Broken Access Control

Security testing skill for A01:2025 Broken Access Control — the #1 OWASP risk for two consecutive cycles. Use this skill whenever the user asks about: access control vulnerabilities, IDOR (insecure direct object references), authorization bugs, SSRF testing, CORS misconfiguration, privilege escalation, JWT/session manipulation, CSRF protection, or auditing FastAPI/Flask endpoints for missing auth guards. Also trigger when the user says "test my API for access control", "check authorization", "find IDOR bugs", "review permissions", "audit my routes", or mentions CWE-284, CWE-285, CWE-352, CWE-639, CWE-862, or CWE-918.

scholarly360 1e7383c 2 files · 17.2 KB Updated

File contents

scholarly360/owasp-top10-web-skills/tree/main/skills/broken-access-control commit 1e7383c38b

Frequently asked questions

npx skillmds@latest add scholarly360/broken-access-control