pentest-idor

Community

Discover and exploit IDOR vulnerabilities.

Authoryhy0
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill helps penetration testers identify and exploit Insecure Direct Object Reference (IDOR) vulnerabilities, a common flaw allowing unauthorized access to sensitive data or resources.

Core Features & Use Cases

  • Attack Surface Discovery: Identifies high-risk API endpoints and parameters susceptible to IDOR.
  • Exploitation Techniques: Provides methods for testing and exploiting IDOR, including parameter tampering, HTTP method switching, and GraphQL manipulation.
  • Use Case: When testing an e-commerce API, use this Skill to systematically check if you can access or modify another user's order details by manipulating order IDs in API requests.

Quick Start

Use the pentest-idor skill to identify and test for insecure direct object reference vulnerabilities in the target API.

Dependency Matrix

Required Modules

None required

Components

scriptsreferences

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: pentest-idor
Download link: https://github.com/yhy0/ghsa-skill-builder/archive/main.zip#pentest-idor

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.