🔐
QualityJavaScript

Strix•功能级授权缺陷

by asdfgh1445

Strix•功能级授权缺陷 is a Quality skill for Claude Code, published by asdfgh1445 in ctf-super-hub.

764 stars96 forkson asdfgh1445/ctf-super-hubAdded 2026/08/23+1% in starsRepository updated 2026/04/23
agent-skillsai-agentscodexcryptographyctfctf-toolsforensicsosintpwnreverse-engineeringweb-security
Install in seconds
Install Strix•功能级授权缺陷
Copy Strix•功能级授权缺陷 into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/asdfgh1445/ctf-super-hub/tree/main/strix-broken-function-level-authorization ~/.claude/skills/strix-broken-function-level-authorization

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/asdfgh1445/ctf-super-hub.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
strix-broken-function-level-authorization/SKILL.md in asdfgh1445/ctf-super-hub
Installs to
~/.claude/skills/strix-broken-function-level-authorization
Collection
One of 25 skills cataloged from this repository
Category
Quality1354 skills

What Strix•功能级授权缺陷 does

Strix•功能级授权缺陷 is a testing manual for broken function-level authorization, covering privilege bypass, admin-only actions, and API drift. Use it to verify whether restricted actions can be invoked across different transports and encodings.

Strix•功能级授权缺陷 is cataloged under Quality on DirSkills. Strix•功能级授权缺陷 comes from a repository tagged agent-skills, ai-agents, codex, cryptography and ctf.

Documentation

README

Broken Function Level Authorization (BFLA)

BFLA is action-level authorization failure: callers invoke functions (endpoints, mutations, admin tools) they are not entitled to. It appears when enforcement differs across transports, gateways, roles, or when services trust client hints. Bind subject × action at the service that performs the action.

Attack Surface

  • Vertical authz: privileged/admin/staff-only actions reachable by basic users
  • Feature gates: toggles enforced at edge/UI, not at core services
  • Transport drift: REST vs GraphQL vs gRPC vs WebSocket with inconsistent checks
  • Gateway trust: backends trust X-User-Id/X-Role injected by proxies/edges
  • Background workers/jobs performing actions without re-checking authz

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Strix•功能级授权缺陷

  • What else does asdfgh1445 publish alongside Strix•功能级授权缺陷?

    Strix•功能级授权缺陷 is one of 25 skills that DirSkills catalogs from asdfgh1445/ctf-super-hub, the repository it ships in. Its siblings there include CTF AI/ML Attack Hub, CTF Binary Exploitation and CTF Challenge Triage. Each one is a separate skill with its own page in this directory, installs the same way Strix•功能级授权缺陷 does, and is maintained by asdfgh1445 in that same repository. The rest of the collection is listed on the asdfgh1445/ctf-super-hub page.

  • How does Strix•功能级授权缺陷 compare to other Quality skills?

    Strix•功能级授权缺陷 ranks #1012 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Strix•功能级授权缺陷 against them. Open each page to compare what they document and how they install.

More from asdfgh1445/ctf-super-hub

Strix•功能级授权缺陷 is one of 25 skills cataloged on DirSkills from asdfgh1445/ctf-super-hub.

See all 25 skills
🤖
1w ago

CTF AI/ML Attack Hub

CTF AI/ML Attack Hub collects techniques for adversarial examples, model extraction, prompt injection, membership inference, poisoning, LoRA abuse, and LLM jailbreaking. Use it when a challenge involves attacking or analyzing an AI or ML system.
AI Engineering
76496
💥
1w ago

CTF Binary Exploitation

CTF Binary Exploitation covers buffer overflows, format strings, heap exploitation, ROP, ret2libc, shellcode, seccomp bypass, and sandbox escape for pwn-style CTF challenges. Use it when solving binary exploitation tasks.
Quality
76496
🏁
1w ago

CTF Challenge Triage

CTF Challenge Triage classifies a CTF challenge, performs light initial triage, and routes it to the appropriate ctf-* skill. It can also act as the entry point when the category is already clear.
AI Engineering
76496
🔐
1w ago

CTF Cryptography

CTF Cryptography provides quick references for cryptography and math-based CTF challenges, including RSA, AES, ECC, lattices, PRNGs, ZKP, and related attack patterns. Use it when solving crypto puzzles or checking which technique applies.
Quality
76496
🕵️
1w ago

CTF Forensics

CTF Forensics covers disk images, memory dumps, logs, PCAPs, steganography, registry artifacts, audio signals, Docker images, coredumps, and deleted-file recovery for forensic CTF challenges. Use it when a puzzle requires extracting or reconstructing evidence from system and network artifacts.
Quality
76496
🧪
1w ago

CTF Malware Analysis

CTF Malware Analysis helps analyze malicious-script, PE/.NET, shellcode, and C2 traffic challenges in CTFs. Use it when you need to deobfuscate payloads, extract configs, decode protocols, or spot anti-analysis tricks.
Quality
76496