CtrlK
BlogDocsLog inGet started
Tessl Logo

api-security

Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.

72

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

82%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A lean, actionable 10-phase API security testing methodology with concrete commands, a tool table, and clearly signaled references. The main gaps are technique-list style actionability and limited per-phase validation checkpoints.

Suggestions

Add explicit validation/verification checkpoints between phases (e.g. 'confirm findings are reproducible before advancing to the next phase') to strengthen the destructive/batch workflow.

Convert key technique checklists into copy-paste-ready command recipes for the most common cases (JWT analysis, BOLA traversal) to lift actionability toward fully executable.

Move detailed JWT/OAuth and REST/GraphQL technique lists fully into the reference files and keep SKILL.md as a tighter overview to reduce inline/reference overlap.

DimensionReasoningScore

Conciseness

Dense checkbox-style technique lists and concrete tool commands with no padding explaining what APIs, JWT, or OAuth are; assumes Claude's competence and every line earns its place.

5 / 5

Actionability

Provides concrete commands (e.g. 'jwt_tool -C -d wordlist.txt', 'Entropy --ci --watch') and specific attack patterns, but most guidance is technique enumeration rather than fully copy-paste-ready command sequences for common cases.

4 / 5

Workflow Clarity

A clear 10-phase sequence with a pre-flight 'ACTION REQUIRED' checklist and a final '任务完成自检' completion checklist providing validation; minor gaps in per-phase verification checkpoints.

4 / 5

Progressive Disclosure

Well-structured overview with two real, one-level-deep references clearly signaled under '## 参考'; the body still inlines substantial technique detail that overlaps the reference material, leaving minor organization gaps.

4 / 5

Total

17

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, third-person description that clearly states what the skill does and when to use it, with concrete capabilities and a well-scoped niche. Its only weakness is trigger-term diversity, which leans on protocol names rather than natural synonyms.

DimensionReasoningScore

Specificity

Names the API security domain and lists multiple concrete actions — 'discovery, authentication, authorization, rate-limit, and CI/CD testing' — giving comprehensive coverage of specific capabilities.

5 / 5

Completeness

Explicitly answers both what ('authorized security assessment of ... APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing') and when ('Use for ...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Good keyword coverage with REST, GraphQL, WebSocket, and SOAP, but relies on protocol jargon and omits natural synonyms (e.g. 'API testing', 'endpoint security') and any file extensions.

4 / 5

Distinctiveness Conflict Risk

The 'authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs' framing carves a clear niche with distinct triggers and minimal overlap with general web or code security skills.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zhaoxuya520/reverse-skill
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.