Search

Security · GraphQL · For developers

12 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input…

utkusen/sast-skills1.3k—~4.7kAutomated safety check: PassMIT6 mo ago
2

Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.

Gabson0x/bountyforge442—~11kAutomated safety check: WarnNo licence24 days ago
3

Comprehensive API security review against OWASP API Security Top 10 (2023).

OWASP/secure-agent-playbook188—~744Automated safety check: PassCC-BY-4.016 days ago
4

IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

Encod3d-Sec/TORCH329—~2.6kAutomated safety check: PassMIT1 mo ago
5

Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling…

awarexone/Agentic-Bug-Hunter5.3k—~20kAutomated safety check: WarnMIT2 days ago
6

Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

telagod/code-abyss244—~777Automated safety check: PassMIT2 mo ago
7

DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…

modu-ai/moai-adk1.2k—~2.6kAutomated safety check: PassApache-2.0yesterday
8

Hunting skill for sqli vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

elementalsouls/Claude-BugHunter4.8k—~5.5kAutomated safety check: PassMITyesterday
9

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago
10

GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE.

Encod3d-Sec/TORCH329—~2kAutomated safety check: PassMIT1 mo ago
11

Backend tech-stack identification — web servers, runtimes, languages, frameworks, databases, APIs, and CMS via HTTP headers, cookies, error pages, and API discovery.

transilienceai/communitytools563—~381Automated safety check: PassMIT2 mo ago
12

Use sqlmap to confirm and characterize suspected SQL injection with faithful requests and bounded evidence.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago