Automated API security testing starting from domains. Discovers REST, GraphQL, and SOAP APIs, reconstructs schemas, and tests for BOLA/IDOR, BFLA, mass assignment, JWT attacks, rate limiting bypass, and business logic flaws. Use when user asks to "test API security", "break API", "find API vulnerabilities", "test GraphQL", "test JWT", "API pentest", or provides domains with API endpoints. For authorized testing only.
$npx -y skills add orizon-eu/claude-code-pentest --skill api-breakerInstalls into the current project.
Run `npx skills use "https://github.com/orizon-eu/claude-code-pentest" --skill "orizon-eu/claude-code-pentest/api-breaker"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/orizon-eu/claude-code-pentest" that are relevant to the current task. Run `npx skills add "https://github.com/orizon-eu/claude-code-pentest"` and select the relevant skills, then follow their instructions.