api-security

Assess REST, GraphQL, gRPC, WebSocket, and MCP APIs against OWASP API Top 10 2023.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill api-security-blamejs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: api-security
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/api-security
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill api-security-blamejs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Legacy security frameworks and tools are built for pre-AI, network-centric environments and fail to address modern API attack surfaces including AI-API abuse, MCP transport risks, and non-REST protocol-specific weaknesses like GraphQL query complexity attacks and gRPC reflection exposure. This skill fills that gap with guidance grounded in mid-2026 threat reality, not outdated framework documentation.

Core Features & Use Cases

  • Comprehensive API Surface Coverage: Assesses REST, GraphQL, gRPC, WebSocket, and MCP API deployments against OWASP API Top 10 2023, MITRE ATT&CK Enterprise, and MITRE ATLAS v2026.06 TTPs.
  • Compliance Gap Analysis: Explicitly flags where major frameworks (NIST 800-53, ISO 27001, PCI DSS, NIS2, UK CAF) fail to cover AI-API and agentic attack patterns, helping teams avoid "compliance theater" for API security.
  • Structured Assessment Output: Generates auditable API inventory tables, OWASP risk scorecards, authentication coverage matrices, rate-limit policy ledgers, and prioritized remediation roadmaps.
  • Use Case: A security team assessing a customer-facing AI chatbot API can use this skill to identify BOLA vulnerabilities in order endpoints, AI-API denial-of-wallet risks from leaked API keys, and MCP transport misconfigurations, then produce a compliance-ready report for stakeholders.

Quick Start

Use the api-security skill to conduct a full assessment of your organization's REST, GraphQL, and MCP API surfaces and generate a prioritized remediation roadmap for OWASP API Top 10 2023 and AI-API specific threats.

Frequently Asked Questions about api-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess API security risks for GraphQL, gRPC, and MCP transport protocols?

Assess API security risks for GraphQL, gRPC, and MCP by mapping OWASP API Top 10 2023, MITRE ATT&CK, and ATLAS TTPs to exploitable protocol-specific weaknesses, generating auditable risk scorecards and remediation roadmaps.

What is the best way to identify BOLA vulnerabilities in AI chatbot APIs?

Identify BOLA vulnerabilities in AI chatbot APIs by evaluating authentication coverage matrices and applying threat assessments that map modern non-REST API attack surfaces to the OWASP API Top 10 2023 framework.

How do I find compliance gaps in NIST 800-53 or ISO 27001 for AI-API attack patterns?

Find compliance gaps in NIST 800-53, ISO 27001, and PCI DSS by explicitly flagging where legacy frameworks fail to cover AI-API abuse, agentic attack patterns, and MCP transport misconfigurations.

Can I use a single assessment to cover REST, WebSocket, and AI-API denial-of-wallet threats?

Assess REST, WebSocket, and AI-API denial-of-wallet threats concurrently by inventorying API surfaces and generating a unified risk scorecard aligned to mid-2026 threat reality and modern compliance requirements.

Why do legacy security frameworks fail to protect modern API attack surfaces?

Legacy security frameworks fail to protect modern API attack surfaces because they are built for pre-AI, network-centric environments and lack coverage for AI-API consumption, MCP transport risks, and GraphQL query complexity attacks.

How do I generate an auditable API inventory and prioritized remediation roadmap?

Generate an auditable API inventory and prioritized remediation roadmap by conducting a full security assessment that outputs structured tables, OWASP risk scorecards, and rate-limit policy ledgers for stakeholder reporting.