LogoClawIndex
CasesSkillsAbout
LogoClawIndex

exploiting-broken-function-level-authorization - Test APIs for Broken Function Level Authorization

Tests APIs for BFLA by probing privileged endpoints with lower-privilege credentials and manipulating HTTP methods, paths, and parameters.

Tags

Updated: 2026-10-01
api-securityowaspauthorizationbflaprivilege-escalationaccess-control

Capabilities

Discover administrative endpointsTest role-based function accessManipulate HTTP methodsTest privilege-related parameters

Typical Inputs

Target APIWritten authorization scopePrivilege-level test accounts

Typical Outputs

Accessible endpoint recordsBFLA finding messagesHTTP response status records

What this skill does

  • Discover administrative endpoints
  • Test role-based function access
  • Manipulate HTTP methods
  • Test privilege-related parameters
  • Compare API version authorization

Inputs

  • Target API
  • Written authorization scope
  • Privilege-level test accounts
  • API documentation
  • Administrative endpoint list

Outputs

  • Accessible endpoint records
  • BFLA finding messages
  • HTTP response status records
  • Observed account role state

Requirements

  • Written authorization
  • Burp Suite Professional
  • Python 3.10 or later
  • Python requests library

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.