Search
GraphQL · Web application vulnerabilities
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023). | briiirussell/ | 413 | — | ~2.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 2 | A skill your agent uses when writing Playwright tests, fixing flaky tests, debugging failures, implementing Page Object Model, configuring CI/CD, optimizing performance, mocking APIs, handling… | sanity-io/ | 6.4k | 7 repos | ~6.4k | Automated safety check: Pass | MIT | yesterday |
| 3 | Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. | Gabson0x/ | 442 | — | ~11k | Automated safety check: Warn | No licence | 24 days ago |
| 4 | Comprehensive API security review against OWASP API Security Top 10 (2023). | OWASP/ | 188 | — | ~744 | Automated safety check: Pass | CC-BY-4.0 | 15 days ago |
| 5 | IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and… | Encod3d-Sec/ | 329 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 6 | Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling… | awarexone/ | 5.3k | — | ~20k | Automated safety check: Warn | MIT | yesterday |
| 7 | Application security defense knowledge for builders. An agent skill from telagod/code-abyss. | telagod/ | 244 | — | ~777 | Automated safety check: Pass | MIT | 2 mo ago |
| 8 | DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 9 | 9.Hunt API API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 10 | GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE. | Encod3d-Sec/ | 329 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 11 | Use sqlmap to confirm and characterize suspected SQL injection with faithful requests and bounded evidence. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |