Search

GraphQL · Web application vulnerabilities

11 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

briiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT4 mo ago
2

A skill your agent uses when writing Playwright tests, fixing flaky tests, debugging failures, implementing Page Object Model, configuring CI/CD, optimizing performance, mocking APIs, handling…

sanity-io/sanity6.4k7 repos~6.4kAutomated safety check: PassMITyesterday
3

Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.

Gabson0x/bountyforge442—~11kAutomated safety check: WarnNo licence24 days ago
4

Comprehensive API security review against OWASP API Security Top 10 (2023).

OWASP/secure-agent-playbook188—~744Automated safety check: PassCC-BY-4.015 days ago
5

IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

Encod3d-Sec/TORCH329—~2.6kAutomated safety check: PassMIT1 mo ago
6

Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling…

awarexone/Agentic-Bug-Hunter5.3k—~20kAutomated safety check: WarnMITyesterday
7

Application security defense knowledge for builders. An agent skill from telagod/code-abyss.

telagod/code-abyss244—~777Automated safety check: PassMIT2 mo ago
8

DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…

modu-ai/moai-adk1.2k—~2.6kAutomated safety check: PassApache-2.0yesterday
9

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago
10

GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE.

Encod3d-Sec/TORCH329—~2kAutomated safety check: PassMIT1 mo ago
11

Use sqlmap to confirm and characterize suspected SQL injection with faithful requests and bounded evidence.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago