CtrlK
BlogDocsLog inGet started
Tessl Logo

api-security-testing

API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.

56

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/api-security-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

61%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, token-efficient orchestration workflow with a clear phase sequence and per-phase skill invocations. Its weaknesses are thin actionability — actions are topic checklists rather than executable guidance — and missing per-phase validation or feedback loops, with verification deferred entirely to a terminal quality-gates checklist.

Suggestions

Add concrete, executable detail to the highest-value actions, e.g. sample test payloads/commands for JWT token testing or a specific GraphQL introspection query, instead of topic-only checklists like "Test JWT tokens".

Insert per-phase validation checkpoints or explicit feedback loops (e.g. "confirm findings are reproducible before moving to the next phase") rather than relying solely on the terminal Quality Gates section.

Convert the referenced skills (e.g. @api-fuzzing-bug-bounty, @idor-testing) into clearly signaled references with locations or a short note on what each provides, so navigation between the orchestrator and its dependencies is unambiguous.

DimensionReasoningScore

Conciseness

The body is lean and assumes Claude's competence — short action lists, no concept explanations, and one-line copy-paste prompts — but the repeated per-phase scaffolding ("Skills to Invoke" / "Actions" / "Copy-Paste Prompts" seven times over) and the "When to Use" list restating the description could be tightened slightly. It is not a 5 because that repetition costs tokens without adding guidance.

4 / 5

Actionability

There is some concrete guidance — each phase supplies an exact copy-paste invocation like "Use @broken-authentication to test API authentication" — but the action lists are topic names ("Test JWT tokens", "Test query depth") with no commands, payloads, or methodology, leaving key execution details missing. This sits between the minimal-guidance (2) and executable-guidance (4) anchors.

3 / 5

Workflow Clarity

The seven phases form a clear, logical sequence (discovery → authentication → authorization → input validation → rate limiting → GraphQL → error handling) with end-of-document Quality Gates, but there are no per-phase validation checkpoints or feedback loops, and active API testing is a batch/impactful operation where missing validation caps the score at 3. It is not a 2 because the sequence and per-phase structure are well defined.

3 / 5

Progressive Disclosure

The skill is a single well-organized file with clear sections, phased structure, and checklists; content is appropriately inline for a workflow overview and there are no nested or buried references. It is not a 5 because the cross-skill references (e.g. "@api-fuzzing-bug-bounty") and related bundles are name-dropped without file-level navigation or one-level-deep reference files.

4 / 5

Total

14

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid, domain-specific description that names concrete security testing areas with natural trigger keywords. Its main weakness is the absence of any explicit "Use when..." trigger guidance, which limits discoverability and caps completeness.

Suggestions

Add an explicit trigger clause, e.g. "Use when testing API security, pentesting REST or GraphQL endpoints, or investigating API authentication, authorization, or rate-limiting issues."

Include natural user variations and synonyms such as "API pentest", "endpoint security", or "API bug bounty" to broaden trigger coverage.

Replace the generic phrase "security best practices" with a concrete capability (e.g., "audit error handling and information disclosure") to sharpen the what.

DimensionReasoningScore

Specificity

The description lists several specific areas — "covering authentication, authorization, rate limiting, input validation" — for a named domain (REST and GraphQL API security testing), but they are topic areas rather than concrete actions and "security best practices" is a generic tail, so it falls between the 3 and 5 anchors rather than clearly matching either.

4 / 5

Completeness

The "what" is clearly stated (a testing workflow covering five security areas), but there is no "Use when..." clause or equivalent explicit trigger guidance, which per the judging guidelines caps completeness at 3. It is not a 2 because the "what" is specific and multi-part, not vague.

3 / 5

Trigger Term Quality

Natural terms like "API security testing", "REST", "GraphQL", "authentication", and "rate limiting" are phrases users would actually say, but common variations such as "API pentest", "endpoint security", or "bug bounty" are missing, matching the good-but-incomplete keyword coverage anchor.

4 / 5

Distinctiveness Conflict Risk

The REST/GraphQL API security testing niche is mostly distinct with clear triggers, but it risks minor overlap with closely related skills like web security testing or general API fuzzing. It is not a 5 because the description does not carve out a fully unambiguous trigger boundary.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
sickn33/agentic-awesome-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.