Agent skill

Access Control And Idor

by makifbaysal in makifbaysal/tasktrooper

A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…

Apache-2.0Auto-check passedSecurity

Install Access Control And Idor

skills CLI
$ npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install makifbaysal/tasktrooper access-control-and-idor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/agents/security-agent/skills/access-control-and-idor .claude/skills/access-control-and-idor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
access-control-and-idor
GitHub stars
112
Token cost
~1.7k tokens
SKILL.md length
623 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…

  • Works in 5 steps: Object-Level Authorization (BOLA / IDOR… → Function-Level Authorization (BFLA —… → Property-Level Authorization (mass… → …
  • Changes an endpoint
  • SKILL.md covers Overview, 1. Object-Level Authorization…, 2. Function-Level… and 3. Property-Level…, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Access Control And Idor is an agent skill from makifbaysal/tasktrooper. Use when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level authorization, mass assignment and tenant scoping

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Authorization and RBAC and GraphQL. The repository describes itself as: Local-first agent platform: board + role agents + agent CLI runs (Claude Code, Cursor, Antigravity, OpenCode) or local and API models (Ollama, LM Studio), all on your own Mac. The licence is Apache-2.0.

When your agent uses it

  • Changes an endpoint
  • Query that takes an object id
  • A request binding
  • A tenant filter - BOLA/IDOR

Example prompts

  • “/access-control-and-idor”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Object-Level Authorization (BOLA / IDOR — CWE-639, CWE-862)
  2. Function-Level Authorization (BFLA — CWE-285, CWE-863)
  3. Property-Level Authorization (mass assignment — CWE-915; excessive exposure — CWE-213)
  4. Tenant Scoping
  5. Failing Open (CWE-280, OWASP A10:2025)

What it can do on your machine

Read from SKILL.md and the folder at commit 411ab00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are go, kotlin, typescript, python and javascript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • owasp.org
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Access Control And Idor loads about 1.7k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 623 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from makifbaysal/tasktrooper at commit 411ab00, republished under its Apache-2.0 licence (© makifbaysal). 623 words, ~1,674 tokens.

Download SKILL.mdSave it as .claude/skills/access-control-and-idor/SKILL.md (or your agent's skills folder).
name
access-control-and-idor
description
Use when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level authorization, mass assignment and tenant scoping
category
security
tech_stack
Web & API
source
original; informed by trailofbits/skills (CC BY-SA 4.0, ideas only, own wording); OWASP API Security Top 10 2023, OWASP Top 10:2025 and ASVS 5.0 cited by name…

Access Control and IDOR

Overview

Broken access control is the most common serious finding in real diffs, and it rarely looks dangerous: there is no exec, no string-built query — just a lookup by id with nothing after it. You find it by asking one question of every entry point the diff touches:

"If user A sends user B's id, what stops it?"

If the answer is not a line of code you can point at, it is a finding.

1. Object-Level Authorization (BOLA / IDOR — CWE-639, CWE-862)

Enumerate every id the new code accepts: path, query, body, header, nested in a JSON object, inside a batch array, in a GraphQL argument, in a WebSocket message. Follow each to the data layer.

go
// ❌ any authenticated user reads any invoice
inv, err := h.repo.Get(ctx, r.PathValue("id"))

// ✅ scoped to the caller's organisation in the query itself
inv, err := h.repo.GetForOrg(ctx, r.PathValue("id"), auth.OrgID(ctx))
kotlin
// ❌ Spring: findById alone, the principal is never consulted
@GetMapping("/orders/{id}") fun get(@PathVariable id: UUID) = repo.findById(id)

// ✅ ownership is part of the lookup
@GetMapping("/orders/{id}") fun get(@PathVariable id: UUID, @AuthenticationPrincipal u: User) =
    repo.findByIdAndCustomerId(id, u.customerId) ?: throw NotFound()

Check the second id too: an endpoint that verifies the project in the path, then updates the task whose id is in the body, without checking the task belongs to that project.

ts
// ❌ project ownership checked, task id from the body never tied to it
await assertProjectOwner(req.params.projectId, user.id);
await db.task.update({ where: { id: req.body.taskId }, data: { title } });

// ✅ the task is looked up inside the checked project
await db.task.update({ where: { id: req.body.taskId, projectId: req.params.projectId }, data: { title } });

2. Function-Level Authorization (BFLA — CWE-285, CWE-863)

A privileged action needs a role check, not just "logged in".

