# Improper Access Control (CWE-284) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. **Stack:** Go - Prevalence: Alta Frecuentemente explotada - Impact: Alto 3 reglas de severidad alta - Prevention: Documentada 4 ejemplos de corrección **OWASP:** Broken Access Control (A01:2021-Broken Access Control) - #1 ## Description Access control involves determining which subjects can access which objects. When access control is implemented incorrectly, it can lead to unauthorized access to sensitive data or functionality. ## Prevention Estrategias de prevención para Improper Access Control basadas en 1 reglas de detección de Shoulder. ### Go Validate tool inputs against strict schemas and use an allowlist for permitted tools ## Warning Signs - [HIGH] Insecure plugin implementation: ... - [HIGH] insecure plugin/function calling implementations in AI/LLM systems without proper validation ## Consequences - Leer datos de la aplicación - Modificar datos de la aplicación - Ejecutar código no autorizado - Obtener privilegios ## Mitigations - Implementa comprobaciones adecuadas de control de acceso en todos los recursos - Aplica el principio de mínimo privilegio - Aplica los controles de acceso del lado del servidor, no solo en la UI ## Detection - Total rules: 4 - Languages: go, javascript, typescript, kubernetes, yaml, python ## Rules by Language ### Go (1 rules) - **LLM Insecure Plugin Design** [HIGH]: Detects insecure plugin/function calling implementations in AI/LLM systems without proper validation. - Remediation: Validate tool inputs against strict schemas and use an allowlist for permitted tools. ```go if _, ok := toolRegistry[toolCall.Name]; !ok { return errors.New("unknown tool") } ``` Learn more: https://shoulder.dev/learn/go/cwe-284/llm-insecure-plugin