All skills
hardw00t avatar

/api-security

@f9bb3b2

Router skill for API penetration testing across REST, GraphQL, gRPC, and WebSocket. Covers OWASP API Top 10 (2023) including BOLA/BFLA/BOPLA, JWT attack chains, GraphQL introspection abuse, and mass assignment. Invoke when the user asks to pentest an API, analyze OpenAPI/Swagger, test auth/authorization, fuzz endpoints, or find API vulnerabilities.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/api-security

This session only. Nothing lands on disk.

workflowsgraphql_introspection_triage.md

≈712 tokens on demand. Your agent reads this file only when SKILL.md points to it.

GraphQL Introspection Triage

Decide how to obtain the schema and whether introspection exposure is itself a finding.

          POST /graphql  { __schema { types { name } } }
                           |
           +---------------+----------------+
           |                                |
      200 with data                   Error / 400 / 403
           |                                |
   [INTROSPECTION ON]                [INTROSPECTION OFF ?]
           |                                |
           |                      Try alternate transports:
           |                        - GET  /graphql?query=...
           |                        - Content-Type: application/graphql
           |                        - Content-Type: text/plain
           |                        - Batched JSON array
           |                        - Persisted-query bypass
           |                                |
           |                      +---------+---------+
           |                      |                   |
           |                 Any returns schema    Still blocked
           |                      |                   |
           |              [PARTIAL INTROSPECTION]  [Field-name
           |                      |                 brute force /
           |                      |                 client scraping]
           v                      v                   v
  Dump full schema        Dump what you can      Use graphql-cop,
  (graphql-cop,           via working transport  clairvoyance,
  clairvoyance, or the    and mark as finding    schema-inference
  __schema query in       (introspection gated   against error
  payloads/graphql_       by transport = weak    messages
  queries.txt)            control)
           |                      |                   |
           +----------+-----------+-------------------+
                      |
                      v
         Proceed to workflows/graphql_testing.md
         Phase 2 (schema-driven mapping)

Scoring

  • Production introspection ON by default: API8:2023 Security Misconfiguration (medium-high) + API9:2023 Improper Inventory Management (medium).
  • Introspection OFF but leaking via alternate transport: same rating; the gating is just transport filtering, not a real control.
  • Introspection OFF and uniformly blocked: not a finding; note the defense and move on.

When introspection is fully blocked

Tools to reconstruct schema:

  • clairvoyance — uses field-name suggestions from error responses.
  • Static analysis of client bundles (JS, mobile APK) — GraphQL queries are usually hardcoded or in generated files.
  • graphql-cop and inql for partial fingerprinting.

Do NOT waste reasoning budget on blocked-introspection targets; mine the client first — it's cheaper and often complete.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The analyzed skill contains standard penetration testing guides, methodology documents, and common vulnerability checklists for API security auditing. No malicious behavior, prompt injection, or hidden execution channels were detected.

  • Socket16d

    3 alerts: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/api-security