跳到主要内容
场景指南Scenario guide

API 安全审计

在用户发现之前找出鉴权、注入、数据泄漏问题。

要解决的问题 · The problem

API 安全评审常被放到最后且做得浅。团队需要按方法论走的评审,覆盖 OWASP 经典案例、AI 特有风险、历史泄漏案例。

推荐 skillRecommended skills

3 个推荐 · 按匹配度排序,首选在前
可选 · strong
api-security-testing
by Ed1s0nZ

API安全测试的专业技能和方法论

  • auto-discovered
  • github
  • star-1000-plus
可选 · strong
wooyun-legacy
by tanweai

WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws, misconfiguration) and 33 vulnerability classes. Use for ANY security testing, auditing, or code review of web apps, APIs, or business systems — even without explicit "security" keywords. Triggers: penetration testing, security audit, vulnerability, bug bounty, payment security, IDOR, password reset, weak credentials, unauthorized access, race condition, parameter tampering, code review, 渗透测试, 安全审计, 漏洞挖掘, 支付安全, 越权, 逻辑漏洞, 业务安全, SRC, 代码审计. Also triggers on implicit intent: "test this endpoint", "find bugs", "can I bypass this", "帮我测测这个接口", "这个参数能不能改", "帮我找bug".

  • auto-discovered
  • github
  • star-1000-plus
可选 · strong
aig-scanner
by Tencent

A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via Tencent Zhuque Lab AI-Infra-Guard. Uses built-in exec + Python script, no plugin required. Requires AIGBASEURL to be configured. Triggers on: scan AI service, AI vulnerability scan, scan AI infra, check CVE, audit AI service, scan MCP, scan skills, audit AI tools, scan agent, red-team LLM, jailbreak test, 扫描AI服务, 检查AI漏洞, 扫描AI工具, 检查MCP安全, 审计Agent, 越狱测试.

  • auto-discovered
  • github
  • star-1000-plus
Skill Market
按品类找最好用的 AI 技能·Find the best AI skills for the job
v0.4 · 收录 1252 个 skill · 上次评测 2026-06-03