LogoClawIndex
CasesSkillsAbout
LogoClawIndex

performing-graphql-security-assessment - Assess GraphQL APIs for Security Weaknesses

Assess GraphQL endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized tests.

Tags

Updated: 2026-09-28

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Discover GraphQL endpoints
  • Fingerprint GraphQL engines
  • Extract GraphQL schemas
  • Test authorization controls
  • Test injection vulnerabilities
  • Assess denial-of-service controls
  • Test batch authentication bypass

Inputs

  • Authorized GraphQL targets
  • Authorization tokens
  • GraphQL test queries
  • GraphQL schema wordlists

Outputs

  • GraphQL endpoint responses
  • Extracted schema files
  • Discovered schema files
  • Schema visualizations

Requirements

  • Written penetration testing authorization
  • Burp Suite Professional with InQL
  • GraphQL Voyager
  • InQL Scanner
  • Altair GraphQL Client
  • clairvoyance
  • curl

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
penetration-testing
graphql
api-security
owasp
web-security
introspection
Discover GraphQL endpoints
Fingerprint GraphQL engines
Extract GraphQL schemas
Test authorization controls
Authorized GraphQL targets
Authorization tokens
GraphQL test queries
GraphQL endpoint responses
Extracted schema files
Discovered schema files