Skip to content

feat(skill): tenant-aware-cache-key-review — reviews multi-tenant caches for tenant context omission and authorization bypass - #3070

Closed
Mystic-commits wants to merge 1 commit into
UnitOneAI:mainfrom
Mystic-commits:new-skill/tenant-aware-cache-key-review
Closed

Mystic-commits wants to merge 1 commit into
UnitOneAI:mainfrom
Mystic-commits:new-skill/tenant-aware-cache-key-review

Conversation

@Mystic-commits

@Mystic-commits Mystic-commits commented Sep 29, 2026 •

Copy link
Copy Markdown

What this PR does

Adds the dedicated tenant-aware-cache-key-review AppSec skill for multi-tenant applications and cache-backed APIs. Reviews caching layers (Redis, Memcached, DynamoDB DAX, in-memory caches, GraphQL DataLoaders, and shared CDN/edge caches) for tenant context omissions, authorization bypass on cache hit, cross-tenant cache pollution, and role/privilege leakage.

Linked approved issue (required for new skills)

Closes #3071
Closes #2416

Type of change

  • New skill
  • Improvement to an existing skill
  • Bug fix / documentation

Reproduction — independently runnable (required)

  • Public link to the full run: https://github.com/Mystic-commits/SecuritySkills/tree/new-skill/tenant-aware-cache-key-review/skills/appsec/tenant-aware-cache-key-review
  • Target codebase (public repo URL) at a pinned commit SHA: Mystic-commits/SecuritySkills@08c30d5c273a2185857300b4c6cd12593af1b4fa
  • Exact command / tool invocation used:
    ruby scripts/validate_skill_schema.rb skills/appsec/tenant-aware-cache-key-review/SKILL.md
    ruby scripts/validate_index.rb
    ruby scripts/test_skill_fixtures.rb
    ruby scripts/test_remediation_fixtures.rb
    ruby scripts/generate_quality_scorecard.rb --check
    ruby scripts/validate_framework_registry.rb
    ruby scripts/validate_codeowners.rb
    ruby scripts/validate_ci_cd_examples.rb
    git diff --check origin/main...HEAD

Discrimination evidence — true positive AND true negative (required)

  • True positive (vulnerable case it correctly flagged), with file:line:
    tests/fixtures/tenant-aware-cache-key-review/tenant-context-drop-vulnerable/routes.js:12 — correctly detects cacheKey = project:${projectId}; omitting tenantId and role, causing cross-tenant and privilege leakage (OWASP-API-Security-2023 API1/API3, CWE-639, CWE-863). Includes verified auto-fix regression diff in manifest.yaml.
  • True negative (safe case it correctly did NOT flag), with file:line:
    tests/fixtures/tenant-aware-cache-key-review/tenant-isolated-key-benign/routes.js:12 — correctly passes with 0 findings when cache key explicitly binds tenantId, projectId, and role with Cache-Control: private, no-store.

Framework grounding

  • Frameworks / control IDs used:
    • OWASP API Security Top 10 2023: API1:2023 (Broken Object Level Authorization), API3:2023 (Broken Object Property Level Authorization), API5:2023 (Broken Function Level Authorization), API8:2023 (Security Misconfiguration)
    • OWASP ASVS 4.0.3: V4.1 (General Access Control Design), V14.4 (HTTP Configuration Architecture)
    • CWE: CWE-639 (Authorization Bypass Through User-Controlled Key), CWE-863 (Incorrect Authorization), CWE-200 (Exposure of Sensitive Information), CWE-525 (Use of Web Browser Cache Containing Sensitive Information), CWE-613 (Insufficient Session Expiration)

Attestation & checklist

Anything else for a reviewer

  • Achieves a deterministic 5/5 readiness score and covered status in docs/quality-scorecard.md.
  • Full compliance with all repo validation gates: schema validation, index validation, fixture harness, remediation regression harness, framework registry, and CODEOWNERS.
  • Includes sibling references patterns.md (Node, Python, Go, GraphQL DataLoader, and Edge CDN rules) and checklist.md.
  • Clean diff with zero trailing whitespace errors (git diff --check passes).

…hes for tenant context omission and authorization bypass
@github-actions github-actions Bot added the needs-approved-issue PR has no linked maintainer-approved issue label Sep 29, 2026
@github-actions

Copy link
Copy Markdown

Thanks for the submission! 🙏 SecuritySkills is now issue-first: contributions need a linked issue that a maintainer has marked approved before a PR is opened.

Please open an issue describing the skill, wait for the approved label, then reopen this PR with Closes #<issue> in the description. The PR template lists everything we'll look for (including an independently runnable reproduction).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-approved-issue PR has no linked maintainer-approved issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[NEW SKILL] tenant-aware-cache-key-review [NEW SKILL] tenant-aware-cache-key-review

1 participant