4.5 KiB
| lens | cli_aliases | status | summary | primary_skill | supported_skills | severity | ranking | scope_disclaimer | required_artifacts | optional_artifacts | required_context | optional_context | allowed_evidence_kinds | on_missing_required_evidence | invocation_triggers | evidence_threshold | materiality_threshold | escalation_policy | autofix_policy | safety_directive | ||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| insider-abuse |
|
READY | Finds where legitimate internal authority can be converted into an unauthorized outcome without timely attribution or detection. |
|
|
|
blast radius multiplied by detection failure and ease of abuse | Defensive controls review. It does not provide procedural exploit instructions or replace a full insider-threat assessment. |
|
|
|
|
|
INSUFFICIENT_EVIDENCE |
|
STRONG_OR_MODERATE | MATERIAL_OR_BLOCKING | ADVISORY_PLUS_MATERIAL | ask_always | Describe abuse conditions, missing controls, and detection gaps. Do not provide procedural exploit steps, credential-theft methods, evasion techniques, or data-exfiltration instructions. |
==== LENS PROMPT START | INSIDER ABUSE ====
When I use this lens
I use this lens when a change affects administrative or support tooling, user impersonation, privileged data access, sensitive exports, permission changes, service accounts, secrets, financial actions, destructive actions, production access, audit records, approval workflows, maintenance paths, or emergency access.
I generally do not use it for a public read-only path with no sensitive data, privileged authority, or internal control surface.
Objective
I want the evidence reviewed for one question:
Where can an employee, contractor, administrator, support operator, developer, service account, or compromised internal identity convert legitimate authority into an unauthorized outcome without timely prevention, detection, attribution, or recovery?
This is a defensive controls review. It is not a general external-attacker review and it must not become an exploitation guide.
Search strategy
Look for:
- Privileges broader than the role requires
- Administrative actions without durable, tamper-resistant audit records
- Sensitive exports without approval, reason codes, rate limits, watermarking, or attribution
- Support tools that impersonate users or mutate user state without traceability
- Authorization derived from client-controlled state, headers, request parameters, or mutable metadata
- Missing separation of duties for destructive, financial, identity, or high-impact actions
- Debug, maintenance, migration, or emergency paths that can survive into production
- Data-access paths that bypass the normal authorization layer
- Sensitive actions without reauthentication, secondary approval, or bounded delegation
- Broad service-account permissions with weak ownership, rotation, or review
- Audit records that a privileged actor can modify, suppress, or route around
- Controls designed for external attackers that assume internal identities are trustworthy
- Recovery mechanisms that restore the service but cannot reconstruct responsibility
- Abuse that would be visible only through ad hoc log correlation rather than an explicit control signal
A valid finding must identify:
- The legitimate authority that exists
- The unauthorized outcome that authority can enable
- The affected asset or decision
- Why prevention, detection, attribution, or recovery is insufficient
- The smallest control that materially reduces the risk
Lens-specific output fields
For each finding, middle_fields must contain:
existing_authorityabuse_scenarioblast_radiusdetection_riskcontrol_gap
Use one of these severities:
INSIDER_ABUSE_RISKPRIVILEGE_ESCALATIONAUDIT_GAPDATA_EXPOSUREAPPROVAL_GAP
Rank by blast radius, likelihood of detection failure, and ease of abuse.
==== LENS PROMPT END | INSIDER ABUSE ====