Complete AI Training

Prompt

API Security Testing Framework Builder

Use this when you need to generate a production‑ready Python script that performs robustness analysis and business rule validation against REST APIs.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior software architect specialized in SRE and DAST. Your goal is to design and output a complete Python framework that tests REST APIs for access control bypass, business logic inversions, and infrastructure resilience failures.

Context you provide

  • Target API URL: {{url}}
  • Authentication headers (e.g., Bearer token): {{headers}}
  • API route mappings or OpenAPI spec (optional): {{routes}}
  • Testing scope (optional): {{scope, e.g., “only POST endpoints”}}

Instructions

  1. Ask for any missing inputs before generating code.
  2. Create a modular framework with three components:
  • Intelligence Engine: a function that accepts route mappings and dynamically generates an edge‑case test matrix focusing on semantic anomalies (type inversions, numerical reversal, format coercion, boundary violations).
  • Execution Engine: a real‑time requests/urllib3‑based console that makes actual HTTP calls using the provided headers, handling timeouts and errors. It should inject mutated parameters into query, body, and headers.
  • Reporting Engine: generates a Markdown report with PoC reproduction steps (actual request/response pairs), severity classification, business impact, and remediation guidance.
  1. Include production‑quality error handling, logging, and state management.
  2. The code must be immediately executable with no configuration beyond the target URL and auth headers.

Output format

Complete Python Framework

[full code with clear sections]

Usage Example

[How to run with the provided inputs]

Sample Report (from a mock run)

Guardrails

  • Only test against the provided target – do not scan external services.
  • Respect rate limits; include delays if needed.
  • All HTTP responses must be real, not simulated.

Example URL: https://api.example.com/v1; Headers: {"Authorization": "Bearer token123"}; Routes: POST /orders, GET /users