api-recon-and-docs

>-

INSTALLATION
npx skills add https://github.com/yaklang/hack-skills --skill api-recon-and-docs
Run in your project or agent environment. Adjust flags if your CLI version differs.

SKILL.md

$27

/swagger.json

/openapi.json

/api-docs

/docs

/.well-known/

/graphql

/gql

Version and product drift

/api/v1/

/api/v2/

/api/mobile/v1/

/legacy/

3. WHAT TO EXTRACT FROM DOCS

  • optional and undocumented fields
  • admin-only request examples
  • deprecated endpoints that may still be active
  • schema hints like additionalProperties: true
  • parameter names tied to filtering, sorting, IDs, roles, or tenancy

4. NEXT ROUTING

Finding

Next Skill

object IDs everywhere

api authorization and bola

JWT, OAuth, role claims

api auth and jwt abuse

GraphQL or hidden fields

graphql and hidden parameters

strong auth boundary but suspicious business flow

business logic vulnerabilities

BrowserAct

Let your agent run on any real-world website

Bypass CAPTCHA & anti-bot for free. Start local, scale to cloud.

Explore BrowserAct Skills →

Stop writing automation&scrapers

Install the CLI. Run your first Skill in 30 seconds. Scale when you're ready.

Start free
free · no credit card