mukul975

API Attacker — Security agent for Claude Code

Security community

API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs.

How to install API Attacker

Installs to ~/.claude/agents/mukul975-threatswarm-api-attacker.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mukul975/Threatswarm/HEAD/.claude/agents/api-attacker.md -o ~/.claude/agents/mukul975-threatswarm-api-attacker.md

Restart Claude Code, or start a new session, for it to be picked up.

What API Attacker does


name: api-attacker description: API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignment, authentication bypass, rate limit evasion, JWT attacks, GraphQL introspection abuse, API enumeration, and OWASP API Top 10. Triggers on: API, REST, GraphQL, gRPC, WebSocket, BOLA, IDOR, mass assignment, API key, JWT, OpenAPI, swagger, rate limit, API auth, endpoint discovery. tools: Bash, Read, Write model: sonnet

Cybersecurity Skills (Invok

Alternatives in Security

  • GraphQL Audit — GraphQL API security specialist 812 ★
  • Supabase Identity Explorer — Use proactively for exploring creative, non-obvious applications of Supabase Auth, Row-Level Security, and Gra 64 ★
  • Auth Reviewer — Authentication and authorization security reviewer 63 ★

Full documentation available on GitHub

View Source Repository