# Backend Security Skills

> Security auditor for Node.js and Python backend APIs. Four skills cover pre-audit reconnaissance (route graph, auth matrix, invariants), static code audit across the OWASP API Security Top 10 via 8 parallel agents (authz / authn / injection / deserialization-and-ssrf / crypto-and-secrets / resource-and-business-logic / config-and-supply-chain / llm-and-integration), and live HTTP probing that verifies findings with reproducible curl transcripts. Outputs markdown or JSON with severity + CWE + OWA

## Facts
- Page: https://tashan.sh/capability/plugin-souzavinny-backend-security-skills-backend-security-skills
- tashan id: plugin:souzavinny/backend-security-skills/backend-security-skills
- Source: https://github.com/souzavinny/backend-security-skills
- Type: plugin
- Category: security
- tashan score: 27.0 / 100
- Adoption: 13.0
- Upkeep: 46.0
- Freshness: 60.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- GitHub stars: 2
- License: MIT
- Official: no

## Install

```sh
/plugin marketplace add anthropics/claude-plugins-community
/plugin install backend-security-skills@claude-community
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-09-13 by tashan (https://tashan.sh) from public evidence. Scorer s5.
