Skip to main content
Run any Skill in Manus
with one click

graphql-hunter

Stars15
Forks7
UpdatedJune 28, 2026 at 16:46

Tests GraphQL endpoints for enabled production introspection, BOLA via guessable relay/global IDs, deeply-nested DoS, query batching bypass, injection in query arguments (SQLi / command injection through GraphQL resolvers), custom-scalar validation gaps, and field-level authorization flaws. Use when the target exposes /graphql, /graphiql, /playground, /v1/graphql, /query endpoints; or when response bodies have top-level `data` or `errors` keys; or when the orchestrator's recon confirmed GraphQL use. Produces findings with CWE-200 / CWE-639 / CWE-400 / CWE-89 mapping, introspection-driven schema evidence, and per-vector remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly