Agent skill

Marketplace Rbac Audit

by sickn33 in sickn33/agentic-awesome-skills

Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions.

MITAuto-check passedBackend & APIs

Install Marketplace Rbac Audit

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill marketplace-rbac-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills marketplace-rbac-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/marketplace-rbac-audit .claude/skills/marketplace-rbac-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
marketplace-rbac-audit
GitHub stars
47k
Used in
1 other repo
Token cost
~3.1k tokens
SKILL.md length
1,427 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions.

  • Works in 8 steps: Inventory Entry Points → Trace Identity and Scope → Trace Object Authorization → …
  • Access rules need evidence
  • SKILL.md covers Overview, When to Use This Skill, Establish the Authorization… and Build the Policy Matrix, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Marketplace Rbac Audit is an agent skill from sickn33/agentic-awesome-skills. Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Access rules need evidence
  • Not UI assumptions

Example prompts

  • “/marketplace-rbac-audit”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Inventory Entry Points
  2. Trace Identity and Scope
  3. Trace Object Authorization
  4. Check Field-Level Authorization
  5. Audit State Transitions
  6. Verify Indirect Paths
  7. Design Negative Tests
  8. Report Evidence and Gaps

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Marketplace Rbac Audit loads about 3.1k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 1,427 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,427 words, ~3,129 tokens.

Download SKILL.mdSave it as .claude/skills/marketplace-rbac-audit/SKILL.md (or your agent's skills folder).
name
marketplace-rbac-audit
description
Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions.
category
security
risk
safe
source
self
source_type
self
date_added
2026-09-12
author
mosinlshaikh
tags
marketplace, rbac, authorization, access-control, security
tools
claude, cursor, codex, gemini

Marketplace RBAC Audit

Overview

Audit authorization in marketplaces where customers, vendors, fulfillment staff, couriers, support agents, administrators, and service accounts act on shared orders and resources. Build an explicit policy matrix, trace enforcement from route to data access, and verify both allowed and denied behavior without treating hidden UI controls as security.

This is a read-only review by default. It does not grant permission to scan a live service, create test accounts, alter permissions, or access another person's data.

When to Use This Skill

  • Reviewing authorization in a marketplace, delivery platform, multi-vendor store, or fulfillment system.
  • Adding or changing roles, administrative powers, ownership rules, or order-state transitions.
  • Investigating whether one customer, vendor, courier, hub, or tenant can access another party's resources.
  • Preparing negative authorization tests before release or after an access-control incident.

Do not use this skill for authentication design alone, generic multi-tenant architecture, offensive ID enumeration, or penetration testing outside an explicitly authorized test environment.

Establish the Authorization Contract

Record the actual actors and resources instead of assuming standard role names.

For each actor, capture:

  • identity source and role-assignment authority;
  • tenant, organization, store, hub, region, or assignment scope;
  • resource relationships such as owner, seller, assigned courier, servicing hub, or support case;
  • permitted operations and state transitions;
  • emergency, support, delegated, and service-account access;
  • audit-log and approval requirements for privileged actions.

Separate these policy dimensions:

  1. Role — what this actor type may generally do.
  2. Relationship — which specific object the actor may access.
  3. Tenant or operational scope — where the permission applies.
  4. Resource state — whether the operation is valid now.
  5. Field scope — which attributes may be viewed or changed.

A matching role is not sufficient when ownership, assignment, tenant, state, or field rules fail.

Build the Policy Matrix

Create one row per meaningful actor-resource-operation combination.

FieldRequired content
ActorRole plus relevant tenant/store/hub/assignment
ResourceOrder, product, inventory, payout, address, profile, delivery, refund, or admin object
OperationList, view, create, update, delete, assign, transition, refund, export, or impersonate
RelationshipOwner, seller, assignee, servicing hub, same tenant, or none
Required stateOrder/payment/delivery state in which the operation is allowed
Field scopeAllowed and prohibited fields
Expected resultAllow or deny, including disclosure policy such as 403 versus 404
Enforcement pointRoute, policy layer, service, query predicate, database policy, or queue consumer
EvidenceCode reference, test ID, request ID, or audit event

Mark an undocumented decision as UNDEFINED; do not invent a permission merely because current code allows it.

Audit Workflow

1. Inventory Entry Points

Map HTTP routes, GraphQL operations, server actions, background jobs, webhooks, file downloads, exports, administrative tools, and queue consumers that access marketplace resources. Include bulk operations and alternate HTTP methods.

2. Trace Identity and Scope

For every entry point, trace how the authenticated principal becomes an authorization context. Confirm that role, tenant, store, hub, assignment, and delegation claims come from a trusted server-side source and are current enough for the operation.

