What problem does it solve?
This Skill fills the gap left by standard web application scanners, which often miss high-value GraphQL-specific vulnerabilities including IDOR, SSRF, race conditions, and authorization bypasses that can lead to critical data breaches or top-tier bug bounty payouts.
Core Features & Use Cases
- Comprehensive Vulnerability Coverage: Hunts 12+ distinct GraphQL flaw classes including IDOR via global node IDs, mutation auth bypasses, SSRF via query arguments, batch DoS, query cost bypass, PII exposure from missing field-level authz, and cross-tenant data access flaws.
- Proven Step-by-Step Methodology: Provides a full hunting workflow from endpoint discovery and schema mapping to REST/GraphQL overlap analysis and cross-API state desync testing, with clear validation gates to ensure findings are reportable and reproducible.
- Verified Real-World Examples: Includes 12 public bug bounty reports with payouts up to $20,000 from platforms including GitHub, Shopify, Stripe, and GitLab, each with working proof-of-concept details and root cause analysis.
- Defense Bypass Techniques: Includes proven workarounds for common security controls including disabled introspection, depth limiting, rate limiting, WAF blocks, and persisted query whitelisting.
Quick Start
Use the hunt-graphql skill to test a target's GraphQL endpoint for IDOR, auth bypass, and SSRF vulnerabilities, and develop a valid proof-of-concept for any high-severity findings you identify.