Skip to content
appsgit

API Fuzzing Bug Bounty

API Fuzzing Bug Bounty is an agent skill (a SKILL.md file) from zebbern/claude-code-guide. It should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing"… It works with Claude Code, Codex and Cursor and has 4,648 GitHub stars across a repository of 4 listed skills.

github.com/zebbern/claude-code-guide/skills/api-fuzzing-bug-bounty (opens in a new tab)

Add this skill

Claude

Claude Code loads skills from ~/.claude/skills/ (all projects) or .claude/skills/ (one project):

git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/api-fuzzing-bug-bounty ~/.claude/skills/api-fuzzing-bug-bounty   # personal, or .claude/skills in a project

In the Claude apps, zip the api-fuzzing-bug-bounty folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

ChatGPT / Codex

Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:

git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/api-fuzzing-bug-bounty .agents/skills/api-fuzzing-bug-bounty   # repo; ~/.agents/skills for all projects

Standalone skills also load in the ChatGPT desktop app.

Cursor

Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:

git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/api-fuzzing-bug-bounty .cursor/skills/api-fuzzing-bug-bounty   # project; ~/.cursor/skills for all projects

Source (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)

What this skill does

This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques. Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.

When it triggers

  • used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
  • "test API security"
  • "fuzz APIs"
  • "find IDOR vulnerabilities"
  • "test REST API"
  • "test GraphQL"
  • "API penetration testing"
  • "bug bounty API testing"

More skills in zebbern/claude-code-guide

4 skills are listed from this repository.

FAQ

API Fuzzing Bug Bounty FAQ

Still curious? Email info@appsgit.com.

What is the API Fuzzing Bug Bounty skill?

API Fuzzing Bug Bounty is an agent skill (a SKILL.md file) from zebbern/claude-code-guide. It should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing"… It works with Claude Code, Codex and Cursor and has 4,648 GitHub stars across a repository of 4 listed skills. Its SKILL.md lives at github.com/zebbern/claude-code-guide/skills/api-fuzzing-bug-bounty.

How do I install the API Fuzzing Bug Bounty skill?

Copy the api-fuzzing-bug-bounty folder (the one containing SKILL.md) into ~/.claude/skills/ for Claude Code, .agents/skills/ for Codex or .cursor/skills/ for Cursor. The agent picks it up automatically when a task matches its description.

Is the API Fuzzing Bug Bounty skill free?

Yes. The repository is open source under the MIT license.

Is API Fuzzing Bug Bounty maintained?

The repository's most recent commit was on Oct 7, 2026. appsgit only lists skills from repositories with a commit in the last six months.