Review agent · Identity & access
Access control & authorization
Checks that each sensitive action is authorized for the specific object, not just a logged-in user.
Illustrative example of how this agent reviews a finding.
Why this agent matters
Broken access control is number one in the OWASP Top 10 (A01), and broken object-level authorization (IDOR) tops the OWASP API Security Top 10. It is how one customer reads another customer's data.
Scanners struggle here because the bug is an absence — a missing ownership check. This agent reads the handler and asks whether the action is scoped to the current user or tenant, and calls out mass-assignment of protected fields.
What it checks
- Object IDs from the request used without an ownership or tenant check
- Missing role checks on privileged operations
- Mass-assignment that lets clients set protected fields
- Authorization bypass through user-controlled keys
When it marks a finding as a likely false positive
- An explicit check scopes the action to the current user or tenant
The fix it suggests
- A per-object authorization check on every sensitive route
- Allow-listing writable fields
- Centralizing tenant scoping in a shared layer
Scope and limits
This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.
Common questions
Can static analysis find IDOR?
Partly. Scanners flag suspicious patterns; this agent reviews the surrounding handler to judge whether an ownership check is present, and says so in plain English.
Related agents
- Authentication & JWT — Checks that identity, tokens and sessions are actually verified and hardened.
- Directory & LDAP integration — Reviews Active Directory and LDAP code for injection, cleartext binds and hard-coded credentials.
See all 20 review agents → · Agent setup reviewer · How the pipeline works
Run the Access control & authorization agent on your repository
100 free credits, no credit card. Every finding comes with a verdict and a fix.
Get started free