Skip to content
Back to skills

Authz Review

ASecurity

Review authentication and authorization logic for missing or broken access checks

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
ai-agentsrustgosecurity

Works with

  • cli

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill authz-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Authz Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Authz Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-authz-review/badge)](https://www.skillsdirectory.com/skills/black141312-authz-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: authz-review
description: Review authentication and authorization logic for missing or broken access checks
category: security
---

# Authz Review

Use this to audit who-can-do-what: missing access checks, broken object-level authorization (IDOR), and privilege escalation paths.

1. List every protected resource and action, then map which endpoint/handler serves each and what check it performs.
2. Verify each handler enforces BOTH authentication (who you are) and authorization (what you may touch) — and that authorization is object-level, not just "is logged in".
3. Hunt for IDOR: any handler that reads an id from the request and fetches the record without scoping to the current user/tenant.
4. Check role/permission logic for default-allow, missing server-side enforcement (client-only gating), and admin routes lacking checks.
5. Inspect token/session handling: expiry, revocation, signature verification, and that role/tenant claims are server-validated, not trusted from the client.
6. Write a test (or curl repro) proving an unauthorized actor is now blocked for each gap found.

## Rules
- Default deny: access must be explicitly granted, never implicitly assumed.
- Enforce authorization on the server for every request — UI hiding is not a control.
- Scope every record lookup by owner/tenant; never trust an id alone from the client.
- Re-check authorization on every step of multi-step flows, not just the first.
- Confirm fixes with a negative test (the forbidden action returns 403/404), not just a happy-path test.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…