API Security Auditor — Security agent for Claude Code
API endpoint security assessment for auth, injection, and rate limiting.
How to install API Security Auditor
Installs to ~/.claude/agents/vibery-studio-templates-api-security-auditor.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/vibery-studio/templates/HEAD/agents/api-security-auditor.md -o ~/.claude/agents/vibery-studio-templates-api-security-auditor.md Restart Claude Code, or start a new session, for it to be picked up.
What API Security Auditor does
name: api-security-auditor description: API endpoint security assessment for auth, injection, and rate limiting
Focus Areas
- Security vulnerability assessment and remediation
- OWASP Top 10 compliance verification
- Code security review and best practices
- Dependency security auditing
- Authentication and authorization patterns
- Input validation and sanitization
- Secure coding standards enforcement
Approach
- Perform systematic security analysis of codebase
- Identify poten
Alternatives in Security
- Gitnexus Security Boundary Reviewer — GitNexus security and trust-boundary reviewer 45.8k ★
- Threat Modeling Expert — Expert in threat modeling methodologies, security architecture review, and risk assessment 31.9k ★
- Retool Endpoint Audit — Checks a migration slice against the main app's API surface — whether a local implementation duplicates an exi 7.2k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Timps API Security Tester
Run an OWASP API Security Top-10 (2023) audit against an OpenAPI spec or live endpoint — broken auth, BOLA, ma
Kavach API
KAVACH API security + auth/session specialist. Traces every endpoint for BOLA/IDOR, BFLA, broken auth, mass as
Legal Compliance Checker
API compliance specialist for GDPR, data privacy, rate limiting, data retention, and security headers. Use whe
Astro Security
Delegated by the astro orchestrator during /astro audit to review env and secret handling, HTML injection, Act
PM Security Review
Read-only security reviewer for Product Masters LMS diffs. Finds the input/actor that breaks auth, access, RLS
Kavach Config
KAVACH infrastructure/config/ops-security specialist. Audits security headers, debug/verbose in prod, stack-tr
Related Skills
Secure LLM Gateway
Security-focused gateway in front of an LLM API — auth, prompt-injection defense, output filtering, audit logg
Arcjet Py
Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data r
Auth Audit
Full auth & session audit: login flow, session/cookie security, JWT handling, middleware safety, privilege esc