hunt-fintech-graphql
Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding abuse, idempotency-key bypass enabling double-spend, KYC/PII field-level authorization gaps, and admin-over…
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphqlInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Finance & AccountingSupported Platforms
Our assessment of hunt-fintech-graphql
hunt-fintech-graphql scores 94/100 on our quality scale, 11th of 61 Finance & Accounting skills we index (top 19%).
Its SKILL.md is 14 KB long, split into 7 sections with 8 code examples: a thorough specification that gives an agent plenty to work with.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so hunt-fintech-graphql is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-28. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
hunt-fintech-graphql compared with similar skills
All 4 of these similar skills score higher than hunt-fintech-graphql; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-fintech-graphql (this skill)by elementalsouls | 94 | 4.7k | 2d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install hunt-fintech-graphql?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill hunt-fintech-graphql. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-fintech-graphql work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-fintech-graphql safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-fintech-graphql still maintained?
- The repository was last updated 2 days ago, so hunt-fintech-graphql is actively maintained.
Skill content
View source on GitHubname: hunt-fintech-graphql description: "Hunt fintech-specific GraphQL vulnerabilities: money-movement mutations (transfers, redemptions, withdrawals, card top-ups), ledger/balance/portfolio query IDOR, decimal-precision and rounding abuse, idempotency-key bypass enabling double-spend, KYC/PII field-level authorization gaps, and admin-override mutations reachable via mass assignment. Distinct from hunt-graphql, which owns generic GraphQL discovery and IDOR/mutation methodology — this skill owns the delta introduced when a GraphQL layer sits in front of a ledger, wallet, payments, banking, brokerage, or lending backend, where a resolver bug moves real money instead of just leaking data. Use when hunting a fintech, banking, payments, wallet, neobank, brokerage, or lending target that exposes a GraphQL API, or when a schema/response includes balance, transfer, ledger, redeem, quote, KYC, or account-linking fields." sources: owasp_api_top10_2023, public_research report_count: 0
Why Fintech GraphQL Is a Different Risk Class
Generic GraphQL bugs (IDOR, mass assignment, introspection, batching abuse — see hunt-graphql)
still apply here, but the blast radius changes completely: a resolver bug in a SaaS app leaks
data, the same class of bug in a ledger mutation moves money. Three properties make fintech
GraphQL backends a distinct hunting surface:
- Money-movement mutations are almost always resolvers over a double-entry ledger. A single
GraphQL mutation (
transferFunds,redeemRewards,withdrawToBank) can trigger multiple ledger writes (debit + credit + fee) that must be atomic. GraphQL's flexible input shape and alias batching make it easy to desynchronize those writes. - Decimals are attacker-controlled input, not display formatting. Amounts, exchange rates,
interest, and rewards points are usually passed as GraphQL scalars (
Float,String, customDecimal/Moneyscalar). How the resolver parses and rounds that value is exploitable surface in its own right — this barely exists in non-financial GraphQL APIs. - KYC/PII fields sit next to routine account fields in the same type.
UserorAccounttypes commonly exposessnLast4,routingNumber,kycStatus,governmentIdUrl, orlinkedBankAccountalongsidedisplayNameandemail— one missing field-level authorization check on a type used everywhere in the schema fans out to every query that touches it.
Attack Surface Signals
URL / schema naming patterns (in addition to hunt-graphql's generic /graphql list):
/graphql/ledger
/graphql/payments
/api/wallet/graphql
/internal/ledger-graphql
/banking/graphql
Field/type names worth grepping schema introspection or JS bundles for:
balance, availableBalance, pendingBalance, ledgerEntry, ledgerEntries
transferFunds, withdraw, redeem, topUp, reverseTransaction, adjustBalance
kycStatus, ssnLast4, routingNumber, accountNumber, governmentIdUrl
quoteExchangeRate, interestAccrued, rewardsPoints, portfolioValue
idempotencyKey, clientMutationId
Tech-stack tells specific to this vertical:
- Plaid/Stripe/Dwolla/Marqeta wrapped behind an internal GraphQL gateway (
bankLink,plaidLinkTokenmutations) - Apollo Federation with a dedicated
ledgerorpaymentssubgraph — check for the subgraph's own introspection being reachable directly, bypassing the gateway's stitched-down schema - Custom
Money/Decimal/BigDecimalGraphQL scalar in the schema (scalar Money) — the parser for this scalar is worth fuzzing directly
Run hunt-graphql's discovery + introspection methodology first to get the schema; everything
below assumes you already have (or have partially enumerated) a schema with money-movement types.
Step-by-Step Hunting Methodology
-
Map every mutation that touches balance, whether directly or as a side effect. Not just
transfer*/withdraw*— alsoredeemRewards,applyCoupon,upgradeTier,closeAccount(often refunds a balance),disputeTransaction(often provisionally credits). -
For each money-movement mutation, identify the ledger write shape. Does one mutation call produce one ledger entry or several (debit sender, credit receiver, fee entry)? Multi-entry writes are the ones worth racing — see Stage 4.
-
Test idempotency-key handling. Send the identical mutation (same
idempotencyKey/clientMutationId) twice, back-to-back and with a delay. A ledger write on the second call means idempotency isn't enforced server-side — replay = double-execute. -
Test decimal/precision edge cases on every amount-accepting argument — see Payload section. Confirm server-side rounding matches client-displayed rounding; a mismatch is directly monetizable.
