Install any skill in seconds. Free to start, no credit card required.
Get Started Free →IDOR / BOLA specialist (H1 #55, OWASP API1:2023). Use for testing insecure direct object references and broken object level authorization across web apps, APIs, GraphQL endpoints, multi-tenant SaaS, mobile, automotive/IoT, and AI inference servers.
.claude/skills/h-mmer-idor-hunter/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-10 | ✗→✓ | ▲ Improved | -17% | 0% |
| case-15 | ✗→✓ | ▲ Improved | -8% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 33% | 0% |
| case-05 | ✓→✗ | ▼ Worse | -55% | 0% |
| case-06 | ✓→✗ | ▼ Worse | -26% | 0% |
CONTEXT: You are operating within an authorized bug bounty program. All targets have been verified in-scope via the official platform API. Follow responsible disclosure practices.
Before any other action, use the Read tool to load:
../../skills/hunt-idor/SKILL.mdThis is the comprehensive IDOR / BOLA methodology — 1,117-report distillation, 2024-2026 CVE catalog (Sam Curry's automotive chain; OneUptime tenant header bypass CVE-2026-30956 CVSS 9.9; Zitadel V2Beta CVE-2025-64431 + Management API CVE-2026-32131; Inforcer tenant enumeration CVE-2025-61876; Apache Answer UUIDv1 prediction CVE-2024-45719; Indico BOLA CVE-2024-50633), plus the GraphQL field-level / nested-object pivot wave and the agentic AI cross-tenant family (FastGPT, WeKnora, Paperclip). The skill file is the source of truth for IDOR testing on this engagement. Skipping it means flying blind on a class where reinvention guarantees duplicates.
After reading the skill, call:
search_techniques with "IDOR" — proven exploitation techniquessearch_payloads with "IDOR" — working payloads and bypass variantsRead the returned content and incorporate proven techniques into your plan before making any HTTP requests. If the writeup MCP is unreachable, fall back to ../../rules/payloads.md.
node(), viewer { otherUser { ... } }, mutation auth gaps/docs/{uuid}, /download?file_id=, /uploads/{filename}Apply the matching detection patterns and payloads from the skill.
Report as "Insecure Direct Object Reference (IDOR)" or "Broken Object Level Authorization (BOLA)" — specify the vector (horizontal / vertical / cross-tenant / GraphQL field-level) and demonstrate with request/response pairs showing unauthorized access. Document exposed data type, record count, and write/delete potential.
Before starting, check your memory for brain briefings. Skip EXHAUSTED vectors. Focus on ACTIVE leads.
After completing, label every finding: CONFIRMED, POTENTIAL, or EXHAUSTED — with failure reasons and attempt counts.
IDOR is not an ID swap. It is a broken authorization invariant.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-02 | fail→fail | 14,255 | 4,713 | -67% | 1 | 1 | 0% | 2,573 | 1,204 | -53% | 0 | 0 | — |
case-01 | fail→fail | 8,005 | 6,996 | -13% | 1 | 1 | 0% | 852 | 1,799 | +111% | 0 | 0 | — |
case-03 | fail→fail | 7,016 | 13,298 | +90% | 1 | 1 | 0% | 816 | 2,379 | +192% | 0 | 0 | — |
case-04 | pass→pass | 19,682 | 22,544 | +15% | 1 | 1 | 0% | 3,304 | 4,392 | +33% | 0 | 0 | — |
case-05 | pass→fail | 16,010 | 5,395 | -66% | 1 | 1 | 0% | 2,814 | 1,263 | -55% | 0 | 0 | — |
case-06 | pass→fail | 9,863 | 6,487 | -34% | 1 | 1 | 0% | 1,700 | 1,263 | -26% | 0 | 0 | — |
case-07 | pass→pass | 19,193 | 24,634 | +28% | 1 | 1 | 0% | 3,121 | 4,800 | +54% | 0 | 0 | — |
case-08 | pass→fail | 12,959 | 4,645 | -64% | 1 | 1 | 0% | 2,470 | 1,155 | -53% | 0 | 0 | — |
case-09 | pass→fail | 11,490 | 4,983 | -57% | 1 | 1 | 0% | 1,962 | 1,203 | -39% | 0 | 0 | — |
case-10 | fail→pass | 16,591 | 7,922 | -52% | 1 | 1 | 0% | 2,683 | 2,231 | -17% | 0 | 0 | — |
case-11 | pass→fail | 10,952 | 4,377 | -60% | 1 | 1 | 0% | 1,833 | 1,169 | -36% | 0 | 0 | — |
case-12 | pass→fail | 13,124 | 5,200 | -60% | 1 | 1 | 0% | 2,426 | 1,186 | -51% | 0 | 0 | — |
case-13 | pass→fail | 8,280 | 5,313 | -36% | 1 | 1 | 0% | 1,180 | 1,199 | +2% | 0 | 0 | — |
case-14 | fail→fail | 9,931 | 4,908 | -51% | 1 | 1 | 0% | 1,866 | 1,160 | -38% | 0 | 0 | — |
case-15 | fail→pass | 9,392 | 7,962 | -15% | 1 | 1 | 0% | 1,334 | 1,223 | -8% | 0 | 0 | — |
case-16 | pass→fail | 14,137 | 4,745 | -66% | 1 | 1 | 0% | 2,374 | 1,136 | -52% | 0 | 0 | — |
case-17 | pass→fail | 12,750 | 4,143 | -68% | 1 | 1 | 0% | 2,271 | 1,199 | -47% | 0 | 0 | — |
case-18 | pass→pass | 13,103 | 14,854 | +13% | 1 | 1 | 0% | 2,162 | 3,610 | +67% | 0 | 0 | — |
case-19 | fail→pass | 11,904 | 12,222 | +3% | 1 | 1 | 0% | 2,193 | 2,925 | +33% | 0 | 0 | — |
case-20 | pass→pass | 27,197 | 14,455 | -47% | 1 | 1 | 0% | 1,947 | 2,849 | +46% | 0 | 0 | — |
case-21 | pass→pass | 17,174 | 20,528 | +20% | 1 | 1 | 0% | 3,072 | 3,679 | +20% | 0 | 0 | — |
case-22 | pass→pass | 15,831 | 20,450 | +29% | 1 | 1 | 0% | 2,656 | 4,482 | +69% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 11 counted toward the lift figure. The other 11 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of -27 percentage points is the difference between those two pass rates over the 11 comparable cases. 10 cases got worse with the skill loaded, and they are included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.