The IDOR Agent (Insecure Direct Object Reference) is a specialist agent in BugTraceAI that detects and exploits IDOR vulnerabilities. It uses a WET→DRY two-phase pipeline with LLM-powered deduplication and optional deep exploitation analysis.
REST and GraphQL API testing — OpenAPI schema fuzzing, GraphQL introspection + abuse, verb tampering, mass assignment, rate-limit bypass. Triggered when recon found an OpenAPI / Swagger URL, a /graphql endpoint, or ID-bearing REST routes without those found.
Client-side vulnerability testing — reflected / stored XSS, CSRF, clickjacking, postMessage handlers, open redirect, DOM sinks. Use for any live web host with user-facing interactivity.
Performs ultra-granular per-function deep analysis for security audit context building. Use when analyzing dense functions, data-flow chains, cryptographic implementations, or state machines.