sast-missingauth
Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify (check auth/authz in parallel subagents, 3 endpoints each), and merge (consolidate batch results).
Install / Use
npx skills add utkusen/sast-skills --skill sast-missingauthInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Tags
Our assessment of sast-missingauth
sast-missingauth scores 89/100 on our quality scale, 1190th of 4,259 Development & Engineering skills we index (top 28%).
Its SKILL.md is 23 KB long, well organised into 37 sections with 16 code examples: a thorough specification that gives an agent plenty to work with.
With 1,321 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated about 6 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 98/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
sast-missingauth compared with similar skills
All 4 of these similar skills score higher than sast-missingauth; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| sast-missingauth (this skill)by utkusen | 89 | 1.3k | 6mo ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.6k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | today | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
Frequently asked questions
- How do I install sast-missingauth?
- Run
npx skills add utkusen/sast-skills --skill sast-missingauth. The install tabs above show the steps for each supported agent. - Which AI agents does sast-missingauth work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is sast-missingauth safe to use?
- It is MIT-licensed and scores 98/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is sast-missingauth still maintained?
- The repository was last updated about 6 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
Skill content
View source on GitHubname: sast-missingauth description: >- Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify (check auth/authz in parallel subagents, 3 endpoints each), and merge (consolidate batch results). Covers unauthenticated access and vertical privilege escalation (e.g., regular user accessing admin-only functions). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/missingauth-results.md. Use when asked to find missing auth, broken access control, or privilege escalation bugs.
Missing Authentication & Broken Function-Level Authorization Detection
You are performing a focused security assessment to find missing authentication and broken function-level authorization vulnerabilities in a codebase. This skill uses a three-phase approach with subagents: recon (map endpoints and the permission system), batched verify (check authentication and authorization in parallel batches of 3 endpoints each), and merge (consolidate batch results into the final report).
Prerequisites: sast/architecture.md must exist. Run the analysis skill first if it doesn't.
What This Skill Covers
Missing Authentication
An endpoint performs a sensitive action but requires no login at all — any anonymous HTTP request can trigger it.
Broken Function-Level Authorization
An endpoint requires authentication (user must be logged in) but does not check whether the authenticated user has the required role or permission to invoke that function. The classic example: a regular user calling an admin-only API.
What This Skill Is NOT
Do not conflate with:
- IDOR / Horizontal privilege escalation: Authenticated user A accessing user B's resource by changing an ID. This skill covers vertical privilege escalation and unauthenticated access.
- JWT weaknesses: Flawed token signing/verification (covered by sast-jwt).
- Business logic flaws: Price manipulation, workflow bypass — these are separate.
Vulnerability Classes
Class 1: Unauthenticated Sensitive Endpoint
The endpoint modifies data, returns private information, or performs an administrative action — with no authentication required.
GET /api/admin/users → returns full user list, no token needed
DELETE /api/admin/users/5 → deletes a user, no token needed
POST /api/settings/smtp → updates server config, no token needed
Class 2: Authenticated but Missing Role Check
The endpoint requires a valid session/token but performs no role or permission check. Any authenticated user — regardless of role — can invoke admin or privileged functions.
Regular user sends:
DELETE /api/admin/users/5
Authorization: Bearer <regular_user_token>
→ Server deletes the user without checking if the caller is an admin
Class 3: Incomplete or Bypassable Authorization
Authorization logic is present but can be bypassed:
- Role check exists in the GET handler but not in the corresponding DELETE/POST handler
- Role check is conditional on a request header or parameter the attacker controls
- Middleware is registered but the route is mounted before the middleware applies
Authorization Patterns That PREVENT Vulnerabilities
When you see these patterns, the endpoint is likely not vulnerable:
1. Authentication + role-check middleware on a route group
// Express: all /admin routes protected
router.use('/admin', auth, requireRole('admin'));
router.delete('/admin/users/:id', deleteUser); // protected by above
// Flask-Login + custom decorator
@app.route('/admin/users')
@login_required
@admin_required
def list_users(): ...
2. Declarative role annotations (Java / Spring)
@PreAuthorize("hasRole('ADMIN')")
@DeleteMapping("/api/admin/users/{id}")
public ResponseEntity<?> deleteUser(@PathVariable Long id) { ... }
3. In-handler role check before sensitive action
# Django
@login_required
def delete_user(request, user_id):
if not request.user.is_staff:
return HttpResponseForbidden()
User.objects.filter(id=user_id).delete()
return HttpResponse(status=204)
4. Middleware gate applied to entire prefix
// Chi router — admin group protected
r.Group(func(r chi.Router) {
r.Use(AdminOnly)
r.Delete("/admin/users/{id}", deleteUser)
})
5. Policy/Gate objects
// Laravel Gate
Gate::define('admin-action', fn($user) => $user->role === 'admin');
// In controller
$this->authorize('admin-action');
Vulnerable vs. Secure Examples
Python — Django
# VULNERABLE: No authentication at all
def list_all_users(request):
users = User.objects.values('id', 'email', 'is_staff')
return JsonResponse(list(users), safe=False)
# VULNERABLE: Authenticated but no role check
@login_required
def delete_user(request, user_id):
User.objects.filter(id=user_id).delete()
return HttpResponse(status=204)
# SECURE
@login_required
def delete_user(request, user_id):
if not request.user.is_staff:
return HttpResponseForbidden()
User.objects.filter(id=user_id).delete()
return HttpResponse(status=204)
Python — Flask
# VULNERABLE: No auth decorator
@app.route('/admin/users')
def list_users():
return jsonify([u.to_dict() for u in User.query.all()])
# VULNERABLE: Login required but no role check
@app.route('/admin/users/<int:user_id>', methods=['DELETE'])
@login_required
def delete_user(user_id):
user = User.query.get_or_404(user_id)
db.session.delete(user)
db.session.commit()
return '', 204
# SECURE
@app.route('/admin/users/<int:user_id>', methods=['DELETE'])
@login_required
def delete_user(user_id):
if current_user.role != 'admin':
abort(403)
user = User.query.get_or_404(user_id)
db.session.delete(user)
db.session.commit()
return '', 204
Node.js — Express
// VULNERABLE: No auth middleware
router.get('/api/admin/users', async (req, res) => {
const users = await User.find({});
res.json(users);
});
// VULNERABLE: Auth middleware present but no role check
router.delete('/api/admin/users/:id', auth, async (req, res) => {
await User.findByIdAndDelete(req.params.id);
res.sendStatus(204);
});
// SECURE
const requireAdmin = (req, res, next) => {
if (req.user.role !== 'admin') return res.sendStatus(403);
next();
};
router.delete('/api/admin/users/:id', auth, requireAdmin, async (req, res) => {
await User.findByIdAndDelete(req.params.id);
res.sendStatus(204);
});
Ruby on Rails
# VULNERABLE: No before_action
def destroy
User.find(params[:id]).destroy
head :no_content
end
# VULNERABLE: Authenticated but no admin check
before_action :authenticate_user!
def destroy
User.find(params[:id]).destroy
head :no_content
end
# SECURE
before_action :authenticate_user!
before_action :require_admin
def destroy
User.find(params[:id]).destroy
head :no_content
end
private
def require_admin
head :forbidden unless current_user.admin?
