Comprehensive security audit for REST and GraphQL APIs, covering authentication, authorization, input validation, and protection against OWASP API Top 10 threats.
24
Total Checks
3
Delivery Formats
3
Categories
5
Versions
Included
Never included
Quality hardening: added counting/enumeration, numeric thresholds, anti-sycophancy patterns, cross-references to all checks. Manifests tightened to exact tolerances.
2026-04-03
Added chunked format for browser-based tools
2026-03-01
Improved Step 3: paste URL is now primary submission method
2026-03-01
Hardened curl commands with -sS -L flags for redirect following and error visibility. Added response validation guidance to Step 3.
2026-02-23
Initial release
2026-02-20
Picked by pack overlap with this audit.
Production-ready authentication assessment covering session management, login flow security, password handling, and OAuth integrations.
Authorization layer assessment covering access control, resource authorization, API permissions, and admin boundary enforcement.
Data handling assessment across the AI processing pipeline, covering storage, retention, PII protection, and user control over third-party model data sharing.
Safety assessment against prompt injection attacks, identifying vulnerabilities where untrusted user input might cause the AI to ignore instructions or exfiltrate data.
API design quality assessment covering naming consistency, HTTP semantics, request/response shape, security controls, and developer experience.