Auth Review
Static security review for authentication and authorization vulnerabilities. Use when the user invokes /auth-review, asks to audit auth, find identity breaches, review access control, hunt for IDOR/BOLA, or check authorization. Framework- and vendor-agnostic. Enumerates every route/endpoint, builds an authorization matrix, applies a vulnerability catalog, and writes a triage report ready to turn into issues or PRs.
Works with: Claude Code (native) · Cursor, Codex CLI (manual)
native: this artifact type is that client's own format
Category: Other — see all ranked ›
Install (Claude Code):
cp -r auth-review ~/.claude/skills/- Adoption: 1 repos
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
source ↗ · skill:descope/auth-review
Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›
Measured 2026-08-03 · scorer s5 · how · something wrong here?