Skip to main content
在 Manus 中运行任何 Skill
一键导入
$pwd:

hunt-graphql

// Hunting skill for graphql vulnerabilities. Built from 12 public bug bounty reports across IDOR via node() / GID, mutation IDOR including AI/LLM features, cross-tenant IDOR, SSRF via argument, batching-DoS, query-cost-bypass, SQLi via argument, broken-object-level-authz, auth-bypass via unscoped mutations, and PII exposure from missing field-level authz. Use when hunting graphql on any target.

$ git log --oneline --stat
stars:1,380
forks:195
updated:2026年5月25日 20:56
SKILL.md
readonly