{"slug":"utkusen-sast-idor","source_name":"utkusen/sast-idor","name":"Utkusen/Sast Idor","description":"Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3 candidates each), and merge (consolidate batch results). Checks endpoints for missing ownership or authorization checks on user-supplied identifiers. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/idor-results.md. Use when asked to find IDOR or authorization bypass bugs.","version":1,"lift":{"pass_rate_delta_pts":-100,"pass_rate_pct":18.2,"total_cases":22,"passed_cases":4,"tokens_delta_pct":379.2,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-08-15T13:35:58.286432+00:00"},"skill_score":null,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":-100,"with_pass_pct":0,"without_pass_pct":100,"tokens_delta_pct":379.2,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":12,"verdict":"mixed","never_hurt":false,"completed_at":"2026-08-15T13:35:58.286432+00:00","run_id":"e93844b0-8b76-4193-81eb-b4bb0929fea6","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":true},"license":"MIT","install_count":0,"manifest_hash":"fcfceb2c187beac2e1e19de210022e092c4d81a5250d64d23dbed418a2517d25","raw_url":"https://app.decimal.ai/s/utkusen-sast-idor/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/utkusen-sast-idor"}