  • Spring Security: a new requestMatchers(...).permitAll() or .authenticated() on an admin path; a @PreAuthorize removed from a method; a check on the URL that a second mapping of the same handler bypasses.
  • Quarkus: a new resource method with no @RolesAllowed where its class's siblings have one; @PermitAll added.
  • Express/Nest/Fastify: a route registered before the auth middleware, or on a router that never mounts it.
  • Django/DRF: permission_classes = [AllowAny], a view missing @login_required beside decorated siblings.
python
# ❌ DRF: a staff-only action reachable by any authenticated user
@action(detail=True, methods=["post"])
def refund(self, request, pk=None): ...

# ✅ the action carries the same permission as the admin viewset
@action(detail=True, methods=["post"], permission_classes=[IsAdminUser])
def refund(self, request, pk=None): ...

3. Property-Level Authorization (mass assignment — CWE-915; excessive exposure — CWE-213)

Binding a request straight onto an entity lets the client set fields it should not: role, isAdmin, ownerId, orgId, price, emailVerified.

js
// ❌ Mongoose: whatever the client sends becomes the document
const user = await User.create(req.body);

// ✅ an explicit allowlist of client-settable fields
const { name, email } = req.body;
const user = await User.create({ name, email });

Equivalents: Django ModelForm / DRF serializer with fields = "__all__"; Spring @ModelAttribute or @RequestBody on a JPA entity; Rails params.permit!; Pydantic/request DTO that includes role; Go json.Decode into the domain struct. The response side is the mirror: returning the entity serialises passwordHash, internal flags or other users' rows in a list.

4. Tenant Scoping

In multi-tenant code, every read and write needs the tenant predicate — including the ones people forget:

  • list/search/export/count endpoints and their pagination cursors;
  • background jobs and queue consumers that receive an id from a message;
  • caches keyed by object id without tenant (one tenant warms, another reads);
  • object storage keys built from a user-supplied filename;
  • GraphQL nested resolvers (the parent was checked, the child field loads by raw id);
  • batch endpoints taking ids: [...] — each id must be checked, not the first.
Show full SKILL.md (219 more words)Show less

5. Failing Open (CWE-280, OWASP A10:2025)

go
// ❌ a lookup error is treated as "no restriction"
perms, err := h.authz.For(ctx, userID)
if err == nil && !perms.CanDelete { return ErrForbidden }
return h.repo.Delete(ctx, id)

// ✅ any error denies
perms, err := h.authz.For(ctx, userID)
if err != nil || !perms.CanDelete { return ErrForbidden }

Also: a switch on role with a permissive default; a feature flag that disables the check when unset; an inverted comparison.

Severity Guide

  • Reading or changing another tenant's or user's data → HIGH; CRITICAL when unauthenticated, when it reaches credentials or payment data, or when it is admin takeover.
  • Exposure of non-sensitive fields of another user → MEDIUM.

Common Mistakes

  • Reporting "ids are guessable": UUIDs are not, and guessability is not the bug — the missing check is. A sequential id with a correct check is fine.
  • Missing a check that exists one layer down: read the repository method; GetForOwner may already scope the query.
  • Reporting a missing check in client code — find the server endpoint and judge that.
  • Treating 403 vs 404 as a vulnerability. Follow the repo's convention; it is not your finding.

Red Flags

  • WHERE id = $1 with no second predicate on a caller-scoped resource.
  • findById, get_object_or_404(Model, pk=pk), Model.findByPk(id) returning straight to the response.
  • A new route that its neighbours' middleware chain does not cover.
  • A request DTO that is also the entity.
  • An authorization helper whose error path returns nil, true or falls through.

OWASP API Security Top 10 2023 — API1 BOLA, API3 BOPLA, API5 BFLA · OWASP Top 10:2025 A01 Broken Access Control · ASVS 5.0 V8 Authorization

© makifbaysal, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in catalog/agents/security-agent/skills/access-control-and-idor of makifbaysal/tasktrooper.

Open the folder on GitHubat commit 411ab00

Compare with similar skills

Access Control And Idor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Access Control And Idor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Access Control And Idor this skillmakifbaysal/tasktrooper112—~1.7kAutomated safety check: PassApache-2.0
Hunt IdorEncod3d-Sec/TORCH329—~2.6kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Security Reviewlangfuse/langfuse36k—~1.4kAutomated safety check: PassCustom licence
Security ConvexIgorWarzocha/Opencode-Workflows122—~3.1kAutomated safety check: PassNone
Security And Hardeningdzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.0

Similar skills

  • Hunt Idor

    Encod3d-Sec/TORCH

    IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

    329 GitHub stars~2.6k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    36k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Security Convex

    IgorWarzocha/Opencode-Workflows

    Review Convex security audit patterns for authentication and authorization.

