GRAPHQL Audit

GraphQL security hunting — introspection abuse, field suggestion enumeration (clairvoyance), batching DoS, IDOR via aliasing, auth bypass, injection via arguments, subscription abuse, depth/complexity bombs, and WAF bypass. Covers graphw00f fingerprinting, gqlmap, graphql-cop, and inql. Use when a target exposes a /graphql, /api/graphql, or GQL-over-HTTP endpoint.

shuvonsec Updated

File contents

shuvonsec/claude-bug-bounty commit 96d918505c

Frequently asked questions

npx skillmds@latest add shuvonsec/graphql-audit