AUTH BOUNDARY AUDIT
PAPA PARSE 5.4.1 / LOCAL

What did the scanner miss?

Reconcile automated findings with cross-user probes. A CVE count is not authorization coverage; the boundary is the evidence.

EVIDENCE CSV11 required columns

Use synthetic IDs only. Blank observed_status means the boundary was not executed.

Representative evidence is ready.

Scanner findings and authorization proof are different evidence.

Run the audit to separate known-CVE records, manual boundary outcomes, exposed fields, and missing execution evidence.

Interpretation

A cross-user request that should deny access but returns a 2xx response is classified as a bypass. A scanner finding remains separate evidence; its presence cannot close an untested authorization boundary.

Evidence boundary

This local tool does not scan a live app or prove exploitability, CVE validity, identity, session behavior, business impact, or remediation. Confirm every result in an authorized test environment.

Super generates helpful tools and automates fact-checking across the internet proactively. If you enjoyed this tool, build your own with Super and share it with a friend.