Api Security Scanner
Scan APIs for security vulnerabilities and OWASP API Top 10
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 1.25.0
- Author
- Jeremy Longshore
What Api Security Scanner is
Api Security Scanner is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Api Security Scanner adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Api Security Scanner
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install api-security-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Api Security Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/api-development/api-security-scanner/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Scan APIs for OWASP API Security Top 10 vulnerabilities with remediation guidance.
Installation
/plugin install api-security-scanner@claude-code-plugins-plusUsage
/scan-api-securityFeatures
- OWASP API Top 10 checks
- Authentication testing
- Authorization flaws
- Injection vulnerabilities
- Security misconfiguration
License
MIT
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Api Security Scanner?
Api Security Scanner is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Scan APIs for security vulnerabilities and OWASP API Top 10
How do I install Api Security Scanner in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install api-security-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Api Security Scanner in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Api Security Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Api Security Scanner safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Jeremy Genkit Terraform Terraform modules for Firebase Genkit infrastructure and deployments Plugin · jeremylongshore/tons-of-skills-marketplace
- Jeremy Google Adk Google Agent Development Kit (ADK) SDK starter kit for building Claude-powered AI agents with React patterns, multi-agent orchestration, and tool integration Plugin · jeremylongshore/tons-of-skills-marketplace
- Jeremy Vertex Engine Vertex AI Agent Engine deployment inspector and runtime validator Plugin · jeremylongshore/tons-of-skills-marketplace
- Jeremy Vertex Ai Comprehensive Vertex AI integration plugin for building generative AI agents with Gemini, Vertex AI Studio, and production deployment on Google Cloud Plugin · jeremylongshore/tons-of-skills-marketplace
- Api Test Automation Automated API endpoint testing with request generation, validation, and comprehensive test coverage Plugin · jeremylongshore/tons-of-skills-marketplace
- Api Sdk Generator Generate client SDKs from OpenAPI specs for multiple languages Plugin · jeremylongshore/tons-of-skills-marketplace
- Api Throttling Manager Manage API throttling with dynamic rate limits and quota management Plugin · jeremylongshore/tons-of-skills-marketplace
- Api Schema Validator Validate API schemas with JSON Schema, Joi, Yup, or Zod Plugin · jeremylongshore/tons-of-skills-marketplace