Agent skill

Idor Testing

by zebbern in zebbern/claude-code-guide

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

MITAuto-check passedSecurity

Install Idor Testing

skills CLI
$ npx skills add zebbern/claude-code-guide --skill idor-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zebbern/claude-code-guide idor-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zebbern/claude-code-guide.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/idor-testing .claude/skills/idor-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
idor-testing
GitHub stars
4.6k
Used in
7 other repos
Token cost
~3.1k tokens
SKILL.md length
611 words
Files
1
Skills in repo
46
Repo updated
First seen
Licence
MIT

At a glance

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

  • Works in 5 steps: Understand IDOR Vulnerability Types → Reconnaissance and Setup → Detection Techniques → …
  • Asks to test for insecure direct object references
  • SKILL.md covers Purpose, Inputs / Prerequisites, Outputs / Deliverables and Core Workflow, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Idor Testing is an agent skill from zebbern/claude-code-guide. This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities, Authorization and RBAC and Penetration testing. It works with Burp Suite. The repository describes itself as: Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user! The licence is MIT.

When your agent uses it

  • Asks to test for insecure direct object references
  • Find IDOR vulnerabilities
  • Exploit broken access control
  • Enumerate user IDs

Example prompts

  • “test for insecure direct object references,”
  • “find IDOR vulnerabilities,”
  • “exploit broken access control,”
  • “/idor-testing”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Understand IDOR Vulnerability Types
  2. Reconnaissance and Setup
  3. Detection Techniques
  4. Exploitation with Burp Suite
  5. Common IDOR Locations

What it can do on your machine

Read from SKILL.md and the folder at commit 4698e3b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Idor Testing loads about 3.1k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 611 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zebbern/claude-code-guide at commit 4698e3b, republished under its MIT licence (© zebbern). 611 words, ~3,142 tokens.

Download SKILL.mdSave it as .claude/skills/idor-testing/SKILL.md (or your agent's skills folder).
name
idor-testing
description
This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.
metadata.author
zebbern
metadata.version
1.1

IDOR Vulnerability Testing

Purpose

Provide systematic methodologies for identifying and exploiting Insecure Direct Object Reference (IDOR) vulnerabilities in web applications. This skill covers both database object references and static file references, detection techniques using parameter manipulation and enumeration, exploitation via Burp Suite, and remediation strategies for securing applications against unauthorized access.

Inputs / Prerequisites

  • Target Web Application: URL of application with user-specific resources
  • Multiple User Accounts: At least two test accounts to verify cross-user access
  • Burp Suite or Proxy Tool: Intercepting proxy for request manipulation
  • Authorization: Written permission for security testing
  • Understanding of Application Flow: Knowledge of how objects are referenced (IDs, filenames)

Outputs / Deliverables

  • IDOR Vulnerability Report: Documentation of discovered access control bypasses
  • Proof of Concept: Evidence of unauthorized data access across user contexts
  • Affected Endpoints: List of vulnerable API endpoints and parameters
  • Impact Assessment: Classification of data exposure severity
  • Remediation Recommendations: Specific fixes for identified vulnerabilities

Core Workflow

1. Understand IDOR Vulnerability Types
Direct Reference to Database Objects

Occurs when applications reference database records via user-controllable parameters:

# Original URL (authenticated as User A)
example.com/user/profile?id=2023

# Manipulation attempt (accessing User B's data)
example.com/user/profile?id=2022
Direct Reference to Static Files

Occurs when applications expose file paths or names that can be enumerated:

# Original URL (User A's receipt)
example.com/static/receipt/205.pdf

# Manipulation attempt (User B's receipt)
example.com/static/receipt/200.pdf
2. Reconnaissance and Setup
Create Multiple Test Accounts
Account 1: "attacker" - Primary testing account
Account 2: "victim" - Account whose data we attempt to access
Identify Object References

Capture and analyze requests containing:

  • Numeric IDs in URLs: /api/user/123
  • Numeric IDs in parameters: ?id=123&action=view
  • Numeric IDs in request body: {"userId": 123}
  • File paths: /download/receipt_123.pdf
  • GUIDs/UUIDs: /profile/a1b2c3d4-e5f6-...
Map User IDs
# Access user ID endpoint (if available)
GET /api/user-id/

# Note ID patterns:
# - Sequential integers (1, 2, 3...)
# - Auto-incremented values
# - Predictable patterns
3. Detection Techniques
URL Parameter Manipulation
# Step 1: Capture original authenticated request
GET /api/user/profile?id=1001 HTTP/1.1
Cookie: session=attacker_session

