CtrlK
BlogDocsLog inGet started
Tessl Logo

api-security-testing

API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.

32

Quality

26%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/api-security-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

20%Scale 1-3

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is essentially a high-level table of contents that delegates all actual work to other skills without providing any concrete, actionable guidance of its own. It suffers from extreme verbosity through repetitive templated phases, each containing vague action items that Claude already knows how to approach. The skill would benefit enormously from concrete examples, specific tool commands, actual payloads, and meaningful validation steps.

Suggestions

Replace vague action items like 'Test JWT tokens' with concrete, executable examples showing specific curl commands, payloads, or tool invocations with expected outputs.

Consolidate the repetitive phase structure - each phase follows an identical template that could be dramatically condensed into a summary table with links to detailed sub-skills.

Add concrete validation checkpoints between phases, such as 'Verify you have at least N endpoints discovered before proceeding to authentication testing' with specific commands to check.

Remove the 'Copy-Paste Prompts' sections entirely or replace them with substantive, multi-step prompts that include specific parameters, target configurations, and expected output formats.

DimensionReasoningScore

Conciseness

Extremely verbose and repetitive. Each phase follows an identical template with numbered action lists that are essentially checklists of obvious testing steps Claude already knows. The 'Copy-Paste Prompts' sections are trivial one-liners that add no value. The entire skill could be condensed to a fraction of its size.

1 / 3

Actionability

No concrete code, commands, or executable examples anywhere. Every phase consists of vague action items like 'Test JWT tokens' and 'Test SQL injection' without any specific techniques, tools, payloads, or commands. The 'Copy-Paste Prompts' are just generic invocations of other skills with no substance.

1 / 3

Workflow Clarity

The phases are clearly sequenced and logically ordered from discovery through various testing types. However, there are no validation checkpoints between phases, no feedback loops for when issues are found, and no guidance on how to handle failures or prioritize findings. The quality gates at the end are generic checklists without actionable criteria.

2 / 3

Progressive Disclosure

References to other skills are present and clearly signaled (e.g., @api-fuzzing-bug-bounty, @broken-authentication), but no bundle files exist to support them. The content is a monolithic document that repeats the same structural pattern seven times, with inline content that could be better organized or condensed.

2 / 3

Total

6

/

12

Passed

Description

32%Scale 1-3

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description identifies a clear domain (API security testing) and lists relevant topic areas, but falls short by not specifying concrete actions performed and completely lacking a 'Use when...' clause. The topic areas listed (authentication, authorization, etc.) read as a syllabus rather than actionable capabilities, making it harder for Claude to determine when to select this skill.

Suggestions

Add an explicit 'Use when...' clause, e.g., 'Use when the user asks to test API endpoints for security vulnerabilities, audit API authentication flows, or review API security configurations.'

Replace topic areas with concrete actions, e.g., 'Tests authentication flows for broken auth, validates authorization boundaries between roles, checks rate limiting configurations, and fuzzes input parameters for injection vulnerabilities.'

Include additional natural trigger terms users might say, such as 'OWASP', 'API vulnerability', 'security audit', 'pen test', or 'API hardening'.

DimensionReasoningScore

Specificity

Names the domain (API security testing) and lists several areas covered (authentication, authorization, rate limiting, input validation, security best practices), but these read more as topic areas than concrete actions. It doesn't specify what actions are performed, like 'tests for broken authentication' or 'generates security reports'.

2 / 3

Completeness

Describes what the skill covers (API security testing across several domains) but completely lacks a 'Use when...' clause or any explicit trigger guidance for when Claude should select this skill. Per the rubric, a missing 'Use when...' clause should cap completeness at 2, and since the 'what' is also somewhat vague (listing topics rather than actions), this scores a 1.

1 / 3

Trigger Term Quality

Includes relevant keywords like 'API', 'REST', 'GraphQL', 'authentication', 'authorization', 'rate limiting', and 'input validation' which users might naturally mention. However, it misses common variations like 'OWASP', 'penetration testing', 'API pen test', 'security audit', 'vulnerability scanning', or file extensions/tool names.

2 / 3

Distinctiveness Conflict Risk

The combination of 'API security testing' with 'REST and GraphQL' provides some distinctiveness, but 'security best practices' and 'input validation' are broad enough to overlap with general security skills or web application testing skills.

2 / 3

Total

7

/

12

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
popey/claude-code-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.