{"product_id":"sibylla-api-security-engineer","title":"Sibylla - API Security Engineer AI Skill","description":"\u003cdiv style=\"font-family: 'DM Sans', sans-serif; color: #1A1A18; max-width: 680px;\"\u003e\n  \u003cp style=\"font-size: 16px; font-weight: 600; line-height: 1.5; margin: 0 0 8px 0;\"\u003eDrop Sibylla into Claude and get an API security engineer who goes straight for broken object level authorization, because that is what is actually getting exploited.\u003c\/p\u003e\n  \u003cp style=\"font-size: 13px; color: #555550; line-height: 1.7; margin: 0 0 28px 0;\"\u003eSibylla secures APIs as their own attack surface: the OWASP API Security Top 10 with BOLA and broken function-level authorization treated as the dominant real-world findings, API discovery and inventory including shadow, zombie and undocumented endpoints, schema and contract validation across OpenAPI, GraphQL and gRPC, authentication and authorization done properly with OAuth 2.0 grant selection, OIDC, JWT validation failures, scopes versus entitlements, token lifetime and revocation and mTLS for service-to-service, rate limiting and abuse prevention, gateway and WAAP policy on Kong, Apigee, AWS API Gateway and Cloudflare, mass assignment and excessive data exposure, webhook and callback security, machine-to-machine credentials, business logic abuse no scanner will find, API testing in CI and in production, and the third-party API you consume being your problem too.\u003c\/p\u003e\n  \u003cdiv style=\"background: #fbeff3; border-radius: 12px; padding: 24px 28px; margin-bottom: 24px;\"\u003e\n    \u003cp style=\"font-size: 10px; font-weight: 600; color: #d3225d; letter-spacing: 0.08em; text-transform: uppercase; margin: 0 0 16px 0;\"\u003eWhat you get\u003c\/p\u003e\n    \u003cul style=\"margin: 0; padding: 0; list-style: none;\"\u003e\n\u003cli style=\"font-size: 13px; padding: 7px 0; border-bottom: 1px solid rgba(211,34,93,0.14); display: flex; gap: 10px;\"\u003e\n\u003cspan style=\"color:#d3225d; font-weight:600;\"\u003e→\u003c\/span\u003e\u003cspan\u003eBOLA, IDOR and function-level authorization testing\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli style=\"font-size: 13px; padding: 7px 0; border-bottom: 1px solid rgba(211,34,93,0.14); display: flex; gap: 10px;\"\u003e\n\u003cspan style=\"color:#d3225d; font-weight:600;\"\u003e→\u003c\/span\u003e\u003cspan\u003eAPI discovery: shadow, zombie and undocumented endpoints\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli style=\"font-size: 13px; padding: 7px 0; border-bottom: 1px solid rgba(211,34,93,0.14); display: flex; gap: 10px;\"\u003e\n\u003cspan style=\"color:#d3225d; font-weight:600;\"\u003e→\u003c\/span\u003e\u003cspan\u003eOAuth 2.0, OIDC, JWT validation and token lifetime design\u003c\/span\u003e\n\u003c\/li\u003e\n\u003cli style=\"font-size: 13px; padding: 7px 0;  display: flex; gap: 10px;\"\u003e\n\u003cspan style=\"color:#d3225d; font-weight:600;\"\u003e→\u003c\/span\u003e\u003cspan\u003eGateway, rate limit and abuse policy plus CI security testing\u003c\/span\u003e\n\u003c\/li\u003e\n    \u003c\/ul\u003e\n  \u003c\/div\u003e\n  \u003cdiv style=\"display:flex; align-items:center; gap:20px; background:#FFFFFF; border:1px solid #E8E6E0; border-radius:8px; padding:14px 20px; margin-bottom:24px;\"\u003e\n    \u003cspan style=\"font-size:11px; color:#888780; font-family:monospace;\"\u003e📄 sibylla-api-security-engineer.skill\u003c\/span\u003e\n    \u003cspan style=\"font-size:11px; color:#888780;\"\u003eUnder 2 min install\u003c\/span\u003e\n    \u003cspan style=\"font-size:11px; color:#888780;\"\u003eWorks with Claude, ChatGPT \u0026amp; any AI chat\u003c\/span\u003e\n  \u003c\/div\u003e\n  \u003cdiv style=\"border-left:3px solid #d3225d; padding-left:16px;\"\u003e\n    \u003cp style=\"font-size:10px; font-weight:600; color:#d3225d; letter-spacing:0.08em; text-transform:uppercase; margin:0 0 6px 0;\"\u003eHow to install\u003c\/p\u003e\n    \u003cp style=\"font-size:12px; color:#555550; line-height:1.7; margin:0;\"\u003eDownload the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Sibylla builds the answer. Includes a full worked example so you see exactly what you get.\u003c\/p\u003e\n  \u003c\/div\u003e\n\u003c\/div\u003e","brand":"KissMySkills","offers":[{"title":"Default Title","offer_id":58390415147272,"sku":null,"price":29.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1036\/1444\/7880\/files\/sibylla-api-security-book.jpg?v=1787067109","url":"https:\/\/kissmyskills.com\/products\/sibylla-api-security-engineer","provider":"KissMySkills","version":"1.0","type":"link"}