{"slug":"42crunch-api-security-testing--community","title":"42crunch-api-security-testing","description":"Automate API security directly in Claude Code with 42Crunch. This plugin enables developers to audit OpenAPI specifications, detect OWASP API vulnerabilities including BOLA and BFLA, run live conformance and authorization tests, and apply AI-assisted fixes, all through natural language.\nDesigned for AI-assisted development workflows, the plugin provides continuous security guardrails across the full lifecycle of your API. It combines static analysis of OpenAPI definitions with dynamic runtime testing to ensure your APIs behave securely in real conditions.\nWith a simple audit to scan to remediate to validate loop, developers can identify issues early, fix them with confidence, and verify that security requirements are met before deployment. The plugin integrates seamlessly into Claude Code, allowing teams to embed API security directly into their development process without switching tools.\nKey capabilities include static security audit of OpenAPI specifications with scored findings, detection of OWASP API Security risks including authorization flaws like BOLA and BFLA, live API scanning for conformance and runtime behavior validation, AI-assisted remediation with user-controlled changes, an end to end security testing pipeline combining audit and scan, and automatic generation of OpenAPI specifications from source code.\nWhether you are working with existing APIs or generating new ones, 42Crunch helps ensure that security is built in from the start and continuously validated throughout development.","developer":null,"category":null,"reported_installs":null,"active":true,"first_seen_at":"2026-10-03T22:13:33.942Z","last_seen_at":"2026-10-04T06:00:01.308Z","last_changed_at":"2026-10-03T22:13:33.942Z","platform":"claude","sources":["Community"],"works_with":["Claude Code"],"marketplace_url":null,"repository_url":"42Crunch-AI/claude-plugins","web_data":{},"github_data":{},"catalog_sources":{"community":[{"name":"42crunch-api-security-testing","source":{"ref":"v1.0.1","sha":"30287f5e3f122a646d1ac5ca3ab96e130c52a3ad","url":"42Crunch-AI/claude-plugins","path":"plugins/api-security-testing","source":"git-subdir"},"homepage":"https://docs.42crunch.com","description":"Automate API security directly in Claude Code with 42Crunch. This plugin enables developers to audit OpenAPI specifications, detect OWASP API vulnerabilities including BOLA and BFLA, run live conformance and authorization tests, and apply AI-assisted fixes, all through natural language.\nDesigned for AI-assisted development workflows, the plugin provides continuous security guardrails across the full lifecycle of your API. It combines static analysis of OpenAPI definitions with dynamic runtime testing to ensure your APIs behave securely in real conditions.\nWith a simple audit to scan to remediate to validate loop, developers can identify issues early, fix them with confidence, and verify that security requirements are met before deployment. The plugin integrates seamlessly into Claude Code, allowing teams to embed API security directly into their development process without switching tools.\nKey capabilities include static security audit of OpenAPI specifications with scored findings, detection of OWASP API Security risks including authorization flaws like BOLA and BFLA, live API scanning for conformance and runtime behavior validation, AI-assisted remediation with user-controlled changes, an end to end security testing pipeline combining audit and scan, and automatic generation of OpenAPI specifications from source code.\nWhether you are working with existing APIs or generating new ones, 42Crunch helps ensure that security is built in from the start and continuously validated throughout development."}]}}