API Security Review
ПродвинутыйsecurityМинимальный контекст: 64K
Reviews an HTTP API against the common API risk classes: broken object and function level authorization, weak authentication, excessive data exposure, missing rate and resource limits, mass assignment, injection, and misconfiguration. Maps each finding to the affected endpoint, rates severity, and proposes concrete fixes and tests.
Варианты использования
- Auditing a REST or GraphQL API before a public launch
- Finding object-level authorization gaps across endpoints
- Reviewing an OpenAPI spec for excessive data exposure
- Producing a prioritized remediation list for an API
Пример промпта
Review this API for security issues. Context: [OpenAPI spec or routes, auth model, roles, sample handlers] Return: 1. Findings per endpoint with risk class and severity. 2. Authorization matrix gaps by role and resource. 3. Input validation and data exposure issues. 4. Rate and resource limit gaps. 5. Fixes and regression tests for each finding.
Рекомендуемые модели
Совместимые инструменты
claude-codecursorkiroany
Модальности
Вход: text, code
→Выход: text, code
Похожие Skills
Автор
OpenModels Community