performing-graphql-introspection-attack - Test GraphQL schemas and query abuse defenses
Extracts and analyzes GraphQL schemas, identifies sensitive operations, and tests introspection, query complexity, batching, and authorization weaknesses.
Tags
Updated: 2026-10-06Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Discover GraphQL endpoints
- Extract complete API schemas
- Identify sensitive schema elements
- Reconstruct disabled schemas
- Test query depth limits
- Test query complexity limits
- Test batching defenses
- Test field authorization
Inputs
- Authorized GraphQL endpoint
- Testing scope
- Authentication headers
- GraphQL field wordlists
- GraphQL type wordlists
Outputs
- Discovered endpoint messages
- Extracted GraphQL schema file
- Schema summary messages
- Sensitive field findings
- Sensitive mutation findings
- Query testing results
Requirements
- Written testing authorization
- Burp Suite Professional
- InQL extension version 6.1+
- Python 3.10+
- requests library
- gql library
- GraphQL Voyager or Playground
- Clairvoyance tool
