Skip to main content
Ejecuta cualquier Skill en Manus
con un clic

sast-graphql

// Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input to those sites in parallel subagents, up to 3 candidate sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/graphql-results.md. If no GraphQL technology is found in Phase 1, later phases are skipped. Use when asked to find GraphQL injection, unsafe GraphQL document construction, or operation string injection bugs.

$ git log --oneline --stat
stars:648
forks:29
updated:31 de marzo de 2026, 15:54
SKILL.md
readonly