APIsec Skills
Your AI coding assistant writes secure APIs by default.
APIsec Skills put the OWASP API Security Top 10 inside the assistant your developers already use. Five always-on rules harden every endpoint it writes, and six skills load when the task calls for them and return a security report. There is nothing to configure, and nothing leaves your machine.
claude code
Same request, different code
Ask an assistant to add an endpoint that fetches orders by id. Without security context it returns the most direct answer, which lets any user read any order. With APIsec Skills loaded, it returns the version a security reviewer would have asked for.
Without APIsec Skills
orders.js
With APIsec Skills
orders.js
Five rules that shape every line the assistant writes
Rules load at the start of a session and ship in the native rule format of each assistant. The developer never has to ask for secure output.
Every route that touches data has authentication middleware.
Every query is scoped to the authenticated user. This closes broken object level authorization, the most common API flaw.
User input is validated before it reaches a database, a shell, or a file path.
Error responses carry no stack traces, file paths, or query details.
Admin and elevated operations require an explicit role check.
Six skills that load when the task calls for them
Until a task matches, each skill costs only its short description. When it matches, the full skill loads and returns a report with the finding, the OWASP reference, and the fix.
bola-detector
Loads when you write route handlers with id parameters or lookups by id.
auth-rbac-scaffold
Loads when you build login flows, JWT handling, middleware, or role checks.
injection-checker
Loads when you write SQL, MongoDB queries, shell commands, file paths, or templates.
security-test-generator
Loads when you add tests in Jest, pytest, or JUnit.
api-security-review
Loads when you ask whether code is secure, or review a controller.
openapi-hardener
Loads when you edit OpenAPI specs or Zod, Joi, Pydantic, and JSON schemas.
A report you can act on
Every finding carries the OWASP reference, the severity, the line, and the exact change. The report ends with the three changes that improve security the most.
api-security-review
One repository for every major coding assistant
The skills use the open Agent Skills format, so the same files work everywhere. The rules ship in the native format of each assistant. Claude Code installs as a plugin. For the others, clone the repository and copy.
Claude Code
claude code
Cursor
cursor
GitHub Copilot
github copilot
Codex, Gemini CLI, Windsurf
codex · gemini · windsurf
Replit, Kiro, Roo Code and other assistants that read the Agent Skills format are covered too. The full steps are in the README.
Write it safely, check what ships, prove what is exploitable
APIsec Skills
The assistant writes the secure version first
While the code is being written
AI Surface
What AI attack surface a change is about to ship
At pull request time, before merge
APIsec platform
Which findings an attacker can use against the running application
At runtime, with replayable evidence
Rules and skills reduce what gets written wrong. AI Surface shows what AI attack surface a change adds. The APIsec platform tests the running application as your own users and roles, and reports the attacks that worked.