marketplace-rbac-audit
marketplace-rbac-audit is an code AI skill with a core value of Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions. It
helps developers solve real-world problems in the code domain, boosting
efficiency, automating repetitive tasks, and optimizing workflows.
Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions.
Quick Facts
mkdir -p ./skills/marketplace-rbac-audit && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/marketplace-rbac-audit/SKILL.md -o ./skills/marketplace-rbac-audit/SKILL.md Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).
Skill Content
# Marketplace RBAC Audit
Overview
Audit authorization in marketplaces where customers, vendors, fulfillment staff, couriers, support agents, administrators, and service accounts act on shared orders and resources. Build an explicit policy matrix, trace enforcement from route to data access, and verify both allowed and denied behavior without treating hidden UI controls as security.
This is a read-only review by default. It does not grant permission to scan a live service, create test accounts, alter permissions, or access another person's data.
When to Use This Skill
- Reviewing authorization in a marketplace, delivery platform, multi-vendor store, or fulfillment system.
- Adding or changing roles, administrative powers, ownership rules, or order-state transitions.
- Investigating whether one customer, vendor, courier, hub, or tenant can access another party's resources.
- Preparing negative authorization tests before release or after an access-control incident.
Do not use this skill for authentication design alone, generic multi-tenant architecture, offensive ID enumeration, or penetration testing outside an explicitly authorized test environment.
Establish the Authorization Contract
Record the actual actors and resources instead of assuming standard role names.
For each actor, capture:
- identity source and role-assignment authority;
- tenant, organization, store, hub, region, or assignment scope;
- resource relationships such as owner, seller, assigned courier, servicing hub, or support case;
- permitted operations and state transitions;
- emergency, support, delegated, and service-account access;
- audit-log and approval requirements for privileged actions.
Separate these policy dimensions:
1. **Role** — what this actor type may generally do.
2. **Relationship** — which specific object the actor may access.
3. **Tenant or operational scope** — where the permission applies.
4. **Resource state** — whether the operation is valid now.
5. **Field scope** — which attributes may be viewed or changed.
A matching role is not sufficient when ownership, assignment, tenant, state, or field rules fail.
Build the Policy Matrix
Create one row per meaningful actor-resource-operation combination.
| Field | Required content |
|---|---|
| Actor | Role plus relevant tenant/store/hub/assignment |
| Resource | Order, product, inventory, payout, address, profile, delivery, refund, or admin object |
| Operation | List, view, create, update, delete, assign, transition, refund, export, or impersonate |
| Relationship | Owner, seller, assignee, servicing hub, same tenant, or none |
| Required state | Order/payment/delivery state in which the operation is allowed |
| Field scope | Allowed and prohibited fields |
| Expected result | Allow or deny, including disclosure policy such as 403 versus 404 |
| Enforcement point | Route, policy layer, service, query predicate, database policy, or queue consumer |
| Evidence | Code reference, test ID, request ID, or audit event |
Mark an undocumented decision as **UNDEFINED**; do not invent a permission merely because current code allows it.
Audit Workflow
1. Inventory Entry Points
Map HTTP routes, GraphQL operations, server actions, background jobs, webhooks, file downloads, exports, administrative tools, and queue consumers that access marketplace resources. Include bulk operations and alternate HTTP methods.
2. Trace Identity and Scope
For every entry point, trace how the authenticated principal becomes an authorization context. Confirm that role, tenant, store, hub, assignment, and delegation claims come from a trusted server-side source and are current enough for the operation.
Do not accept actor, tenant, owner, vendor, hub, courier, price, payout, or privilege fields from the request merely because they are present in a signed-in session.
3. Trace Object Authorization
Follow the resource identifier from request to data access. Prefer a scoped query or a
🎯 Best For
- UI designers
- Product designers
- Claude users
- Software engineers
- Development teams
💡 Use Cases
- Generating component mockups
- Creating design system tokens
- Code quality improvement
- Best practice enforcement
📖 How to Use This Skill
- 1
Install the Skill
Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.
- 2
Load into Your AI Assistant
Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.
- 3
Apply marketplace-rbac-audit to Your Work
Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.
- 4
Review and Refine
Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.
❓ Frequently Asked Questions
Does this work with Figma?
Some design skills integrate with Figma plugins. Check the Works With section for supported tools.
Is marketplace-rbac-audit compatible with Cursor and VS Code?
Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.
Do I need specific dependencies for marketplace-rbac-audit?
Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.
How do I install marketplace-rbac-audit?
Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/marketplace-rbac-audit/SKILL.md, ready to use.
Can I customize this skill for my team?
Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.
⚠️ Common Mistakes to Avoid
Skipping usability testing
AI-generated designs should be validated with real users before development.
Skipping validation
Always test AI-generated code changes, even for simple refactors.
Missing dependency updates
Check if the skill requires updated dependencies or new packages.