offensive-api-security
SnailSploit/Claude-Red
A comprehensive guide to conducting authorized security assessments across API-driven applications. This skill covers REST, gRPC, and WebSocket protocols, addressing the full OWASP API Security Top 10 2023. Techniques include identifying Broken Object Level Authorization (BOLA/IDOR), broken authentication, excessive data exposure, and implementing fuzzing for various API endpoints. Designed for professional penetration testing engagements.