The action scans your codebase looking for unintended changes to authorization. This can happen in custom code, endpoints, guards, rbac, abac, policy-as-code files, etc. and can lead to broken access control or data exposure.
The scanner doesn't use LLMs and is blazing fast. The results show up as a comment on each pull request so you can maintain and improve authz for any volume of human and agentic coders.