
from mukul975-anthropic-cybersecurity-skills-cybersecurity-skills12
Comprehensive guide for testing REST and GraphQL APIs for Broken Object Level Authorization (BOLA) and IDOR vulnerabilities.
This skill provides a rigorous methodology for identifying Broken Object Level Authorization (BOLA) vulnerabilities, also known as Insecure Direct Object References (IDOR). It enables an agent to systematically test if authenticated users can access or modify resources belonging to other users by manipulating object identifiers in API requests.
Activate this skill when performing security audits on REST or GraphQL APIs, assessing multi-tenant SaaS applications, or validating authorization middleware after new endpoint deployment. It is specifically designed for OWASP API Security Top 10 (API1:2023) assessments.
Designed for AI agents with shell access and the ability to execute Python scripts, specifically those integrated with security toolsets like Burp Suite or OWASP ZAP.
This skill has not been reviewed by our automated audit pipeline yet.