LogoClawIndex
CasesSkillsAbout
LogoClawIndex

exploiting-broken-function-level-authorization - Test APIs for broken function-level authorization

Tests APIs for broken function-level authorization by finding privileged endpoints and probing them with regular-user credentials.

Tags

Updated: 2026-10-01

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Discover administrative endpoints
  • Test role-based access
  • Switch HTTP methods
  • Tamper with parameters
  • Test API path variants
  • Identify privilege escalation

Inputs

  • Written authorization scope
  • Target API
  • Privilege-level accounts
  • API documentation
  • API request credentials

Outputs

  • Endpoint access results
  • Role-based access results
  • BFLA findings
  • Privilege escalation results

Requirements

  • Written authorization
  • Burp Suite Professional
  • Python 3.10 or later
  • Python requests library

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
API security
OWASP API5:2023
authorization
BFLA
access control
privilege escalation
Discover administrative endpoints
Test role-based access
Switch HTTP methods
Tamper with parameters
Written authorization scope
Target API
Privilege-level accounts
Endpoint access results
Role-based access results
BFLA findings