CtrlK
BlogDocsLog inGet started
Tessl Logo

api-fuzzing-bug-bounty

Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.

54

Quality

61%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/api-fuzzing-bug-bounty/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A technique-rich catalog with strong concrete payloads and a recognizable five-step workflow, but it reads as a reference dump rather than a guided skill: no validation checkpoints, monolithic single-file structure, and duplicated/filler sections that inflate token cost. Splitting reference material into bundle files and adding finding-verification steps would lift most dimensions.

Suggestions

Move the Tools Reference, Common API Vulnerabilities Checklist, and Quick Reference tables into a references/ file and link them from SKILL.md, keeping the body as a concise workflow overview.

Add verification checkpoints to the workflow (e.g. after Step 1 confirm discovered endpoints; after Step 3 confirm the IDOR response actually returns another user's data before reporting).

Delete the filler 'When to Use' sentence and the 'Purpose' section that duplicates the description, and consolidate the IDOR techniques that currently appear in three places.

DimensionReasoningScore

Conciseness

The payload and command listings are dense and mostly lean, but the 'Purpose' section repeats the frontmatter description verbatim, the 'When to Use' section is pure filler ('This skill is applicable to execute the workflow or actions described in the overview.'), and IDOR material is duplicated across Core Workflow, Quick Reference, and Examples.

3 / 5

Actionability

Provides concrete, mostly ready-to-use payloads and commands (JSON SQLi payloads, GraphQL introspection queries with a curl example, 403 bypass path list), but several blocks are notation rather than executable commands (e.g. 'GET /api/users/1234 → GET /api/users/1235' and bare path lists inside bash blocks).

4 / 5

Workflow Clarity

The 'Core Workflow' gives a clear Step 1–5 sequence, but there are no verification checkpoints between steps (no confirmation that recon found endpoints, no guidance on validating a suspected IDOR/SQLi finding before reporting), and the exploitation operations would benefit from explicit validation given data extraction is involved.

3 / 5

Progressive Disclosure

Sections and tables are well organized and easy to navigate, but the skill is a 440-line monolith with no bundle files; the 20-row Tools table, vulnerability checklists, and quick reference clearly belong in separate reference files that SKILL.md should point to.

3 / 5

Total

13

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solidly specific, domain-rich description that clearly communicates what the skill covers. Its main weakness is the complete absence of 'when to use' trigger guidance, which both caps completeness and limits how naturally a user or Claude would select this skill over related pentest skills.

Suggestions

Add an explicit trigger clause, e.g. 'Use when testing REST, SOAP, or GraphQL APIs during bug bounty hunting, authorized pentests, or when the user mentions API security, IDOR, or endpoint fuzzing.'

Replace generic padding ('comprehensive techniques', 'API-specific attack vectors') with one or two more concrete capabilities (e.g. GraphQL introspection, endpoint discovery via Kiterunner/Swagger).

Include common user synonyms such as 'pentest', 'API security testing', or 'endpoint fuzzing' to broaden natural trigger coverage.

DimensionReasoningScore

Specificity

Names the domain ('REST, SOAP, and GraphQL APIs') and lists several concrete actions ('vulnerability discovery, authentication bypass, IDOR exploitation'), but 'comprehensive techniques' and 'API-specific attack vectors' are generic padding, so coverage has minor gaps rather than being comprehensive.

4 / 5

Completeness

The 'what' is clear and concrete, but there is no 'Use when...' clause or equivalent explicit trigger guidance, which caps completeness at 3 per the rubric guidelines.

3 / 5

Trigger Term Quality

Includes natural terms users would say ('bug bounty', 'REST', 'GraphQL', 'penetration testing'), but misses common variations such as 'pentest', 'API security testing', or 'API hacking'.

4 / 5

Distinctiveness Conflict Risk

The API-fuzzing-for-bug-bounty niche is mostly distinct with specific technology triggers, though 'penetration testing engagements' leaves minor overlap risk with general web-pentest skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.