API Pentest — Security skill for Claude Code
Perform API security testing on: $ARGUMENTS.
How to install API Pentest
Installs to ~/.claude/commands/h3nr1-d14z-ai-redteam-toolkit-api-pentest.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/h3nr1-d14z/ai-redteam-toolkit/HEAD/.claude/commands/api-pentest.md -o ~/.claude/commands/h3nr1-d14z-ai-redteam-toolkit-api-pentest.md Restart Claude Code, or start a new session, for it to be picked up.
What API Pentest does
Perform API security testing on: $ARGUMENTS
Identify API type (REST/GraphQL/gRPC/WebSocket). Map all endpoints from docs, traffic, JS analysis. Test: authentication (JWT with tools/web/jwt-toolkit.py, OAuth, API keys), authorization (IDOR, BOLA, BFLA), injection (SQLi, NoSQL, command), rate limiting, mass assignment, excessive data exposure. For GraphQL: test introspection, nested queries, batch attacks. For WebSocket: test origin validation, message injection. Reference: methodology/api-pentes
Alternatives in Security
- Defense In Depth — Implement multi-layered testing and security best practices 98.1k ★
- Anthropic Cybersecurity Skills — 734+ structured cybersecurity skills for AI agents · MITRE ATT&CK mapped · agentskills.io open standard · Work 3.8k ★
- Security Advanced Pack — Advanced security testing and analysis 1.6k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Cloud Pentest
Perform cloud security assessment on: $ARGUMENTS
Ad Pentest
Perform Active Directory penetration test on: $ARGUMENTS
KeyHunter Skill
Academic research toolkit for AI gateway panel security studies (Sub2API / New-API / One-API): FOFA discovery,
API QA
Use when testing API endpoints for contract compliance, error handling, security, and performance. Covers 'tes
Coverage Checklist
Instantiate the internal-network pentest coverage checklist for an engagement. Copies the master template (met
Kali Pentest
Kali Linux penetration testing skill for AI agents (Claude Code, OpenClaw, Hermes Agent). 200+ CLI tools, 15 s
Related Agents
Pentest Auditor
Runs automated penetration testing — web, API, browser, GitHub, and local code security probing. Dispatched by
API Skill Tester
Use this agent when you need to run tests for API skills, validate skill functionalities through direct invoca
Security Review
This agent should be invoked when the user asks to review code for security vulnerabilities, check for secrets