Can it review an OpenAPI specification?
Yes, when you supply the relevant OpenAPI excerpt or contract. A bounded endpoint group is easier to review and verify than an entire large specification.
Does it run or test the API?
No. The GPT reviews the interface material you provide and must not claim runtime, repository, infrastructure, or implementation access.
Is this a complete API security review?
No. It can flag visible interface misuse risks and unsafe defaults, but it is not a penetration test, threat model, or security certification.
What happens when important context is missing?
The review should mark the point as context-dependent or ask one focused question instead of inventing authentication, callers, data flows, or backend behavior.