acc-check-mass-assignment

Installation
SKILL.md

Mass Assignment Security Check (A01:2021)

Analyze PHP code for mass assignment vulnerabilities where user input directly populates model attributes.

Detection Patterns

1. Request::all() Passed to Create/Update

// CRITICAL: All request data used to create model
class UserController
{
    public function store(Request $request): Response
    {
        $user = User::create($request->all());
        // Attacker can set: is_admin=true, role=superadmin, balance=999999
        return new Response($user);
    }
}
Related skills
Installs
1
GitHub Stars
71
First Seen
Feb 11, 2026
Security Audits