api-security

Assess REST, GraphQL, gRPC, WebSocket, and MCP APIs against OWASP API Top 10 2023.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill api-security-blamejs
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: api-security
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/api-security
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill api-security-blamejs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Legacy security frameworks and tools are built for pre-AI, network-centric environments and fail to address modern API attack surfaces including AI-API abuse, MCP transport risks, and non-REST protocol-specific weaknesses like GraphQL query complexity attacks and gRPC reflection exposure. This skill fills that gap with guidance grounded in mid-2026 threat reality, not outdated framework documentation.

Core Features & Use Cases

  • Comprehensive API Surface Coverage: Assesses REST, GraphQL, gRPC, WebSocket, and MCP API deployments against OWASP API Top 10 2023, MITRE ATT&CK Enterprise, and MITRE ATLAS v2026.06 TTPs.
  • Compliance Gap Analysis: Explicitly flags where major frameworks (NIST 800-53, ISO 27001, PCI DSS, NIS2, UK CAF) fail to cover AI-API and agentic attack patterns, helping teams avoid "compliance theater" for API security.
  • Structured Assessment Output: Generates auditable API inventory tables, OWASP risk scorecards, authentication coverage matrices, rate-limit policy ledgers, and prioritized remediation roadmaps.
  • Use Case: A security team assessing a customer-facing AI chatbot API can use this skill to identify BOLA vulnerabilities in order endpoints, AI-API denial-of-wallet risks from leaked API keys, and MCP transport misconfigurations, then produce a compliance-ready report for stakeholders.

Quick Start

Use the api-security skill to conduct a full assessment of your organization's REST, GraphQL, and MCP API surfaces and generate a prioritized remediation roadmap for OWASP API Top 10 2023 and AI-API specific threats.

Frequently Asked Questions about api-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess API security risks for GraphQL, gRPC, and MCP transport protocols?▼

Assess API security risks for GraphQL, gRPC, and MCP by mapping OWASP API Top 10 2023, MITRE ATT&CK, and ATLAS TTPs to exploitable protocol-specific weaknesses, generating auditable risk scorecards and remediation roadmaps.

What is the best way to identify BOLA vulnerabilities in AI chatbot APIs?▼

Identify BOLA vulnerabilities in AI chatbot APIs by evaluating authentication coverage matrices and applying threat assessments that map modern non-REST API attack surfaces to the OWASP API Top 10 2023 framework.

How do I find compliance gaps in NIST 800-53 or ISO 27001 for AI-API attack patterns?▼

Find compliance gaps in NIST 800-53, ISO 27001, and PCI DSS by explicitly flagging where legacy frameworks fail to cover AI-API abuse, agentic attack patterns, and MCP transport misconfigurations.

Can I use a single assessment to cover REST, WebSocket, and AI-API denial-of-wallet threats?▼

Assess REST, WebSocket, and AI-API denial-of-wallet threats concurrently by inventorying API surfaces and generating a unified risk scorecard aligned to mid-2026 threat reality and modern compliance requirements.

Why do legacy security frameworks fail to protect modern API attack surfaces?▼

Legacy security frameworks fail to protect modern API attack surfaces because they are built for pre-AI, network-centric environments and lack coverage for AI-API consumption, MCP transport risks, and GraphQL query complexity attacks.

How do I generate an auditable API inventory and prioritized remediation roadmap?▼

Generate an auditable API inventory and prioritized remediation roadmap by conducting a full security assessment that outputs structured tables, OWASP risk scorecards, and rate-limit policy ledgers for stakeholder reporting.