Sstack Ownership Attacker — Data & AI agent for Claude Code
Ownership lens attacker.
How to install Sstack Ownership Attacker
Installs to ~/.claude/agents/mhenke-sstack-sstack-ownership-attacker.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mhenke/sstack/HEAD/agents/sstack-ownership-attacker.md -o ~/.claude/agents/mhenke-sstack-sstack-ownership-attacker.md Restart Claude Code, or start a new session, for it to be picked up.
What Sstack Ownership Attacker does
name: sstack-ownership-attacker description: "Ownership lens attacker. Attacks authorization decisions across function, data, and field level: BOLA/IDOR, BOPLA, deny-by-default, least privilege, permission-not-role checks, token/session integrity, header/IP bypasses, CORS/CSRF, cross-tenant, and intermediary delegation. Invoked as a subagent after the orchestrator writes the surface map. Rubric and Report format arrive inline in the dispatch."
Ownership attacker
You are a **subagent*
Alternatives in Data & AI
- Svelte Correctness Review — Reviews a feature segment in any SvelteKit app (apps/moderator, apps/auth, apps/creator-studio) for correctnes 7.2k ★
- Module Migration — Use this agent to create, review, or fix database migrations for LaraDashboard modules — handles table creatio 407 ★
- Reverse SQL Function Analyst — Spécialiste des FONCTIONS SQL (scalaires, inline, table) du reverse base de données 193 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Sstack State Attacker
State lens attacker. Attacks every mapped surface for stale cached reads, write-through to caller data, partia
MCP Integrator
Decides what tool or data access a task needs and how to wire it via MCP, preferring an existing server over a
Database Attacker
Delegates to this agent when the user wants database-specific offensive testing on an authorized target — SQL
Theme Discoverer
Finds at least 10 investment theme candidates inside one assigned sector, recording each theme's positive and
Sf Metadata Engineer
Implements declarative Salesforce metadata - custom objects and fields, permission sets, Flows, layouts, Flexi
Injection Attacker
インジェクション検出エージェント。静的解析でSQL/Command Injection脆弱性を検出。
Related Skills
API Security
API security audit (OWASP API Security Top 10 2023): BOLA/IDOR, broken authentication, broken object-property-
Hunt Access
Active IDOR / BOLA / BFLA / mass-assignment hunt for an ingested program. Consumes the webvuln-surface seeds +
Airlock
Runtime firewall for AI coding agents. Gate every tool, MCP and skill call against a least-privilege policy.