bugsyhewitt/possession
Possession takes a valid authenticated request and wears its skin under other identities, roles, stripped auth, and corrupted tokens to see what still opens. It exposes weak access control—dragging IDORs, privilege escalation, and auth bypasses out of the dark.
GitHub repository with 6 stars and 0 forks.
Language: Go