← Claude plugins
CLAUDE PLUGIN

42crunch-api-security-testing

Publisher not specified · Claude Code

What this plugin does

Automate API security directly in Claude Code with 42Crunch. This plugin enables developers to audit OpenAPI specifications, detect OWASP API vulnerabilities including BOLA and BFLA, run live conformance and authorization tests, and apply AI-assisted fixes, all through natural language.
Designed for AI-assisted development workflows, the plugin provides continuous security guardrails across the full lifecycle of your API. It combines static analysis of OpenAPI definitions with dynamic runtime testing to ensure your APIs behave securely in real conditions.
With a simple audit to scan to remediate to validate loop, developers can identify issues early, fix them with confidence, and verify that security requirements are met before deployment. The plugin integrates seamlessly into Claude Code, allowing teams to embed API security directly into their development process without switching tools.
Key capabilities include static security audit of OpenAPI specifications with scored findings, detection of OWASP API Security risks including authorization flaws like BOLA and BFLA, live API scanning for conformance and runtime behavior validation, AI-assisted remediation with user-controlled changes, an end to end security testing pipeline combining audit and scan, and automatic generation of OpenAPI specifications from source code.
Whether you are working with existing APIs or generating new ones, 42Crunch helps ensure that security is built in from the start and continuously validated throughout development.

Catalog observations

Sources
Community
Works with
Claude Code
Reported installs
Not provided
First observed
2026-10-03 22:13 UTC
Last observed
2026-10-04 06:00 UTC

Installation counts are reported by Claude Marketplace, not independently verified active users. Observation dates are not release dates. Pricing and account requirements must be checked with the publisher.

Install in Claude Code

Choose a source and review what the plugin adds before installing.

Community

/plugin marketplace add anthropics/claude-plugins-community
/plugin install 42crunch-api-security-testing@claude-community

Claude Code installation documentation

Source evidence

Listing and manifest JSON

Descriptions and compatibility labels come from the linked sources. Where both sources match, the GitHub description is used because web summaries may be shortened. We have not independently tested the declared capabilities.