Loading...
Loading...
GraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, schema abuse, and GraphQL authorization gaps.
npx skill4agent add yaklang/hack-skills graphql-and-hidden-parametersAI LOAD INSTRUCTION: Use this skill when GraphQL exists or when REST documentation suggests optional, deprecated, or undocumented fields. Focus on schema discovery, hidden parameter abuse, and batching as a force multiplier.
query { __typename }
query {
__schema {
types { name }
}
}__type(name: "User")| Theme | Example |
|---|---|
| IDOR | |
| batching | array of login or object fetch operations |
| hidden fields | admin-only fields exposed in type definitions |
| nested authz gaps | related object fields with weaker checks |
additionalProperties