- OpenAPI-driven detection of (collection, item) resource pairs.
- Multi-identity ownership discovery via list endpoints.
- Probes: BOLA, IDOR/enumeration, enumerable identifiers, missing authentication, existence oracle.
- Console / JSON / Markdown / JUnit reporters and a severity-thresholded exit code.
- Intentionally-vulnerable and secure demo ATS targets; end-to-end demo.
- Test suite, CI (3.10-3.12), Dockerfile/Compose, authorized-use guardrails.