attacking-graphql
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional and provides examples for security researchers to manually test GraphQL endpoints. It does not contain any malicious scripts or automated attack payloads.
- [COMMAND_EXECUTION]: The documentation includes standard
curlcommand examples for API introspection and diagnostic testing against a user-defined target URL. - [EXTERNAL_DOWNLOADS]: The skill references established open-source security tools (such as
graphql-cop,clairvoyance, andgraphw00f) as recommended utilities for GraphQL analysis. These tools are mentioned for informational purposes and are not installed or executed by the skill itself.
Audit Metadata