Screened · automated checks passed
idor-testing
What the author says it does
This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.
Quoted from the skill's own SKILL.md trigger description — this is what tells
Claude when to activate it. Not yet verified by us.
Automated screening
100/100 validator score
Scored by the same rules as our free SKILL.md validator: trigger description quality, body substance, structure. Automated — a human bench test is the next step in the pipeline.
Install (unverified — review first)
git clone https://github.com/zebbern/claude-code-guide # skill lives at: skills/idor-testing/SKILL.md
SkillProof status
This skill is in our test queue. We install every skill in a clean environment, run a trigger battery and score output against a baseline before it earns a catalog page — the full protocol is public. Until then, treat it like any unreviewed dependency: read the SKILL.md and any scripts before installing.
Already tested in Testing & QA
- Screen Reader Testing Screen reader testing playbook for VoiceOver, NVDA, and JAWS with ARIA fixes.
- Skill Security Auditor OWASP-mapped code/secrets/config audit with working bundled scan scripts
- Web Quality Audit Lighthouse-style audit across Performance, Accessibility, SEO, and Best Practices with severity tiers.
- OSINT Methodology Structured 5-stage external recon methodology with confidence levels, severity rubric, and OpSec rules.