CtrlK
BlogDocsLog inGet started
Tessl Logo

idor-testing

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," or "bypass authorization to access other users' data." It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications.

64

Quality

75%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/idor-testing/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

56%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Technically strong content with genuinely executable request-level guidance and a well-sequenced workflow, but it is a monolithic 440-line document whose Examples section largely duplicates the workflow sections and whose remediation/troubleshooting material should live in referenced files. Splitting the Examples, Troubleshooting, and Remediation sections into references and cutting the duplication would lift both the conciseness and progressive-disclosure scores.

Suggestions

Move Examples, Troubleshooting, and Remediation Guidance into separate one-level-deep files under references/ (e.g., references/examples.md, references/troubleshooting.md, references/remediation.md) and keep only concise pointers in SKILL.md.

Remove the Examples section entries that repeat the Detection Techniques and Burp Intruder workflows verbatim, keeping only the two examples (static file IDOR, horizontal-to-vertical escalation) that add new material.

Drop or trim content that teaches Claude what it already knows, such as the generic HTTP status-code interpretation table and the 'Occurs when applications reference database records' definitional prose.

DimensionReasoningScore

Conciseness

The ~440-line body is noticeably padded and repetitive: the Examples section (Examples 1–4) restates the detection and Burp Intruder workflows almost verbatim, and the "Response Analysis" table explains HTTP basics ("403 Forbidden | Access control working", "404 Not Found | Resource doesn't exist") that Claude already knows. It is above a 1 because the core workflow sections themselves are dense with concrete request/response detail rather than tutorial prose, but several sections are unnecessary duplication.

2 / 5

Actionability

Guidance is mostly executable: full HTTP requests with headers ("GET /api/user/profile?id=1001 ... Cookie: session=attacker_session"), step-by-step Burp Intruder configuration with payload type/range/step, and concrete Python remediation snippets. Not a 5 because the Python examples are simplified pseudo-Django (e.g., "address.update(request.data)") that would not run as written, and some troubleshooting steps ("Rotate IP addresses (proxy chains)") are hints rather than commands.

4 / 5

Workflow Clarity

The core workflow is clearly sequenced (understand types → recon/setup → detection → exploitation → locations), with per-step vulnerability indicators ("Vulnerable if: Returns victim's data with attacker's session", "verify data ownership") and a Troubleshooting section giving issue → cause → solution feedback loops. Although the Intruder enumeration is a batch operation, verification guidance is present (response analysis, the "Cannot Verify IDOR Impact" section), so the missing-validation cap does not apply; it stays at 4 rather than 5 because there is no consolidated end-of-run checklist ordering the validation steps.

4 / 5

Progressive Disclosure

The file has good section structure (Purpose, Inputs, Outputs, Core Workflow, Quick Reference, Examples, Troubleshooting, Remediation), but there is no bundle at all — no references/, scripts/, or assets/ — so roughly 200 lines of Examples, Troubleshooting, and Remediation guidance that clearly belong in separate one-level-deep reference files are inlined in SKILL.md. This matches the anchor for some structure with content that should be separate kept inline; not a 2 because headers and a quick-reference table keep it navigable.

3 / 5

Total

13

/

20

Passed

Description

95%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: explicit third-person 'what' plus a well-quoted 'when' clause with natural trigger phrases and good synonym coverage. Its only weakness is that the capability list stays at a moderately high level (detect/exploit/remediate) rather than enumerating the specific techniques the skill body actually delivers.

DimensionReasoningScore

Specificity

The description names the domain ("IDOR vulnerabilities in web applications") and several specific actions — "detecting, exploiting, and remediating" — which matches the anchor for several specific actions with minor gaps. It falls short of a 5 because the actions are stated at a moderately high level without finer-grained capabilities (e.g., parameter manipulation, enumeration, Burp-based testing) that the skill actually covers.

4 / 5

Completeness

It explicitly answers 'when' ("This skill should be used when the user asks to ...") with concrete quoted trigger phrases, and 'what' ("It provides comprehensive guidance for detecting, exploiting, and remediating IDOR vulnerabilities in web applications"). Both halves are explicit with concrete triggers, matching the top anchor exactly.

5 / 5

Trigger Term Quality

Quoted trigger phrases — "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references," "bypass authorization to access other users' data" — cover the natural phrasings and synonyms (IDOR, broken access control, authorization bypass, enumeration) a user would say. Not a 4 because no common natural variant is missing; the phrase list is comprehensive for this niche.

5 / 5

Distinctiveness Conflict Risk

The description carves out a clear niche (IDOR / object-reference access-control testing) with distinct quoted triggers, so it is unlikely to fire for unrelated skills. The mildly broad phrase "exploit broken access control" gives only minimal overlap risk with general web-security skills, keeping it at the top anchor rather than signaling a real conflict.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.