Skip to main content

api-overview

Modern API category — gRPC, SOAP/WSDL, WebSocket, Server-Sent Events. Routing skill: identify the API protocol from the response Content-Type or wire format, then load the matching sub-skill.

来源信息

仓库
BitterSecurity/Decepticon
最近来源活动
2026年5月26日 09:25
检测到的 SKILL.md 语言
英语
星标
5,666
分支
1,067

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

文件资源管理器
5 个文件

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
api-overview
description
Modern API category — gRPC, SOAP/WSDL, WebSocket, Server-Sent Events. Routing skill: identify the API protocol from the response Content-Type or wire format, then load the matching sub-skill.
allowed-tools
Bash Read Write
metadata
{"when_to_use":"api protocol modern grpc soap wsdl websocket ws sse server-sent-events http2 streaming","subdomain":"api","tags":"api, modern-protocols","mitre_attack":"T1190"}
# Modern API Attack Category This is a routing skill. Identify the API protocol then load the matching sub-skill. ## Sub-skills | Protocol | Sub-skill | Wire signature | |---|---|---| | **gRPC** | `grpc` | HTTP/2 + `application/grpc[+proto|+json]`, port 50051/443 | | **SOAP/WSDL** | `soap-wsdl` | XML body in `text/xml`/`application/soap+xml`, `?wsdl` discovery | | **WebSocket** | `websocket` | HTTP `Upgrade: websocket` handshake, then framed binary/text | | **Server-Sent Events** | `server-sent-events` | `Content-Type: text/event-stream`, one-way streaming | ## Quick fingerprint ```bash # gRPC? curl -sk -I --http2 https://target/svc | grep -i 'application/grpc' # SOAP? curl -sk "https://target/endpoint?wsdl" | head -1 # XML WSDL doc curl -sk -X POST -H 'Content-Type: text/xml' https://target/endpoint # 500 with SOAP fault # WebSocket? curl -sk -I -H "Connection: Upgrade" -H "Upgrade: websocket" https://target/ws | head -1 # 101 = WS upgrade # SSE? curl -sk -i https://target/stream -H "Accept: text/event-stream" | grep 'text/event-stream' ``` ## Sibling skills For REST + GraphQL go to: - `load_skill("/skills/standard/exploit/web/SKILL.md")` — sub-skills `graphql`, `idor`, `mass-assignment`, etc.
在 GitHub 查看