LogoClawIndex
CasesSkillsAbout
LogoClawIndex

exploiting-broken-function-level-authorization - Test APIs for Broken Function Level Authorization

Tests APIs for BFLA by checking whether lower-privileged users can invoke administrative functions or access privileged endpoints.

Tags

Updated: 2026-10-01
api-securityowaspauthorizationbflaprivilege-escalationaccess-control

Capabilities

Discover administrative endpointsCompare role-based accessTest HTTP method authorizationTest parameter-based escalation

Typical Inputs

Target APIAuthorization scopePrivilege-level test accounts

Typical Outputs

Accessible endpoint resultsBFLA findingsHTTP response statuses

What this skill does

  • Discover administrative endpoints
  • Compare role-based access
  • Test HTTP method authorization
  • Test parameter-based escalation
  • Check API access controls

Inputs

  • Target API
  • Authorization scope
  • Privilege-level test accounts
  • API documentation
  • Authentication tokens

Outputs

  • Accessible endpoint results
  • BFLA findings
  • HTTP response statuses
  • Role access comparisons
  • Observed privilege changes

Requirements

  • Written authorization
  • Burp Suite Professional
  • Python 3.10 or later
  • Python requests library

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.