API Security Review

FortgeschrittensecurityMindestens 64K Kontext

Reviews an HTTP API against the common API risk classes: broken object and function level authorization, weak authentication, excessive data exposure, missing rate and resource limits, mass assignment, injection, and misconfiguration. Maps each finding to the affected endpoint, rates severity, and proposes concrete fixes and tests.

Anwendungsfälle

  • Auditing a REST or GraphQL API before a public launch
  • Finding object-level authorization gaps across endpoints
  • Reviewing an OpenAPI spec for excessive data exposure
  • Producing a prioritized remediation list for an API

Beispiel-Prompt

Review this API for security issues.

Context: [OpenAPI spec or routes, auth model, roles, sample handlers]

Return:
1. Findings per endpoint with risk class and severity.
2. Authorization matrix gaps by role and resource.
3. Input validation and data exposure issues.
4. Rate and resource limit gaps.
5. Fixes and regression tests for each finding.

Empfohlene Modelle

Kompatible Werkzeuge

claude-codecursorkiroany

Modalitäten

Eingabe: text, code
→
Ausgabe: text, code

Ähnliche Skills

Autor

OpenModels Community

@openmodelsrun