api-security
zhaoxuya520/reverse-skill
A comprehensive, 10-phase methodology for authorized security assessment of modern APIs, including REST, GraphQL, WebSocket, and SOAP. This guide covers the entire testing lifecycle—from endpoint discovery and authentication bypass (JWT/OAuth 2.0) to sophisticated authorization flaws (BOLA/IDOR/BFLA), input validation, rate limiting, and CI/CD integration testing.