π¦ ClawHub
Pentest Api Attacker
by @0x-professor
Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.
TERMINAL
clawhub install pentest-api-attackerπ About This Skill
name: pentest-api-attacker description: Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.
Pentest API Attacker
Stage
Objective
Enumerate and test API endpoints and business logic attack vectors.
Required Workflow
1. Validate scope before any active action and reject out-of-scope targets. 2. Run only authorized checks aligned to PTES, OWASP WSTG, NIST SP 800-115, and MITRE ATT&CK. 3. Write findings in canonical finding_schema format with reproducible PoC notes. 4. Honor dry-run mode and require explicit --i-have-authorization for live execution. 5. Export deterministic artifacts for downstream skill consumption.
Execution
python skills/pentest-api-attacker/scripts/api_attacker.py --scope scope.json --target --input --output --format json --dry-run
Outputs
api-endpoints.jsonapi-findings.jsonapi-attack-report.jsonReferences
references/tools.mdskills/autonomous-pentester/shared/scope_schema.jsonskills/autonomous-pentester/shared/finding_schema.jsonLegal and Ethical Notice
WARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.