Skip to the card

Card 774 of 9852026-09-16 issue

Observed arrival · 2026-09-16

SickHaxx Tries to Break Your App’s Authorization Rules

sickhaxx.dev Observed source
Editorial interest 78/100 Selection signal · not a rating of the site

An automated security agent tests whether the right users can read, write, update, or delete the right records in AI-built web apps.

Landing page captured for the 2026-09-16 issue.

Field notes

SickHaxx models authorization as an executable contract: a team states who should read, write, update, or delete a resource, then the system tests those rules under several identities. The homepage’s sample finding is unusually concrete, identifying SUPA-005, a rental_applications record, and a 200 OK response when Bob reads Alice’s row. The site says later steps can send the affected policy, route, or configuration to a coding agent and replay the same exploit after a proposed fix.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

OpenPublic substance visible
PrettyNotable craft visible
ProPolished or operationally mature
NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Wiring Is Not Learning

428,563 arrived 1,000 judged 985 catalogued Enter the complete issue
sickhaxx.dev

Landing page observed 2026-09-16. The live site may have changed.