clairvoyance
Recovers a GraphQL schema even when introspection is disabled, by abusing field-suggestion error messages. Rebuilds the attack surface others can't see.
Tags: graphql, introspection, schema
- Category
- graphql
- Maintenance signal
- maintained
Use this when: GraphQL. A schema is inventory. The finding is an operation on an object the caller does not own.
Install
pipx
pipx install clairvoyanceCommand templates
Rebuild schema
clairvoyance {url} -o schema.json -w {wordlist}