offensive-idor
IDOR (Insecure Direct Object Reference) testing checklist: object ID enumeration, horizontal/vertical privilege escalation, GUID predictability, indirect references via hashes, chained IDOR, and API endpoint IDOR. Use for web app pentests and bug bounty IDOR discovery. Use when performing authorized red-team, pentest, or research work involving idor.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-idor/SKILL.md
- skills/offensive-idor/LICENSE
- skills/offensive-idor/README.md
- skills/offensive-idor/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.