Skip to content

feat(web-security): add graphql-pentest skill for systematic GraphQL …#39

Merged
GangGreenTemperTatum merged 1 commit into
mainfrom
ads/cap-1002-add-web-security-capability-for-graphql-agents
Jun 5, 2026
Merged

feat(web-security): add graphql-pentest skill for systematic GraphQL …#39
GangGreenTemperTatum merged 1 commit into
mainfrom
ads/cap-1002-add-web-security-capability-for-graphql-agents

Conversation

@GangGreenTemperTatum
Copy link
Copy Markdown
Contributor

…security testing

Covers endpoint discovery, capability matrix (batching, aliases, introspection, circular fragments, depth limits), resource abuse (CWE-674 uncontrolled recursion, CWE-400 batching amplification), content-type CSRF, and introspection mining. Includes reference files for backend fingerprints, attack payloads, and matrix template.

…security testing

Covers endpoint discovery, capability matrix (batching, aliases, introspection, circular
fragments, depth limits), resource abuse (CWE-674 uncontrolled recursion, CWE-400 batching
amplification), content-type CSRF, and introspection mining. Includes reference files for
backend fingerprints, attack payloads, and matrix template.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@GangGreenTemperTatum GangGreenTemperTatum merged commit 5c7c1ed into main Jun 5, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant