All skills
getsentry avatar

/django-access-review

@3482d8d official
by Sentrygetsentry/skills1k stars
53

Django access control and IDOR security review. Use when reviewing Django views, DRF viewsets, ORM queries, or any Python/Django code handling user authorization. Trigger keywords: "IDOR", "access control", "authorization", "Django permissions", "object permissions", "tenant isolation", "broken access".

Use this Skill: https://skilld.dev/gh/getsentry/skills/django-access-review

This session only. Nothing lands on disk.

referencesdjango-views.md

≈450 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Django Views - Context for Investigation

This is background context to help you understand Django authorization patterns when investigating. Not a checklist.

Where Authorization Can Happen

When tracing a request, check these layers:

URL conf → Middleware → View decorators → View class → Method → Query

URL-Level

# urls.py - decorators applied at routing
from django.contrib.admin.views.decorators import staff_member_required

urlpatterns = [
    path('admin/', staff_member_required(admin_view)),
]

Middleware

# settings.py MIDDLEWARE list
# Look for custom auth middleware that might set user context or enforce checks

View Decorators

@login_required
@permission_required('app.view_document')
@user_passes_test(lambda u: u.is_staff)

CBV Mixins

# Check the ENTIRE inheritance chain
class MyView(LoginRequiredMixin, PermissionRequiredMixin, DetailView):
    ...

# Also check for project-specific base classes
class MyView(BaseCompanyView, DetailView):
    # What does BaseCompanyView do?

View Methods

# get_queryset() - often where scoping happens
# get_object() - may have custom logic
# dispatch() - sometimes has permission checks

DRF-Specific Layers

# Permission classes - check what they actually do
permission_classes = [IsAuthenticated, IsOwner]

# get_queryset() - critical for scoping
def get_queryset(self):
    return Model.objects.filter(...)

# has_object_permission() - called by get_object()
def has_object_permission(self, request, view, obj):
    return obj.owner == request.user

Key Insight

has_object_permission() is only called when get_object() is called. List views don't trigger it - they need get_queryset() scoping.

Source: SKILL.md on GitHub

1 warning1d5 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    This skill is a security auditing tool for Django applications that uses search commands to identify access control vulnerabilities. It is safe for its intended use, although it has the inherent attack surface associated with reading and analyzing untrusted source code.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: LOW · No issues

  • Runlayer7mo

    2/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 3482d8d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 days ago
All 1 allowed tools
Read Grep Glob Bash Task
  • django
  • authorization
  • idor
  • access-control
  • security-review
  • permissions
  • drf
  • vulnerability-assessment

README badge

README badge for getsentry/skills/django-access-review

Reviews Django views, DRF viewsets, and ORM queries for access control vulnerabilities and IDOR flaws by tracing authorization enforcement mechanisms. Guides investigation through understanding the codebase's ownership model, mapping attack surface, and confirming gaps between resource IDs and permission checks rather than matching against preset patterns.

Generated from the current SKILL.md.

Does this skill work with Django REST Framework?
Yes. The skill is designed to review DRF viewsets, permission classes, and has_object_permission() implementations alongside Django views and custom authorization patterns.
What kinds of access control vulnerabilities does this skill find?
The skill focuses on IDOR (Insecure Direct Object Reference) and broken access control—situations where one user can access, modify, or delete another user's data by knowing or guessing an ID. It investigates query scoping, permission checks, and ownership enforcement.
Does this skill pattern-match for vulnerabilities or require investigation?
It requires investigation. The skill is designed to understand how authorization works in the specific codebase, trace data flows, and confirm gaps rather than scan for predefined vulnerable patterns.
What authorization models can this skill review?
It handles single-user ownership, organization/tenant ownership, hierarchical ownership structures, and role-based access within contexts. It works with decorators, middleware, base classes, DRF permission classes, custom managers, and manual checks.
Does this skill suggest fixes?
Yes, but only code-based fixes that actually enforce authorization. The skill does not accept documentation or comments as fixes and will not suggest them as mitigations.

Generated from the current SKILL.md. These answers refresh after source changes.