graphql-idor-via-introspection-leak

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional text and documentation for security researchers to identify authorization flaws in GraphQL APIs. It contains no executable code or malicious instructions.
  • [EXTERNAL_DOWNLOADS]: The documentation recommends several third-party security tools including graphql-cop, clairvoyance, InQL, and GraphQL Voyager. These are provided as external resource suggestions for the user and are not automatically downloaded or installed by the skill.
  • [COMMAND_EXECUTION]: Provides an example shell command echo -n "User:1234" | base64 within a documentation block to demonstrate how Relay global IDs are constructed. This is an educational example of a standard utility and does not represent a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:34 PM
Security Audit — agent-trust-hub — graphql-idor-via-introspection-leak