Install in seconds
Install this skill
Copy the command and run it in your terminal. You can review the source before installing.
terminal
git clone https://github.com/xalgord/xalgorix

Works with Git. The repository opens in your current directory.

🛡️
QualityGo

API Security Testing with 42Crunch

by xalgord

Perform static and dynamic API security testing using 42Crunch. Integrates into CI/CD pipelines to detect OWASP API Security Top 10 vulnerabilities before deployment.

807 stars144 forksAdded 2026/07/20
ai-agentai-securityautomationautonomous-pentestingbug-bountycybersecurityethical-hackinggolangpenetration-testingpentestpentesting-toolsreconsecuritysecurity-researchsecurity-toolstypescriptvulnerability-detectionvulnerability-scanner

Documentation

README

Implementing API Security Testing with 42Crunch

Overview

42Crunch is an API security platform that combines Shift-Left security testing with Shield-Right runtime protection. It provides API Audit for static security analysis of OpenAPI definitions, API Conformance Scan for dynamic vulnerability detection, and API Protect for real-time threat prevention. The platform integrates into CI/CD pipelines and IDEs to identify OWASP API Security Top 10 vulnerabilities before and after deployment.

When to Use

  • When deploying or configuring implementing api security testing with 42crunch capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Common Misconfigurations & Verification

  • Audit score without a dynamic scan: a high static audit score on the OAS says nothing about the running API - always pair Audit with a Conformance Scan against a live target.
  • Spec does not equal implementation: the deployed API may expose endpoints/fields absent from the audited spec; scan the real instance and reconcile.
  • additionalProperties/readOnly gaps: Audit flags these but they must be enforced at runtime (API Protect or backend), not just documented.
  • CI gate that doesn't fail the build: a min-score set too low or an ignored exit code lets regressions merge.
  • Auth misconfigured for the scan: a scan running unauthenticated reports a false "clean" - supply valid tokens in 42c-conf.yaml.

How to verify it works: run Audit and confirm it flags missing auth/constraints; run the Conformance Scan against staging with valid auth and confirm OWASP checks (BOLA/BFLA/injection) execute; intentionally break the spec (remove a constraint) and confirm the CI min-score gate fails the build; diff scanned endpoints against the OAS to catch undocumented routes.

Prerequisites

  • 42Crunch platform account (free tier available for evaluation)
  • OpenAPI Specification (OAS) v2.0, v3.0, or v3.1 definitions for target APIs
  • IDE with 42Crunch extension (VS Code, IntelliJ, or Eclipse)
  • CI/CD pipeline (Jenkins, GitHub Actions, Azure DevOps, or GitLab CI)
  • Running API instance for dynamic scanning (conformance scan)
  • Node.js or Python environment for CLI tooling

Core Concepts

API Audit (Static Analysis)

API Audit performs static security analysis of OpenAPI definitions without requiring a running API. It evaluates the specification against 300+ security checks organized into categories:

Security Score Categories:

  • Data Validation: Schema definitions, parameter constraints, response validation
  • Authentication: Security scheme definitions, scope requirements
  • Transport Security: Server URL schemes, TLS requirements
  • Error Handling: Error response definitions, information leakage prevention

Running API Audit via VS Code Extension:

  1. Install the 42Crunch extension from the VS Code marketplace
  2. Open an OpenAPI specification file (YAML or JSON)
  3. Click the security audit icon in the editor toolbar
  4. Review the security score (0-100) and individual findings
  5. Address issues using the inline remediation guidance

Example OpenAPI Definition with Security Controls:

openapi: 3.0.3
info:
  title: Secure User API
  version: 1.0.0
servers:
  - url: https://api.example.com/v1
    description: Production server (HTTPS only)
security:
  - BearerAuth: []
paths:
  /users/{userId}:
    get:
      operationId: getUserById
      summary: Retrieve user by ID
      parameters:
        - name: userId
          in: path
          required: true
          schema:
            type: string
            format: uuid
            pattern: '^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$'
            maxLength: 36
      responses:
        '200':
          description: User details
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/User'
        '400':
          description: Invalid request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Unauthorized
        '404':
          description: User not found
components:
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
  schemas:
    User:
      type: object
      required:
        - id
        - email
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
        email:
          type: string
          format: email
          maxLength: 254
        name:
          type: string
          maxLength: 100
          pattern: '^[a-zA-Z\s\-]+$'
      additionalProperties: false
    Error:
      type: object
      required:
        - code
        - message
      properties:
        code:
          type: integer
          format: int32
        message:
          type: string
          maxLength: 256
      additionalProperties: false

API Conformance Scan (Dynamic Testing)

The conformance scan dynamically tests a running API against its OpenAPI contract to detect runtime vulnerabilities including OWASP API Security Top 10 issues:

Scan v2 Configuration:

# 42c-conf.yaml
version: "2.0"
scan:
  target:
    url: https://api.example.com/v1
  authentication:
    - type: bearer
      token: "${API_TOKEN}"
      in: header
      name: Authorization
  settings:
    maxScanTime: 3600
    requestsPerSecond: 10
    followRedirects: false
  tests:
    owasp:
      - bola
      - bfla
      - injection
      - ssrf
      - massAssignment
      - excessiveDataExposure

Running Conformance Scan via CLI:

# Install the 42Crunch CLI
npm install -g @42crunch/cicd-cli

# Run conformance scan
42crunch-cli scan \
  --api-definition ./openapi.yaml \
  --target-url https://api.example.com/v1 \
  --token $CRUNCH_TOKEN \
  --min-score 70 \
  --report-format sarif \
  --output scan-report.sarif