Do not accept actor, tenant, owner, vendor, hub, courier, price, payout, or privilege fields from the request merely because they are present in a signed-in session.

3. Trace Object Authorization

Follow the resource identifier from request to data access. Prefer a scoped query or atomic mutation that includes every required predicate:

text
resource_id
+ tenant/store/hub scope
+ owner/seller/assignee relationship
+ permitted current state
= authorized object or no match

A separate “check then update” sequence may race with reassignment or state changes. Record where a transaction, conditional update, row-level lock, or equivalent consistency control is required.

4. Check Field-Level Authorization

Compare request and response schemas by role. Verify that mass assignment, serializer defaults, ORM spreads, exports, and error payloads cannot expose or change protected fields.

Examples of sensitive fields include:

  • another customer's address or contact details;
  • vendor settlement and payout configuration;
  • courier identity or precise location outside an active delivery need;
  • internal fraud, moderation, cost, or risk fields;
  • role, tenant, hub, assignment, price, refund, and payment-state attributes.
5. Audit State Transitions

Build an allowlist of valid transitions with authorized actors and invariants. For example, “assigned courier may mark picked up” is incomplete unless the order is assigned to that courier, is in the expected prior state, belongs to the same operational scope, and has not been cancelled.

Reject client-selected final states when the server should derive the transition. Verify idempotency and concurrency behavior for assignment, cancellation, refund, fulfillment, and delivery confirmation.

6. Verify Indirect Paths

Apply the same policy to:

  • nested resources and parent-child ownership;
  • invoice, receipt, label, media, and document downloads;
  • search, autocomplete, counts, and analytics;
  • bulk update, import, and export;
  • webhook and queue-triggered changes;
  • cached responses and pre-signed URLs;
  • support tools, impersonation, and “view as user” modes.

UI visibility is evidence of presentation only. A hidden button, disabled control, or unpublished link does not enforce authorization.

7. Design Negative Tests

Use synthetic identities and records in an authorized test environment. For every important allowed case, add the nearest denied cases:

  • same role, different owner;
  • same role, different vendor/store/hub/tenant;
  • correct role, wrong assignment;
  • correct relationship, invalid resource state;
  • expired, disabled, removed, or downgraded membership;
  • protected field added to an otherwise valid request;
  • bulk request containing one unauthorized object;
  • stale session after role or assignment revocation;
  • guessed nested-resource or download identifier.

Do not use real customer records as “victim” data. Do not enumerate identifiers or run live probes without explicit target authorization and a bounded test plan.

Show full SKILL.md (555 more words)Show less
8. Report Evidence and Gaps

Report confirmed behavior separately from code inference. A route with no test is not proven secure; mark it NOT VERIFIED. A permission with no owner is UNDEFINED.

Findings Format

text
MARKETPLACE RBAC AUDIT
Revision: <immutable source revision>
Environment: <code review or authorized test target>
Observed at: <UTC timestamp>

POLICY COVERAGE: <covered rows>/<required rows>
ALLOWED-PATH TESTS: PASS | FAIL | NOT VERIFIED
DENIED-PATH TESTS: PASS | FAIL | NOT VERIFIED
OBJECT OWNERSHIP: PASS | FAIL | NOT VERIFIED
TENANT/STORE/HUB ISOLATION: PASS | FAIL | NOT VERIFIED
STATE TRANSITIONS: PASS | FAIL | NOT VERIFIED
FIELD-LEVEL ACCESS: PASS | FAIL | NOT VERIFIED
INDIRECT PATHS: PASS | FAIL | NOT VERIFIED
PRIVILEGED ACTION AUDITABILITY: PASS | FAIL | NOT VERIFIED

OVERALL: PASS | FAIL | INCOMPLETE
Findings: <IDs with actor, resource, operation, evidence, and impact>
Undefined policies: <explicit list>
Untested paths: <explicit list>

Example Policy Rows

ActorResource and operationRelationship/stateExpected
CustomerView orderOwn orderAllow
CustomerView orderAnother customer's orderDeny
Vendor operatorUpdate productProduct belongs to vendor; editable stateAllow permitted fields only
Vendor operatorView payoutDifferent vendorDeny
CourierUpdate delivery statusAssigned delivery; valid next stateAllow one transition
CourierRead customer locationUnassigned or completed deliveryDeny
Hub operatorAssign courierOrder belongs to serviced hub; assignable stateAllow
Hub operatorRefund paymentNo refund permissionDeny
Support agentView orderActive support purposeAllow redacted fields and audit access
AdministratorChange user roleExplicit privilege plus required approvalAllow and emit audit event

Severity Guidance

  • Critical: cross-tenant administrative access, payout destination changes, role escalation, mass customer-data access, or unauthorized refunds.
  • High: cross-owner order/address access, unauthorized fulfillment transitions, courier location exposure, or vendor isolation failure.
  • Medium: excessive fields, missing privileged audit events, stale-role access, or enumeration through counts and metadata.
  • Low: policy/documentation gaps with no demonstrated access bypass.

