API rate limiting and resource exhaustion testing skill. Covers rate limit bypass, resource exhaustion, pagination abuse, batch endpoint abuse, and denial-of-service via API resource consumption. Use when testing API rate limiting and resource controls.
API cost/resource exhaustion: pagination abuse, expensive endpoint DoS, async job flooding, nested object expansion, and size limit bypass. Use when testing API resource limits.
API supply chain security testing skill. Covers dependency confusion, package hijacking, CI/CD pipeline attacks, third-party API trust, and upstream dependency vulnerability assessment. Use when evaluating API supply chain security.
API versioning abuse: outdated version endpoint discovery, version diff analysis for weaker security controls, deprecated endpoint access, and authorization bypass via older API versions.
Stateful API fuzzing: sequence-dependent endpoint testing, multi-step workflow fuzzing, state machine violation, and resource lifecycle manipulation. Use when testing complex API workflows.
OAuth 2.0 attack checklist: authorization code interception, redirecturi bypass, CSRF on OAuth flow, state parameter abuse, open redirector chaining, token leakage via Referer, PKCE bypass, and scope escalation. Use when testing OAuth implementations in web apps or bug bounty.
IDOR (Insecure Direct Object Reference) testing checklist: object ID enumeration, horizontal/vertical privilege escalation, GUID predictability, indirect references via hashes, chained IDOR, and API endpoint IDOR. Use for web app pentests and bug bounty IDOR discovery.
GraphQL security testing checklist: introspection abuse, batching attacks, query depth/complexity DoS, field suggestion enumeration, IDOR via GraphQL, injection through arguments, authorization bypass. Use when assessing GraphQL endpoints in web app tests or bug bounty.
★not rated 5 1mo agoA58 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: