Agent skill

Attacking Grpc Protobuf

by trilwu in trilwu/secskills

Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…

MITAuto-check passedBackend & APIs

Install Attacking Grpc Protobuf

skills CLI
$ npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills attacking-grpc-protobuf --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/attacking-grpc-protobuf .claude/skills/attacking-grpc-protobuf && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
attacking-grpc-protobuf
GitHub stars
157
Token cost
~2.2k tokens
SKILL.md length
828 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…

  • A target speaks gRPC
  • SKILL.md covers When to Use, When NOT to Use, Recover the Schema and Calling Methods, plus 5 more sections
  • Calls rg and python3
  • HTTP/2 with application/grpc

What it does

Attacking Grpc Protobuf is an agent skill from trilwu/secskills. Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web traffic, and fuzzing unknown message schemas with protobuf-inspector. Use when a target speaks gRPC, HTTP/2 with application/grpc, or when a request body is opaque binary protobuf rather than JSON.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering gRPC and Protobuf. It works with gRPC. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • A target speaks gRPC
  • HTTP/2 with application/grpc
  • A request body is opaque binary protobuf rather than JSON

Example prompts

  • “/attacking-grpc-protobuf”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • attack.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Attacking Grpc Protobuf loads about 2.2k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 828 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 828 words, ~2,233 tokens.

Download SKILL.mdSave it as .claude/skills/attacking-grpc-protobuf/SKILL.md (or your agent's skills folder).
name
attacking-grpc-protobuf
description
Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web traffic, and fuzzing unknown message schemas with protobuf-inspector. Use when a target speaks gRPC, HTTP/2 with application/grpc, or when a request body is opaque binary protobuf rather than JSON.
verified
2026-07-27

Attacking gRPC and Protobuf Services

gRPC breaks the tooling assumption that a request is readable text over HTTP/1.1. Burp shows a binary blob or nothing at all, and without the schema you cannot even name the methods. Recover the schema and it becomes an ordinary API test — with the twist that gRPC services are frequently internal services newly exposed, which means their authorization is often weaker than the REST API in front of them.

When to Use

  • Traffic uses HTTP/2 with content-type: application/grpc
  • A request or response body is opaque binary with no JSON structure
  • The app is a mobile or desktop client talking to a backend over protobuf
  • You find .proto files, *_pb2.py, *.pb.go, or grpc in a codebase
  • application/grpc-web or application/grpc-web+proto appears in a browser app

When NOT to Use

  • REST or GraphQL — use testing-apis
  • The proxy cannot see the traffic at all on mobile — use bypassing-mobile-pinning; gRPC clients often ignore system proxy settings
  • Source code is available — use auditing-code-for-vulnerabilities, and read the .proto files directly
  • Binary protocol that is not protobuf — use analyzing-binaries

Recover the Schema

Everything depends on this. Four routes, in order of cost.

1. Server reflection. Many services ship it enabled, often unintentionally.

bash
grpcurl -plaintext target:50051 list
grpcurl -plaintext target:50051 list package.ServiceName
grpcurl -plaintext target:50051 describe package.ServiceName.MethodName
grpcurl -plaintext target:50051 describe package.RequestMessage

# TLS
grpcurl target:443 list
grpcurl -insecure target:443 list          # self-signed / proxy in path

Reflection enabled on an internet-facing service is itself worth reporting — it is the gRPC equivalent of GraphQL introspection in production.

2. Descriptors compiled into a client. Protobuf embeds a serialized FileDescriptorProto in generated code, so the schema is recoverable from any client binary.

bash
# Mobile/desktop client: find and extract descriptor blobs
rg -a -o 'google/protobuf/descriptor.proto|\.proto' target_binary | head
# protobuf-inspector and protod can reconstruct .proto from embedded descriptors
protod target_binary -o ./protos

# JS/web clients: the descriptor is usually in the bundle as base64 or an array
rg -n 'grpc-web|serializeBinary|deserializeBinary' bundle.js | head

3. From the app's source or artifacts. .proto files in a repo, a Swagger gateway config, or generated stubs in a package.

4. Field-by-field inference. When you have neither, decode the wire format directly. Protobuf is self-describing enough to recover structure without the schema:

bash
protoc --decode_raw < message.bin
protobuf-inspector < message.bin
# Output: field numbers, wire types, and values — enough to fuzz and to
# recognize strings, nested messages, and integers

You lose field names but keep field numbers, which is all the wire format needs. That is sufficient to modify values and to add fields the client never sends.

Calling Methods

bash
# With reflection
grpcurl -plaintext -d '{"user_id": 1}' target:50051 package.Service/GetUser

# With a local .proto
grpcurl -import-path ./protos -proto api.proto \
        -d '{"user_id": 1}' target:50051 package.Service/GetUser

# Interactive browser UI, good for exploring
grpcui -plaintext target:50051

# Headers, including auth
grpcurl -H 'authorization: Bearer eyJ...' -plaintext target:50051 package.Service/List

For streaming methods, grpcurl accepts newline-delimited JSON on stdin for client streaming, and prints each message for server streaming. Streaming endpoints are frequently less-tested than unary ones and worth specific attention.

Intercepting Traffic

bash
# mitmproxy speaks HTTP/2 and can decode gRPC with a schema
mitmproxy --mode regular --set http2=true
#   the gRPC content-view renders protobuf; supply .proto for field names

# Burp: enable HTTP/2, and use a protobuf decoder extension
#   without one, you see length-prefixed binary frames

# gRPC-Web is easier — it rides HTTP/1.1 with base64 or binary framing,
# so a normal proxy sees the requests

gRPC framing: each message is a 1-byte compression flag, a 4-byte big-endian length, then the protobuf bytes. When a decoder shows nothing, strip those five bytes before feeding the payload to protoc --decode_raw.

bash
python3 -c "
import sys
d = sys.stdin.buffer.read()
sys.stdout.buffer.write(d[5:])" < frame.bin | protoc --decode_raw

Clients that ignore the system proxy need a network-layer redirect; see bypassing-mobile-pinning.

Show full SKILL.md (435 more words)Show less

What to Test

The bug classes are the same as any API, but gRPC changes where they hide.

Authorization per method. gRPC has no path-based access control, so a reverse proxy or WAF that filters /admin/* does nothing. Each method must check authorization itself — enumerate every method from reflection and call each one with a low-privilege token.

bash
for m in $(grpcurl -plaintext target:50051 list package.Service | tail -n +2); do
  echo "== $m"; grpcurl -H "authorization: Bearer $LOW_PRIV" -plaintext -d '{}' target:50051 "$m" 2>&1 | head -3
done

Internal services exposed. gRPC is a service-mesh protocol, so many services were written assuming only other services would call them. If you can reach one directly, expect no authentication at all — and expect it to trust identity claims passed as ordinary request fields or metadata.

Metadata trust. Look for headers the service reads as identity: x-user-id, x-tenant-id, x-forwarded-user. If a gateway sets them and the service trusts them, sending them yourself is a complete authentication bypass.

bash
grpcurl -H 'x-user-id: 1' -H 'x-role: admin' -plaintext -d '{}' target:50051 package.Service/GetProfile

Unknown-field injection. Protobuf ignores fields it does not recognize, but intermediate services may forward them. More usefully: add fields the client never sends but the server schema defines — is_admin, internal_notes, tenant_id — the mass-assignment equivalent.

Type confusion and resource exhaustion. Wire types are loosely enforced; send a bytes where a string is expected, deeply nested messages to blow the recursion limit, or a huge repeated field. Check for a configured message size limit.

TLS and mTLS posture. Many gRPC deployments use insecure channels internally. Check whether the service accepts plaintext, and whether mTLS is required or merely optional.

Rationalizations to Reject

  • "Burp shows nothing, the app isn't making requests." Burp needs HTTP/2 enabled, and gRPC clients often bypass the system proxy entirely.
  • "I don't have the .proto, so I can't test it." protoc --decode_raw recovers structure from any message. Field numbers are all you need.
  • "Reflection is disabled, so the methods are hidden." The client knows the schema. Extract the descriptors from the client binary.
  • "The gateway enforces authorization." The gateway sees method names, not intent, and anything that reaches the service directly bypasses it entirely.
  • "It's internal-only." Confirm that. Service meshes leak, and "internal" usually means "no authentication".
  • "The client never sends that field." You are not the client.
<!-- attack:start -->

ATT&CK Coverage

Generated from secskills-core/ttp-index.json — edit that file, then run python3 scripts/sync_attack.py --write. Re-verify IDs against the current ATT&CK release before citing them in a report.

