API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
56
63%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./skills/api-security-testing/SKILL.mdSpecialized workflow for testing REST and GraphQL API security including authentication, authorization, rate limiting, input validation, and API-specific vulnerabilities.
Use this workflow when:
api-fuzzing-bug-bounty - API fuzzingscanning-tools - API scanningUse @api-fuzzing-bug-bounty to discover API endpointsbroken-authentication - Auth testingapi-security-best-practices - API authUse @broken-authentication to test API authenticationidor-testing - IDOR testingUse @idor-testing to test API authorizationapi-fuzzing-bug-bounty - API fuzzingsql-injection-testing - Injection testingUse @api-fuzzing-bug-bounty to fuzz API parametersapi-security-best-practices - Rate limitingUse @api-security-best-practices to test rate limitingapi-fuzzing-bug-bounty - GraphQL fuzzingUse @api-fuzzing-bug-bounty to test GraphQL securityapi-security-best-practices - Error handlingUse @api-security-best-practices to audit API error handlingsecurity-audit - Security auditingweb-security-testing - Web securityapi-development - API development1f67c44
Also appears in
since Feb 24, 2026
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.