Skip to main content
Execute qualquer Skill no Manus
com um clique

graphql-hunter

Estrelas15
Forks7
Atualizado28 de junho de 2026 às 16:46

Tests GraphQL endpoints for enabled production introspection, BOLA via guessable relay/global IDs, deeply-nested DoS, query batching bypass, injection in query arguments (SQLi / command injection through GraphQL resolvers), custom-scalar validation gaps, and field-level authorization flaws. Use when the target exposes /graphql, /graphiql, /playground, /v1/graphql, /query endpoints; or when response bodies have top-level `data` or `errors` keys; or when the orchestrator's recon confirmed GraphQL use. Produces findings with CWE-200 / CWE-639 / CWE-400 / CWE-89 mapping, introspection-driven schema evidence, and per-vector remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

Instalação

Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.

SKILL.md
readonly