API Attacker — Security agent for Claude Code
API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs.
How to install API Attacker
Installs to ~/.claude/agents/mukul975-threatswarm-api-attacker.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mukul975/Threatswarm/HEAD/.claude/agents/api-attacker.md -o ~/.claude/agents/mukul975-threatswarm-api-attacker.md Restart Claude Code, or start a new session, for it to be picked up.
What API Attacker does
name: api-attacker description: API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignment, authentication bypass, rate limit evasion, JWT attacks, GraphQL introspection abuse, API enumeration, and OWASP API Top 10. Triggers on: API, REST, GraphQL, gRPC, WebSocket, BOLA, IDOR, mass assignment, API key, JWT, OpenAPI, swagger, rate limit, API auth, endpoint discovery. tools: Bash, Read, Write model: sonnet
Cybersecurity Skills (Invok
Alternatives in Security
- GraphQL Audit — GraphQL API security specialist 812 ★
- Supabase Identity Explorer — Use proactively for exploring creative, non-obvious applications of Supabase Auth, Row-Level Security, and Gra 64 ★
- Auth Reviewer — Authentication and authorization security reviewer 63 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Timps API Security Tester
Run an OWASP API Security Top-10 (2023) audit against an OpenAPI spec or live endpoint — broken auth, BOLA, ma
Kavach API
KAVACH API security + auth/session specialist. Traces every endpoint for BOLA/IDOR, BFLA, broken auth, mass as
Pentester
Adversarial security expert. Thinks like an attacker — chains primitives into exploits, finds auth bypass, IDO
Pentest Validator
Optional, disabled-by-default Dynamic Security Validation agent. Interacts with a running, explicitly authoriz
API Security
Delegates to this agent when the user asks about API security testing, REST API attacks, GraphQL exploitation,
Crypto Attacker
Cryptography and TLS security specialist. Handles TLS configuration auditing, JWT algorithm confusion, padding
Related Skills
API Security
API security audit (OWASP API Security Top 10 2023): BOLA/IDOR, broken authentication, broken object-property-
Hunt Access
Active IDOR / BOLA / BFLA / mass-assignment hunt for an ingested program. Consumes the webvuln-surface seeds +
Sec Scan Auth
인증/인가/어뷰징 취약점 진단 — Auth Bypass / IDOR / Mass Assignment / Rate Limit / 멱등성 / 클라이언트 신뢰 로직 — scan_api.py + scan_