Skip to main content
Manus에서 모든 스킬 실행
원클릭으로
$pwd:

idor-blast-radius

// When you find an Insecure Direct Object Reference (a URL/body parameter that lets you read or write another user's object), quantify the blast radius — how many records reachable, what data class, whether write is also unauthorized — and persist a finding sized by real impact rather than by the existence of the flaw. Use when an ID parameter (numeric, UUID, hash, slug) changes the response content across IDs, when CWE-639/CWE-284 was flagged, or when an audit finding hints at object-level access control gaps.

$ git log --oneline --stat
stars:586
forks:90
updated:2026년 5월 23일 16:43
SKILL.md
readonly