Find weak token trust and authentication boundaries.
API security testing
Guides testing of API authentication and JWT trust boundaries, including claims, headers, rate limits, and API keys.
When to use it
Use when testing APIs that rely on JWTs, bearer tokens, API keys, or weak request identity signals.
It changes how the agent tests API authentication by focusing on token trust, claim misuse, header spoofing, and rate-limit bypass.
This skill
target APIs
Sends crafted requests to APIs
No setup requirements listed in the analysis.