Initial Access (TA0001)

  • T1190 Exploit Public-Facing Application — see also testing-web-applications, testing-apis, enumerating-network-services, attacking-graphql, exploiting-deserialization, exploiting-ssrf, exploiting-xxe

Detection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.

<!-- attack:end -->

References

  • testing-apis — the general API methodology this specializes
  • auditing-code-for-vulnerabilities — reading .proto and handlers in source
  • bypassing-mobile-pinning — when a mobile gRPC client ignores your proxy
  • exploiting-cloud-platforms — service mesh and internal exposure context
  • grpcurl, grpcui, protoc, protobuf-inspector, protod, mitmproxy

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-offense/skills/attacking-grpc-protobuf of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Attacking Grpc Protobuf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Attacking Grpc Protobuf compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Attacking Grpc Protobuf this skilltrilwu/secskills157—~2.2kAutomated safety check: PassMIT
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT
Golang Proantoniopaya22/go-rest-template1723 repos~1.2kAutomated safety check: PassMIT
Debug Grpc ConnectionGetBindu/Bindu10k—~1.2kAutomated safety check: PassCustom licence
Aspnet Corefanslead/ReverseProxy.Store1612 repos~1.4kAutomated safety check: PassApache-2.0
Regenerate Grpc StubsGetBindu/Bindu10k—~810Automated safety check: PassCustom licence

Similar skills

  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Golang Pro

    antoniopaya22/go-rest-template

    Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…

    172 GitHub starsUsed in 3 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Debug Grpc Connection

    GetBindu/Bindu

    Diagnose gRPC connection issues between the Bindu core and a language SDK.

    10k GitHub stars~1.2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Aspnet Core

    fanslead/ReverseProxy.Store

    Build, review, refactor, or architect ASP.NET Core web applications using current official guidance for .NET web development.

    161 GitHub starsUsed in 2 repos~1.4k tokens
    Backend & APIsAuto-check passed
  • Regenerate Grpc Stubs

    GetBindu/Bindu

    Regenerate Python + TypeScript gRPC stubs after editing proto files.

    10k GitHub stars~810 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Spider King

    aoyunyang/spider-king-skill

    Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.

    509 GitHub stars~7.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Attacking Grpc Protobuf

What does Attacking Grpc Protobuf do?

Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…. Attacking Grpc Protobuf is an agent skill from trilwu/secskills.proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web traffic, and fuzzing unknown message schemas with protobuf-inspector.

When should I use Attacking Grpc Protobuf?

Attacking Grpc Protobuf fits situations like: A target speaks gRPC; HTTP/2 with application/grpc; A request body is opaque binary protobuf rather than JSON.

How do I install Attacking Grpc Protobuf in Claude Code?

Run `npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a claude-code`. Or copy the skill folder (secskills-offense/skills/attacking-grpc-protobuf in trilwu/secskills) into .claude/skills/attacking-grpc-protobuf in your project. Claude Code loads it when a task matches its description.

How do I install Attacking Grpc Protobuf in Codex?

Run `npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a codex`. Or copy the skill folder (secskills-offense/skills/attacking-grpc-protobuf in trilwu/secskills) into .agents/skills/attacking-grpc-protobuf in your project. Codex loads it when a task matches its description.

Can I use Attacking Grpc Protobuf in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/attacking-grpc-protobuf, .gemini/skills/attacking-grpc-protobuf, .github/skills/attacking-grpc-protobuf and .opencode/skills/attacking-grpc-protobuf in your project.

What does Attacking Grpc Protobuf need to run?

Going by SKILL.md and its folder, Attacking Grpc Protobuf needs the command-line tools its instructions call (rg and python3). Our summary lists: Python 3.

Does Attacking Grpc Protobuf access the network?

SKILL.md names 1 domain. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.

Is Attacking Grpc Protobuf safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Attacking Grpc Protobuf use?

Attacking Grpc Protobuf is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Attacking Grpc Protobuf use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Attacking Grpc Protobuf?

Skills that share tags, products or a category with Attacking Grpc Protobuf: Use Yaak (mountain-loop/yaak, 19k stars), Golang Pro (antoniopaya22/go-rest-template, 172 stars), Debug Grpc Connection (GetBindu/Bindu, 10k stars) and Aspnet Core (fanslead/ReverseProxy.Store, 161 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Attacking Grpc Protobuf?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.