Skip to main content
Glama

api_graphql_fuzz

Fuzz GraphQL APIs to uncover hidden queries, mutations, and vulnerabilities by generating and sending malformed requests. Identify security issues like introspection leaks and injection points.

Instructions

GraphQL fuzz.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYes
depthNo
queryNo
Behavior1/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of behavioral disclosure. It fails to mention whether the fuzzing is destructive, what kind of requests are sent, what the 'depth' and 'query' parameters do, or any other behavioral characteristics.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness2/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is extremely concise to the point of under-specification. While it contains no wasted words, it omits essential details, making it inadequate rather than efficiently brief.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness1/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

This tool has 3 parameters, no annotations, no output schema, and no parameter descriptions. The description 'GraphQL fuzz' is wholly insufficient for an agent to select and invoke it correctly in the context of sibling tools.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters1/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, and the description provides no explanations for the three parameters (url, depth, query). The names hint at their roles but do not clarify required formats, defaults, or interactions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose2/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description 'GraphQL fuzz' is a fragment that vaguely indicates the tool performs fuzzing against GraphQL, but lacks a clear verb and full context. It does distinguish slightly from sibling tools like api_graphql_introspect, but is far too terse to clearly state its function.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines1/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

No guidance is provided on when to use this tool vs. alternatives such as api_fuzz_endpoint or api_ffuf_fuzz. There is no mention of target selection, prerequisites, or scenarios where this tool is preferred.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Install Server

Other Tools

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/cryptopepy/chungus-kali-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server