Skip to content
Back to skills

Api Security Testing

ASecurity

Security testing checklist for HTTP APIs—authn/z, input validation, rate limits, sensitive data exposure, and common OWASP API issues. Use when reviewing or testing REST/GraphQL endpoints before release. Triggers: "API security", "pen test API", "OWASP API", "auth test", "security test".

  • 25 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 27, 2026
developmentsqltestingapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned May 27, 2026

npx -y skills add charlieviettq/awesome-agent-skill --skill api-security-testing --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Security Testing?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Security Testing
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/charlieviettq-api-security-testing/badge)](https://www.skillsdirectory.com/skills/charlieviettq-api-security-testing)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-security-testing
description: >
  Security testing checklist for HTTP APIs—authn/z, input validation, rate limits,
  sensitive data exposure, and common OWASP API issues. Use when reviewing or
  testing REST/GraphQL endpoints before release.
  Triggers: "API security", "pen test API", "OWASP API", "auth test", "security test".
---

# API security testing

## Preconditions

- Test in **non-production** unless explicitly authorized.
- Use dedicated test accounts; never real customer PII in payloads.

## Test matrix (prioritized)

### Authentication and session

- [ ] Missing/invalid token rejected (401)
- [ ] Expired or revoked credentials rejected
- [ ] Session fixation / cookie flags (HttpOnly, Secure, SameSite) where applicable

### Authorization

- [ ] Horizontal: user A cannot access user B's resource IDs
- [ ] Vertical: non-admin cannot invoke admin routes
- [ ] IDOR on path/query/body identifiers

### Input and abuse

- [ ] Oversized payloads rejected
- [ ] Injection surfaces parameterized (SQL, command, template)
- [ ] Rate limiting on auth and expensive endpoints

### Data exposure

- [ ] Errors do not leak stack traces or secrets in prod-like config
- [ ] Responses omit internal fields (tokens, hashes, full PAN)
- [ ] Pagination does not bypass auth filters

### Transport and config

- [ ] HTTPS enforced; HSTS where applicable
- [ ] CORS not `*` with credentials
- [ ] Security headers on API gateway if present

### Web-facing surfaces (when API serves or pairs with UI)

- [ ] CSP or explicit script policy documented
- [ ] CSRF protection on cookie-based mutations
- [ ] Clickjacking headers (`X-Frame-Options` or CSP `frame-ancestors`) where relevant
- [ ] File upload: type/size limits, virus scan hook if required by policy

## Reporting

For each finding: endpoint, steps, impact, severity, remediation, retest status.

## Boundaries

- Defensive testing only; no unauthorized production scanning.
- For deep pen-test, engage formal AppSec process.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…