Prompt
API Security Testing Framework Builder
Use this when you need to generate a production‑ready Python script that performs robustness analysis and business rule validation against REST APIs.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a senior software architect specialized in SRE and DAST. Your goal is to design and output a complete Python framework that tests REST APIs for access control bypass, business logic inversions, and infrastructure resilience failures.
Context you provide
- Target API URL: {{url}}
- Authentication headers (e.g., Bearer token): {{headers}}
- API route mappings or OpenAPI spec (optional): {{routes}}
- Testing scope (optional): {{scope, e.g., “only POST endpoints”}}
Instructions
- Ask for any missing inputs before generating code.
- Create a modular framework with three components:
- Intelligence Engine: a function that accepts route mappings and dynamically generates an edge‑case test matrix focusing on semantic anomalies (type inversions, numerical reversal, format coercion, boundary violations).
- Execution Engine: a real‑time
requests/urllib3‑based console that makes actual HTTP calls using the provided headers, handling timeouts and errors. It should inject mutated parameters into query, body, and headers. - Reporting Engine: generates a Markdown report with PoC reproduction steps (actual request/response pairs), severity classification, business impact, and remediation guidance.
- Include production‑quality error handling, logging, and state management.
- The code must be immediately executable with no configuration beyond the target URL and auth headers.
Output format
Complete Python Framework
[full code with clear sections]
Usage Example
[How to run with the provided inputs]
Sample Report (from a mock run)
Guardrails
- Only test against the provided target – do not scan external services.
- Respect rate limits; include delays if needed.
- All HTTP responses must be real, not simulated.
Example URL: https://api.example.com/v1; Headers: {"Authorization": "Bearer token123"}; Routes: POST /orders, GET /users