# mcp-api-pentest

> mcp-api-pentest — josenieto-mcp-api-pentest. Use this tool when you need to automate security audits on APIs to detect vulnerabilities such as BOLA/IDOR. It takes API endpoints and user tokens as input and outputs vulnerability reports, enabling AI assistants to identify potential security risks. Ideal for use cases where API security testing is crucial, such as prior to deployment or during regular security assessments.

Canonical page: https://skillsregistry.net/skills/josenieto-mcp-api-pentest  
JSON: https://api.skillsregistry.net/v1/skills/josenieto-mcp-api-pentest

## Description

Enables AI assistants to perform automated security audits on APIs, detecting BOLA/IDOR vulnerabilities by comparing responses across user tokens.

## Trust

- **Trust score (0–1):** 0.60
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-08-29

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/h7iy6t0wsi)
- **Repository:** <https://github.com/josenieto/mcp-api-pentest>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "josenieto-mcp-api-pentest"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/josenieto-mcp-api-pentest` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/josenieto-mcp-api-pentest/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
