Audit authentication, resource scope, IDOR, and apply-time authorization.
Scanned 9/23/2026
npx -y skills add startmeupai/swe-agents --skill access-control-audit --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Access Control Audit?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/startmeupai-access-control-audit)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: access-control-audit
description: Audit authentication, resource scope, IDOR, and apply-time authorization.
---
# Access-Control Audit
## Trigger Conditions
Use after route/action changes or during a security review of authorization surfaces.
## Required Inputs
- Route/action inventory, auth helpers, resource identifiers, data queries, and actor profiles.
## Workflow
1. Enumerate public and protected entrypoints.
2. Confirm authentication precedes sensitive lookup.
3. Trace every identifier to tenant/project scope in the data query.
4. Confirm mutations re-authorize at apply time.
5. Inspect AI/tool-supplied identifiers and delayed operations.
6. Check both allowed and denied profiles and enumeration behavior.
## Deterministic Checks
- Entry-point inventory, guard search, scoped-query inspection, and positive/negative tests.
## Safety and Permission Boundaries
- Audit read-only; never test against real tenant data or widen access.
## Required Evidence
- Precise file locations, actor, reachable resource, missing control, and confirmed query path.
## Completion Condition
- Every in-scope entrypoint is assessed or explicitly listed as not reviewed.
## Example
`Audit Project Alpha settings routes for IDOR and apply-time authorization.`
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!