Skip to main content

api-overview

Modern API category — gRPC, SOAP/WSDL, WebSocket, Server-Sent Events. Routing skill: identify the API protocol from the response Content-Type or wire format, then load the matching sub-skill.

소스 정보

저장소
BitterSecurity/Decepticon
최근 소스 활동
2026년 5월 26일 09:25
감지된 SKILL.md 언어
영어
스타
5,611
포크
1,061

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
5 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
api-overview
description
Modern API category — gRPC, SOAP/WSDL, WebSocket, Server-Sent Events. Routing skill: identify the API protocol from the response Content-Type or wire format, then load the matching sub-skill.
allowed-tools
Bash Read Write
metadata
{"when_to_use":"api protocol modern grpc soap wsdl websocket ws sse server-sent-events http2 streaming","subdomain":"api","tags":"api, modern-protocols","mitre_attack":"T1190"}
# Modern API Attack Category This is a routing skill. Identify the API protocol then load the matching sub-skill. ## Sub-skills | Protocol | Sub-skill | Wire signature | |---|---|---| | **gRPC** | `grpc` | HTTP/2 + `application/grpc[+proto|+json]`, port 50051/443 | | **SOAP/WSDL** | `soap-wsdl` | XML body in `text/xml`/`application/soap+xml`, `?wsdl` discovery | | **WebSocket** | `websocket` | HTTP `Upgrade: websocket` handshake, then framed binary/text | | **Server-Sent Events** | `server-sent-events` | `Content-Type: text/event-stream`, one-way streaming | ## Quick fingerprint ```bash # gRPC? curl -sk -I --http2 https://target/svc | grep -i 'application/grpc' # SOAP? curl -sk "https://target/endpoint?wsdl" | head -1 # XML WSDL doc curl -sk -X POST -H 'Content-Type: text/xml' https://target/endpoint # 500 with SOAP fault # WebSocket? curl -sk -I -H "Connection: Upgrade" -H "Upgrade: websocket" https://target/ws | head -1 # 101 = WS upgrade # SSE? curl -sk -i https://target/stream -H "Accept: text/event-stream" | grep 'text/event-stream' ``` ## Sibling skills For REST + GraphQL go to: - `load_skill("/skills/standard/exploit/web/SKILL.md")` — sub-skills `graphql`, `idor`, `mass-assignment`, etc.
GitHub에서 보기