Hunt Idor
Encod3d-Sec/TORCH
IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…
A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…
$ npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install makifbaysal/tasktrooper access-control-and-idor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/catalog/agents/security-agent/skills/access-control-and-idor .claude/skills/access-control-and-idor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "access-control-and-idor" agent skill from https://github.com/makifbaysal/tasktrooper/tree/main/catalog/agents/security-agent/skills/access-control-and-idor into .claude/skills/access-control-and-idor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "access-control-and-idor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/makifbaysal/tasktrooper/tree/main/catalog/agents/security-agent/skills/access-control-and-idorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install makifbaysal/tasktrooper access-control-and-idor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .agents/skills && cp -r skills-src/catalog/agents/security-agent/skills/access-control-and-idor .agents/skills/access-control-and-idor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "access-control-and-idor" agent skill from https://github.com/makifbaysal/tasktrooper/tree/main/catalog/agents/security-agent/skills/access-control-and-idor into .agents/skills/access-control-and-idor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "access-control-and-idor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install makifbaysal/tasktrooper access-control-and-idor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/catalog/agents/security-agent/skills/access-control-and-idor .cursor/skills/access-control-and-idor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "access-control-and-idor" agent skill from https://github.com/makifbaysal/tasktrooper/tree/main/catalog/agents/security-agent/skills/access-control-and-idor into .cursor/skills/access-control-and-idor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "access-control-and-idor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/makifbaysal/tasktrooper.git --path catalog/agents/security-agent/skills/access-control-and-idor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install makifbaysal/tasktrooper access-control-and-idor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/catalog/agents/security-agent/skills/access-control-and-idor .gemini/skills/access-control-and-idor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "access-control-and-idor" agent skill from https://github.com/makifbaysal/tasktrooper/tree/main/catalog/agents/security-agent/skills/access-control-and-idor into .gemini/skills/access-control-and-idor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "access-control-and-idor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install makifbaysal/tasktrooper access-control-and-idorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .github/skills && cp -r skills-src/catalog/agents/security-agent/skills/access-control-and-idor .github/skills/access-control-and-idor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "access-control-and-idor" agent skill from https://github.com/makifbaysal/tasktrooper/tree/main/catalog/agents/security-agent/skills/access-control-and-idor into .github/skills/access-control-and-idor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "access-control-and-idor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install makifbaysal/tasktrooper access-control-and-idor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/makifbaysal/tasktrooper.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/catalog/agents/security-agent/skills/access-control-and-idor .opencode/skills/access-control-and-idor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "access-control-and-idor" agent skill from https://github.com/makifbaysal/tasktrooper/tree/main/catalog/agents/security-agent/skills/access-control-and-idor into .opencode/skills/access-control-and-idor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "access-control-and-idor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
access-control-and-idorA skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…
Access Control And Idor is an agent skill from makifbaysal/tasktrooper. Use when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level authorization, mass assignment and tenant scoping
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Web application vulnerabilities, Authorization and RBAC and GraphQL. The repository describes itself as: Local-first agent platform: board + role agents + agent CLI runs (Claude Code, Cursor, Antigravity, OpenCode) or local and API models (Ollama, LM Studio), all on your own Mac. The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 411ab00. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are go, kotlin, typescript, python and javascript).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
owasp.orggithub.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Access Control And Idor loads about 1.7k tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 623 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from makifbaysal/tasktrooper at commit 411ab00, republished under its Apache-2.0 licence (© makifbaysal). 623 words, ~1,674 tokens.
.claude/skills/access-control-and-idor/SKILL.md (or your agent's skills folder).Broken access control is the most common serious finding in real diffs, and it rarely looks dangerous: there is no exec, no string-built query — just a lookup by id with nothing after it. You find it by asking one question of every entry point the diff touches:
"If user A sends user B's id, what stops it?"
If the answer is not a line of code you can point at, it is a finding.
Enumerate every id the new code accepts: path, query, body, header, nested in a JSON object, inside a batch array, in a GraphQL argument, in a WebSocket message. Follow each to the data layer.
// ❌ any authenticated user reads any invoice
inv, err := h.repo.Get(ctx, r.PathValue("id"))
// ✅ scoped to the caller's organisation in the query itself
inv, err := h.repo.GetForOrg(ctx, r.PathValue("id"), auth.OrgID(ctx))// ❌ Spring: findById alone, the principal is never consulted
@GetMapping("/orders/{id}") fun get(@PathVariable id: UUID) = repo.findById(id)
// ✅ ownership is part of the lookup
@GetMapping("/orders/{id}") fun get(@PathVariable id: UUID, @AuthenticationPrincipal u: User) =
repo.findByIdAndCustomerId(id, u.customerId) ?: throw NotFound()Check the second id too: an endpoint that verifies the project in the path, then updates the task whose id is in the body, without checking the task belongs to that project.
// ❌ project ownership checked, task id from the body never tied to it
await assertProjectOwner(req.params.projectId, user.id);
await db.task.update({ where: { id: req.body.taskId }, data: { title } });
// ✅ the task is looked up inside the checked project
await db.task.update({ where: { id: req.body.taskId, projectId: req.params.projectId }, data: { title } });A privileged action needs a role check, not just "logged in".
requestMatchers(...).permitAll() or .authenticated() on an admin path; a @PreAuthorize removed from a method; a check on the URL that a second mapping of the same handler bypasses.@RolesAllowed where its class's siblings have one; @PermitAll added.permission_classes = [AllowAny], a view missing @login_required beside decorated siblings.# ❌ DRF: a staff-only action reachable by any authenticated user
@action(detail=True, methods=["post"])
def refund(self, request, pk=None): ...