end
Java — Spring Boot
// VULNERABLE: No security annotation
@DeleteMapping("/api/admin/users/{id}")
public ResponseEntity<?> deleteUser(@PathVariable Long id) {
userRepo.deleteById(id);
return ResponseEntity.noContent().build();
}
// VULNERABLE: Authenticated but wrong role
@DeleteMapping("/api/admin/users/{id}")
@Secured("ROLE_USER") // any user can call this
public ResponseEntity<?> deleteUser(@PathVariable Long id) {
userRepo.deleteById(id);
return ResponseEntity.noContent().build();
}
// SECURE
@DeleteMapping("/api/admin/users/{id}")
@PreAuthorize("hasRole('ADMIN')")
public ResponseEntity<?> deleteUser(@PathVariable Long id) {
userRepo.deleteById(id);
return ResponseEntity.noContent().build();
}
Go
// VULNERABLE: No auth middleware on route
r.Delete("/admin/users/{id}", deleteUser)
// VULNERABLE: Auth middleware but no role check in handler
r.With(AuthMiddleware).Delete("/admin/users/{id}", deleteUser)
func deleteUser(w http.ResponseWriter, r *http.Request) {
id := chi.URLParam(r, "id")
db.DeleteUser(id) // no role check
w.WriteHeader(http.StatusNoContent)
}
// SECURE
r.Group(func(r chi.Router) {
r.Use(AuthMiddleware)
r.Use(AdminOnlyMiddleware)
r.Delete("/admin/users/{id}", deleteUser)
})
PHP — Laravel
// VULNERABLE: No auth middleware
Route::delete('/admin/users/{id}', [AdminController::class, 'destroy']);
// VULNERABLE: Auth but no role gate
Route::middleware('auth')->delete('/admin/users/{id}', [AdminController::class, 'destroy']);
// SECURE
Route::middleware(['auth', 'role:admin'])->delete('/admin/users/{id}', [AdminController::class, 'destroy']);
// SECURE (using Gate in controller)
public function destroy($id) {
Gate::authorize('admin-action');
User::findOrFail($id)->delete();
return response()->noContent();
}
C# — ASP.NET Core
// VULNERABLE: No authorization attribute
[HttpDelete("api/admin/users/{id}")]
public async Task<IActionResult> DeleteUser(int id) {
await _userService.DeleteAsync(id);
return NoContent();
}
// VULNERABLE: [Authorize] but no role
[Authorize]
[HttpDelete("api/admin/users/{id}")]
public async Task<IActionResult> DeleteUser(int id) {
await _userService.DeleteAsync(id);
return NoContent();
}
// SECURE
[Authorize(Roles = "Admin")]
[HttpDelete("api/admin/users/{id}")]
public async Task<IActionResult> DeleteUser(int id) {
await _userService.DeleteAsync(id);
return NoContent();
}
Execution
This skill runs in three phases using subagents. Pass the contents of sast/architecture.md to all subagents as context.
Phase 1: Recon — Map Endpoints and Permission System
Launch a subagent with the following instructions:
Goal: Build a complete map of (1) all application endpoints/routes and their current authentication/authorization posture, and (2) the role/permission system. Write results to
sast/missingauth-recon.md.Context: You will be given the project's architecture summary. Use it to understand the tech stack, frameworks, route definitions, and the auth/authz strategy.
What to search for:
- All route/endpoint definitions — collect every HTTP handler, REST endpoint, GraphQL mutation/query, RPC method, or WebSocket handler:
- Express/Koa:
router.get/post/put/delete/patch/use- Django:
urlpatterns,path(),re_path()- Flask:
@app.route,@blueprint.route- Rails:
routes.rb—get,post,resources,namespace- Spring:
@GetMapping,@PostMapping,@RequestMapping,@DeleteMapping,@PutMapping- Go/Chi:
r.Get,r.Post,r.Delete,r.Handle- Laravel:
Route::get/post/put/delete- FastAPI:
@router.get/post/put/delete- ASP.NET:
[HttpGet],[HttpPost],[HttpDelete],[HttpPut]- Authentication middleware and decorators currently applied:
- Identify the pattern used:
@login_required,authmiddleware,[Authorize],authenticate_user!, JWT verification middleware, session checks- Note which routes or route groups they are applied to
- Note any routes explicitly excluded from auth (e.g.,
except: [:index, :show])- Role/permission system — identify how roles are defined and checked:
- Role constants/enums:
ROLE_ADMIN,'admin',UserRole.ADMIN,is_staff,is_superuser- Permission decorators:
@admin_required,@roles_required,@PreAuthorize,requireRole()- Middleware:
AdminOnly,requireAdmin,role:admin- Policy/Gate/Ability objects:
Gate::define,Policy,CanCanCan,Pundit- In-handler checks:
if user.role != 'admin',if not current_user.is_admin- **Sensitive/privileged
Truncated for display — read the full file on GitHub.
Related Skills
ai-job-search
44.6kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
