graphql-and-hidden-parameters

>-

INSTALLATION
npx skills add https://github.com/yaklang/hack-skills --skill graphql-and-hidden-parameters
Run in your project or agent environment. Adjust flags if your CLI version differs.

SKILL.md

$27

  • field suggestions and error-based discovery
  • known type probes like __type(name: "User")
  • JS and mobile bundle route extraction

2. HIGH-VALUE GRAPHQL TESTS

Theme

Example

IDOR

user(id: "victim")

batching

array of login or object fetch operations

hidden fields

admin-only fields exposed in type definitions

nested authz gaps

related object fields with weaker checks

3. HIDDEN PARAMETER DISCOVERY

Look for:

  • fields present in admin docs but not public docs
  • additionalProperties or permissive schemas
  • frontend code using richer request bodies than visible UI controls
  • mobile endpoints carrying role, org, feature-flag, or internal filter fields

4. NEXT ROUTING

BrowserAct

Let your agent run on any real-world website

Bypass CAPTCHA & anti-bot for free. Start local, scale to cloud.

Explore BrowserAct Skills →

Stop writing automation&scrapers

Install the CLI. Run your first Skill in 30 seconds. Scale when you're ready.

Start free
free · no credit card