# Step 2: Modify ID to target another user
GET /api/user/profile?id=1000 HTTP/1.1
Cookie: session=attacker_session

# Vulnerable if: Returns victim's data with attacker's session
Request Body Manipulation
# Original POST request
POST /api/address/update HTTP/1.1
Content-Type: application/json
Cookie: session=attacker_session

{"id": 5, "userId": 1001, "address": "123 Attacker St"}

# Modified request targeting victim
{"id": 5, "userId": 1000, "address": "123 Attacker St"}
HTTP Method Switching
# Original GET request may be protected
GET /api/admin/users/1000 → 403 Forbidden

# Try alternative methods
POST /api/admin/users/1000 → 200 OK (Vulnerable!)
PUT /api/admin/users/1000 → 200 OK (Vulnerable!)
4. Exploitation with Burp Suite
Manual Exploitation
1. Configure browser proxy through Burp Suite
2. Login as "attacker" user
3. Navigate to profile/data page
4. Enable Intercept in Proxy tab
5. Capture request with user ID
6. Modify ID to victim's ID
7. Forward request
8. Observe response for victim's data
Automated Enumeration with Intruder
1. Send request to Intruder (Ctrl+I)
2. Clear all payload positions
3. Select ID parameter as payload position
4. Configure attack type: Sniper
5. Payload settings:
   - Type: Numbers
   - Range: 1 to 10000
   - Step: 1
6. Start attack
7. Analyze responses for 200 status codes
Battering Ram Attack for Multiple Positions
# When same ID appears in multiple locations
PUT /api/addresses/§5§/update HTTP/1.1

{"id": §5§, "userId": 3}

Attack Type: Battering Ram
Payload: Numbers 1-1000
5. Common IDOR Locations
API Endpoints
/api/user/{id}
/api/profile/{id}
/api/order/{id}
/api/invoice/{id}
/api/document/{id}
/api/message/{id}
/api/address/{id}/update
/api/address/{id}/delete
File Downloads
/download/invoice_{id}.pdf
/static/receipts/{id}.pdf
/uploads/documents/{filename}
/files/reports/report_{date}_{id}.xlsx
Query Parameters
?userId=123
?orderId=456
?documentId=789
?file=report_123.pdf
?account=user@email.com

Quick Reference

IDOR Testing Checklist
TestMethodIndicator of Vulnerability
Increment/Decrement IDChange id=5 to id=4Returns different user's data
Use Victim's IDReplace with known victim IDAccess granted to victim's resources
Enumerate RangeTest IDs 1-1000Find valid records of other users
Negative ValuesTest id=-1 or id=0Unexpected data or errors
Large ValuesTest id=99999999System information disclosure
String IDsChange format id=user_123Logic bypass
GUID ManipulationModify UUID portionsPredictable UUID patterns
Response Analysis
Status CodeInterpretation
200 OKPotential IDOR - verify data ownership
403 ForbiddenAccess control working
404 Not FoundResource doesn't exist
401 UnauthorizedAuthentication required
500 ErrorPotential input validation issue
Show full SKILL.md (237 more words)Show less
Common Vulnerable Parameters
Parameter TypeExamples
User identifiersuserId, uid, user_id, account
Resource identifiersid, pid, docId, fileId
Order/TransactionorderId, transactionId, invoiceId
Message/CommunicationmessageId, threadId, chatId
File referencesfilename, file, document, path

Constraints and Limitations

Operational Boundaries
  • Requires at least two valid user accounts for verification
  • Some applications use session-bound tokens instead of IDs
  • GUID/UUID references harder to enumerate but not impossible
  • Rate limiting may restrict enumeration attempts
  • Some IDOR requires chained vulnerabilities to exploit
Detection Challenges
  • Horizontal privilege escalation (user-to-user) vs vertical (user-to-admin)
  • Blind IDOR where response doesn't confirm access
  • Time-based IDOR in asynchronous operations
  • IDOR in websocket communications
  • Only test applications with explicit authorization
  • Document all testing activities and findings
  • Do not access, modify, or exfiltrate real user data
  • Report findings through proper disclosure channels

Examples

Example 1: Basic ID Parameter IDOR
# Login as attacker (userId=1001)
# Navigate to profile page

