api-review
01Command
Focused review of REST, GraphQL, RPC, and webhook surfaces.
Defensive AI security audit skill for Claude and Codex. Reviews codebases and web apps for OWASP Top 10, auth and authorization flaws, business logic bugs, tenant isolation gaps, insecure defaults, secret leaks, and ORM or N+1 query issues, then produces clear remediation guidance.
Command
Focused review of REST, GraphQL, RPC, and webhook surfaces.
Command
Converts raw findings into an engineering-ready report.
Command
Focused review of authentication, authorization, session, token, and reset flows.
Command
Focused review of business invariants, approval flows, sequencing assumptions, and abuse cases.
Command
Reviews a pull request diff for security regressions.
Command
Focused review of ORM usage, raw SQL, N+1 patterns, and tenant scoping in the data-access layer.
Command
Fast pass over a narrow area when time is constrained.
Command
Runs a full defensive review of a codebase, service, or focused path.
Command
Builds a lightweight threat model for a feature or service.