mass-assignment

Official

Exploit API mass assignment flaws.

Authorsecurityfortech
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill helps identify and exploit vulnerabilities in web applications and APIs where user-controlled input can be used to modify sensitive backend data fields that should not be directly accessible.

Core Features & Use Cases

  • Detects Mass Assignment: Identifies frameworks and endpoints susceptible to mass assignment.
  • Exploits Privilege Escalation: Attempts to gain administrative privileges by injecting role or isAdmin fields.
  • Facilitates IDOR: Enables changing ownership of resources by injecting ownerId or userId.
  • Use Case: An attacker can exploit a profile update endpoint to change their user role to administrator, gaining full control of the application.

Quick Start

Use the mass-assignment skill to test the PUT /api/users/me endpoint for privilege escalation by sending a payload with an admin role.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: mass-assignment
Download link: https://github.com/securityfortech/hacking-skills/archive/main.zip#mass-assignment

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.