Audits GraphQL APIs for security misconfiguration and abuse — introspection/GraphiQL/playground exposed in production, missing query depth and complexity limits, resolver-level authorization gaps and IDOR, error/stacktrace/field-suggestion leakage, query-batching abuse, CSRF with cookie auth, and unbounded custom scalars. Covers Apollo, graphql-yoga, express-graphql, graphql-js, graphene/strawberry/ariadne, gqlgen, Hasura. Use when the project has a GraphQL server, .graphql schema files, or GraphQL dependencies.