GraphQL Security Toolkit
With the increasing popularity of GraphQL technology, we will be using this repository to publish scripts and other resources that can facilitate security testing efforts.
A tool to query a GraphQL endpoint with introspection in order to retrieve queries & mutations
Author: Paolo Stagno (@Void_Sec)
$python GraphQL_Introspection.py -t http://192.168.1.82/examples/04-bank/graphql -o report.html
The resulting HTML page will contain details for available queries and mutations, as shown here: