- Home
- Skills
- Agents & Orchestration
- Tenant Isolation Auditor
More screenshots
Works with the AI tools you already use
Tenant Isolation Auditor
Find tenant-scoping gaps in SaaS data access before they become cross-tenant exposure.
$24.99
Tenant Isolation Auditor
Example session with this skill installed
Audit this Flask + SQLAlchemy fragment for tenant-isolation failures. Assume a shared-schema model, tenant key tenant_id, and app-level WHERE enforcement. Review the invoice lookup, ticket-comment join, dashboard cache key, nightly usage job, raw report query, and the two supplied clean paths. Return the strict Tenant Isolation Audit contract with exact evidence and a scope-limited verdict.
- Read your context and instructions
- Compiled the tenant isolation auditor
- Generated the document
Tenant Isolation Audit
Model: shared-schema | Key: tenant_id | Enforcement: mixed app/ORM
Audited paths: 7 of 7 visible
| ID | Pattern | Tier | Location | Evidence |
|---|---|---|---|---|
| TI-001 | P1 Unscoped Read | CRITICAL | get_invoice | Invoice.query.filter_by(id=invoice_id) has no tenant_id predicate |
| TI-002 | P2 Join-Only Scoping | HIGH | get_ticket_comments | Tenant filtering appears only on Ticket; Comment has no restated tenant predicate |
| TI-003 | P3 Side-Channel Leak | HIGH | cache_dashboard_stats | Shared key dashboard:stats has no tenant component |
| TI-004 | P4 Background Escape | CRITICAL | nightly_usage_rollup | Invoice.query.all() processes all tenants outside an approved global workflow |
| TI-005 | P5 Enforcement Gap | CRITICAL | raw_report | Raw SQL reads invoices without tenant filter or a logged admin gate |
Clean paths: list_invoices is scoped by tenant_id; list_plans is a global-table candidate and must be confirmed against the model.
Tier counts: CRITICAL 3, HIGH 2, MEDIUM 0, LOW 0.
Posture verdict: BREACH-POSSIBLE — critical paths remain open in the audited fragment. This verdict covers only the seven visible paths.
Discriminating test: execute each risky path with two fixtures that share an object identifier but have different tenant_id values; assert that tenant A can never observe tenant B data or cache output. Convert list_plans to a confirmed allowlist entry only after schema and authorization evidence agree.
tenant-isolation-auditor.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Audit multi-tenant SaaS code against one hard invariant: every customer-data access path must be tenant-scoped at retrieval. Tenant Isolation Auditor reviews the code and configuration you supply, classifies five recurring leak patterns across ORM queries, joins, cache keys, background jobs, and raw access paths, then cites the exact evidence behind every finding.
You receive a structured audit with exposure tiers, explicit clean paths, global-table allowlist candidates, evidence gaps, and one discriminating test for unresolved cases. The package includes the full SKILL.md workflow, reference protocol, JSON-ready output contract, deterministic checker, worked sample, tests, and a six-page PDF buyer guide.
This is an evidence-bounded review tool. It does not access production, execute penetration tests, certify an entire application, or replace a professional security assessment.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install