graphify
Supports Graphify query, path, and explain operations on graph.json. Identifies graphifyy as the package and /graphify as the slash command, while excluding graph.html as a query source.
Your agent can do more. Find the skill that makes it happen.
Find your next superpower If you are an agent, refer to our llms.txt for full access.Supports Graphify query, path, and explain operations on graph.json. Identifies graphifyy as the package and /graphify as the slash command, while excluding graph.html as a query source.
Creates a structural code index containing classes, functions, imports, and a call graph using tree-sitter. Supports exploration of unfamiliar codebases before code searches or after edits, with coverage for 12 languages.
Supports working with Graphite through the gt CLI. Covers creating, navigating, and managing pull request stacks.
Covers GraphQL schema design, resolvers, DataLoader for N+1 prevention, and federation for microservices. Includes Apollo/urql client integration and controls to prevent excessive query load, treating the schema as an API contract and documentation.
Provides a GraphQL and hidden-parameter testing playbook. Covers introspection, batching, undocumented fields, hidden parameters, schema abuse, and authorization gaps.
Builds GraphQL architectures with Apollo Federation and federation directives. Implements DataLoader-backed resolvers, query optimization, and real-time subscriptions.
Exploit GraphQL API architectural features to execute highly efficient brute-force, Credential Stuffing, and Denial of Service (DoS) attacks. Utilize Query Batching and Alias injection to bypass rate limits by packing thousands of requests into a single HTTP POST request.
Identify and exploit Insecure Direct Object Reference (IDOR) or Broken Object Level Authorization (BOLA) vulnerabilities specifically within GraphQL APIs. This skill focuses on manipulating node IDs, changing variables, and utilizing aliases to access unauthorized data.
Covers object-level authorization bypass in GraphQL APIs where introspection reveals hidden fields or mutations that accept arbitrary user/resource IDs without ownership checks. Trigger on keywords like "GraphQL", "query", "mutation", "introspection", "resolver", "node ID", "relay", "object type", "schema", "batching", or "alias". Applies to dual-stack REST+GraphQL apps, Relay-style global IDs, an…
Identify and exploit GraphQL API vulnerabilities by leveraging Introspection queries to dump the entire database schema, performing query batching to bypass rate limits (brute forcing), and extracting deeply nested unauthorized data via graph relationship abuse.
Exploit exposed GraphQL introspection endpoints to map the entire API schema. This skill details how to extract available queries, mutations, types, and fields, which significantly aids in identifying hidden endpoints, Broken Object Level Authorization (BOLA/IDOR), and mass assignment vulnerabilities.
Organize GraphQL operations with fragments and improve data fetching efficiency. Set up type generation or linting and review queries and mutations against best practices.
Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.
A name only tells half the story. Search the full description and instructions to find the right fit.
Read the skill, visit its source, and see exactly what you’re adding to your agent.
Copy the install command from a skill page and run it in your project.
npx skillycli add owner/repo --skill name