
API-Security
OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Open-source access management platform offering single sign-on, adaptive authentication, authorization, and federation for secure access to web,…

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

Your gateway to OWASP. Discover, engage, and help shape the future!

PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

Open-source AI agent firewall that scans HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, emitting verifiable…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC

This skill helps Claude write secure code and prevent common vulnerabilities.

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Core framework for identity and access management, providing authentication, authorization, and identity governance capabilities for enterprise…