API security testing workflow for REST and GraphQL APIs covering authentication, authorization, rate limiting, input validation, and security best practices.
51
26%
Does it follow best practices?
Impact
96%
1.10xAverage score across 3 eval scenarios
Passed
No known issues
Optimize this skill with Tessl
npx tessl skill review --optimize ./skills/api-security-testing/SKILL.mdMulti-phase security workflow structure
7 phases present
46%
53%
Phase 1 discovery actions
100%
100%
Phase 2 auth actions
60%
60%
Phase 3 authorization actions
100%
100%
Phase 4 injection types
50%
100%
Phase 5 rate limit actions
100%
100%
Phase 7 error handling actions
80%
100%
Security checklist items
100%
100%
Quality gate: remediation
100%
100%
Quality gate: report
100%
100%
GraphQL security testing phases
Introspection testing
100%
100%
Query depth testing
100%
100%
Query complexity testing
100%
100%
Batch query testing
100%
100%
Field suggestion testing
0%
100%
Error message testing
100%
100%
Information disclosure check
100%
100%
Logging verification
30%
100%
Security checklist coverage
100%
100%
Quality gate: report and remediation
100%
100%
Auth/authorization vulnerability documentation
JWT expiration finding
100%
100%
Hardcoded secret finding
100%
100%
OAuth2/token validation coverage
85%
100%
Object-level authorization finding
100%
100%
Privilege escalation finding
100%
100%
Unauthorized admin access finding
100%
100%
SQL injection finding
100%
100%
Information disclosure finding
100%
100%
Quality gate: remediation provided
100%
100%
Quality gate: report structure
100%
100%
7241463
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.