api-security-review

Identify and assess API security weaknesses across OpenAPI/Swagger specs and implementations.

141|14|Updated Mar 22, 2026
One-click install
npx skills add https://github.com/OWASP/secure-agent-playbook --skill api-security-review-owasp
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: api-security-review
Source: https://github.com/OWASP/secure-agent-playbook/tree/main/skills/api-security-review
Command: npx skills add https://github.com/OWASP/secure-agent-playbook --skill api-security-review-owasp

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Identify and assess API security weaknesses across OpenAPI/Swagger specs and API implementations.

Core Features & Use Cases

  • OWASP API Top 10 coverage across API risks (API1-API10).
  • Automated testing & artifact generation with PoC examples and remediation guidance.
  • OpenAPI/spec and gateway review for configuration weaknesses and misconfigurations.

Quick Start

Invoke the API security review against your OpenAPI spec or REST/GraphQL/gRPC implementations to generate a comprehensive findings report.

Frequently Asked Questions about api-security-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check my OpenAPI spec for OWASP API Top 10 vulnerabilities?

An API security review assesses OpenAPI/Swagger specs to identify weaknesses across OWASP API Top 10 risks, generating actionable findings with proof-of-concept examples and remediation guidance for your authentication flows and endpoints.

Can I run an API security assessment on GraphQL and gRPC services?

Yes, API security reviews apply to REST, GraphQL, and gRPC services to assess authentication flows, gateway configurations, and versioned endpoints, producing structured findings that cover OWASP API Top 10 risks.

What is the best way to generate PoC examples for API security findings?

The best way to generate PoC examples for API security findings is to run an API security review that automates testing and artifact generation, producing structured output with proof-of-concept examples and remediation references.

Does an API security review cover gateway configuration weaknesses?

Yes, an API security review evaluates OpenAPI specs and gateway configurations to identify configuration weaknesses and misconfigurations across your API implementations and authentication flows.

How do I get structured remediation guidance for API authentication vulnerabilities?

To get structured remediation guidance for API authentication vulnerabilities, perform an API security review that assesses authentication flows and produces actionable findings with references for OWASP API risks.