Skip to main content
Run any Skill in Manus
with one click

hunt-graphql

// Hunting skill for graphql vulnerabilities. Built from 12 public bug bounty reports across IDOR via node() / GID, mutation IDOR including AI/LLM features, cross-tenant IDOR, SSRF via argument, batching-DoS, query-cost-bypass, SQLi via argument, broken-object-level-authz, auth-bypass via unscoped mutations, and PII exposure from missing field-level authz. Use when hunting graphql on any target.

$ git log --oneline --stat
stars:1,380
forks:195
updated:May 25, 2026 at 20:56
SKILL.md
readonly