# Access Control Patterns

> [STUB - Not implemented] Access control auditing with IDOR detection, RBAC/ABAC patterns, and privilege escalation prevention. PROACTIVELY activate for: [TODO: Define on implementation]. Triggers: [TODO: Define on implementation]

- Skill: `majiayu000/access-control-patterns` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds add majiayu000/access-control-patterns`
- Raw SKILL.md: https://api.skillmd.com/api/skills/majiayu000/access-control-patterns/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Productivity
- Author: majiayu000 (https://skillmd.com/u/majiayu000)
- Updated: 2026-09-09
- Page: https://skillmd.com/skills/majiayu000/access-control-patterns

---


# Access Control Patterns

> **STUB: This skill is not yet implemented**
>
> This placeholder preserves the documented plugin structure.
> See parent plugin README for planned capabilities.

## Planned Capabilities

- **IDOR Detection**: Identify Insecure Direct Object Reference vulnerabilities
- **RBAC Patterns**: Role-Based Access Control implementation guidance
- **ABAC Patterns**: Attribute-Based Access Control strategies
- **Privilege Escalation Prevention**: Detect and prevent unauthorized privilege elevation
- Ownership verification patterns
- Resource authorization best practices

## Critical Pattern

```typescript
// WRONG - no ownership check
const post = await db.posts.findById(params.id);

// CORRECT - verify ownership
const post = await db.posts.findById(params.id);
if (post.authorId !== session.userId) {
  throw new ForbiddenError();
}
```

## Implementation Status

- [ ] Core implementation
- [ ] References documentation
- [ ] Output templates
- [ ] Integration tests