    122 GitHub stars~3.1k tokensUpdated 8 mo ago
    SecurityAuto-check passed
  • Security And Hardening

    dzhalaevd/Donatello

    Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

    135 GitHub stars~5.1k tokensUpdated 7 days ago
    SecurityAuto-check: notes
  • Php Yii Audit

    0xShe/PHP-Code-Audit-Skill

    Yii 框架特效安全审计工具。针对 Yii(通常指 Yii2)访问控制(AccessControl/RBAC)、CSRF、输入过滤规则、输出编码策略、URL/重定向安全等进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/CFG/LOGIC 等)。

    402 GitHub starsUsed in 1 repo~528 tokens
    SecurityAuto-check passed

More from makifbaysal/tasktrooper

All 12 skills in this repo
  • Acceptance Criteria Gwt

    makifbaysal/tasktrooper

    A skill your agent uses when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases

    112 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Accessibility Check

    makifbaysal/tasktrooper

    A skill your agent uses when a task changes any screen, form, dialog, menu or control - Lighthouse/axe scan of the changed screens, a keyboard walk, and the thresholds that fail a task

    112 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Analiz Gate

    makifbaysal/tasktrooper

    A skill your agent uses when deciding whether a request needs an analiz task before implementation - the conditions that require the architect's analysis versus going straight to implementation

    112 GitHub stars~679 tokensUpdated today
    Auto-check passed
  • Analiz HTML Report

    makifbaysal/tasktrooper

    A skill your agent uses when you write or revise the analiz deliverable - the ONE self-contained HTML report (spec and plan as sections) a human reviews passage by passage

    112 GitHub stars~3.9k tokensUpdated today
    Auto-check passed
  • Analiz Human Review Gate

    makifbaysal/tasktrooper

    A skill your agent uses when you finish an analiz report - the human must approve the analysis before any implementation task is created, via the analizreview column

    112 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Android Compose Patterns

    makifbaysal/tasktrooper

    A skill your agent uses when building native Android with Jetpack Compose - stateless composables, state hoisting, ViewModel-owned state, edge-to-edge, predictive back, adaptive layout, atomic…

    112 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed

Questions about Access Control And Idor

What does Access Control And Idor do?

A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…. Access Control And Idor is an agent skill from makifbaysal/tasktrooper.

When should I use Access Control And Idor?

Access Control And Idor fits situations like: changes an endpoint; query that takes an object id; A request binding; A tenant filter - BOLA/IDOR.

How do I install Access Control And Idor in Claude Code?

Run `npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a claude-code`. Or copy the skill folder (catalog/agents/security-agent/skills/access-control-and-idor in makifbaysal/tasktrooper) into .claude/skills/access-control-and-idor in your project. Claude Code loads it when a task matches its description.

How do I install Access Control And Idor in Codex?

Run `npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a codex`. Or copy the skill folder (catalog/agents/security-agent/skills/access-control-and-idor in makifbaysal/tasktrooper) into .agents/skills/access-control-and-idor in your project. Codex loads it when a task matches its description.

Can I use Access Control And Idor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/access-control-and-idor, .gemini/skills/access-control-and-idor, .github/skills/access-control-and-idor and .opencode/skills/access-control-and-idor in your project.

What does Access Control And Idor need to run?

SKILL.md names no scripts, command-line tools or credentials: Access Control And Idor is instructions for the agent only. Our summary lists: Python 3.

Does Access Control And Idor access the network?

SKILL.md names 2 domains. As links in the text: owasp.org and github.com. This is read from the text; nothing was executed.

Is Access Control And Idor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Access Control And Idor use?

Access Control And Idor is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Access Control And Idor use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Access Control And Idor?

Skills that share tags, products or a category with Access Control And Idor: Hunt Idor (Encod3d-Sec/TORCH, 329 stars), API Audit (briiirussell/cybersecurity-skills, 413 stars), Security Review (langfuse/langfuse, 36k stars) and Security Convex (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Access Control And Idor?

makifbaysal (a GitHub user) maintains it in makifbaysal/tasktrooper, which has 112 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 10, 2026.

Source: makifbaysal/tasktrooper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.