Improper Inventory Management
rule → The reason shadowaudit exists. Undocumented routes, env-only endpoints, stale versions — HIGH + authed + undocumented → API9, INFO undocumented warnings → API9.
Coverage
Every shadowaudit finding maps to the OWASP API Security Top 10 (2023). Four categories are in the scanner today. Six are not. This page shows exactly which is which — the rules below are the real heuristics from our MIT-licensed source, not marketing copy.
Improper Inventory Management
rule → The reason shadowaudit exists. Undocumented routes, env-only endpoints, stale versions — HIGH + authed + undocumented → API9, INFO undocumented warnings → API9.
Broken Object Level Authorization
rule → CRITICAL or HIGH + no auth + GET → unauthenticated object access, flagged as BOLA.
Broken Authentication
rule → Per-route auth-state analysis — every finding carries auth: YES/NO. Routes with no auth middleware are the scanner’s primary signal.
Broken Function Level Authorization
rule → CRITICAL + no auth + POST/PUT/PATCH/DELETE → exposed admin function, flagged as BFLA.
Broken Object Property Level Authorization
Property-level exposure and mass assignment need response-schema analysis — beyond a static route inventory. Out of scope today — and we say so.
Unrestricted Resource Consumption
Rate limits and quotas are runtime behavior. A static analyzer can’t measure them. Out of scope today — and we say so.
Unrestricted Access to Sensitive Business Flows
Detecting abnormal business flows requires domain context about what “normal” means for your product. Out of scope today — and we say so.
Server Side Request Forgery
We inventory your routes; we don’t trace outbound requests to user-supplied URLs. Out of scope today — and we say so.
Security Misconfiguration
Headers, CORS policies, verbose errors — a different tool category than route auditing. Out of scope today — and we say so.
Unsafe Consumption of APIs
How your code trusts third-party APIs sits outside your own route inventory. Out of scope today — and we say so.
No security tool covers all ten. The ones that claim broad coverage do it with generic heuristics that flood you with false positives. We'd rather show the gaps than fake them.
Mapping source: src/utils/owasp.ts in the public repo — auditable, MIT licensed.