Api Pentest banner
h3nr1-d14z h3nr1-d14z

Api Pentest

Security community

Description

Perform API security testing on: $ARGUMENTS Identify API type (REST/GraphQL/gRPC/WebSocket). Map all endpoints from docs, traffic, JS analysis. Test: authentication (JWT with tools/web/jwt-toolkit.py, OAuth, API keys), authorization (IDOR, BOLA, BFLA), injection (SQLi, NoSQL, command), rate limiting, mass assignment, excessive data exposure. For GraphQL: test introspection, nested queries, batch attacks. For WebSocket: test origin validation, message injection. Reference: methodology/api-pentes

Installation

Installs to ~/.claude/commands/h3nr1-d14z-ai-redteam-toolkit-api-pentest.md

Terminal
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/h3nr1-d14z/ai-redteam-toolkit/HEAD/.claude/commands/api-pentest.md -o ~/.claude/commands/h3nr1-d14z-ai-redteam-toolkit-api-pentest.md

Restart Claude Code, or start a new session, for it to be picked up.

Full documentation available on GitHub

View Source Repository