Skip to main content
在 Manus 中运行任何 Skill
一键导入

bola-bfla-hunter

星标15
分支7
更新时间2026年6月28日 16:46

Tests APIs for Broken Object-Level Authorization (API1:2023 BOLA - cross-user resource access by ID manipulation) and Broken Function-Level Authorization (API5:2023 BFLA - non-admin users reaching admin-only endpoints via URL guessing or HTTP-method swap). Complements idor-hunter for web apps; this is the API-specific sister skill with API-class methodology and OWASP API Top 10 mapping. Use when `api-recon` surfaced resource-ID parameters and multi-role endpoints; when the orchestrator identifies administrative paths; or when two test accounts at different privilege levels are available. Produces findings with CWE-639 / CWE-285 mapping and authorization-middleware remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly