Sibylla - API 보안 엔지니어 AI Skill
Complete skill package instant downloadsibylla-api-security-engineer.skill
Choose how to get it
Start All-Access, from $8.25/mo$99 a year, or $19 a month. 14-day refund on the first charge.
// all-access
You do not download skills. Your AI fetches them.
The KissMySkills connector is a small server your AI chat talks to. Add it once to Claude, ChatGPT, Claude Code or Cursor. From then on, any of our 1,000+ skills is one sentence away.
- 01Add the connector. Settings, Connectors, paste one link. A minute.
- 02Sign in once. The email from your subscription. Nothing installs.
- 03Ask for a skill. "Load Sibylla." It arrives in the conversation and your AI answers as that specialist.
Every skill, prompt pack and agent, new releases included. Single files can still be bought and kept. Cancel any time from your account. Compare plans
Secure checkout by Shopify
Add it once. Your AI works like a specialist.
Claude, ChatGPT 또는 Gemini에 추가하세요 - 귀하의 AI가 이 분야의 전문가로 작동합니다.
즉시 다운로드 · 30일 환불 보장. 한 번만 결제하고 영구적으로 사용하세요 - 구독 없음. GitHub에서 무단 수집한 것이 아니라, 저희가 직접 작성하고 테스트했습니다. 환불 정책
Ask Sibylla something hard.
구매 전에 궁금한 점이 있나요?
저희에게 문의하시면 보통 당일에 담당자가 직접 답변해 드립니다. 봇도 아니고, 문의 티켓 대기열도 아닙니다.
hello@kissmyskills.comTrademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.
당신은 읽지 않습니다. 당신의 AI가 읽습니다.
Claude, ChatGPT 또는 Gemini에 스킬 파일을 한 번만 추가하세요. 그러면 그다음 메시지부터 이 분야의 전문가로 작동하며 Sibylla으로 답변합니다.
한 번 구매하면 파일을 영원히 소장할 수 있습니다. 또는 All-Access를 구독하고 KissMySkills 커넥터가 요청에 따라 해당 파일과 다른 모든 스킬을 채팅에 불러오도록 하세요.
// what's inside
이 스킬에는 무엇이 들어 있나요
- BOLA, IDOR and function-level authorization testing
- API discovery: shadow, zombie and undocumented endpoints
- OAuth 2.0, OIDC, JWT validation and token lifetime design
- Gateway, rate limit and abuse policy plus CI security testing
Product and platform teams shipping APIs fast who need authorization and inventory under control before someone enumerates their object IDs.
An API security engineer bills $140+/hr, the complete skill is yours forever.
What you're actually buying
Drop Sibylla into Claude and get an API security engineer who goes straight for broken object level authorization, because that is what is actually getting exploited.
Sibylla secures APIs as their own attack surface: the OWASP API Security Top 10 with BOLA and broken function-level authorization treated as the dominant real-world findings, API discovery and inventory including shadow, zombie and undocumented endpoints, schema and contract validation across OpenAPI, GraphQL and gRPC, authentication and authorization done properly with OAuth 2.0 grant selection, OIDC, JWT validation failures, scopes versus entitlements, token lifetime and revocation and mTLS for service-to-service, rate limiting and abuse prevention, gateway and WAAP policy on Kong, Apigee, AWS API Gateway and Cloudflare, mass assignment and excessive data exposure, webhook and callback security, machine-to-machine credentials, business logic abuse no scanner will find, API testing in CI and in production, and the third-party API you consume being your problem too.
What you get
- →BOLA, IDOR and function-level authorization testing
- →API discovery: shadow, zombie and undocumented endpoints
- →OAuth 2.0, OIDC, JWT validation and token lifetime design
- →Gateway, rate limit and abuse policy plus CI security testing
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Sibylla builds the answer. Includes a full worked example so you see exactly what you get.
# Sibylla - API Security Engineer You are Sibylla, a senior API security engineer. You start from authorization per object and a real endpoint inventory, because that is where APIs actually fail. ## How you work 1. Build the endpoint inventory, including what nobody documented 2. Test authorization per object and per function, not just authentication 3. Fix token design: grant type, lifetime, scope, revocation, validation 4. Apply gateway, rate limit and abuse policy to the real traffic shape 5. Encode the tests in CI so the next endpoint inherits them Test only systems you are authorized to test. Confirm current specifications and vendor behaviour before relying on them.
다운로드할 실제 파일의 샘플입니다.
네 단계. 어떤 AI 채팅.
- 01파일 다운로드
결제 후 다운로드 링크가 받은편지함으로 전송됩니다. 파일을 기기의 원하는 위치에 저장하세요.
- 02AI 채팅 열기
Claude, ChatGPT, Gemini, Grok 또는 Copilot - 이미 사용 중인 것을 선택하세요.
- 03파일 내용을 붙여넣으세요
시스템 prompt, 프로젝트 지침 또는 맞춤 지침 필드에 입력하세요.
- 04작업 시작
이제 AI가 전문가로 설정되었습니다. 해당 분야와 관련된 내용이라면 무엇이든 질문해 보세요.
기술 지식이 필요하지 않습니다. 구독도 없습니다. 한 번만 결제하고 영원히 사용하세요.
모든 주요 AI 채팅과 호환됩니다.
파일을 AI의 시스템 prompt, 프로젝트 지침 또는 맞춤 지침에 넣으세요. 설정이 필요 없습니다. 코드도 필요 없습니다. 특정 공급업체에 종속되지 않습니다.
이 제품에 대한 질문
What does the Sibylla skill do?+
Secure your APIs where they actually break: authorization per object, a real endpoint inventory, and gateway and CI controls that hold. Load it once into Claude Projects and you get a configured API Security Engineer without re-explaining context at the start of every session. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
How do I install this skill file?+
Download the .skill package (it contains SKILL.md), paste the contents into Claude Projects Instructions or your AI's system prompt, add your own context and start your first session. Works with Claude, ChatGPT, or any AI chat that accepts system prompts.
Which AI tools does this skill work with?+
Works with Claude (recommended), ChatGPT, Gemini, Perplexity and Copilot, and any AI chat that accepts system prompts. Claude Projects gives the best results.
What is included in this download?+
One .skill package delivered instantly after purchase: the full SKILL.md role configuration plus a worked-example file with a real scenario so you see the quality before you rely on it. No subscription, yours permanently.
How is this different from using Claude without the Sibylla skill?+
Without a skill file your AI starts every session as a general assistant. With Sibylla loaded it applies API Security Engineer methodology from the first message, with consistent quality every time. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
Do I have to read it myself?+
No. The file is written for your AI to read, not for you. Upload it or paste it in once and the AI takes on the role. After that you just ask it questions the way you normally would. You're welcome to open it and read it, but nothing here depends on you doing that.
Is this a physical book?+
No, it's digital. You download it the moment the order goes through and it's yours permanently. The cover is styled like a book because each edition is written and edited as one self-contained piece of work. The reading part is your AI's job, not yours.
AI를 전문화할 준비가 되셨나요?
파일 하나로 바로 사용하세요. 한 번만 결제하면 영구적으로 사용할 수 있습니다 - Claude 및 ChatGPT와 호환됩니다.