๐Ÿ”’
QualityJavaScript

Strix IDOR Test

by asdfgh1445

Strix IDOR Test is a Quality skill for Claude Code, published by asdfgh1445 in ctf-super-hub.

764 stars96 forkson asdfgh1445/ctf-super-hubAdded 2026/08/23+1% in starsRepository updated 2026/04/23
agent-skillsai-agentscodexcryptographyctfctf-toolsforensicsosintpwnreverse-engineeringweb-security
Install in seconds
Install Strix IDOR Test
Copy Strix IDOR Test into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/asdfgh1445/ctf-super-hub/tree/main/strix-idor ~/.claude/skills/strix-idor

Requires Node.js. Downloads this skill only โ€” not the rest of the repository โ€” into your Claude Code skills folder.

Without Node.js

git clone https://github.com/asdfgh1445/ctf-super-hub.git

Clones the whole repository, then copy the skillโ€™s own directory into your skills folder yourself.

In this catalog

Source file
strix-idor/SKILL.md in asdfgh1445/ctf-super-hub
Installs to
~/.claude/skills/strix-idor
Collection
One of 25 skills cataloged from this repository
Category
Quality โ€” 1354 skills

What Strix IDOR Test does

Strix IDOR Test is a manual for finding object-level authorization flaws (BOLA/IDOR) that allow cross-account data access and unauthorized state changes. Use it when testing APIs, web apps, GraphQL, microservices, and multi-tenant systems.

Strix IDOR Test is cataloged under Quality on DirSkills. Strix IDOR Test comes from a repository tagged agent-skills, ai-agents, codex, cryptography and ctf.

Documentation

README

IDOR

Object-level authorization failures (BOLA/IDOR) lead to cross-account data exposure and unauthorized state changes across APIs, web, mobile, and microservices. Treat every object reference as untrusted until proven bound to the caller.

Attack Surface

Scope

  • Horizontal access: access another subject's objects of the same type
  • Vertical access: access privileged objects/actions (admin-only, staff-only)
  • Cross-tenant access: break isolation boundaries in multi-tenant systems
  • Cross-service access: token or context accepted by the wrong service

Reference Locations

  • Paths, query params, JSON bodies, form-data, headers, cookies
  • JWT claims, GraphQL arguments, WebSocket messages, gRPC messages

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Strix IDOR Test

  • What else does asdfgh1445 publish alongside Strix IDOR Test?

    Strix IDOR Test is one of 25 skills that DirSkills catalogs from asdfgh1445/ctf-super-hub, the repository it ships in. Its siblings there include CTF AI/ML Attack Hub, CTF Binary Exploitation and CTF Challenge Triage. Each one is a separate skill with its own page in this directory, installs the same way Strix IDOR Test does, and is maintained by asdfgh1445 in that same repository. The rest of the collection is listed on the asdfgh1445/ctf-super-hub page.

  • How does Strix IDOR Test compare to other Quality skills?

    Strix IDOR Test ranks #1016 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Strix IDOR Test against them. Open each page to compare what they document and how they install.

More from asdfgh1445/ctf-super-hub

Strix IDOR Test is one of 25 skills cataloged on DirSkills from asdfgh1445/ctf-super-hub.

See all 25 skills โ†’
๐Ÿค–
1w ago

CTF AI/ML Attack Hub

CTF AI/ML Attack Hub collects techniques for adversarial examples, model extraction, prompt injection, membership inference, poisoning, LoRA abuse, and LLM jailbreaking. Use it when a challenge involves attacking or analyzing an AI or ML system.
AI Engineering
76496
๐Ÿ’ฅ
1w ago

CTF Binary Exploitation

CTF Binary Exploitation covers buffer overflows, format strings, heap exploitation, ROP, ret2libc, shellcode, seccomp bypass, and sandbox escape for pwn-style CTF challenges. Use it when solving binary exploitation tasks.
Quality
76496
๐Ÿ
1w ago

CTF Challenge Triage

CTF Challenge Triage classifies a CTF challenge, performs light initial triage, and routes it to the appropriate ctf-* skill. It can also act as the entry point when the category is already clear.
AI Engineering
76496
๐Ÿ”
1w ago

CTF Cryptography

CTF Cryptography provides quick references for cryptography and math-based CTF challenges, including RSA, AES, ECC, lattices, PRNGs, ZKP, and related attack patterns. Use it when solving crypto puzzles or checking which technique applies.
Quality
76496
๐Ÿ•ต๏ธ
1w ago

CTF Forensics

CTF Forensics covers disk images, memory dumps, logs, PCAPs, steganography, registry artifacts, audio signals, Docker images, coredumps, and deleted-file recovery for forensic CTF challenges. Use it when a puzzle requires extracting or reconstructing evidence from system and network artifacts.
Quality
76496
๐Ÿงช
1w ago

CTF Malware Analysis

CTF Malware Analysis helps analyze malicious-script, PE/.NET, shellcode, and C2 traffic challenges in CTFs. Use it when you need to deobfuscate payloads, extract configs, decode protocols, or spot anti-analysis tricks.
Quality
76496