Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计通过

graphqlGraphQL 接口开发

Agent Skill

用于辅助 API 设计、接口文档、请求响应结构和服务集成说明。它适合让 Agent 梳理 endpoint、生成 OpenAPI 草稿、检查字段命名、整理错误码或辅助前后端联调。使用时需要确认真实业务语义、鉴权方式、分页和错误处理规则;涉及生成接口文档时,应避免凭空补字段,最好从现有代码、schema 或接口样例中提取事实。

总安装

247

周安装

10

GitHub Stars

9

下载量

78
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:graphql(GraphQL 接口开发)
来源仓库:https://github.com/florianbuetow/claude-code
仓库路径:skills/graphql
安装命令:
npx skills add https://github.com/florianbuetow/claude-code --skill graphql
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/florianbuetow/claude-code --skill graphql

简介

用于辅助 GraphQL 接口设计和文档编写。

  • 适合梳理 endpoint 和生成 schema 草稿。
  • 需结合项目现有代码确认字段和业务语义。
  • 安装前建议核实权限范围和维护状态。适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。
  • 涉及接口文档时应避免凭空补字段。graphql 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

GraphQL Security (GQL)

Analyze GraphQL APIs for security vulnerabilities including introspection enabled in production, missing query depth limits, no complexity analysis, batching abuse, alias-based denial of service, and missing per-field authorization. GraphQL's flexibility makes it a rich attack surface when default configurations are deployed to production without hardening.

Supported Flags

Read ../../shared/schemas/flags.md for the full flag specification. This skill supports all cross-cutting flags. Key flags for this skill:

  • --scope determines which files to analyze (default: changed)
  • --depth standard reads code and checks GraphQL configuration
  • --depth deep traces resolvers to data sources and maps authorization coverage
  • --severity filters output (GraphQL issues range from medium to critical)

Framework Context

Key CWEs in scope:

  • CWE-200: Exposure of Sensitive Information (introspection)
  • CWE-400: Uncontrolled Resource Consumption (depth/complexity)
  • CWE-862: Missing Authorization (per-field auth)
  • CWE-770: Allocation of Resources Without Limits (batching)
  • CWE-284: Improper Access Control

Detection Patterns

Read references/detection-patterns.md for the full catalog of code patterns, search heuristics, language-specific examples, and false positive guidance.

Workflow

1. Determine Scope

Parse flags and resolve the file list per ../../shared/schemas/flags.md. Filter to files likely to contain GraphQL logic:

  • Schema definitions (**/*.graphql, **/schema.*, **/typeDefs*)
  • Resolver implementations (**/resolvers/**, **/graphql/**)
  • GraphQL server configuration (**/server.*, **/app.*, **/index.*)
  • Middleware and plugins (**/middleware/**, **/plugins/**)
  • Authorization directives (**/directives/**, **/guards/**)

2. Check for Available Scanners

Detect scanners per ../../shared/schemas/scanners.md:

  1. semgrep -- primary scanner for GraphQL patterns
  2. graphql-cop -- specialized GraphQL security auditor (if available)

Record which scanners are available and which are missing.

3. Run Scanners (If Available)

If semgrep is available, run with rules targeting GraphQL:

semgrep scan --config auto --json --quiet <target>

Filter results to rules matching GraphQL security patterns. Normalize output to the findings schema.

4. Claude Code Analysis

Regardless of scanner availability, perform manual code analysis:

  1. Introspection check: Find GraphQL server configuration and verify introspection is disabled in production environments.
  2. Depth limiting: Check for depth limiting middleware (graphql-depth-limit, @graphql-tools/utils, custom validation rules).
  3. Complexity analysis: Verify query complexity is calculated and limited before execution (graphql-query-complexity, cost analysis).
  4. Batching controls: Check whether query batching is enabled and if there are limits on the number of operations per request.
  5. Alias abuse: Verify aliases are counted toward rate limiting and complexity calculations.
  6. Per-field authorization: Trace resolvers for sensitive fields and verify each checks the requesting user's permissions.

When --depth deep, additionally trace:

  • Full resolver chain from query to data source
  • Authorization directive/guard coverage across all types and fields
  • Subscription authentication and authorization

5. Report Findings

Format output per ../../shared/schemas/findings.md using the GQL prefix (e.g., GQL-001, GQL-002).

Include for each finding:

  • Severity and confidence
  • Exact file location with code snippet
  • Exploit scenario (example malicious query when applicable)
  • Concrete fix with diff when possible
  • CWE references

What to Look For

These are the high-signal patterns specific to GraphQL security. Each maps to a detection pattern in references/detection-patterns.md.

  1. Introspection enabled in production -- __schema and __type queries are accessible, revealing the entire API schema to attackers.
  2. No query depth limit -- Deeply nested queries can exhaust server resources (e.g., user {friends {friends {friends {...}}}}).
  3. No query complexity limit -- Expensive queries with many fields or computed values can cause denial of service.
  4. Batching abuse -- Multiple queries in a single request bypass per-request rate limiting and can brute-force authentication.
  5. Alias-based denial of service -- Using aliases to repeat expensive fields/resolvers many times in a single query.
  6. Missing per-field authorization -- Sensitive fields (email, SSN, balance) exposed to any authenticated user without field-level access checks.

Scanner Integration

ScannerCoverageCommand
semgrepIntrospection, missing auth directivessemgrep scan --config auto --json --quiet <target>
graphql-copIntrospection, depth, batching, aliasesgraphql-cop -t <endpoint>

Fallback (no scanner): Use Grep with patterns from references/detection-patterns.md to find GraphQL server configuration, depth/complexity middleware, resolver authorization, and batching settings. Report findings with confidence: medium.

Output Format

Use the findings schema from ../../shared/schemas/findings.md.

  • ID prefix: GQL (e.g., GQL-001)
  • metadata.tool: graphql
  • metadata.framework: specialized
  • metadata.category: GQL
  • references.cwe: CWE-200, CWE-400, CWE-862
  • references.owasp: A05:2021 (Security Misconfiguration)
  • references.stride: I (Information Disclosure) or D (Denial of Service)

Severity guidance for this category:

  • critical: Missing per-field auth on sensitive data, introspection exposing internal schemas
  • high: No depth or complexity limits, batching with no limits on auth endpoints
  • medium: Introspection enabled in prod (non-sensitive schema), alias abuse possible
  • low: Overly permissive but rate-limited batching, minor information disclosure

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

37.54%
按下载量换算29

Claude

30.43%
按下载量换算24

Cursor

18.3%
按下载量换算14

Gemini CLI

9.08%
按下载量换算7

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills