hunt-broken-function-level-auth

Installation
SKILL.md

Broken Function Level Authorization

Hunt for endpoints where authorization is enforced at the controller/middleware level but bypassed through HTTP verb drift, legacy routes, shadow endpoints, or transport protocol inconsistencies. Unlike IDOR (object-level), this targets ACTION-level authorization — can a user invoke admin functions despite lacking the admin role.

When to Use

  • API has distinct user roles (admin, moderator, user) but role checks are per-controller, not per-method.
  • Legacy or deprecated endpoints still served behind updated middleware.
  • GraphQL, gRPC, and WebSocket transports exist alongside REST APIs without authorization parity.
  • Feature flags or beta endpoints expose functionality before security review.
  • Batch/job endpoints accept internal requests without role verification.

Quick Detection

Installs
11
GitHub Stars
1.2K
First Seen
Jul 9, 2026
hunt-broken-function-level-auth — uphiago/recon-skills