api-security-review
OWASP/secure-agent-playbookComprehensive API security review against OWASP API Security Top 10 (2023). Use when reviewing OpenAPI/Swagger specs, auditing REST/GraphQL/gRPC…
Scores out of 100 · grade B
2026-08-09Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score76/100
- no commits in the last 12 weeks
- no license file
Adopted
20% of the score29/100
- 141 stars on the source repo.
Documented
15% of the score48/100
- No usage example or code block.
- 351-word body.
Install
npx skills add OWASP/secure-agent-playbook/api-security-reviewWhat the check found
| Finding | What it means |
|---|---|
| No license | The repository ships no license file, so the reuse terms are unclear. |
What it says it does
Comprehensive API security review against OWASP API Security Top 10 (2023). Use when reviewing OpenAPI/Swagger specs, auditing REST/GraphQL/gRPC implementations, testing authentication mechanisms, or checking API gateway configurations. Covers BOLA/IDOR, broken auth, mass assignment, rate limiting, SSRF, and more with real-world attack scenarios.
Also in OWASP/secure-agent-playbook
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| security-guidanceOWASP/secure-agent-playbook | No license | Skill | 141 stars | 1 months ago | |
| ai-security-verificationOWASP/secure-agent-playbook | No license | Skill | 141 stars | 1 months ago | |
| multi-agentic-threat-modelOWASP/secure-agent-playbook | No license | Skill | 141 stars | 1 months ago | |
| prompt-injection-testOWASP/secure-agent-playbook | No license | Skill | 141 stars | 1 months ago | |
| security-team-leadOWASP/secure-agent-playbook | No license | Subagent | 141 stars | 1 months ago | |
| ai-security-assessorOWASP/secure-agent-playbook | No license | Subagent | 141 stars | 1 months ago |
Other backend & apis skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| find-skillsvercel-labs/skills | clean | Backend & APIs | 3,055,082 installs | 3 days ago | |
| write-api-referencevercel/next.js | clean | Backend & APIs | 142k stars | today | |
| fastapifastapi/fastapi | clean | Backend & APIs | 8,017 installs | 2 days ago | |
| paperclippaperclipai/paperclip | clean | Backend & APIs | 3,217 installs | today | |
| onchain-pay-open-apiccxt/ccxt | clean | Backend & APIs | 44k stars | today | |
| namecheapgithub/awesome-copilot | clean | Backend & APIs | 38k stars | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=OWASP%2Fsecure-agent-playbook)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
