What problem does it solve?
Legacy security frameworks and tools are built for pre-AI, network-centric environments and fail to address modern API attack surfaces including AI-API abuse, MCP transport risks, and non-REST protocol-specific weaknesses like GraphQL query complexity attacks and gRPC reflection exposure. This skill fills that gap with guidance grounded in mid-2026 threat reality, not outdated framework documentation.
Core Features & Use Cases
- Comprehensive API Surface Coverage: Assesses REST, GraphQL, gRPC, WebSocket, and MCP API deployments against OWASP API Top 10 2023, MITRE ATT&CK Enterprise, and MITRE ATLAS v2026.06 TTPs.
- Compliance Gap Analysis: Explicitly flags where major frameworks (NIST 800-53, ISO 27001, PCI DSS, NIS2, UK CAF) fail to cover AI-API and agentic attack patterns, helping teams avoid "compliance theater" for API security.
- Structured Assessment Output: Generates auditable API inventory tables, OWASP risk scorecards, authentication coverage matrices, rate-limit policy ledgers, and prioritized remediation roadmaps.
- Use Case: A security team assessing a customer-facing AI chatbot API can use this skill to identify BOLA vulnerabilities in order endpoints, AI-API denial-of-wallet risks from leaked API keys, and MCP transport misconfigurations, then produce a compliance-ready report for stakeholders.
Quick Start
Use the api-security skill to conduct a full assessment of your organization's REST, GraphQL, and MCP API surfaces and generate a prioritized remediation roadmap for OWASP API Top 10 2023 and AI-API specific threats.