Security · inspect by default

/security-authz

Test access decisions and cross-user or cross-tenant exposure

Use for permission bypass inspection; backend-permissions implements an accepted access matrix, and security-fix repairs a confirmed bypass.

Make it your own.

In Claude Code, use the slash command and add your context. In Codex, select security-authz from the just-vibe skill picker, then send the same brief.

Version 0.11.0 also supports /jv security-authz, /just-vibe security-authz and /jv:security-authz in Claude. See shortcut setup and context examples.

Example · inspect
/just-vibe:security-authz Audit direct API access to another organization's records using isolated identities.
edge · inspect
/just-vibe:security-authz Audit an endpoint that hides buttons but accepts cross-tenant direct requests.
blocked · inspect
/just-vibe:security-authz Review source without real accounts or retrieving private records as proof.

What the agent does

  1. Trace policy checks at server and data boundaries.
  2. Design allowed and denied cases across direct IDs, alternate endpoints and methods, exports and background tasks, using synthetic identities.
  3. Execute only permitted isolated probes.

Inputs

  • access matrix, endpoints/resources, roles/tenants, and authorized test identities.

Optional context: scope, references, constraints, successCriteria, environment, mode, budget.

Scope

Reads
Authorization bypass, object ownership, privilege escalation, and cross-tenant access.
Writes
No source changes in inspect/plan. Save only requested planning artifacts. A separately requested repair uses the relevant implementation workflow.
Mode
Inspect; access matrix, endpoints/resources, roles/tenants, and authorized test identities.
Prerequisites
Defined application boundary, authorized code/environment, relevant trust/access rules, and evidence sources. Default to defensive inspection; active tests use owned or explicitly authorized isolated targets. Minimize sensitive evidence and never print usable credentials.

Expected output

  • Subject/action/resource cases, enforcement paths, evidence-backed findings with safe reproduction, and remediation or check proposals.

How the work is checked

  • Direct object references cannot bypass tenant policy; privileged and ordinary roles are tested distinctly.

When to stop or clarify

  • Do not use unauthorized real accounts or retrieve private records as proof. Missing policy prevents judging ambiguous access as a confirmed vulnerability.

Handling missing context

Infer
Resolve the requested surface, source/runtime version, reachable callers and actual trust/access boundaries.
Assume
Start with source analysis and bounded owned fixtures; treat scanner output as leads and preserve legitimate controls.
Ask
Ask when target authorization or necessary trust semantics are unresolved before active probing; source inspection need not wait for production access.

Technical guidance

Evidence
Inspect identity derivation, subject/action/resource rules, tenant filters and indirect entry points.
Method
Use the identity guide to trace object-level and function-level authorization, including mass assignment, exports and workers.
Pitfall
Authentication middleware proves identity, not ownership; an admin test can bypass the same controls being evaluated.
Check
Verify denied cross-user/cross-tenant requests cause no reads or writes and that legitimate access remains possible using isolated identities.

Situational decisions

When policy itself is unspecified: Separate demonstrated missing enforcement from an unresolved product permission decision.

The coding agent follows this workflow using its available tools. Installation does not grant service access or guarantee an outcome. Read the compatibility notes.

Keep exploring