API discovery & fuzzing
SkillAI & modelsDiscover and fuzz API endpoints, methods, params, and versions systematically. Load when you have an API base but not its full surface, an OpenAPI/Swagger/Postman spec, or "map/fuzz the API". Signals: /api, /v1, swagger.json, GraphQL, mobile backend, undocumented routes.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the API discovery & fuzzing skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/api/api-fuzzing/SKILL.md and read by ahel’s review.
When it applies
You need the API's real surface before attacking it: hidden endpoints, accepted methods, extra params, and old versions. Complete inventory is where BOLA/mass-assignment/auth bugs surface.
Why it works
APIs expose far more than the client uses; specs, JS, and mobile apps reveal routes, and version drift leaves un-patched endpoints. Enumerating the surface turns guesswork into targeted testing.
Method
- Harvest from specs/clients: OpenAPI/Swagger (
swagger.json,/api-docs), Postman collections, GraphQL introspection, and endpoints in JS bundles / mobile apps. - Route brute:
kiterunner(API-aware wordlists incl. methods) orffufagainst/api/FUZZ,/v{1,2,3}/; try each with GET/POST/PUT/PATCH/DELETE — method matters. - Param discovery:
arjun/Burp param miner per endpoint to find hidden inputs (feed mass-assignment, injection, IDOR tests). - Version & shadow: enumerate
/v1../v3,/internal,/beta; compare behaviour/auth across versions. - Feed the results into
api-bola,api-mass-assignment,api-auth-attacks, injection.
Gotchas
- Respect rate limits and scope — API fuzzing is noisy; throttle and stay on in-scope hosts.
- A route that 401s still counts — note it for auth testing; 404 vs 401 vs 403 map the surface.
- Method-fuzzing finds actions the client never issues (hidden admin verbs).
Verify success
A materially larger, documented endpoint/param inventory (with methods/versions) ready for vuln-class testing — including routes not in the official docs.
References
OWASP API Security (API9); kiterunner; PortSwigger API testing guide.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
api-fuzzing-noorqureshi- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)skill-creator
Skill · anthropics
More in AI & modelswayfinder
Skill · mattpocock
More in AI & models