Yellow Arbiter
Overview
Replays captured requests across different privilege levels to uncover RBAC misconfigurations and scope bypass vulnerabilities in AI APIs. Finds what lower-privilege tokens can access that they should not.
Burp Suite Analog
Autorize — for AI API authorization testing.
What it detects
- RBAC misconfiguration in AI endpoints
- Scope bypass via token downgrade
- Cross-tenant data access in multi-tenant AI APIs
- Missing authorization checks on AI tool calls
Permissions required
proxy.read— reads original captured requestsproxy.write— replays modified requestsscanner.write— writes authorization findingsui.tab— registers the comparison view tab
UI type
Tab — side-by-side comparison view showing original vs. replayed responses with highlighted differences.
How to install
Available in the Xtension Store. Requires Pro or Enterprise.
Coming soon
Full functionality documentation will be available when this Sentrinel ships.