SkillAgentSearch skills...

sast-missingauth

Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify (check auth/authz in parallel subagents, 3 endpoints each), and merge (consolidate batch results).

Install / Use

npx skills add utkusen/sast-skills --skill sast-missingauth

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

89/100

Supported Platforms

Universal

Tags

Our assessment of sast-missingauth

sast-missingauth scores 89/100 on our quality scale, 1190th of 4,259 Development & Engineering skills we index (top 28%).

Its SKILL.md is 23 KB long, well organised into 37 sections with 16 code examples: a thorough specification that gives an agent plenty to work with.

With 1,321 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
30/30
Structure
20/20
Description
15/15
Adoption
13/20
Freshness
11/15

Maintenance, license and trust

  • The repository was last updated about 6 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 98/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

sast-missingauth compared with similar skills

All 4 of these similar skills score higher than sast-missingauth; compare them before choosing.

SkillScoreStarsUpdatedFormat
sast-missingauth (this skill)by utkusen891.3k6mo agoSKILL.md
ai-job-searchby MadsLorentzen10044.6k1d agoCLAUDE.md
claude-howtoby luongnv8910041.7ktodayCLAUDE.md
algorithmic-artby anthropics100177.9k8d agoSKILL.md
pptxby anthropics100177.9k8d agoSKILL.md

Frequently asked questions

How do I install sast-missingauth?
Run npx skills add utkusen/sast-skills --skill sast-missingauth. The install tabs above show the steps for each supported agent.
Which AI agents does sast-missingauth work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is sast-missingauth safe to use?
It is MIT-licensed and scores 98/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is sast-missingauth still maintained?
The repository was last updated about 6 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.

name: sast-missingauth description: >- Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify (check auth/authz in parallel subagents, 3 endpoints each), and merge (consolidate batch results). Covers unauthenticated access and vertical privilege escalation (e.g., regular user accessing admin-only functions). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/missingauth-results.md. Use when asked to find missing auth, broken access control, or privilege escalation bugs.

Missing Authentication & Broken Function-Level Authorization Detection

You are performing a focused security assessment to find missing authentication and broken function-level authorization vulnerabilities in a codebase. This skill uses a three-phase approach with subagents: recon (map endpoints and the permission system), batched verify (check authentication and authorization in parallel batches of 3 endpoints each), and merge (consolidate batch results into the final report).

Prerequisites: sast/architecture.md must exist. Run the analysis skill first if it doesn't.


What This Skill Covers

Missing Authentication

An endpoint performs a sensitive action but requires no login at all — any anonymous HTTP request can trigger it.

Broken Function-Level Authorization

An endpoint requires authentication (user must be logged in) but does not check whether the authenticated user has the required role or permission to invoke that function. The classic example: a regular user calling an admin-only API.

What This Skill Is NOT

Do not conflate with:

  • IDOR / Horizontal privilege escalation: Authenticated user A accessing user B's resource by changing an ID. This skill covers vertical privilege escalation and unauthenticated access.
  • JWT weaknesses: Flawed token signing/verification (covered by sast-jwt).
  • Business logic flaws: Price manipulation, workflow bypass — these are separate.

Vulnerability Classes

Class 1: Unauthenticated Sensitive Endpoint

The endpoint modifies data, returns private information, or performs an administrative action — with no authentication required.

GET /api/admin/users          → returns full user list, no token needed
DELETE /api/admin/users/5     → deletes a user, no token needed
POST /api/settings/smtp       → updates server config, no token needed

Class 2: Authenticated but Missing Role Check

The endpoint requires a valid session/token but performs no role or permission check. Any authenticated user — regardless of role — can invoke admin or privileged functions.

Regular user sends:
DELETE /api/admin/users/5
Authorization: Bearer <regular_user_token>
→ Server deletes the user without checking if the caller is an admin

Class 3: Incomplete or Bypassable Authorization

Authorization logic is present but can be bypassed:

  • Role check exists in the GET handler but not in the corresponding DELETE/POST handler
  • Role check is conditional on a request header or parameter the attacker controls
  • Middleware is registered but the route is mounted before the middleware applies

Authorization Patterns That PREVENT Vulnerabilities

When you see these patterns, the endpoint is likely not vulnerable:

1. Authentication + role-check middleware on a route group

// Express: all /admin routes protected
router.use('/admin', auth, requireRole('admin'));
router.delete('/admin/users/:id', deleteUser);   // protected by above

// Flask-Login + custom decorator
@app.route('/admin/users')
@login_required
@admin_required
def list_users(): ...

