alice retrieved bob's document (doc_2001), response carried the victim's unique data.
Is your app one guessed ID
away from a breach?
Change one number in a URL and you could be reading another user's data. That's IDOR, and it hides in almost every fast-built app. Argus is an autonomous agent that hunts it and proves each finding with a real exploit, run in an isolated sandbox. No maybes: confirmed with evidence, or rejected.
$ pip install argus-idor $ argus scan --provider <provider> # gemini, deepseek, or openai $ argus eval # the benchmark · no key
Works with DeepSeek, OpenAI, or Gemini (free flash tier). Runs locally against a target you authorize, in a sandbox that can reach nothing else.
Benchmarked across 2 target apps: saas (12) · clinic (36). 24 real IDORs confirmed, 24 decoys rejected, 0 false positives.
Watch it work
0/39 stepsConfirmed exploits
6 in this run · with proofbob retrieved alice's document (doc_1001), response carried the victim's unique data.
alice retrieved bob's invoice (inv_2001), response carried the victim's unique data.
bob retrieved alice's invoice (inv_1001), response carried the victim's unique data.
alice retrieved bob's message (msg_2001), response carried the victim's unique data.
bob retrieved alice's message (msg_1001), response carried the victim's unique data.
Rejected · false positives
6 in this run · access heldaccess denied (HTTP 403); access control held.
access denied (HTTP 403); access control held.
access denied (HTTP 403); access control held.
access denied (HTTP 403); access control held.
access denied (HTTP 403); access control held.
access denied (HTTP 403); access control held.