Activate this skill whenever the user mentions API endpoint, REST API, RESTful, GraphQL, GraphQL introspection, GraphQL mutation, gRPC, gRPC reflection, WebSocket, WebSocket upgrade, WS endpoint, API security, API fuzzing, API enumeration, API versioning, API gateway, API rate limit, JWT, JSON Web Token, bearer token, access token, refresh token, API key, OAuth, OAuth2, OIDC, OpenID Connect, PKCE, authorization code, client credentials, implicit grant, BOLA, broken object level authorization, BFLA, broken function level authorization, mass assignment, parameter pollution, parameter tampering, parameter discovery, IDOR, insecure direct object reference, horizontal privilege escalation, vertical privilege escalation, authorization bypass, auth bypass, authentication bypass, token manipulation, content-type confusion, type confusion, deserialization, API injection, rate limiting, rate limit bypass, race condition, TOCTOU, Swagger, OpenAPI, API documentation, API specification, WSDL, WADL, API enumeration, endpoint discovery, hidden endpoints, undocumented API, GraphQL batching, query depth, nested query, introspection query, API gateway bypass, WAF bypass API, API fingerprinting, CORS misconfiguration, CORS bypass, origin header, HTTP method override, verb tampering, content negotiation, API key leakage, bearer token theft, token replay, server-sent events, SSE, long polling, streaming API, gRPC-web, protobuf, protocol buffers, service definition, arjun, x8, paramspider, postman, insomnia, burp repeater, burp intruder, comprehensive API audit, API pentest, API attack surface, or discusses testing API security, API hacking, API exploitation, or API reconnaissance.
$npx -y skills add ogrodev/fsociety --skill api-testingInstalls into the current project.
Run `npx skills use "https://github.com/ogrodev/fsociety" --skill "ogrodev/fsociety/api-testing"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/ogrodev/fsociety" that are relevant to the current task. Run `npx skills add "https://github.com/ogrodev/fsociety"` and select the relevant skills, then follow their instructions.