Skip to main content
Run any Skill in Manus
with one click

idor-hunter

Stars15
Forks7
UpdatedJune 28, 2026 at 16:46

Systematic testing for Insecure Direct Object Reference (IDOR) vulnerabilities in web applications. Use when auditing endpoints that expose resource identifiers in URLs, body parameters, headers, or cookies; when a multi-tenant app grants object access based on request-supplied IDs; or when the orchestrator identifies object-ID parameters during API recon. Produces findings with CWE-639 mapping, per-endpoint PoC request pairs, and developer-facing remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
3 files
SKILL.md
readonly