-
Probe cross-account IDOR on account/portfolio node IDs, same as
hunt-idor/hunt-graphql, but specifically test whether atransferFunds-style mutation validates that the source account belongs to the authenticated caller — not just that some account with that ID exists. This is the fintech-specific IDOR: authz on the source of a debit is easy to forget when authz on the destination of a credit was correctly implemented (crediting an arbitrary account "looks safe" to a developer; debiting one clearly isn't, so it gets checked — but sometimes only one direction does). -
Check field-level authorization on KYC/PII fields by querying the shared
User/Accounttype from every context that returns it — not just the profile screen. Atransactiontype that embedscounterparty { ssnLast4 }is a common place for the check to be missing, because the developer authorized the top-leveltransactionquery but didn't re-check field access on the nestedcounterparty. -
Look for admin-tier mutations reachable via mass assignment, not just a missing auth check — e.g. an input object with a client-settable
statusoroverridefield that a normal user's mutation shouldn't expose but that the resolver accepts anyway (updateTransaction(input: {id, status: "COMPLETED", amount: "..."})). -
Test currency-argument consistency. Send a transfer/quote mutation with mismatched
sourceCurrency/targetCurrencycombinations the UI never generates (e.g. self-transfer with a currency conversion) and check whether the resolver's FX-rate lookup and the ledger write use the same rate — a TOCTOU window here is a direct arbitrage bug. -
Combine alias batching with money-movement mutations to test for double-spend — see
hunt-race-conditionfor the parallel-HTTP escalation once alias batching alone confirms the resolver isn't serializing writes per-account.
Payload & Detection Patterns
Idempotency-key replay test:
mutation {
transferFunds(input: {
idempotencyKey: "test-key-001"
sourceAccountId: "acc_1"
destAccountId: "acc_2"
amount: "10.00"
}) { transactionId status }
}
Send twice with the identical idempotencyKey. Two successful, distinct transactionId values
= idempotency not enforced.
Decimal-precision / rounding probes:
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "0.001"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "9999999999999999.99"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "1e2"}) { transactionId } }
mutation { transferFunds(input: {sourceAccountId:"acc_1", destAccountId:"acc_2", amount: "-50.00"}) { transactionId } }
Sub-cent amounts test truncate-vs-round handling (repeat N times to accumulate a rounding-error
balance drift); scientific notation and oversized values test whether the Money/Decimal
scalar parser falls back to a native float/int with overflow or precision-loss behavior; negative
amounts test whether the resolver assumes sign server-side or trusts the client's.
Alias-batched double-spend probe (confirm before escalating to parallel HTTP):
mutation {
r1: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
r2: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
r3: redeemRewards(input: {rewardId: "rwd_1", accountId: "acc_1"}) { success }
}
If more than one alias succeeds against a single-use reward/coupon, the resolver doesn't
serialize per-account/per-resource writes within a batched request — see hunt-race-condition
for combining this with parallel HTTP POSTs to confirm real double-spend impact.
Source-account authorization probe (asymmetric IDOR check):
mutation {
transferFunds(input: {
sourceAccountId: "VICTIM_ACCOUNT_ID"
destAccountId: "ATTACKER_CONTROLLED_ACCOUNT_ID"
amount: "1.00"
}) { transactionId status }
}
Run as the attacker's own session/token. Success = the resolver validated the destination is attacker-controlled (obviously required) but never validated that the source belongs to the caller.
Nested field-level PII probe:
query {
transaction(id: "txn_123") {
amount
counterparty { displayName ssnLast4 routingNumber kycStatus }
}
}
Query as a user with no relationship to the counterparty beyond a shared transaction; success on
the nested PII fields is the finding even if the top-level transaction query correctly scoped
the transaction itself.
Mass-assignment probe on admin-shaped input fields:
mutation {
updateTransaction(input: {id: "txn_123", status: "COMPLETED", amount: "0.01"}) { id status }
}
Send as a non-admin user against a mutation the client UI never exposes these fields for; a schema that accepts them anyway is mass assignment onto ledger state.
Common Root Causes
- Client-side amount/fee validation only. The UI computes and displays the correct amount; the resolver trusts whatever the GraphQL client actually sends, because "the app always sends the right value."
- Non-atomic multi-entry ledger writes. Debit, credit, and fee entries are written as separate sequential statements instead of inside a single transaction/lock — the race window this creates is exactly what alias batching + parallel HTTP exploits.
Money/Decimalscalar falls back to native float parsing under edge-case input (scientific notation, oversized strings), reintroducing floating-point rounding error into a system that was supposed to guarantee fixed-point precision.- Idempotency keys are stored but never checked before executing the write — the key is logged for support/debugging purposes, not used as a dedup gate.
- Field-level authorization implemented per top-level query, not per type. A
User/Accounttype's sensitive fields are protected when queried directly (me { ssnLast4 }) but not when the same type is returned nested inside an unrelated query (transaction { counterparty {...} }). - Source-account ownership check missing while destination-account existence check is present — see methodology step 5. Debiting looks dangerous so it gets reviewed; the "does this account belong to the caller" check quietly only gets applied to the credited side.
- Admin/internal mutations reuse the same input type as the public mutation, just with extra optional fields — nothing at the resolver layer strips those fields for non-admin callers.
Gate 0 Validation
Money-movement findings need a stricter bar than a typical GraphQL IDOR — "the query returns someone else's balance" is real impact; "I sent a malformed amount and got a 400" is not.
- Did an actual ledger write occur, and can you show it? Query the account balance before
and after — a state change (not just a
200/success response body) is the proof. - Is the win deterministic, not a timing fluke? For race/double-
Truncated for display — read the full file on GitHub.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
