{"slug":"utkusen-sast-missingauth","source_name":"utkusen/sast-missingauth","name":"Utkusen/Sast Missingauth","description":"Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify (check auth/authz in parallel subagents, 3 endpoints each), and merge (consolidate batch results). Covers unauthenticated access and vertical privilege escalation (e.g., regular user accessing admin-only functions). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/mis","version":1,"lift":{"pass_rate_delta_pts":36.36,"pass_rate_pct":81.8,"total_cases":22,"passed_cases":18,"tokens_delta_pct":319.7,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-08-14T13:05:27.702602+00:00"},"skill_score":null,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":36.36,"with_pass_pct":81.8,"without_pass_pct":45.5,"tokens_delta_pct":319.7,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":20,"verdict":"mixed","never_hurt":false,"completed_at":"2026-08-14T13:05:27.702602+00:00","run_id":"c30d544c-9aee-4e1a-99b6-1231268009d7","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":"safe","content_status":"clean","indexable":true},"license":"MIT","install_count":0,"manifest_hash":"ac5dc2be092a2e32fd01b8274da9f2508828057109f1c54f123d9cb1e62f2ce8","raw_url":"https://app.decimal.ai/s/utkusen-sast-missingauth/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/utkusen-sast-missingauth"}