All skills
getsentry avatar

/django-access-review

@3482d8d official
by Sentrygetsentry/skills1k stars
53

Django access control and IDOR security review. Use when reviewing Django views, DRF viewsets, ORM queries, or any Python/Django code handling user authorization. Trigger keywords: "IDOR", "access control", "authorization", "Django permissions", "object permissions", "tenant isolation", "broken access".

Use this Skill: https://skilld.dev/gh/getsentry/skills/django-access-review

This session only. Nothing lands on disk.

referencestenant-isolation.md

≈392 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Multi-Tenant Isolation - Context for Investigation

Background on multi-tenant architectures. Use this to understand the ownership model you're investigating.

Ownership Hierarchy

Most apps have layered ownership:

Organization/Tenant
    └── Team (optional)
        └── User
            └── Resource

Key question: At which level is authorization enforced?

Common Implementation Patterns

Tenant from Session

# User's current tenant stored in session/request
request.user.organization
request.user.current_tenant

Tenant from URL

# URL: /orgs/{org_id}/projects/
# Question: Is user verified as member of this org?

Automatic Scoping

# Middleware sets tenant context
# Manager auto-filters by current tenant
# All queries implicitly scoped

Questions When Investigating

  1. How is tenant determined?

    • From authenticated user's profile?
    • From URL parameter?
    • From request header?
  2. If from URL, is membership validated?

    • Can user access /orgs/999/ if they're not in org 999?
  3. Are all queries scoped to tenant?

    • Check for auto-scoping managers
    • Check for explicit tenant filters
  4. Can user switch context to another tenant?

    • If yes, is that switch validated?

The Core Multi-Tenant Question

"Can a user in Organization A access data belonging to Organization B?"

Trace the code to answer this. Check:

  • Where org context comes from
  • Whether membership is validated
  • Whether queries are scoped to that org

Source: SKILL.md on GitHub

1 warning1d5 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    This skill is a security auditing tool for Django applications that uses search commands to identify access control vulnerabilities. It is safe for its intended use, although it has the inherent attack surface associated with reading and analyzing untrusted source code.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: LOW · No issues

  • Runlayer7mo

    2/5 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 3482d8d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 days ago
All 1 allowed tools
Read Grep Glob Bash Task
  • django
  • authorization
  • idor
  • access-control
  • security-review
  • permissions
  • drf
  • vulnerability-assessment

README badge

README badge for getsentry/skills/django-access-review

Reviews Django views, DRF viewsets, and ORM queries for access control vulnerabilities and IDOR flaws by tracing authorization enforcement mechanisms. Guides investigation through understanding the codebase's ownership model, mapping attack surface, and confirming gaps between resource IDs and permission checks rather than matching against preset patterns.

Generated from the current SKILL.md.

Does this skill work with Django REST Framework?
Yes. The skill is designed to review DRF viewsets, permission classes, and has_object_permission() implementations alongside Django views and custom authorization patterns.
What kinds of access control vulnerabilities does this skill find?
The skill focuses on IDOR (Insecure Direct Object Reference) and broken access control—situations where one user can access, modify, or delete another user's data by knowing or guessing an ID. It investigates query scoping, permission checks, and ownership enforcement.
Does this skill pattern-match for vulnerabilities or require investigation?
It requires investigation. The skill is designed to understand how authorization works in the specific codebase, trace data flows, and confirm gaps rather than scan for predefined vulnerable patterns.
What authorization models can this skill review?
It handles single-user ownership, organization/tenant ownership, hierarchical ownership structures, and role-based access within contexts. It works with decorators, middleware, base classes, DRF permission classes, custom managers, and manual checks.
Does this skill suggest fixes?
Yes, but only code-based fixes that actually enforce authorization. The skill does not accept documentation or comments as fixes and will not suggest them as mitigations.

Generated from the current SKILL.md. These answers refresh after source changes.