# ✅ the action carries the same permission as the admin viewset
@action(detail=True, methods=["post"], permission_classes=[IsAdminUser])
def refund(self, request, pk=None): ...Binding a request straight onto an entity lets the client set fields it should not: role, isAdmin, ownerId, orgId, price, emailVerified.
// ❌ Mongoose: whatever the client sends becomes the document
const user = await User.create(req.body);
// ✅ an explicit allowlist of client-settable fields
const { name, email } = req.body;
const user = await User.create({ name, email });Equivalents: Django ModelForm / DRF serializer with fields = "__all__"; Spring @ModelAttribute or @RequestBody on a JPA entity; Rails params.permit!; Pydantic/request DTO that includes role; Go json.Decode into the domain struct. The response side is the mirror: returning the entity serialises passwordHash, internal flags or other users' rows in a list.
In multi-tenant code, every read and write needs the tenant predicate — including the ones people forget:
ids: [...] — each id must be checked, not the first.// ❌ a lookup error is treated as "no restriction"
perms, err := h.authz.For(ctx, userID)
if err == nil && !perms.CanDelete { return ErrForbidden }
return h.repo.Delete(ctx, id)
// ✅ any error denies
perms, err := h.authz.For(ctx, userID)
if err != nil || !perms.CanDelete { return ErrForbidden }Also: a switch on role with a permissive default; a feature flag that disables the check when unset; an inverted comparison.
GetForOwner may already scope the query.WHERE id = $1 with no second predicate on a caller-scoped resource.findById, get_object_or_404(Model, pk=pk), Model.findByPk(id) returning straight to the response.nil, true or falls through.OWASP API Security Top 10 2023 — API1 BOLA, API3 BOPLA, API5 BFLA · OWASP Top 10:2025 A01 Broken Access Control · ASVS 5.0 V8 Authorization
© makifbaysal, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in catalog/agents/security-agent/skills/access-control-and-idor of makifbaysal/tasktrooper.
Open the folder on GitHubat commit 411ab00
Access Control And Idor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Access Control And Idor this skillmakifbaysal/tasktrooper | 112 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Hunt IdorEncod3d-Sec/TORCH | 329 | — | ~2.6k | Automated safety check: Pass | MIT | |
| API Auditbriiirussell/cybersecurity-skills | 413 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Security Reviewlangfuse/langfuse | 36k | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| Security ConvexIgorWarzocha/Opencode-Workflows | 122 | — | ~3.1k | Automated safety check: Pass | None | |
| Security And Hardeningdzhalaevd/Donatello | 135 | — | ~5.1k | Automated safety check: Notes | Apache-2.0 |
Encod3d-Sec/TORCH
IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
langfuse/langfuse
Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.
IgorWarzocha/Opencode-Workflows
Review Convex security audit patterns for authentication and authorization.
dzhalaevd/Donatello
Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.
0xShe/PHP-Code-Audit-Skill
Yii 框架特效安全审计工具。针对 Yii(通常指 Yii2)访问控制(AccessControl/RBAC)、CSRF、输入过滤规则、输出编码策略、URL/重定向安全等进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/XSS/CFG/LOGIC 等)。
makifbaysal/tasktrooper
A skill your agent uses when writing acceptance criteria for a task - express each as an observable Given/When/Then that QA can execute, including negative cases
makifbaysal/tasktrooper
A skill your agent uses when a task changes any screen, form, dialog, menu or control - Lighthouse/axe scan of the changed screens, a keyboard walk, and the thresholds that fail a task
makifbaysal/tasktrooper
A skill your agent uses when deciding whether a request needs an analiz task before implementation - the conditions that require the architect's analysis versus going straight to implementation
makifbaysal/tasktrooper
A skill your agent uses when you write or revise the analiz deliverable - the ONE self-contained HTML report (spec and plan as sections) a human reviews passage by passage
makifbaysal/tasktrooper
A skill your agent uses when you finish an analiz report - the human must approve the analysis before any implementation task is created, via the analizreview column
makifbaysal/tasktrooper
A skill your agent uses when building native Android with Jetpack Compose - stateless composables, state hoisting, ViewModel-owned state, edge-to-edge, predictive back, adaptive layout, atomic…
Categories
A skill your agent uses when the diff adds or changes an endpoint, resolver, RPC, job or query that takes an object id, a role check, a request binding or a tenant filter - BOLA/IDOR, function-level…. Access Control And Idor is an agent skill from makifbaysal/tasktrooper.
Access Control And Idor fits situations like: changes an endpoint; query that takes an object id; A request binding; A tenant filter - BOLA/IDOR.
Run `npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a claude-code`. Or copy the skill folder (catalog/agents/security-agent/skills/access-control-and-idor in makifbaysal/tasktrooper) into .claude/skills/access-control-and-idor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a codex`. Or copy the skill folder (catalog/agents/security-agent/skills/access-control-and-idor in makifbaysal/tasktrooper) into .agents/skills/access-control-and-idor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add makifbaysal/tasktrooper --skill access-control-and-idor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/access-control-and-idor, .gemini/skills/access-control-and-idor, .github/skills/access-control-and-idor and .opencode/skills/access-control-and-idor in your project.
SKILL.md names no scripts, command-line tools or credentials: Access Control And Idor is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 2 domains. As links in the text: owasp.org and github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Access Control And Idor is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Access Control And Idor: Hunt Idor (Encod3d-Sec/TORCH, 329 stars), API Audit (briiirussell/cybersecurity-skills, 413 stars), Security Review (langfuse/langfuse, 36k stars) and Security Convex (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
makifbaysal (a GitHub user) maintains it in makifbaysal/tasktrooper, which has 112 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 10, 2026.
Source: makifbaysal/tasktrooper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.