# 42crunch API Security Testing

> Automate API security directly in Claude Code with 42Crunch. This plugin enables developers to audit OpenAPI specifications, detect OWASP API vulnerabilities including BOLA and BFLA, run live conformance and authorization tests, and apply AI-assisted fixes, all through natural language. Designed for AI-assisted development workflows, the plugin provides continuous security guardrails across the full lifecycle of your API. It combines static analysis of OpenAPI definitions with dynamic runtime te

## Facts
- Page: https://tashan.sh/capability/plugin-42crunch-ai-claude-plugins-42crunch-api-security-testing
- tashan id: plugin:42crunch-ai/claude-plugins/42crunch-api-security-testing
- Source: https://github.com/42Crunch-AI/claude-plugins
- Type: plugin
- Category: security
- tashan score: 47.0 / 100
- Adoption: 18.0
- Upkeep: 90.0
- Freshness: 79.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- GitHub stars: 1
- Official: no

## Install

```sh
/plugin marketplace add anthropics/claude-plugins-community
/plugin install 42crunch-api-security-testing@claude-community
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-09-13 by tashan (https://tashan.sh) from public evidence. Scorer s5.
