Skip to main content
在 Manus 中运行任何 Skill
一键导入
$pwd:

escalate-auth-bypass

// Turn a suspected or confirmed authentication/authorization bypass into impact — admin access, session takeover, privilege escalation, or cross-tenant read. Use when you find a missing auth check on a route, a weak JWT verifier, a session cookie that's predictable or reusable across users, a privilege field client-controllable, or an audit finding tagged CWE-287/CWE-863/CWE-639. Walks from probe to admin-equivalent capability and persists a finding with the highest-impact action you reached.

$ git log --oneline --stat
stars:586
forks:90
updated:2026年5月23日 16:43
SKILL.md
readonly