Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Bounty Api

ASecurity

Use when bug-bountying an API target — REST, GraphQL, gRPC, WebSocket. Covers OWASP API Top 10 (BOLA, BFLA, mass assignment, rate limiting bypass, JWT issues, GraphQL abuse). Triggers on "bounty api", "graphql security", "rest api testing", "api top 10".

65 stars
0 votes
0 copies
0 views
Added 6/12/2026
securityrustgobashtestingapisecurity

Works with

cliapi

Security Analysis

A96/100
mediumUses curl or wget to download content

Pro shows the line behind each finding and how to fix it

Scanned 6/12/2026

$npx -y skills add 26zl/cybersec-toolkit --skill bounty-api --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Bounty Api?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Bounty Api
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/26zl-bounty-api/badge)](https://www.skillsdirectory.com/skills/26zl-bounty-api)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: bounty-api
description: Use when bug-bountying an API target — REST, GraphQL, gRPC, WebSocket. Covers OWASP API Top 10 (BOLA, BFLA, mass assignment, rate limiting bypass, JWT issues, GraphQL abuse). Triggers on "bounty api", "graphql security", "rest api testing", "api top 10".
---

# Bug bounty API testing

## 1. Discover the API

```bash
# Mobile app reverse → APK / IPA → look for endpoints
# JS bundle inspection
katana -u https://target.com -jc -silent | grep -E "/api/|/v1/|/graphql"
LinkFinder -i https://target.com/app.js -o cli

# Common paths
ffuf -w api-paths.txt -u https://target.com/FUZZ -mc 200,401,403
# /api, /api/v1, /v1, /graphql, /rest, /rpc, /swagger.json, /openapi.json,
# /api-docs, /redoc, /docs, /.well-known/

# Schema endpoints (huge if found)
curl https://target.com/swagger.json
curl https://target.com/openapi.json
curl -X POST https://target.com/graphql -d '{"query":"{__schema{types{name}}}"}'
```

If you find a swagger/openapi/graphql introspection — that IS the attack surface map. Use `kiterunner` to brute API routes if not.

## 2. OWASP API Top 10 — checklist per endpoint

### API1: Broken Object Level Authorization (BOLA)

For every endpoint with an ID:

```bash
# Login as user A. Get user B's resource.
curl -H "Authorization: Bearer $A_TOKEN" https://api/users/$B_ID
```

Try: numeric→numeric swap, UUID enumeration via Wayback/JS, encoded ID decoding.

### API2: Broken Authentication

- Missing / weak JWT verification
- Token reuse after logout
- Refresh-token abuse
- Hardcoded API keys in mobile bundles

### API3: Broken Object Property Level (Mass Assignment + Excessive Data Exposure)

Mass assignment:

```bash
# Sign-up sends: {"email": "...", "password": "..."}
# Try: {"email": "...", "password": "...", "is_admin": true, "role": "admin"}
```

Excessive exposure: GET /users/me returns entire user object including hashed password / secret_question_answer / internal_notes — report it.

### API4: Unrestricted Resource Consumption

Endpoints that allow `?limit=99999`, deeply nested GraphQL queries, expensive operations without rate limit.

### API5: Broken Function Level Authorization (BFLA)

Admin endpoints (`POST /admin/users`, `DELETE /admin/posts/N`) accessed as regular user.

### API6: Unrestricted Access to Sensitive Business Flows

Anti-automation gaps: bulk-creating accounts, scraping product data, mass-redeeming gift cards.

### API7: Server-Side Request Forgery (SSRF)

Any endpoint that takes a URL parameter (avatar URL, webhook URL, OAuth callback, image proxy) → SSRF target. See `bounty-web` SSRF section.

### API8: Security Misconfiguration

- CORS: `Access-Control-Allow-Origin: *` with `Allow-Credentials: true` is a vuln
- Verbose error stack traces
- Default keys / debug endpoints
- HTTP methods like `TRACE`, `OPTIONS` revealing info

### API9: Improper Inventory Management

Old API versions with weaker auth (`/api/v1/`) alongside new (`/api/v2/`). Test the old version.

### API10: Unsafe Consumption of APIs

When the target API consumes a third-party API and trusts its response — SSRF chains, prototype pollution from upstream.

## 3. GraphQL specifics

```bash
# Introspection (if not disabled)
graphql-cop -t https://target/graphql
graphw00f https://target/graphql
clairvoyance https://target/graphql -w wordlist.txt    # if introspection is off

# Common issues
# 1. Introspection enabled in prod
# 2. No query depth limit → DoS
# 3. Batched queries bypassing rate limit
# 4. Fields exposed without auth
# 5. Mutations callable from queries (some impls)
# 6. Field-level authz missing — anonymous user fetches private fields
```

Useful tools: `inql` (Burp ext), `gqlmap`, `BatchQL`.

## 4. JWT

```bash
jwt_tool $TOKEN                      # decode + checks
jwt_tool $TOKEN -X a                 # alg=none
jwt_tool $TOKEN -X i                 # weak HMAC, brute
jwt_tool $TOKEN -X k -pk pubkey.pem  # key confusion (RS256→HS256)
jwt_tool $TOKEN -X kid               # kid injection
```

Also test: kid path traversal (`kid: "../../../../dev/null"` → empty key), JKU/X5U server-controlled injection.

## 5. Rate limit bypass

- Add header: `X-Forwarded-For: 1.2.3.4`, `X-Real-IP`, `X-Originating-IP`, `X-Client-IP`, `X-Remote-IP`
- Change `User-Agent` (some rate limiters key on UA+IP)
- Add trailing slash, change case, add path params (`/login` vs `/login/`)
- HTTP/2 — concurrent stream race
- Delay-based: many requesters bucket per second, sub-second burst slips through

## 6. Tool stack

`kiterunner`, `arjun`, `nuclei`, `mitmproxy`, `BurpSuite` (commercial), `inql`, `graphql-cop`, `clairvoyance`, `jwt_tool`, `Postman`/`Hoppscotch` for repro.

## 7. Reporting

Always include the exact request (method, path, headers, body). Mask tokens but show the structure. Demonstrate impact with two accounts (attacker + victim) where applicable.

Attribution

26zl26zl
View sourceSee grades on GitHubMore from 26zl →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →