Find broken authorization before attackers do.
application security
Tests applications and APIs for IDOR, BOLA, BFLA, and related authorization flaws.
When to use it
Use when requests expose identifiers, tenant boundaries, writable fields, or potentially missing object-level authorization.
Give it an application or API; it systematically tests cross-account authorization and reports evidence of confirmed access.
What you provide
This skill
application under test
Modifies other users' data (irreversible)
The workflow authenticates as UserB and uses that session token to replay UserA's requests.