Performing GRAPHQL Introspection Attack

Use when performs GraphQL introspection attacks to extract the full API schema including types, queries, mutations, subscriptions, and field definitions from GraphQL endpoints. The tester uses introspection queries to map the attack surface, identifies sensitive fields and mutations, tests for query depth and complexity limits, and exploits GraphQL-specific vulnerabilities including batching attacks, alias-based brute force, and nested query DoS.

oyi77 18eab44 4.4 KB Updated 10 repo stars

File contents

oyi77/1ai-skills/tree/main/cybersecurity/performing-graphql-introspection-attack commit 18eab444b3

Frequently asked questions

npx skillmds add oyi77/performing-graphql-introspection-attack