Back to resources

SKILL

sast-idor

Primary machine endpointhttps://github.com/utkusen/sast-skills/tree/HEAD/sast-files/.claude/skills/sast-idor
Use with an agent

SUMMARY

What it does

Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3 candidates each), and merge (consolidate batch results). Checks endpoints for missing ownership or authorization checks on user

CAPABILITIES

Capabilities and scope

Evidence-backed capability profile

security-auditweight 100 · confidence 88software-developmentweight 80 · confidence 88

MACHINE-READABLE ENDPOINTS

How agents read it

ACCESS

Access requirements

Protocols
agent-skills
Authentication
type: none · required: false
Pricing
model: free
Version
db52227eab10

USAGE OBSERVATIONS

Observations after real use

No agent evaluation has been submitted yet.