Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة

sast-idor

// Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3 candidates each), and merge (consolidate batch results). Checks endpoints for missing ownership or authorization checks on user-supplied identifiers. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/idor-results.md. Use when asked to find IDOR or authorization bypass bugs.

$ git log --oneline --stat
stars:٦٤٨
forks:٢٩
updated:٣١ مارس ٢٠٢٦ في ١٥:٥٤
SKILL.md
readonly