Skip to main content
Free
Open Source
MIT
No API Key
Runs Locally
OWASP API Top 10

APIsec Skills

Your AI coding assistant writes secure APIs by default.

APIsec Skills put the OWASP API Security Top 10 inside the assistant your developers already use. Five always-on rules harden every endpoint it writes, and six skills load when the task calls for them and return a security report. There is nothing to configure, and nothing leaves your machine.

claude code

/plugin marketplace add apisec-inc/apisec-skills /plugin install apisec@apisec-skills
⭐ Star on GitHub
Claude Code
Cursor
GitHub Copilot
OpenAI Codex
Gemini CLI
Windsurf
The difference

Same request, different code

Ask an assistant to add an endpoint that fetches orders by id. Without security context it returns the most direct answer, which lets any user read any order. With APIsec Skills loaded, it returns the version a security reviewer would have asked for.

Without APIsec Skills

orders.js

app.get('/api/orders/:id', async (req, res) => { const order = await Order.findById(req.params.id); // any user, any order res.json(order); });

With APIsec Skills

orders.js

app.get('/api/orders/:id', authenticate, async (req, res) => { const order = await Order.findOne({ _id: req.params.id, userId: req.user.id, // ownership enforced }); if (!order) return res.status(404).json({ error: 'Not found' }); res.json(serializeOrder(order)); // filtered response });
Always on

Five rules that shape every line the assistant writes

Rules load at the start of a session and ship in the native rule format of each assistant. The developer never has to ask for secure output.

auth-required

Every route that touches data has authentication middleware.

ownership-check

Every query is scoped to the authenticated user. This closes broken object level authorization, the most common API flaw.

input-validation

User input is validated before it reaches a database, a shell, or a file path.

error-sanitization

Error responses carry no stack traces, file paths, or query details.

admin-rbac

Admin and elevated operations require an explicit role check.

On demand

Six skills that load when the task calls for them

Until a task matches, each skill costs only its short description. When it matches, the full skill loads and returns a report with the finding, the OWASP reference, and the fix.

API1

bola-detector

Loads when you write route handlers with id parameters or lookups by id.

API2 · API5

auth-rbac-scaffold

Loads when you build login flows, JWT handling, middleware, or role checks.

API8

injection-checker

Loads when you write SQL, MongoDB queries, shell commands, file paths, or templates.

API1 to API5

security-test-generator

Loads when you add tests in Jest, pytest, or JUnit.

All ten categories

api-security-review

Loads when you ask whether code is secure, or review a controller.

API3

openapi-hardener

Loads when you edit OpenAPI specs or Zod, Joi, Pydantic, and JSON schemas.

The output

A report you can act on

Every finding carries the OWASP reference, the severity, the line, and the exact change. The report ends with the three changes that improve security the most.

api-security-review

## APIsec Security Review File reviewed: src/routes/orders.js Reviewed against: OWASP API Security Top 10 2023 Security Score: D ### Critical Findings #### [API1:2023] Broken Object Level Authorization, line 47 Pattern: Order.findById(req.params.id) without ownership filter Risk: any authenticated user can read, modify, or delete any order Fix: Order.findOne({ _id: req.params.id, userId: req.user.id }) ### Quick Wins 1. [Critical] Add ownership filter to all findById calls 2. [High] Add algorithm whitelist to JWT verification 3. [Medium] Cap pagination limit to 100
Install

One repository for every major coding assistant

The skills use the open Agent Skills format, so the same files work everywhere. The rules ship in the native format of each assistant. Claude Code installs as a plugin. For the others, clone the repository and copy.

Claude Code

claude code

/plugin marketplace add apisec-inc/apisec-skills /plugin install apisec@apisec-skills # always-on rules for the project mkdir -p .claude/rules && cp agents/claude-code/rules/*.md .claude/rules/

Cursor

cursor

cp -r skills .cursor/skills/ cp -r rules .cursor/rules/

GitHub Copilot

github copilot

cp -r skills .github/skills/ cp agents/copilot/copilot-instructions.md .github/copilot-instructions.md

Codex, Gemini CLI, Windsurf

codex · gemini · windsurf

cp -r skills .agents/skills/ cp agents/codex/AGENTS.md AGENTS.md # Codex cp agents/gemini/GEMINI.md GEMINI.md # Gemini CLI mkdir -p .windsurf/rules && cp agents/windsurf/rules/*.md .windsurf/rules/

Replit, Kiro, Roo Code and other assistants that read the Agent Skills format are covered too. The full steps are in the README.

Where it fits

Write it safely, check what ships, prove what is exploitable

APIsec Skills

The assistant writes the secure version first

While the code is being written

AI Surface

What AI attack surface a change is about to ship

At pull request time, before merge

APIsec platform

Which findings an attacker can use against the running application

At runtime, with replayable evidence

Rules and skills reduce what gets written wrong. AI Surface shows what AI attack surface a change adds. The APIsec platform tests the running application as your own users and roles, and reports the attacks that worked.

Give your coding assistant a security reviewer's instincts

install

git clone https://github.com/apisec-inc/apisec-skills cd apisec-skills