Skip to content
Security
Skill

/graphql-and-hidden-parameters

GraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, schema abuse, and GraphQL authorization gaps.

From plugin
hack-skills
1.6k102 skills
Install
$ npx -y skills add yaklang/hack-skills --skill graphql-and-hidden-parameters --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/graphql-and-hidden-parameters

Context preview

The summary Claude sees to decide when to auto-load this skill.

GraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, schema abuse, and GraphQL authorization gaps.

SKILL.md

graphql-and-hidden-parameters.SKILL.md
name: graphql-and-hidden-parameters
description: >-
  GraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, schema abuse, and GraphQL authorization gaps.

SKILL: GraphQL and Hidden Parameters — Introspection, Batching, and Undocumented Fields

> **AI LOAD INSTRUCTION**: Use this skill when GraphQL exists or when REST documentation suggests optional, deprecated, or undocumented fields. Focus on schema discovery, hidden parameter abuse, and batching as a force multiplier.

1. GRAPHQL FIRST PASS

query { __typename }
query {
  __schema {
    types { name }
  }
}

If introspection is restricted, continue with:

  • field suggestions and error-based discovery
  • known type probes like `__type(name: "User")`
  • JS and mobile bundle route extraction

2. HIGH-VALUE GRAPHQL TESTS

| Theme | Example | |---|---| | IDOR | `user(id: "victim")` | | batching | array of login or object fetch operations | | hidden fields | admin-only fields exposed in type definitions | | nested authz gaps | related object fields with weaker checks |

3. HIDDEN PARAMETER DISCOVERY

Look for:

  • fields present in admin docs but not public docs
  • `additionalProperties` or permissive schemas
  • frontend code using richer request bodies than visible UI controls
  • mobile endpoints carrying role, org, feature-flag, or internal filter fields

4. NEXT ROUTING

  • If hidden fields affect privilege: [api authorization and bola](../api-authorization-and-bola/SKILL.md)
  • If GraphQL batching changes auth or rate behavior: [api auth and jwt abuse](../api-auth-and-jwt-abuse/SKILL.md)
  • If endpoint discovery is incomplete: [api recon and docs](../api-recon-and-docs/SKILL.md)
Read more
Ships withhack-skills

Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 101 deep topic skills across 14 security domains.

Get the whole plugin

Other skills on hack-skills.