CheckVibeCodeCheckVibeCode
Checks/Vulnerability
VulnerabilityRequires setup1 check

Tenant Isolation Scanner

Use two authenticated test actors to verify tenant-scoped resources cannot be read across accounts.

How this scan works

  • Genuinely needs two live test accounts on two different tenants, supplied by you
  • Accepts {actorA, actorB} credentials — without them the scan returns requires_setup
  • When supplied: authenticates as Actor A, records a resource ID, requests that same ID as Actor B, and flags any cross-tenant reads