api-recon-and-docs
API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.
来源信息
- 仓库
- Kur1sulab/blackbox
- 最近来源活动
- 2026年8月12日 15:17
- 检测到的 SKILL.md 语言
- 英语
- 星标
- 3
- 分支
- 1
安装方式
默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。
检查来源文件
决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。
正在显示 SKILL.md
SKILL.md
来源说明 · 只读预览- name
- api-recon-and-docs
- description
- API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.
# SKILL: API Recon and Docs — Endpoints, Schemas, and Version Surface
> **AI LOAD INSTRUCTION**: Use this skill first when the target is a REST, mobile, or GraphQL API and you need to enumerate endpoints, documentation, versions, and hidden surface area before exploitation.
## 1. PRIMARY GOALS
1. Discover all reachable API entrypoints.
2. Extract schemas, optional fields, and role differences.
3. Identify old versions, mobile paths, GraphQL endpoints, and undocumented parameters.
## 2. RECON CHECKLIST
### JavaScript and client mining
```bash
curl https://target/app.js | grep -oE '(/api|/rest|/graphql)[^"'\'' ]+' | sort -u
```
### Common documentation and schema paths
```text
/swagger.json
/openapi.json
/api-docs
/docs
/.well-known/
/graphql
/gql
```
### Version and product drift
```text
/api/v1/
/api/v2/
/api/mobile/v1/
/legacy/
```
## 3. WHAT TO EXTRACT FROM DOCS
- optional and undocumented fields
- admin-only request examples
- deprecated endpoints that may still be active
- schema hints like `additionalProperties: true`
- parameter names tied to filtering, sorting, IDs, roles, or tenancy
## 4. NEXT ROUTING
| Finding | Next Skill |
|---|---|
| object IDs everywhere | [api authorization and bola](../hack-api-authorization-and-bola/SKILL.md) |
| JWT, OAuth, role claims | [api auth and jwt abuse](../hack-api-auth-and-jwt-abuse/SKILL.md) |
| GraphQL or hidden fields | [graphql and hidden parameters](../hack-graphql-and-hidden-parameters/SKILL.md) |
| strong auth boundary but suspicious business flow | [business logic vulnerabilities](../hack-business-logic-vulnerabilities/SKILL.md) |
在 GitHub 查看