mitm-find-idor

Installation
SKILL.md

Find IDOR Vulnerabilities

Analyze the mitmproxy dump (log.txt) for IDOR vulnerabilities for: $ARGUMENTS

Requires: log.txt in the current directory. If it's missing, capture traffic first:

mitmdump --set flow_detail=3 2>&1 | tee log.txt

High-Value IDOR Patterns (from 132 real HackerOne bounty reports)

1. User/Account Object References

user_id, userId, user-id, uid, account_id, accountId
customer_id, customerId, member_id, memberId
profile_id, owner_id, creator_id, author_id

Real example: https://zomato.com/gold/payment-success?subscription_id=XXX&user_id=YYY

Related skills
Installs
13
GitHub Stars
49
First Seen
Mar 23, 2026