Node.js GraphQL API client for Ghostwriter penetration test reporting platform.
Automate professional penetration test report generation, finding management, and client delivery workflows.
- β Authentication - JWT-based login and token management
- β Report Management - Create, read, update reports
- β Findings - Create, manage, and query security findings
- β Clients & Projects - List and query available clients and projects
- β Schema Introspection - Discover GraphQL schema at runtime
- β DOCX Formatting - Auto-format rich text for professional document export
- β Error Handling - Comprehensive error messages and validation
- β Self-Signed Certs - Support for self-signed SSL certificates
- β Severity Mapping - Automatic severity level translation
npm install ghostwriter-clientgit clone https://github.com/yourusername/ghostwriter-client.git
cd ghostwriter-client
npm installconst GhostwriterClient = require('ghostwriter-client');
// Initialize client
const gw = new GhostwriterClient({
url: process.env.GHOSTWRITER_URL,
username: process.env.GHOSTWRITER_USERNAME,
password: process.env.GHOSTWRITER_PASSWORD
});
// Authenticate
await gw.authenticate();
console.log('β Connected to Ghostwriter');
// Get projects
const projects = await gw.getProjects();
console.log(`Found ${projects.length} projects`);
// Create a report
const report = await gw.createReport(projectId, 'Penetration Test Report');
console.log(`Created report: ${report.id}`);
// Add findings
await gw.createFinding(report.id, {
title: 'SQL Injection Vulnerability',
severity: 'critical',
description: 'Application is vulnerable to SQL injection',
impact: 'Unauthorized database access',
mitigation: 'Use parameterized queries'
});GHOSTWRITER_URL=https://ghostwriter.example.com/v1/graphql
GHOSTWRITER_USERNAME=admin
GHOSTWRITER_PASSWORD=your-passwordawait gw.authenticate(username, password);
const user = await gw.whoami();
await gw.healthCheck();const clients = await gw.getClients();
const client = await gw.getClient(clientId);
const projects = await gw.getProjects();
const project = await gw.getProject(projectId);const reports = await gw.getReports(projectId);
const report = await gw.createReport(projectId, title, options);
await gw.updateReport(reportId, updates);const findings = await gw.getFindings(reportId);
await gw.createFinding(reportId, finding);
await gw.createFindings(reportId, findingsArray);
await gw.updateFinding(findingId, updates);const fields = await gw.introspectSchema();GHOSTWRITER_URL='https://...' \
GHOSTWRITER_USERNAME='admin' \
GHOSTWRITER_PASSWORD='password' \
node examples/full-test.jsnode examples/test-create-report.jsnode scripts/test-schema.jsnode examples/check-input-type.js report_insert_inputSee examples/ directory for more samples.
The client automatically accepts self-signed SSL certificates. To require certificate validation:
const gw = new GhostwriterClient({
url: 'https://ghostwriter.example.com/v1/graphql',
username: 'admin',
password: 'password',
rejectUnauthorized: true
});const gw = new GhostwriterClient({
url: process.env.GHOSTWRITER_URL,
username: process.env.GHOSTWRITER_USERNAME,
password: process.env.GHOSTWRITER_PASSWORD,
token: process.env.GHOSTWRITER_TOKEN, // Optional: use existing token
timeout: 30000 // Request timeout in ms
});# Test connection
node scripts/test-connection.js
# Test authentication
node examples/basic-auth.js# Discover available fields
node scripts/test-schema.js
# Check specific input type
node examples/check-input-type.js report_insert_inputSee GHOSTWRITER_BLOCKERS.md for known limitations and workarounds.
- SKILL.md - Comprehensive API reference
- SETUP.md - Installation and configuration guide
- INTEGRATION_GUIDE.md - Integrating with your applications
- GHOSTWRITER_BLOCKERS.md - Known issues and solutions
Contributions welcome! Please:
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit changes (
git commit -m 'Add amazing feature') - Push to branch (
git push origin feature/amazing-feature) - Open a Pull Request
This project is licensed under the MIT License - see LICENSE file for details.
- Ghostwriter - Professional penetration test reporting platform
- Hasura - GraphQL engine for PostgreSQL
For issues and questions:
- GitHub Issues: Report a bug
- Discussions: Ask a question
Made with β€οΈ for penetration testers