MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

marketplace-rbac-audit

marketplace-rbac-audit is an code AI skill with a core value of Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Audit multi-role marketplace authorization across roles, resource ownership, tenant boundaries, and order-state transitions; use when access rules need evidence, not UI assumptions.

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/marketplace-rbac-audit && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/marketplace-rbac-audit/SKILL.md -o ./skills/marketplace-rbac-audit/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

# Marketplace RBAC Audit


Overview


Audit authorization in marketplaces where customers, vendors, fulfillment staff, couriers, support agents, administrators, and service accounts act on shared orders and resources. Build an explicit policy matrix, trace enforcement from route to data access, and verify both allowed and denied behavior without treating hidden UI controls as security.


This is a read-only review by default. It does not grant permission to scan a live service, create test accounts, alter permissions, or access another person's data.


When to Use This Skill


- Reviewing authorization in a marketplace, delivery platform, multi-vendor store, or fulfillment system.

- Adding or changing roles, administrative powers, ownership rules, or order-state transitions.

- Investigating whether one customer, vendor, courier, hub, or tenant can access another party's resources.

- Preparing negative authorization tests before release or after an access-control incident.


Do not use this skill for authentication design alone, generic multi-tenant architecture, offensive ID enumeration, or penetration testing outside an explicitly authorized test environment.


Establish the Authorization Contract


Record the actual actors and resources instead of assuming standard role names.


For each actor, capture:


- identity source and role-assignment authority;

- tenant, organization, store, hub, region, or assignment scope;

- resource relationships such as owner, seller, assigned courier, servicing hub, or support case;

- permitted operations and state transitions;

- emergency, support, delegated, and service-account access;

- audit-log and approval requirements for privileged actions.


Separate these policy dimensions:


1. **Role** — what this actor type may generally do.

2. **Relationship** — which specific object the actor may access.

3. **Tenant or operational scope** — where the permission applies.

4. **Resource state** — whether the operation is valid now.

5. **Field scope** — which attributes may be viewed or changed.


A matching role is not sufficient when ownership, assignment, tenant, state, or field rules fail.


Build the Policy Matrix


Create one row per meaningful actor-resource-operation combination.


| Field | Required content |

|---|---|

| Actor | Role plus relevant tenant/store/hub/assignment |

| Resource | Order, product, inventory, payout, address, profile, delivery, refund, or admin object |

| Operation | List, view, create, update, delete, assign, transition, refund, export, or impersonate |

| Relationship | Owner, seller, assignee, servicing hub, same tenant, or none |

| Required state | Order/payment/delivery state in which the operation is allowed |

| Field scope | Allowed and prohibited fields |

| Expected result | Allow or deny, including disclosure policy such as 403 versus 404 |

| Enforcement point | Route, policy layer, service, query predicate, database policy, or queue consumer |

| Evidence | Code reference, test ID, request ID, or audit event |


Mark an undocumented decision as **UNDEFINED**; do not invent a permission merely because current code allows it.


Audit Workflow


1. Inventory Entry Points


Map HTTP routes, GraphQL operations, server actions, background jobs, webhooks, file downloads, exports, administrative tools, and queue consumers that access marketplace resources. Include bulk operations and alternate HTTP methods.


2. Trace Identity and Scope


For every entry point, trace how the authenticated principal becomes an authorization context. Confirm that role, tenant, store, hub, assignment, and delegation claims come from a trusted server-side source and are current enough for the operation.


Do not accept actor, tenant, owner, vendor, hub, courier, price, payout, or privilege fields from the request merely because they are present in a signed-in session.


3. Trace Object Authorization


Follow the resource identifier from request to data access. Prefer a scoped query or a

🎯 Best For

  • UI designers
  • Product designers
  • Claude users
  • Software engineers
  • Development teams

💡 Use Cases

  • Generating component mockups
  • Creating design system tokens
  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply marketplace-rbac-audit to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Does this work with Figma?

Some design skills integrate with Figma plugins. Check the Works With section for supported tools.

Is marketplace-rbac-audit compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for marketplace-rbac-audit?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install marketplace-rbac-audit?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/marketplace-rbac-audit/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Skipping usability testing

AI-generated designs should be validated with real users before development.

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills