Agent skill

Hunt Fintech Graphql

by sickn33 in sickn33/agentic-awesome-skills

Hunt fintech-specific GraphQL vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check passedBackend & APIs

Install Hunt Fintech Graphql

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-fintech-graphql -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hunt-fintech-graphql --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-fintech-graphql .claude/skills/hunt-fintech-graphql && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-fintech-graphql
GitHub stars
47k
Used in
1 other repo
Token cost
~3.9k tokens
SKILL.md length
1,705 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Hunt fintech-specific GraphQL vulnerabilities. An agent skill from sickn33/agentic-awesome-skills.

  • Works in 9 steps: Map every mutation that touches balance,… → For each money-movement mutation,… → Test idempotency-key handling. Send the… → …
  • Tasks that involve GraphQL
  • SKILL.md covers Why Fintech GraphQL Is a…, Attack Surface Signals, Step-by-Step Hunting Methodology and Payload & Detection Patterns, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Hunt Fintech Graphql is an agent skill from sickn33/agentic-awesome-skills. Hunt fintech-specific GraphQL vulnerabilities

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not…

It sits in Backend & APIs, covering GraphQL and Banking and insurance. It works with GraphQL. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve GraphQL
  • Tasks that involve Banking and insurance

Example prompts

  • “/hunt-fintech-graphql”

Requirements

  • Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Map every mutation that touches balance, whether directly or as a side effect. Not just
  2. For each money-movement mutation, identify the ledger write shape. Does one mutation call
  3. Test idempotency-key handling. Send the identical mutation (same idempotencyKey /
  4. Test decimal/precision edge cases on every amount-accepting argument — see Payload section.
  5. Probe cross-account IDOR on account/portfolio node IDs, same as hunt-idor/hunt-graphql,
  6. Check field-level authorization on KYC/PII fields by querying the shared User/Account
  7. Look for admin-tier mutations reachable via mass assignment, not just a missing auth
  8. Test currency-argument consistency. Send a transfer/quote mutation with mismatched
  9. Combine alias batching with money-movement mutations to test for double-spend — see

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are graphql and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hunt Fintech Graphql loads about 3.9k tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 1,705 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,705 words, ~3,929 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-fintech-graphql/SKILL.md (or your agent's skills folder).
name
hunt-fintech-graphql
description
Hunt fintech-specific GraphQL vulnerabilities
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
category
security
risk
offensive
source
https://github.com/elementalsouls/Claude-BugHunter
source_repo
elementalsouls/Claude-BugHunter
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE
sources
owasp_api_top10_2023, public_research
report_count
0

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

Why Fintech GraphQL Is a Different Risk Class

Generic GraphQL bugs (IDOR, mass assignment, introspection, batching abuse — see hunt-graphql) still apply here, but the blast radius changes completely: a resolver bug in a SaaS app leaks data, the same class of bug in a ledger mutation moves money. Three properties make fintech GraphQL backends a distinct hunting surface:

  • Money-movement mutations are almost always resolvers over a double-entry ledger. A single GraphQL mutation (transferFunds, redeemRewards, withdrawToBank) can trigger multiple ledger writes (debit + credit + fee) that must be atomic. GraphQL's flexible input shape and alias batching make it easy to desynchronize those writes.
  • Decimals are attacker-controlled input, not display formatting. Amounts, exchange rates, interest, and rewards points are usually passed as GraphQL scalars (Float, String, custom Decimal/Money scalar). How the resolver parses and rounds that value is exploitable surface in its own right — this barely exists in non-financial GraphQL APIs.
  • KYC/PII fields sit next to routine account fields in the same type. User or Account types commonly expose ssnLast4, routingNumber, kycStatus, governmentIdUrl, or linkedBankAccount alongside displayName and email — one missing field-level authorization check on a type used everywhere in the schema fans out to every query that touches it.

