Skip to content
#

authorization-testing

Here are 9 public repositories matching this topic...

Language: All
Filter by language
overstep

Authorization testing for MCP servers; works on HTTP APIs too. Turns an access-control matrix into positive & negative tests that catch BOLA, BFLA, BOPLA, privilege escalation, token-audience and session-binding flaws across tools and resources — with CWE/OWASP-tagged SARIF for CI/CD.

  • Updated Aug 12, 2026
  • Python

ReqEye is a CLI assistant for HTTP request analysis, designed to help security researchers, bug bounty hunters, and pentesters identify high‑value entry points worth manual testing. It does not scan targets, send traffic, or claim vulnerabilities. ReqEye focuses on where to look, not on making assumptions.

  • Updated Mar 25, 2026
  • Python

A tool that detects unauthorized access vulnerabilities through passive proxies, leveraging mainstream AI systems such as Kimi, DeepSeek, GPT, and others,vulnerabilities, privilege-escalation, authorization-bypass, detects-access

  • Updated Aug 12, 2026
  • Go

A tool that detects unauthorized access vulnerabilities through passive proxies, leveraging mainstream AI systems such as Kimi, DeepSeek, GPT, and others,vulnerabilities, privilege-escalation, authorization-bypass, detects-access

  • Updated Jun 1, 2026
  • Go

MCP server for autonomous API logic penetration testing. AI-driven detection of OWASP API Top 10 vulnerabilities (BOLA/IDOR) via multi-session authorization comparison. Supports Bearer, Basic, API Key, Cookie auth. Generates Markdown security audit reports with evidence.

  • Updated Aug 12, 2026
  • Python

Improve this page

Add a description, image, and links to the authorization-testing topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the authorization-testing topic, visit your repo's landing page and select "manage topics."

Learn more