Hunt Idor

Investigate object-level and tenant authorization boundaries on authorized web or API targets. Use when typed routes or operator context expose object identifiers, account or tenant selectors, user-owned resources, GraphQL object lookups, or suspected cross-identity access.

duriantaco c571ec4 2 files · 1.8 KB Updated

File contents

duriantaco/ravage/tree/main/packages/ravage/src/ravage/agent_knowledge/builtin/hunt-idor commit c571ec48aa

Frequently asked questions

npx skillmds@latest add duriantaco/hunt-idor