Base severity on demonstrated reach, sensitivity, prerequisites, and business impact. Do not inflate severity from a role name alone.

Best Practices

  • Treat authorization as policy over role, relationship, scope, state, and fields.
  • Default new actor-resource-operation combinations to deny until explicitly defined.
  • Enforce policy server-side at every entry point, close to the data mutation.
  • Prefer reusable policy functions plus negative tests over scattered role-name checks.
  • Make role and assignment revocation effective within a defined, tested interval.
  • Require explicit approval and immutable audit events for high-impact privileged actions.
  • Re-run affected matrix rows after route, schema, role, workflow, or ownership changes.

Common Pitfalls

  • Problem: The frontend hides unauthorized actions. Solution: Test the backend operation directly with a synthetic unauthorized principal.

  • Problem: A vendor role can access every vendor's records. Solution: Require both the role and the resource's vendor/store relationship in the query.

  • Problem: A courier can submit any delivery state. Solution: Authorize one server-defined transition from the current state for the assigned courier.

  • Problem: An admin bypass silently applies to support agents. Solution: Define separate privileged operations, field scope, approval requirements, and audit events.

  • Problem: List endpoints are scoped but exports or downloads are not. Solution: Reuse the same policy at every direct and indirect resource path.

Limitations

  • A source review cannot prove runtime identity-provider configuration or database policies without corresponding evidence.
  • Negative tests prove only the identities, resources, operations, states, and environments exercised.
  • This skill does not replace threat modeling, authentication review, privacy assessment, or an authorized penetration test.
  • Marketplace policy varies by product and jurisdiction; unresolved business decisions must remain UNDEFINED.

Security & Safety Notes

  • Keep the audit read-only unless the user separately authorizes test creation or remediation.
  • Use synthetic identities and records; never test by accessing unrelated real users' data.
  • Redact tokens, session material, personal data, internal identifiers, and sensitive topology from evidence.
  • Stop before live probing, privilege changes, impersonation, bulk exports, or state-changing requests unless the exact action and target are authorized.
  • @api-security-best-practices — use for broader API authentication, validation, abuse controls, and secure implementation patterns.
  • @saas-multi-tenant — use for designing tenant isolation and PostgreSQL row-level security.
  • @idor-testing — use only for explicitly authorized offensive IDOR testing.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/marketplace-rbac-audit of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Marketplace Rbac Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Marketplace Rbac Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Marketplace Rbac Audit this skillsickn33/agentic-awesome-skills47k1 repos~3.1kAutomated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
Convex Setup Authspokvulcan/poker-planning1158 repos~1.8kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    spokvulcan/poker-planning

    Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.

    115 GitHub starsUsed in 8 repos~1.8k tokens
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Marketplace Rbac Audit

What does Marketplace Rbac Audit do?

Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions. Marketplace Rbac Audit is an agent skill from sickn33/agentic-awesome-skills. Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions.

When should I use Marketplace Rbac Audit?

Marketplace Rbac Audit fits situations like: access rules need evidence; not UI assumptions.

How do I install Marketplace Rbac Audit in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill marketplace-rbac-audit -a claude-code`. Or copy the skill folder (skills/marketplace-rbac-audit in sickn33/agentic-awesome-skills) into .claude/skills/marketplace-rbac-audit in your project. Claude Code loads it when a task matches its description.

How do I install Marketplace Rbac Audit in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill marketplace-rbac-audit -a codex`. Or copy the skill folder (skills/marketplace-rbac-audit in sickn33/agentic-awesome-skills) into .agents/skills/marketplace-rbac-audit in your project. Codex loads it when a task matches its description.

Can I use Marketplace Rbac Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill marketplace-rbac-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/marketplace-rbac-audit, .gemini/skills/marketplace-rbac-audit, .github/skills/marketplace-rbac-audit and .opencode/skills/marketplace-rbac-audit in your project.

What does Marketplace Rbac Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Marketplace Rbac Audit is instructions for the agent only.

Does Marketplace Rbac Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Marketplace Rbac Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Marketplace Rbac Audit use?

Marketplace Rbac Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Marketplace Rbac Audit use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Marketplace Rbac Audit?

Skills that share tags, products or a category with Marketplace Rbac Audit: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 115 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Marketplace Rbac Audit?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.