graphql-injection

Community

Identify and prevent GraphQL vulnerabilities fast.

Authorvarunisrani
Version1.0.0
Installs0

System Documentation

What problem does it solve?

GraphQL-based APIs often suffer from injection vulnerabilities that can expose data, bypass authorization, or disrupt backend services. This Skill provides practical guidance to discover, characterize, and demonstrate GraphQL injection techniques across queries, mutations, introspection, and batch requests.

Core Features & Use Cases

  • Injection coverage: Test for query parameter injection, mutation argument injection, introspection abuse, and batch/complex queries.
  • Detection & verification: Techniques to verify responses and confirm exploitable weaknesses in GraphQL endpoints.
  • Use Case: Security teams can assess a GraphQL API used by a web application to identify insecure resolvers or missing authorization.

Quick Start

Provide a GraphQL endpoint URL and run a test query with a basic injection payload to observe error handling and responses.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: graphql-injection
Download link: https://github.com/varunisrani/Hare-erp/archive/main.zip#graphql-injection

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.