# API Fuzzing Bug Bounty (agent skill)

> API Fuzzing Bug Bounty is an agent skill (a SKILL.md file) from zebbern/claude-code-guide. It should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing"… It works with Claude Code, Codex and Cursor and has 4,648 GitHub stars across a repository of 4 listed skills.

This skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques. Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/zebbern/claude-code-guide |
| Skill path | skills/api-fuzzing-bug-bounty/SKILL.md |
| Skill name | api-fuzzing-bug-bounty |
| GitHub stars | 4,648 |
| Installs on skills.sh | not listed |
| License | MIT |
| Skills in repo | 4 |
| Plugin marketplace | no |
| Official | no |
| Works with | Claude Code, Codex, Cursor |
| Category | Testing & QA |
| Last commit | Oct 7, 2026 |

## When it triggers

- used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
- "test API security"
- "fuzz APIs"
- "find IDOR vulnerabilities"
- "test REST API"
- "test GraphQL"
- "API penetration testing"
- "bug bounty API testing"

## Add this skill

### Claude Code

```sh
git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/api-fuzzing-bug-bounty ~/.claude/skills/api-fuzzing-bug-bounty   # personal, or .claude/skills in a project
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/api-fuzzing-bug-bounty .agents/skills/api-fuzzing-bug-bounty   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/zebbern/claude-code-guide.git
cp -r claude-code-guide/skills/api-fuzzing-bug-bounty .cursor/skills/api-fuzzing-bug-bounty   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

---

Canonical page: https://appsgit.com/skills/zebbern-api-fuzzing-bug-bounty
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