2. Declarative role annotations (Java / Spring)

@PreAuthorize("hasRole('ADMIN')")
@DeleteMapping("/api/admin/users/{id}")
public ResponseEntity<?> deleteUser(@PathVariable Long id) { ... }

3. In-handler role check before sensitive action

# Django
@login_required
def delete_user(request, user_id):
    if not request.user.is_staff:
        return HttpResponseForbidden()
    User.objects.filter(id=user_id).delete()
    return HttpResponse(status=204)

4. Middleware gate applied to entire prefix

// Chi router — admin group protected
r.Group(func(r chi.Router) {
    r.Use(AdminOnly)
    r.Delete("/admin/users/{id}", deleteUser)
})

5. Policy/Gate objects

// Laravel Gate
Gate::define('admin-action', fn($user) => $user->role === 'admin');
// In controller
$this->authorize('admin-action');

Vulnerable vs. Secure Examples

Python — Django

# VULNERABLE: No authentication at all
def list_all_users(request):
    users = User.objects.values('id', 'email', 'is_staff')
    return JsonResponse(list(users), safe=False)

# VULNERABLE: Authenticated but no role check
@login_required
def delete_user(request, user_id):
    User.objects.filter(id=user_id).delete()
    return HttpResponse(status=204)

# SECURE
@login_required
def delete_user(request, user_id):
    if not request.user.is_staff:
        return HttpResponseForbidden()
    User.objects.filter(id=user_id).delete()
    return HttpResponse(status=204)

Python — Flask

# VULNERABLE: No auth decorator
@app.route('/admin/users')
def list_users():
    return jsonify([u.to_dict() for u in User.query.all()])

# VULNERABLE: Login required but no role check
@app.route('/admin/users/<int:user_id>', methods=['DELETE'])
@login_required
def delete_user(user_id):
    user = User.query.get_or_404(user_id)
    db.session.delete(user)
    db.session.commit()
    return '', 204

# SECURE
@app.route('/admin/users/<int:user_id>', methods=['DELETE'])
@login_required
def delete_user(user_id):
    if current_user.role != 'admin':
        abort(403)
    user = User.query.get_or_404(user_id)
    db.session.delete(user)
    db.session.commit()
    return '', 204

Node.js — Express

// VULNERABLE: No auth middleware
router.get('/api/admin/users', async (req, res) => {
    const users = await User.find({});
    res.json(users);
});

// VULNERABLE: Auth middleware present but no role check
router.delete('/api/admin/users/:id', auth, async (req, res) => {
    await User.findByIdAndDelete(req.params.id);
    res.sendStatus(204);
});

// SECURE
const requireAdmin = (req, res, next) => {
    if (req.user.role !== 'admin') return res.sendStatus(403);
    next();
};
router.delete('/api/admin/users/:id', auth, requireAdmin, async (req, res) => {
    await User.findByIdAndDelete(req.params.id);
    res.sendStatus(204);
});

Ruby on Rails

# VULNERABLE: No before_action
def destroy
    User.find(params[:id]).destroy
    head :no_content
end

# VULNERABLE: Authenticated but no admin check
before_action :authenticate_user!
def destroy
    User.find(params[:id]).destroy
    head :no_content
end

# SECURE
before_action :authenticate_user!
before_action :require_admin

def destroy
    User.find(params[:id]).destroy
    head :no_content
end

private

def require_admin
    head :forbidden unless current_user.admin?
end

Java — Spring Boot

// VULNERABLE: No security annotation
@DeleteMapping("/api/admin/users/{id}")
public ResponseEntity<?> deleteUser(@PathVariable Long id) {
    userRepo.deleteById(id);
    return ResponseEntity.noContent().build();
}

// VULNERABLE: Authenticated but wrong role
@DeleteMapping("/api/admin/users/{id}")
@Secured("ROLE_USER")  // any user can call this
public ResponseEntity<?> deleteUser(@PathVariable Long id) {
    userRepo.deleteById(id);
    return ResponseEntity.noContent().build();
}

// SECURE
@DeleteMapping("/api/admin/users/{id}")
@PreAuthorize("hasRole('ADMIN')")
public ResponseEntity<?> deleteUser(@PathVariable Long id) {
    userRepo.deleteById(id);
    return ResponseEntity.noContent().build();
}

