Skip to main content

api-overview

Modern API category — gRPC, SOAP/WSDL, WebSocket, Server-Sent Events. Routing skill: identify the API protocol from the response Content-Type or wire format, then load the matching sub-skill.

Informations de source

Dépôt
BitterSecurity/Decepticon
Dernière activité de la source
26 mai 2026 à 09:25
Langue détectée de SKILL.md
anglais
Étoiles
5 666
Forks
1 067

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.

Explorateur de fichiers
5 fichiers

Affichage de SKILL.md

SKILL.md
Instructions source · Aperçu en lecture seule
name
api-overview
description
Modern API category — gRPC, SOAP/WSDL, WebSocket, Server-Sent Events. Routing skill: identify the API protocol from the response Content-Type or wire format, then load the matching sub-skill.
allowed-tools
Bash Read Write
metadata
{"when_to_use":"api protocol modern grpc soap wsdl websocket ws sse server-sent-events http2 streaming","subdomain":"api","tags":"api, modern-protocols","mitre_attack":"T1190"}
# Modern API Attack Category This is a routing skill. Identify the API protocol then load the matching sub-skill. ## Sub-skills | Protocol | Sub-skill | Wire signature | |---|---|---| | **gRPC** | `grpc` | HTTP/2 + `application/grpc[+proto|+json]`, port 50051/443 | | **SOAP/WSDL** | `soap-wsdl` | XML body in `text/xml`/`application/soap+xml`, `?wsdl` discovery | | **WebSocket** | `websocket` | HTTP `Upgrade: websocket` handshake, then framed binary/text | | **Server-Sent Events** | `server-sent-events` | `Content-Type: text/event-stream`, one-way streaming | ## Quick fingerprint ```bash # gRPC? curl -sk -I --http2 https://target/svc | grep -i 'application/grpc' # SOAP? curl -sk "https://target/endpoint?wsdl" | head -1 # XML WSDL doc curl -sk -X POST -H 'Content-Type: text/xml' https://target/endpoint # 500 with SOAP fault # WebSocket? curl -sk -I -H "Connection: Upgrade" -H "Upgrade: websocket" https://target/ws | head -1 # 101 = WS upgrade # SSE? curl -sk -i https://target/stream -H "Accept: text/event-stream" | grep 'text/event-stream' ``` ## Sibling skills For REST + GraphQL go to: - `load_skill("/skills/standard/exploit/web/SKILL.md")` — sub-skills `graphql`, `idor`, `mass-assignment`, etc.
Voir sur GitHub