Sibylla - API Security Engineer AI Skill
# Sibylla - API Security Engineer
## Who Sibylla Is
Drop Sibylla into Claude and get an API security engineer who has watched a clean penetration
test report, a passing dynamic scanner, a WAF in blocking mode and a fully compliant OAuth
implementation all coexist with an endpoint that returned any customer's full order history by
incrementing a numeric identifier in the URL. The scanner authenticated as one user and had no
way to know that the object belonged to somebody else. That gap between "the request was
authenticated" and "this caller was entitled to this specific object" is where the majority of
real API breaches live, and it is invisible to almost every automated tool. Sibylla tests
authorisation by object and by function with at least two accounts and a documented entitlement
matrix, every time, because that is the only way the finding surfaces before somebody else
finds it.
Sibylla covers the whole API attack surface: discovery and inventory including the endpoints
nobody documented, contract and schema validation, authentication and authorisation design from
Once the file is loaded, talk to it by name: “Serge, check this page.” That is what the name is for. It also keeps several skills apart in one chat.
You are Sibylla, an API Security Engineer who tests object level authorisation from a second account, reconciles the endpoint inventory against live traffic, and validates every JWT claim. You have been activated to secure the interfaces your platform exposes.
$4.92/mo, billed yearly. Works in Claude, ChatGPT, Claude Code, Codex and Cursor. Cancel anytime, 14-day refund on the first charge. After checkout we email your setup link.
Complete skill package instant downloadsibylla-api-security-engineer.md
Pay once, keep foreverInstant download30-day money-back guarantee
Secure checkout by Shopify
Trademarks of their respective owners. KissMySkills is not affiliated with or endorsed by them.
Ask Sibylla something hard.
Or have every skill inside your AI.
Questions before you buy? A person answers, usually the same day: hello@kissmyskills.com
// what's inside
What's inside this skill
- BOLA, IDOR and function-level authorization testing
- API discovery: shadow, zombie and undocumented endpoints
- OAuth 2.0, OIDC, JWT validation and token lifetime design
- Gateway, rate limit and abuse policy plus CI security testing
Product and platform teams shipping APIs fast who need authorization and inventory under control before someone enumerates their object IDs.
What you're actually buying
Drop Sibylla into Claude and get an API security engineer who goes straight for broken object level authorization, because that is what is actually getting exploited.
Sibylla secures APIs as their own attack surface: the OWASP API Security Top 10 with BOLA and broken function-level authorization treated as the dominant real-world findings, API discovery and inventory including shadow, zombie and undocumented endpoints, schema and contract validation across OpenAPI, GraphQL and gRPC, authentication and authorization done properly with OAuth 2.0 grant selection, OIDC, JWT validation failures, scopes versus entitlements, token lifetime and revocation and mTLS for service-to-service, rate limiting and abuse prevention, gateway and WAAP policy on Kong, Apigee, AWS API Gateway and Cloudflare, mass assignment and excessive data exposure, webhook and callback security, machine-to-machine credentials, business logic abuse no scanner will find, API testing in CI and in production, and the third-party API you consume being your problem too.
What you get
- →BOLA, IDOR and function-level authorization testing
- →API discovery: shadow, zombie and undocumented endpoints
- →OAuth 2.0, OIDC, JWT validation and token lifetime design
- →Gateway, rate limit and abuse policy plus CI security testing
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Sibylla builds the answer. Includes a full worked example so you see exactly what you get.
Four steps. Any AI chat.
- 01Download the file
After checkout, the download link lands in your inbox. Save the file anywhere on your device.
- 02Open your AI chat
Claude, ChatGPT, Gemini, Grok, or Copilot - whichever one you already use.
- 03Paste the file contents
Drop it into the system prompt, Project instructions, or custom instructions field.
- 04Start working
Your AI is now configured as a specialist. Ask it anything inside its domain.
No technical knowledge required.
With Unlimited there is nothing to download. Connect your AI once, then just ask: "Load Sibylla from KissMySkills."
Questions about this product
What does the Sibylla skill do?+
Secure your APIs where they actually break: authorization per object, a real endpoint inventory, and gateway and CI controls that hold. Load it once into Claude Projects and you get a configured API Security Engineer without re-explaining context at the start of every session. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
How do I install this skill file?+
Download the .skill package (it contains SKILL.md), paste the contents into Claude Projects Instructions or your AI's system prompt, add your own context and start your first session. Works with Claude, ChatGPT, or any AI chat that accepts system prompts.
Which AI tools does this skill work with?+
Works with Claude (recommended), ChatGPT, Gemini, Perplexity and Copilot, and any AI chat that accepts system prompts. Claude Projects gives the best results.
What is included in this download?+
One .skill package delivered instantly after purchase: the full SKILL.md role configuration plus a worked-example file with a real scenario so you see the quality before you rely on it. Pay once, keep forever, yours permanently.
How is this different from using Claude without the Sibylla skill?+
Without a skill file your AI starts every session as a general assistant. With Sibylla loaded it applies API Security Engineer methodology from the first message, with consistent quality every time. This skill is for authorized, defensive security work only. Validate findings in your own environment, follow your rules of engagement and written authorization, and confirm current framework, vendor, and regulatory specifics before you act on them.
Do I have to read it myself?+
No. The file is written for your AI to read, not for you. Upload it or paste it in once and the AI takes on the role. After that you just ask it questions the way you normally would. You're welcome to open it and read it, but nothing here depends on you doing that.