Summary
- API security automation skill for REST, GraphQL, gRPC, and WebSocket APIs.
- Covers OpenAPI/AsyncAPI ingestion, authenticated fuzzing, OWASP API Top 10 (BOLA, BFLA, mass assignment, SSRF), schema diffing, GraphQL introspection abuse, JWT and OAuth misuse, rate-limit and replay testing.
- Use to automate API assessments with safe, scoped, evidence-backed findings.