What it does
The skill helps an authorized reviewer map actors, resources, actions, policy inputs, enforcement points, and lifecycle events before reporting access-control weaknesses with evidence.
Maps people, services, agents, resources, actions, and security boundaries.
Checks object, function, field, organization, ownership, sharing, and administrative access.
Separates verified weaknesses from design concerns and unanswered policy questions.
Explains Role-Based, Attribute-Based, and Relationship-Based Access Control in context.
When to use it
- 01You are authorized to review a web application or API.
- 02You need a permission map or authorization threat model.
- 03You want to investigate IDOR, BOLA, privilege escalation, or organization-isolation risks.
- 04You want to connect an IAM lab or implementation to vendor-neutral IAM concepts.
What you receive
An evidence-based access-control review.
A permission map across actors, actions, resources, and conditions.
Clear policy questions when expected behavior is missing.
Durable correction guidance and denied-path regression tests.
A verification plan for important authorization boundaries.
It is working if
Every conclusion identifies the actor, action, resource, and evidence.
The review distinguishes authentication from authorization.
Unknown business rules remain policy questions instead of invented vulnerabilities.
The result includes allowed and denied verification cases.
Read the source
The complete instructions are public. Read the skill before you install it, adapt it for your agent if needed, and report issues in the repository.
Open /review-access-control on GitHub