# Original request
GET /api/profile?id=1001 HTTP/1.1
Cookie: session=abc123

# Response: Attacker's profile data

# Modified request (targeting victim userId=1000)
GET /api/profile?id=1000 HTTP/1.1
Cookie: session=abc123

# Vulnerable Response: Victim's profile data returned!
Example 2: IDOR in Address Update Endpoint
# Intercept address update request
PUT /api/addresses/5/update HTTP/1.1
Content-Type: application/json
Cookie: session=attacker_session

{
  "id": 5,
  "userId": 1001,
  "street": "123 Main St",
  "city": "Test City"
}

# Modify userId to victim's ID
{
  "id": 5,
  "userId": 1000,  # Changed from 1001
  "street": "Hacked Address",
  "city": "Exploit City"
}

# If 200 OK: Address created under victim's account
Example 3: Static File IDOR
# Download own receipt
GET /api/download/5 HTTP/1.1
Cookie: session=attacker_session

# Response: PDF of attacker's receipt (order #5)

# Attempt to access other receipts
GET /api/download/3 HTTP/1.1
Cookie: session=attacker_session

# Vulnerable Response: PDF of victim's receipt (order #3)!
Example 4: Burp Intruder Enumeration
# Configure Intruder attack
Target: PUT /api/addresses/§1§/update
Payload Position: Address ID in URL and body

Attack Configuration:
- Type: Battering Ram
- Payload: Numbers 0-20, Step 1

Body Template:
{
  "id": §1§,
  "userId": 3
}

# Analyze results:
# - 200 responses indicate successful modification
# - Check victim's account for new addresses
Example 5: Horizontal to Vertical Escalation
# Step 1: Enumerate user roles
GET /api/user/1 → {"role": "user", "id": 1}
GET /api/user/2 → {"role": "user", "id": 2}
GET /api/user/3 → {"role": "admin", "id": 3}

# Step 2: Access admin functions with discovered ID
GET /api/admin/dashboard?userId=3 HTTP/1.1
Cookie: session=regular_user_session

# If accessible: Vertical privilege escalation achieved

Troubleshooting

Issue: All Requests Return 403 Forbidden

Cause: Server-side access control is implemented Solution:

# Try alternative attack vectors:
1. HTTP method switching (GET → POST → PUT)
2. Add X-Original-URL or X-Rewrite-URL headers
3. Try parameter pollution: ?id=1001&id=1000
4. URL encoding variations: %31%30%30%30 for "1000"
5. Case variations for string IDs
Issue: Application Uses UUIDs Instead of Sequential IDs

Cause: Randomized identifiers reduce enumeration risk Solution:

# UUID discovery techniques:
1. Check response bodies for leaked UUIDs
2. Search JavaScript files for hardcoded UUIDs
3. Check API responses that list multiple objects
4. Look for UUID patterns in error messages
5. Try UUID v1 (time-based) prediction if applicable
Issue: Session Token Bound to User

Cause: Application validates session against requested resource Solution:

# Advanced bypass attempts:
1. Test for IDOR in unauthenticated endpoints
2. Check password reset/email verification flows
3. Look for IDOR in file upload/download
4. Test API versioning: /api/v1/ vs /api/v2/
5. Check mobile API endpoints (often less protected)
Issue: Rate Limiting Blocks Enumeration

Cause: Application implements request throttling Solution:

# Bypass techniques:
1. Add delays between requests (Burp Intruder throttle)
2. Rotate IP addresses (proxy chains)
3. Target specific high-value IDs instead of full range
4. Use different endpoints for same resources
5. Test during off-peak hours
Issue: Cannot Verify IDOR Impact

Cause: Response doesn't clearly indicate data ownership Solution:

# Verification methods:
1. Create unique identifiable data in victim account
2. Look for PII markers (name, email) in responses
3. Compare response lengths between users
4. Check for timing differences in responses
5. Use secondary indicators (creation dates, metadata)

Remediation Guidance

Implement Proper Access Control
python
# Django example - validate ownership
def update_address(request, address_id):
    address = Address.objects.get(id=address_id)
    
    # Verify ownership before allowing update
    if address.user != request.user:
        return HttpResponseForbidden("Unauthorized")
    
    # Proceed with update
    address.update(request.data)
Use Indirect References
python
# Instead of: /api/address/123
# Use: /api/address/current-user/billing

def get_address(request):
    # Always filter by authenticated user
    address = Address.objects.filter(user=request.user).first()
    return address
Server-Side Validation
python
# Always validate on server, never trust client input
def download_receipt(request, receipt_id):
    receipt = Receipt.objects.filter(
        id=receipt_id,
        user=request.user  # Critical: filter by current user
    ).first()
    
    if not receipt:
        return HttpResponseNotFound()
    
    return FileResponse(receipt.file)

© zebbern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/idor-testing of zebbern/claude-code-guide.

