42crunch-api-security-testing

PackSecurity

42crunch-api-security-testing is a plugin that brings API security testing into an AI-assisted development workflow. It audits OpenAPI specifications for security flaws such as broken authorization, detects vulnerabilities aligned with OWASP API Security risks including BOLA and BFLA, and applies AI-powered fixes. It provides continuous guardrails while an agent writes or reviews API code.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have the OpenAPI specifications for the APIs you want to test available in your project.

What your AI can do with it

  • Automatically audit OpenAPI specifications for security flaws
  • Detect vulnerabilities aligned with OWASP API Security risks
  • Detect broken authorization issues such as BOLA and BFLA
  • Apply AI-powered fixes for detected vulnerabilities
  • Provide continuous guardrails in AI-assisted development workflows

Getting started

  1. Have the OpenAPI specifications for the APIs you want to test available in your project.
  2. Add the 42crunch-api-security-testing plugin to your agent setup.
  3. Ask the agent to audit an OpenAPI spec and review the reported vulnerabilities.
  4. Have the agent apply the suggested AI-powered fixes and re-audit to confirm.

Signals

GitHub stars
37k
Forks
4k
Last commit
Sep 2026

Questions

What kinds of vulnerabilities does it detect?
It detects vulnerabilities aligned with OWASP API Security risks, including broken authorization issues such as BOLA and BFLA, by auditing OpenAPI specifications.
Does it fix the issues it finds?
Yes, it applies AI-powered fixes for the vulnerabilities it detects.
Do I need OpenAPI specifications to use it?
Yes, it audits OpenAPI specifications, so you need specs for the APIs you want to test.
Can it run continuously during development?
It is designed for AI-assisted development workflows and provides continuous guardrails.
Advanced
Item type
plugin
Key
anthropics-claude-plugins-official-42crunch-api-secu-03vq2l5
Source
github.com/anthropics/claude-plugins-official