Escalate Auth Bypass

Turn a suspected or confirmed authentication/authorization bypass into impact — admin access, session takeover, privilege escalation, or cross-tenant read. Use when you find a missing auth check on a route, a weak JWT verifier, a session cookie that's predictable or reusable across users, a privilege field client-controllable, or an audit finding tagged CWE-287/CWE-863/CWE-639. Walks from probe to admin-equivalent capability and persists a finding with the highest-impact action you reached.

vigolium c861cb1 5.8 KB Updated

File contents

vigolium/vigolium/tree/main/internal/resources/olium/skills/escalate-auth-bypass commit c861cb1ea3

Frequently asked questions

npx skillmds@latest add vigolium/escalate-auth-bypass