Show HN: Openapi.security, a fast security checker for REST-based API
Full LLM thinking from the 4-phase benchmark pipeline.
{
"service_type": "platform",
"base_url": "https://openapi.security",
"auth_method": "none",
"auth_config": {},
"endpoints": [],
"pricing_model": {"type": "unknown", "details": {}},
"rate_limits": {},
"capabilities": ["security scanning", "REST API analysis", "vulnerability detection", "OpenAPI schema validation", "automated report generation"],
"raw_analysis": "OpenAPI.security is a web-based tool presented as a 'fast security checker for REST-based APIs' on a Y Combinator Hacker News submission. It likely accepts an OpenAPI specification (YAML/JSON) as input and analyzes it for common security issues like improper authentication, insecure HTTP, missing rate limiting, or excessive data exposure. The platform is developer-oriented, targeting API designers, developers, and security engineers who need quick static analysis without full integration. As a tool that emerged from a Show HN, it may be in early prototype or beta stage, with a public website but no clear documentation or API. Its maturity is low to moderate, and it appears to operate as a SaaS with no public pricing. There is no evidence of a public REST API, official integrations, or rate limits. The project's novelty suggests a niche but growing interest in automating API security checks, aligning with industry trends toward security-as-code."
}0/3 tests passed
| Test | Endpoint | Status | Latency |
|---|---|---|---|
| website_uptime | GET / | None | 90ms |
| robots_txt | GET /robots.txt | None | 90ms |
| llms_txt | GET /llms.txt | None | 84ms |
```json
{
"overall": 5,
"dimensions": {
"token_efficiency": 1.0,
"first_try_success": 1.0,
"response_parseability": 2.0,
"error_clarity": 1.0,
"doc_quality": 1.0,
"auth_simplicity": 1.0,
"latency": 2.0,
"consistency": 1.0
},
"pricing_normalized": {},
"issues": [
"DNS resolution failure: Domain name not found, website appears non-existent or unreachable",
"All 3 checks (website uptime, robots.txt, llms.txt) failed with connection errors",
"No accessible landing page, documentation, or API endpoint could be reached",
"No pricing information available, suggesting no viable product surface",
"Security headers absent due to failed connection",
"Platform name not provided, making verification impossible"
],
"recommendations": [
"Verify the correct domain name or URL for this platform before scoring",
"If the product is in private beta, request access and enable a public-facing status page",
"Deploy the service to a reachable host and configure DNS records properly",
"Create and publish llms.txt and documentation to enable agent discoverability",
"Develop clear onboarding flow with API key or OAuth to enable quick integration"
]
}
```Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.
<a href="https://prowl.world/service/openapisecurity-a-fast-security-checker-for">
<img src="https://prowl.world/badge/openapisecurity-a-fast-security-checker-for.svg" height="56" alt="Agent-readiness on Prowl">
</a>
See operational metrics, LLM evaluations, agent readiness, and more.
Open in Dashboard