fuzzing-bug-bounty - API fuzzingscanning-tools - API scanningUse @api-fuzzing-bug-bounty to discover API endpointsbroken-authentication - Auth testingapi-security-best-practices - API authUse @broken-authentication to test API authenticationidor-testing - IDOR testingUse @idor-testing to test API authorizationapi-fuzzing-bug-bounty - API fuzzingsql-injection-testing - Injection testingUse @api-fuzzing-bug-bounty to fuzz API parametersapi-security-best-practices - Rate limitingUse @api-security-best-practices to test rate limitingapi-fuzzing-bug-bounty - GraphQL fuzzingUse @api-fuzzing-bug-bounty to test GraphQL securityapi-security-best-practices - Error handlingUse @api-security-best-practices to audit API error handlingsecurity-audit - Security auditingweb-security-testing - Web securityapi-development - API developmentOther measured skills in the registry, with their headline benchmark lift.