API Security Tester — Security agent for Claude Code
Generates and runs comprehensive API security tests covering OWASP Top 10, injection attacks, auth bypass, malformed input, and error handling for the Actual-sync dashboard API.
How to install API Security Tester
Installs to ~/.claude/agents/agigante80-actual-sync-api-security-tester.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/agigante80/Actual-sync/HEAD/.claude/agents/api-security-tester.md -o ~/.claude/agents/agigante80-actual-sync-api-security-tester.md Restart Claude Code, or start a new session, for it to be picked up.
What API Security Tester does
name: api-security-tester description: Generates and runs comprehensive API security tests covering OWASP Top 10, injection attacks, auth bypass, malformed input, and error handling for the Actual-sync dashboard API. Use when writing security tests, expanding test coverage, or before production deployment. model: opus
You are an API security testing specialist who generates comprehensive, executable test suites for REST APIs.
Purpose
Generat
Alternatives in Security
- Fleet Security Auditor — Fleet-specific security analysis covering MDM, osquery, API auth, and device management threat models 6.8k ★
- JS Error Handler Auditor — Use this agent when you need to audit a JavaScript codebase for unhandled errors in top-level async operations 6.1k ★
- Claude Agents By Ian Nuttall — Ready-to-use subagents for code refactoring, frontend design, security auditing, project planning, content wri 2k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Genesis Security Reviewer
Security-reviews Genesis code changes. Use for diffs touching auth, credentials/secrets, financial transaction
GraphQL Audit
GraphQL API security specialist. Use for introspection analysis, query complexity attacks, injection testing,
API Attacker
API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignmen
Harness Security Reviewer
Security reviewer — self-scoping OWASP Top 10 and STRIDE audit of a pinned diff, covering auth, secrets, input
Review Security
Reviews code changes for security vulnerabilities including injection attacks, sensitive data exposure, insecu
Python Security Auditor
Production-grade Python security auditor eliminating os.execv() vulnerability, bare exception handlers, and si
Related Skills
Security Sweep
Comprehensive security scanner covering OWASP Top 10 (2025), Mobile Top 10 (2024), and LLM Top 10 (2025). Scan
Audit Security
Security audit (OWASP Top 10, PHP-specific vulnerabilities). Analyzes input validation, injection, authenticat
Skill Lint
Security scanner for Claude Code / agent skills. Catches prompt injection, obfuscation, credential exfiltratio