Authorization & Access Control Testing
When Invoked
The user runs /vapt authz <url> or this skill is triggered as part of Wave 3 during /vapt audit.
Prerequisites
This is the most manual testing category. It requires understanding the application's roles and resources. Check for existing context:
- If
VAPT-WAVE2-CONTEXT.mdexists -> use discovered endpoints - If
VAPT-AUTH.mdexists -> use authentication details and session tokens - If no context -> discover endpoints and atte
[Description truncada. Veja o README completo no GitHub.]