CI/CD Pipeline Integration

GitHub Actions Integration:

name: API Security Testing
on:
  push:
    paths:
      - 'api/**'
      - 'openapi/**'
jobs:
  api-security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: 42Crunch API Audit
        uses: 42Crunch/api-security-audit-action@v3
        with:
          api-token: ${{ secrets.CRUNCH_API_TOKEN }}
          collection-name: "my-api-collection"
          min-score: 75
          upload-to-code-scanning: true

      - name: 42Crunch Conformance Scan
        if: github.ref == 'refs/heads/main'
        uses: 42Crunch/api-conformance-scan@v1
        with:
          api-token: ${{ secrets.CRUNCH_API_TOKEN }}
          target-url: ${{ secrets.STAGING_API_URL }}
          scan-config: ./42c-conf.yaml

Jenkins Pipeline Integration:

pipeline {
    agent any
    stages {
        stage('API Security Audit') {
            steps {
                script {
                    def auditResult = sh(
                        script: '''
                            42crunch-cli audit \
                              --api-definition openapi.yaml \
                              --token ${CRUNCH_TOKEN} \
                              --min-score 75 \
                              --report-format json \
                              --output audit-report.json
                        ''',
                        returnStatus: true
                    )
                    if (auditResult != 0) {
                        error("API Security Audit failed - score below threshold")
                    }
                }
            }
        }
        stage('Conformance Scan') {
            when { branch 'main' }
            steps {
                sh '''
                    42crunch-cli scan \
                      --api-definition openapi.yaml \
                      --target-url ${STAGING_URL} \
                      --token ${CRUNCH_TOKEN} \
                      --scan-config 42c-conf.yaml
                '''
            }
        }
    }
    post {
        always {
            archiveArtifacts artifacts: '*-report.*'
            publishHTML([
                reportDir: '.',
                reportFiles: 'audit-report.html',
                reportName: 'API Security Report'
            ])
        }
    }
}

API Protect (Runtime Protection)

API Protect deploys as a micro-gateway in front of API endpoints to enforce the OpenAPI contract at runtime:

# api-protect-config.yaml
apiVersion: v1
kind: ConfigMap
metadata:
  name: api-protect-config
data:
  protection-config.json: |
    {
      "apiDefinition": "/config/openapi.yaml",
      "enforcement": {
        "validateRequests": true,
        "validateResponses": true,
        "blockOnFailure": true,
        "logLevel": "warn"
      },
      "rateLimit": {
        "enabled": true,
        "requestsPerMinute": 100,
        "burstSize": 20
      },
      "allowlist": {
        "contentTypes": ["application/json"],
        "methods": ["GET", "POST", "PUT", "DELETE"]
      }
    }

Remediation Workflow

When 42Crunch identifies issues, follow this remediation process:

  1. Triage: Review findings sorted by severity (Critical, High, Medium, Low)
  2. Analyze: Understand the specific security control missing from the OpenAPI definition
  3. Fix: Apply the recommended changes to the specification
  4. Validate: Re-run audit to confirm the score improvement
  5. Deploy: Push the updated specification through the CI/CD pipeline

Common Audit Findings and Fixes:

Finding Severity Fix
No authentication defined Critical Add securitySchemes and security requirements
Missing input validation High Add type, format, pattern, maxLength constraints
Server URL uses HTTP High Change server URLs to HTTPS
No error responses defined Medium Add 4xx and 5xx response definitions
additionalProperties not restricted Medium Set additionalProperties: false on object schemas
Missing rate limiting Medium Add x-rateLimit extension or use API Protect

Key Security Checks

42Crunch evaluates APIs against these critical security areas:

  • BOLA Prevention: Validates that object-level authorization patterns are defined
  • BFLA Prevention: Checks for function-level access control definitions
  • Injection Prevention: Ensures input parameters have proper type/format/pattern constraints
  • Data Exposure: Verifies response schemas limit returned properties
  • Security Misconfiguration: Checks authentication schemes, transport security, CORS settings
  • Mass Assignment: Validates that request bodies use explicit property allowlists

References

More from xalgord

Other Claude Code skills by this author in the directory.

🛡️
1w ago

Prompt Injection Detection

Detect prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex, heuristic analysis, and a DeBERTa classifier. Ideal for pre-filtering user inputs in chatbots, AI agents, or RAG pipelines.
AI Engineering
+0%807144
🛡️
1w ago

Exploiting AI Model File RCE

Testing machine-learning model files and model-loading services for remote code execution caused by insecure deserialization. Ideal for authorized pentesting of ML training pipelines, model registries, and inference services.
AI Engineering
+0%807144
🛡️
1w ago

LLM Guardrails

Implements input and output validation guardrails for LLM-powered applications to prevent prompt injection, enforce content policies, and redact PII. Ideal for securing AI agents, chatbots, and RAG pipelines.
AI Engineering
+0%807144
🔍
1w ago

AI-Assisted Vulnerability Discovery

Accelerate vulnerability discovery with LLMs: generate syntax-valid fuzzing seeds, evolve coverage-guided grammars, and scale proof-of-vulnerability generation. Integrates with Burp MCP for evidence-driven web analysis.
AI Engineering
+0%807144
🛡️
1w ago

Testing LLM Prompt Injection and Jailbreaks

A structured methodology for testing LLM-backed applications, chatbots, and AI agents for prompt injection, jailbreaks, and indirect injections. Covers direct attacks, system prompt leaks, encoding bypasses, and agent tool abuse.
AI Engineering
+0%807144
🛡️
1w ago

Testing MCP Server Security

Test MCP servers and AI clients for tool poisoning, prompt injection, supply-chain attacks, and credential theft. Used during security assessments of AI agents like Claude Code or Cursor.
AI Engineering
+0%807144