API Security Review

ПродвинутыйsecurityМинимальный контекст: 64K

Reviews an HTTP API against the common API risk classes: broken object and function level authorization, weak authentication, excessive data exposure, missing rate and resource limits, mass assignment, injection, and misconfiguration. Maps each finding to the affected endpoint, rates severity, and proposes concrete fixes and tests.

Варианты использования

  • Auditing a REST or GraphQL API before a public launch
  • Finding object-level authorization gaps across endpoints
  • Reviewing an OpenAPI spec for excessive data exposure
  • Producing a prioritized remediation list for an API

Пример промпта

Review this API for security issues.

Context: [OpenAPI spec or routes, auth model, roles, sample handlers]

Return:
1. Findings per endpoint with risk class and severity.
2. Authorization matrix gaps by role and resource.
3. Input validation and data exposure issues.
4. Rate and resource limit gaps.
5. Fixes and regression tests for each finding.

Рекомендуемые модели

Совместимые инструменты

claude-codecursorkiroany

Модальности

Вход: text, code
→
Выход: text, code

Похожие Skills

Автор

OpenModels Community

@openmodelsrun