Go

// VULNERABLE: No auth middleware on route
r.Delete("/admin/users/{id}", deleteUser)

// VULNERABLE: Auth middleware but no role check in handler
r.With(AuthMiddleware).Delete("/admin/users/{id}", deleteUser)

func deleteUser(w http.ResponseWriter, r *http.Request) {
    id := chi.URLParam(r, "id")
    db.DeleteUser(id)  // no role check
    w.WriteHeader(http.StatusNoContent)
}

// SECURE
r.Group(func(r chi.Router) {
    r.Use(AuthMiddleware)
    r.Use(AdminOnlyMiddleware)
    r.Delete("/admin/users/{id}", deleteUser)
})

PHP — Laravel

// VULNERABLE: No auth middleware
Route::delete('/admin/users/{id}', [AdminController::class, 'destroy']);

// VULNERABLE: Auth but no role gate
Route::middleware('auth')->delete('/admin/users/{id}', [AdminController::class, 'destroy']);

// SECURE
Route::middleware(['auth', 'role:admin'])->delete('/admin/users/{id}', [AdminController::class, 'destroy']);

// SECURE (using Gate in controller)
public function destroy($id) {
    Gate::authorize('admin-action');
    User::findOrFail($id)->delete();
    return response()->noContent();
}

C# — ASP.NET Core

// VULNERABLE: No authorization attribute
[HttpDelete("api/admin/users/{id}")]
public async Task<IActionResult> DeleteUser(int id) {
    await _userService.DeleteAsync(id);
    return NoContent();
}

// VULNERABLE: [Authorize] but no role
[Authorize]
[HttpDelete("api/admin/users/{id}")]
public async Task<IActionResult> DeleteUser(int id) {
    await _userService.DeleteAsync(id);
    return NoContent();
}

// SECURE
[Authorize(Roles = "Admin")]
[HttpDelete("api/admin/users/{id}")]
public async Task<IActionResult> DeleteUser(int id) {
    await _userService.DeleteAsync(id);
    return NoContent();
}

Execution

This skill runs in three phases using subagents. Pass the contents of sast/architecture.md to all subagents as context.

Phase 1: Recon — Map Endpoints and Permission System

Launch a subagent with the following instructions:

Goal: Build a complete map of (1) all application endpoints/routes and their current authentication/authorization posture, and (2) the role/permission system. Write results to sast/missingauth-recon.md.

Context: You will be given the project's architecture summary. Use it to understand the tech stack, frameworks, route definitions, and the auth/authz strategy.

What to search for:

  1. All route/endpoint definitions — collect every HTTP handler, REST endpoint, GraphQL mutation/query, RPC method, or WebSocket handler:
    • Express/Koa: router.get/post/put/delete/patch/use
    • Django: urlpatterns, path(), re_path()
    • Flask: @app.route, @blueprint.route
    • Rails: routes.rb — get, post, resources, namespace
    • Spring: @GetMapping, @PostMapping, @RequestMapping, @DeleteMapping, @PutMapping
    • Go/Chi: r.Get, r.Post, r.Delete, r.Handle
    • Laravel: Route::get/post/put/delete
    • FastAPI: @router.get/post/put/delete
    • ASP.NET: [HttpGet], [HttpPost], [HttpDelete], [HttpPut]
  2. Authentication middleware and decorators currently applied:
    • Identify the pattern used: @login_required, auth middleware, [Authorize], authenticate_user!, JWT verification middleware, session checks
    • Note which routes or route groups they are applied to
    • Note any routes explicitly excluded from auth (e.g., except: [:index, :show])
  3. Role/permission system — identify how roles are defined and checked:
    • Role constants/enums: ROLE_ADMIN, 'admin', UserRole.ADMIN, is_staff, is_superuser
    • Permission decorators: @admin_required, @roles_required, @PreAuthorize, requireRole()
    • Middleware: AdminOnly, requireAdmin, role:admin
    • Policy/Gate/Ability objects: Gate::define, Policy, CanCanCan, Pundit
    • In-handler checks: if user.role != 'admin', if not current_user.is_admin
  4. **Sensitive/privileged

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars1.3k
CategoryDevelopment
Updated5mo ago
Forks65

Trust signals

98/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 info