Open the folder on GitHubat commit 4698e3b

Used in 7 other repositories

We found 17 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in zebbern/claude-code-guide, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Idor Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Idor Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Idor Testing this skillzebbern/claude-code-guide4.6k7 repos~3.1kAutomated safety check: PassMIT
Burp MCP Vuln Checklangbyyi/CyberStrikeAI-SRC133—~3.1kAutomated safety check: PassApache-2.0
Exploiting SQL Injection With Sqlmapmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Burp Suite Testingaiskillstore/marketplace4304 repos~2.7kAutomated safety check: PassNone
Offensive API SecuritySnailSploit/Claude-Red7.3k—~5kAutomated safety check: PassMIT
Securitytelagod/code-abyss244—~907Automated safety check: PassMIT

Similar skills

  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    133 GitHub stars~3.1k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Exploiting SQL Injection With Sqlmap

    mukul975/Anthropic-Cybersecurity-Skills

    Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Burp Suite Testing

    aiskillstore/marketplace

    This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ...

    430 GitHub starsUsed in 4 repos~2.7k tokens
    SecurityAuto-check passed
  • Offensive API Security

    SnailSploit/Claude-Red

    Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces.

    7.3k GitHub stars~5k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Security

    telagod/code-abyss

    Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

    244 GitHub stars~907 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    67k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed

More from zebbern/claude-code-guide

All 46 skills in this repo
  • Localization Toolkit

    zebbern/claude-code-guide

    This skill should be used when setting up, auditing, or enforcing internationalization/localization in UI codebases (React/TS, i18next or similar, JSON locales), including installing/configuring the…

    4.6k GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed
  • Audit Flow

    zebbern/claude-code-guide

    Interactive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export.

    4.6k GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • Chart Image

    zebbern/claude-code-guide

    Generate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts.

    4.6k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Code To Diagram

    zebbern/claude-code-guide

    Analyze codebases and automatically generate architecture diagrams, flowcharts, and org charts.

    4.6k GitHub stars~972 tokensUpdated today
    Auto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.6k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Data Viz Renderer

    zebbern/claude-code-guide

    Generate self-contained HTML/SVG infographics from JSON data, including stat cards, bar charts, flow diagrams, and mixed dashboards.

    4.6k GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Idor Testing

What does Idor Testing do?

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…. Idor Testing is an agent skill from zebbern/claude-code-guide." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.

When should I use Idor Testing?

Idor Testing fits situations like: asks to test for insecure direct object references; find IDOR vulnerabilities; exploit broken access control; enumerate user IDs.

How do I install Idor Testing in Claude Code?

Run `npx skills add zebbern/claude-code-guide --skill idor-testing -a claude-code`. Or copy the skill folder (skills/idor-testing in zebbern/claude-code-guide) into .claude/skills/idor-testing in your project. Claude Code loads it when a task matches its description.

How do I install Idor Testing in Codex?

Run `npx skills add zebbern/claude-code-guide --skill idor-testing -a codex`. Or copy the skill folder (skills/idor-testing in zebbern/claude-code-guide) into .agents/skills/idor-testing in your project. Codex loads it when a task matches its description.

Can I use Idor Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zebbern/claude-code-guide --skill idor-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/idor-testing, .gemini/skills/idor-testing, .github/skills/idor-testing and .opencode/skills/idor-testing in your project.

What does Idor Testing need to run?

SKILL.md names no scripts, command-line tools or credentials: Idor Testing is instructions for the agent only. Our summary lists: Python 3.

Does Idor Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Idor Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Idor Testing use?

Idor Testing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Idor Testing use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Idor Testing?

Skills that share tags, products or a category with Idor Testing: Burp MCP Vuln Check (langbyyi/CyberStrikeAI-SRC, 133 stars), Exploiting SQL Injection With Sqlmap (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Burp Suite Testing (aiskillstore/marketplace, 430 stars) and Offensive API Security (SnailSploit/Claude-Red, 7.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Idor Testing?

zebbern (a GitHub user) maintains it in zebbern/claude-code-guide, which has 4,648 GitHub stars. The repository holds 46 skills in this directory. The repository was last updated on October 7, 2026.

Source: zebbern/claude-code-guide on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.