graphql-idor-via-introspection-leak
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional text and documentation for security researchers to identify authorization flaws in GraphQL APIs. It contains no executable code or malicious instructions.
- [EXTERNAL_DOWNLOADS]: The documentation recommends several third-party security tools including
graphql-cop,clairvoyance,InQL, andGraphQL Voyager. These are provided as external resource suggestions for the user and are not automatically downloaded or installed by the skill. - [COMMAND_EXECUTION]: Provides an example shell command
echo -n "User:1234" | base64within a documentation block to demonstrate how Relay global IDs are constructed. This is an educational example of a standard utility and does not represent a security risk.
Audit Metadata