From communitytools
Tests API endpoints for vulnerabilities in GraphQL (introspection, batching), REST (BOLA, auth bypass), WebSocket (hijacking), and Web-LLM (prompt injection) using discovery and validation workflow.
npx claudepluginhub transilienceai/communitytoolsThis skill uses the workspace's default tool permissions.
Test API endpoints for security vulnerabilities across REST, GraphQL, WebSocket, and LLM-integrated APIs.
reference/api-testing-cheat-sheet.mdreference/api-testing-comprehensive-guide.mdreference/graphql-cheat-sheet.mdreference/graphql-nosql-combined.mdreference/graphql-quickstart.mdreference/graphql-resources.mdreference/web-llm-attacks-cheat-sheet.mdreference/web-llm-attacks-quickstart.mdreference/web-llm-attacks-resources.mdreference/websockets-cheat-sheet.mdreference/websockets-index.mdreference/websockets-quickstart.mdreference/websockets-resources.mdGuides security testing workflow for REST and GraphQL APIs: authentication, authorization, rate limiting, input validation, vulnerabilities. Use for audits or bug bounties.
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic using OWASP Top 10, Burp Suite, and Postman.
Conducts security testing of REST, GraphQL, and gRPC APIs using OWASP API Security Top 10, Burp Suite, Postman, and scripts to identify auth, authz, rate limiting, input validation, and business logic flaws.
Share bugs, ideas, or general feedback.
Test API endpoints for security vulnerabilities across REST, GraphQL, WebSocket, and LLM-integrated APIs.
| Type | Key Vectors |
|---|---|
| GraphQL | Introspection, batching attacks, nested query DoS, field suggestion |
| REST API | BOLA/IDOR, mass assignment, rate limiting, auth bypass, versioning |
| WebSocket | Cross-site hijacking, message manipulation, auth flaws |
| Web-LLM | Prompt injection via API, excessive agency, data exfiltration |
reference/graphql*.md - GraphQL attack techniques and labsreference/api-testing*.md - REST API security testing guidereference/websockets*.md - WebSocket vulnerability testingreference/web-llm*.md - Web-LLM attack techniques and labs