Attack Surface Signals

URL / schema naming patterns (in addition to hunt-graphql's generic /graphql list):

/graphql/ledger
/graphql/payments
/api/wallet/graphql
/internal/ledger-graphql
/banking/graphql

Field/type names worth grepping schema introspection or JS bundles for:

balance, availableBalance, pendingBalance, ledgerEntry, ledgerEntries
transferFunds, withdraw, redeem, topUp, reverseTransaction, adjustBalance
kycStatus, ssnLast4, routingNumber, accountNumber, governmentIdUrl
quoteExchangeRate, interestAccrued, rewardsPoints, portfolioValue
idempotencyKey, clientMutationId

Tech-stack tells specific to this vertical:

  • Plaid/Stripe/Dwolla/Marqeta wrapped behind an internal GraphQL gateway (bankLink, plaidLinkToken mutations)
  • Apollo Federation with a dedicated ledger or payments subgraph — check for the subgraph's own introspection being reachable directly, bypassing the gateway's stitched-down schema
  • Custom Money/Decimal/BigDecimal GraphQL scalar in the schema (scalar Money) — the parser for this scalar is worth fuzzing directly

Run hunt-graphql's discovery + introspection methodology first to get the schema; everything below assumes you already have (or have partially enumerated) a schema with money-movement types.


Step-by-Step Hunting Methodology

  1. Map every mutation that touches balance, whether directly or as a side effect. Not just transfer*/withdraw* — also redeemRewards, applyCoupon, upgradeTier, closeAccount (often refunds a balance), disputeTransaction (often provisionally credits).

  2. For each money-movement mutation, identify the ledger write shape. Does one mutation call produce one ledger entry or several (debit sender, credit receiver, fee entry)? Multi-entry writes are the ones worth racing — see Stage 4.

  3. Test idempotency-key handling. Send the identical mutation (same idempotencyKey / clientMutationId) twice, back-to-back and with a delay. A ledger write on the second call means idempotency isn't enforced server-side — replay = double-execute.

  4. Test decimal/precision edge cases on every amount-accepting argument — see Payload section. Confirm server-side rounding matches client-displayed rounding; a mismatch is directly monetizable.

  5. Probe cross-account IDOR on account/portfolio node IDs, same as hunt-idor/hunt-graphql, but specifically test whether a transferFunds-style mutation validates that the source account belongs to the authenticated caller — not just that some account with that ID exists. This is the fintech-specific IDOR: authz on the source of a debit is easy to forget when authz on the destination of a credit was correctly implemented (crediting an arbitrary account "looks safe" to a developer; debiting one clearly isn't, so it gets checked — but sometimes only one direction does).

  6. Check field-level authorization on KYC/PII fields by querying the shared User/Account type from every context that returns it — not just the profile screen. A transaction type that embeds counterparty { ssnLast4 } is a common place for the check to be missing, because the developer authorized the top-level transaction query but didn't re-check field access on the nested counterparty.

  7. Look for admin-tier mutations reachable via mass assignment, not just a missing auth check — e.g. an input object with a client-settable status or override field that a normal user's mutation shouldn't expose but that the resolver accepts anyway (updateTransaction(input: {id, status: "COMPLETED", amount: "..."})).

  8. Test currency-argument consistency. Send a transfer/quote mutation with mismatched sourceCurrency/targetCurrency combinations the UI never generates (e.g. self-transfer with a currency conversion) and check whether the resolver's FX-rate lookup and the ledger write use the same rate — a TOCTOU window here is a direct arbitrage bug.

  9. Combine alias batching with money-movement mutations to test for double-spend — see hunt-race-condition for the parallel-HTTP escalation once alias batching alone confirms the resolver isn't serializing writes per-account.


Payload & Detection Patterns

Idempotency-key replay test:

graphql
mutation {
  transferFunds(input: {
    idempotencyKey: "test-key-001"
    sourceAccountId: "acc_1"
    destAccountId: "acc_2"
    amount: "10.00"
  }) { transactionId status }
}

Send twice with the identical idempotencyKey. Two successful, distinct transactionId values = idempotency not enforced.

Decimal-precision / rounding probes:

graphql
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "0.001"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "9999999999999999.99"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "1e2"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "-50.00"}) { transactionId } }

Sub-cent amounts test truncate-vs-round handling (repeat N times to accumulate a rounding-error balance drift); scientific notation and oversized values test whether the Money/Decimal scalar parser falls back to a native float/int with overflow or precision-loss behavior; negative amounts test whether the resolver assumes sign server-side or trusts the client's.

Alias-batched double-spend probe (confirm before escalating to parallel HTTP):

graphql
mutation {
  r1: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
  r2: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
  r3: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
}

If more than one alias succeeds against a single-use reward/coupon, the resolver doesn't serialize per-account/per-resource writes within a batched request — see hunt-race-condition for combining this with parallel HTTP POSTs to confirm real double-spend impact.

Source-account authorization probe (asymmetric IDOR check):

graphql
mutation {
  transferFunds(input: {
    sourceAccountId: "VICTIM_ACCOUNT_ID"
    destAccountId: "ATTACKER_CONTROLLED_ACCOUNT_ID"
    amount: "1.00"
  }) { transactionId status }
}

Run as the attacker's own session/token. Success = the resolver validated the destination is attacker-controlled (obviously required) but never validated that the source belongs to the caller.

Nested field-level PII probe:

graphql
query {
  transaction(id: "txn_123") {
    amount
    counterparty { displayName ssnLast4 routingNumber kycStatus }
  }
}

Query as a user with no relationship to the counterparty beyond a shared transaction; success on the nested PII fields is the finding even if the top-level transaction query correctly scoped the transaction itself.

Mass-assignment probe on admin-shaped input fields:

graphql
mutation {
  updateTransaction(input: {id: "txn_123", status: "COMPLETED", amount: "0.01"}) { id status }
}

Send as a non-admin user against a mutation the client UI never exposes these fields for; a schema that accepts them anyway is mass assignment onto ledger state.


Show full SKILL.md (674 more words)Show less

Common Root Causes

  1. Client-side amount/fee validation only. The UI computes and displays the correct amount; the resolver trusts whatever the GraphQL client actually sends, because "the app always sends the right value."
  2. Non-atomic multi-entry ledger writes. Debit, credit, and fee entries are written as separate sequential statements instead of inside a single transaction/lock — the race window this creates is exactly what alias batching + parallel HTTP exploits.
  3. Money/Decimal scalar falls back to native float parsing under edge-case input (scientific notation, oversized strings), reintroducing floating-point rounding error into a system that was supposed to guarantee fixed-point precision.
  4. Idempotency keys are stored but never checked before executing the write — the key is logged for support/debugging purposes, not used as a dedup gate.
  5. Field-level authorization implemented per top-level query, not per type. A User/Account type's sensitive fields are protected when queried directly (me { ssnLast4 }) but not when the same type is returned nested inside an unrelated query (transaction { counterparty {...} }).
  6. Source-account ownership check missing while destination-account existence check is present — see methodology step 5. Debiting looks dangerous so it gets reviewed; the "does this account belong to the caller" check quietly only gets applied to the credited side.
  7. Admin/internal mutations reuse the same input type as the public mutation, just with extra optional fields — nothing at the resolver layer strips those fields for non-admin callers.

Gate 0 Validation

Money-movement findings need a stricter bar than a typical GraphQL IDOR — "the query returns someone else's balance" is real impact; "I sent a malformed amount and got a 400" is not.

  1. Did an actual ledger write occur, and can you show it? Query the account balance before and after — a state change (not just a 200/success response body) is the proof.
  2. Is the win deterministic, not a timing fluke? For race/double-spend findings, reproduce twice from a clean state. If it only works under specific load conditions, document the window honestly rather than claiming guaranteed exploitability.
  3. Does the finding move value the attacker didn't have, or reveal data they shouldn't see — not just "the mutation accepted an unexpected input type and the API returned an error message." A verbose GraphQL error leaking a stack trace on a malformed Money scalar is a hunt-source-leak-class finding, not a fintech-logic one — don't conflate the two in a report.

  • hunt-graphql — parent skill for generic GraphQL discovery, introspection bypass, node-ID IDOR, and alias-batching mechanics. Load this skill first; hunt-fintech-graphql assumes that methodology and only adds the money-movement-specific delta.
  • hunt-business-logic — coupon/reward double-redemption and other logic-flaw patterns generalize directly to redeemRewards/applyCoupon-style mutations here.
  • hunt-race-condition — the escalation path once alias batching alone confirms a money-movement mutation doesn't serialize writes: combine with parallel-HTTP / single-packet attack for a deterministic double-spend PoC.
  • hunt-api-misconfig — mass assignment and JWT-claim tampering patterns apply directly to admin-shaped GraphQL input objects reachable by normal users.
  • hunt-idor — the source-account-vs-destination-account asymmetric authz pattern (step 5) is a fintech-specific instance of the general IDOR-on-mutation-argument class.
  • evidence-hygiene — balance screenshots and ledger-entry PoCs need the same cookie/PII redaction discipline as any other capture, plus care that a real account number/balance from a live financial account is never included verbatim.
  • triage-validation — apply Gate 0 above before drafting; a fintech program's triage team will kill anything without a demonstrated ledger state change immediately.

When to Use

  • You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
  • You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.

Limitations

  • Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
  • Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
  • Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt  # target list from the authorized engagement brief

Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-fintech-graphql of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hunt Fintech Graphql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Fintech Graphql compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Fintech Graphql this skillsickn33/agentic-awesome-skills47k1 repos~3.9kAutomated safety check: PassMIT
Hunt Fintech Graphqlelementalsouls/Claude-BugHunter4.8k—~3.5kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works16218 repos~4kAutomated safety check: PassAGPL-3.0
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT
GraphQL Operations with CodegenChrisWiles/claude-code-showcase6.1k3 repos~1.5kAutomated safety check: PassNone
API Design Principlesjh941213/my-cc-harness12518 repos~3.4kAutomated safety check: PassNone

Similar skills

  • Hunt Fintech Graphql

    elementalsouls/Claude-BugHunter

    Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding…

    4.8k GitHub stars~3.5k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    162 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • GraphQL Operations with Codegen

    ChrisWiles/claude-code-showcase

    Sets the rules for writing GraphQL queries and mutations in .gql files, running codegen, and using generated Apollo hooks with proper error and loading handling.

    6.1k GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • API Design Principles

    jh941213/my-cc-harness

    REST 및 GraphQL API 설계 원칙 가이드. An agent skill from jh941213/my-cc-harness.

    125 GitHub starsUsed in 18 repos~3.4k tokens
    Backend & APIsAuto-check passed
  • API And Interface Design

    dzhalaevd/Donatello

    Guides stable API and interface design. An agent skill from dzhalaevd/Donatello.

    135 GitHub starsUsed in 8 repos~2.6k tokens
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Categories

Questions about Hunt Fintech Graphql

What does Hunt Fintech Graphql do?

Hunt fintech-specific GraphQL vulnerabilities. An agent skill from sickn33/agentic-awesome-skills. Hunt Fintech Graphql is an agent skill from sickn33/agentic-awesome-skills.

When should I use Hunt Fintech Graphql?

Hunt Fintech Graphql fits situations like: tasks that involve GraphQL; tasks that involve Banking and insurance.

How do I install Hunt Fintech Graphql in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-fintech-graphql -a claude-code`. Or copy the skill folder (skills/hunt-fintech-graphql in sickn33/agentic-awesome-skills) into .claude/skills/hunt-fintech-graphql in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Fintech Graphql in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-fintech-graphql -a codex`. Or copy the skill folder (skills/hunt-fintech-graphql in sickn33/agentic-awesome-skills) into .agents/skills/hunt-fintech-graphql in your project. Codex loads it when a task matches its description.

Can I use Hunt Fintech Graphql in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-fintech-graphql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-fintech-graphql, .gemini/skills/hunt-fintech-graphql, .github/skills/hunt-fintech-graphql and .opencode/skills/hunt-fintech-graphql in your project.

What does Hunt Fintech Graphql need to run?

SKILL.md names no scripts, command-line tools or credentials: Hunt Fintech Graphql is instructions for the agent only. Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..

Does Hunt Fintech Graphql access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Hunt Fintech Graphql safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Fintech Graphql use?

Hunt Fintech Graphql is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Fintech Graphql use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Fintech Graphql?

Skills that share tags, products or a category with Hunt Fintech Graphql: Hunt Fintech Graphql (elementalsouls/Claude-BugHunter, 4.8k stars), Nodejs Backend Patterns (ever-works/ever-works, 162 stars), API Designer (Jeffallan/claude-skills, 12k stars) and GraphQL Operations with Codegen (ChrisWiles/claude-code-showcase, 6.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Fintech Graphql?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.